• —
  • —
  • —
  • —
  • —
Germinate
  • Our Work
  • Services

    Applied AI

    Our Process

    Define & Design

  • About
  • Blog
  • Contact
  • Get Started
  • Our Work
  • Services
  • About
  • Blog
  • Contact
  • Get Started

Back

Applied AI

Our Process

Define & Design

Privacy Policy

Germinate, LLC

Last updated: August 25th, 2026


1. About this policy

Germinate, LLC (“Germinate,” “we,” “us”) is an Oregon limited liability company that builds custom software and operates managed hosting environments for its clients.

This policy covers only this website — germinateapps.com. It describes the limited information we collect from visitors to our own site.

Two things this policy does not cover:

  • Applications we host or build for clients. If you are a user of an application that Germinate hosts or developed, this policy does not govern that application. The company that operates that application decides what data it collects and why, and its own privacy policy applies. See Section 8.
  • Data our clients entrust to us. When we process data on a client's behalf, we do so under a written agreement with that client, not under this policy. See Section 8.

An easy way to tell which policy applies to you: every application we host is served from its operator's own domain, never from a germinateapps.com address. If the site you are using is not germinateapps.com, this policy is not the one that governs it — look for the privacy policy published by the company whose name is on that site.


2. The two roles we play

Privacy laws distinguish between the party that decides why data is collected and the party that merely handles data on someone else's instructions. Germinate occupies both positions, in different contexts, and keeping them apart matters:

Context Our role Whose policy applies
Visitors to germinateapps.com; prospective clients who contact us; job applicants; our own vendors and personnel Controller — we decide the purpose This policy
Data inside applications we host, maintain, or develop for clients Processor / service provider — we act on the client's documented instructions That client's privacy policy

Where we act as a processor, we do not use client data for our own purposes, and we do not decide what is collected, how long it is kept, or who may access it. Those decisions belong to our client.


3. Information we collect on this website

We collect only what you send us:

Information you provide directly. If you fill in a contact form, email us, or call us, we receive what you choose to include — typically your name, email address, phone number, company name, and a description of what you need. If you apply for a role with us, we receive the contents of your application.

Server and delivery logs. Our web infrastructure records standard technical information for each request: IP address, the date and time, the page requested, the referring page, and basic browser and operating system details. These logs exist to keep the site working and to detect abuse.

We do not collect payment information through this website. Client invoicing and payment are handled through QuickBooks, our accounting and payment platform. Paying clients enter their payment details directly with that platform, and Germinate never receives, handles, stores, or transmits payment card numbers or bank account credentials.

We do not ask for sensitive categories of personal information on this website — no government identifiers, no financial account numbers, no health information, no precise geolocation, no biometric data.


4. Cookies, analytics, and tracking

This website does not set cookies, and we do not run third-party analytics, advertising pixels, or session-recording tools on it.

We do not track visitors across other websites or services. We do not build advertising profiles. There is no cross-context behavioral advertising associated with this site.

Do Not Track and Global Privacy Control

Because we do not track visitors across sites and do not sell or share personal information, there is no cross-site tracking here for a browser signal to switch off. We nonetheless honor the Global Privacy Control (GPC) signal where it applies to any future processing that would require it. Browser Do Not Track signals are not standardized and we do not respond to them separately.


5. How we use website information

We use the information described in Section 3 to:

  • respond to your inquiry and communicate with you about your request;
  • provide, secure, maintain, and improve this website;
  • evaluate your application if you have applied for a role;
  • send you information about our services where you have asked for it, or where we have a legitimate interest in contacting you in a business capacity — you can opt out of these at any time;
  • keep business records, prepare invoices, and meet our accounting, tax, and insurance obligations;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service; and
  • comply with the law and enforce or defend our legal rights.

Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract or steps preparatory to one (responding to your inquiry); legitimate interests (site security, business communications, record-keeping, fraud prevention); consent where we ask for it; and legal obligation where a law requires the processing.


6. When we disclose information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding twelve months.

We disclose website information only in these circumstances:

Service providers. A small number of vendors process information on our behalf under contracts that restrict them to that purpose — our email and productivity provider, our cloud infrastructure provider, and our accounting, invoicing, and payment platform (QuickBooks). They may not use the information for their own purposes.

Legal requirements. We disclose information where we are required to by law, subpoena, court order, or other valid legal process, or where disclosure is necessary to protect our rights, our safety, or the safety of others. Where we are legally permitted to notify you first, we will.

Business transfers. If Germinate is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require the receiving party to honor commitments in this policy, and we will post notice here if the transaction materially changes how information is handled.

We do not disclose website visitor information to any company we host or develop software for. Those are separate, independent businesses — see Section 9.


7. Protected health information

Some applications Germinate hosts are operated by clients who are subject to the Health Insurance Portability and Accountability Act (HIPAA). Where a hosted environment contains protected health information (PHI):

  • Germinate handles that PHI solely as a business associate or subcontractor under an executed Business Associate Agreement, and only to the extent needed to provide the hosting, maintenance, and support services our client has engaged us for.
  • This privacy policy does not govern that PHI. The Notice of Privacy Practices issued by the covered entity — the healthcare provider or health plan whose patients or members the data concerns — governs it, together with the applicable Business Associate Agreements.
  • Germinate does not use or disclose PHI for its own purposes, does not use it for marketing, and does not sell it.

If you are a patient, client, or member and you want to see, correct, or ask questions about your health information, contact the provider organization that serves you. We cannot act on those requests directly, because we are not the party that holds the relationship with you and, in most cases, we are contractually prohibited from responding. If you contact us, we will refer you to the right party without acting on the request ourselves.


8. Applications we host and client data

Germinate operates managed hosting environments and builds custom software. In both cases, the data inside those systems belongs to our client's relationship with its own users, not to ours.

For that data:

  • our client determines what is collected, why, how long it is retained, and who may access it;
  • we process it only on our client's documented instructions, under a Master Services Agreement and Data Processing Agreement, and under a Business Associate Agreement where PHI is involved;
  • we treat it as confidential and restrict access to personnel who need it to deliver the service; and
  • we do not use it to develop our own products, to train models, or for any purpose beyond delivering the contracted service.

Every application we host runs on its operator's own domain, not on germinateapps.com. If the application you are using is reached at some other company's web address, that company operates it and its privacy policy governs your use of it.

If you are a user of an application Germinate hosts and you want to exercise a privacy right — access, correction, deletion, portability, or objection — please direct your request to the company that operates that application. They are the controller and only they can act on it. If you send the request to us, we will pass it to the relevant client and tell you we have done so, but we cannot decide it ourselves.


9. The companies we host for

Germinate provides hosting, infrastructure, development, and support services to many companies. Each of them is a separate, independent business. Being hosted by Germinate does not make a company our subsidiary, our parent, our affiliate, or a partner of any other company we host.

Each of those companies owns its own product, holds its own relationship with its own users, and publishes its own privacy policy. That policy — not this one — governs the product it operates.

Our commitments across all of them are the same:

  • we act as each client's service provider, processing data only on that client's instructions;
  • client environments are logically separated from one another;
  • we do not pool data across clients, and we do not access one client's data for another client's benefit or for our own; and
  • we do not use any client's data to develop our own products or to train models.

We do not publish our client list here. Individual clients may identify Germinate as their hosting or development provider in their own privacy policies or security documentation, and they are free to do so.


10. How long we keep information

Category Retention
Inquiries and correspondence that do not become client relationships 24 months from last contact, then deleted
Client and prospect records supporting an active or past engagement Duration of the engagement plus 10 years, to meet contract, tax, and limitations-period requirements
Job applications 12 months from decision, unless you ask us to keep them longer
Server and delivery logs 90 days, then deleted or aggregated
Accounting and invoicing records As required by tax and accounting law, generally 10 years

Where a longer retention period is required by law, or where information is subject to a legal hold, we keep it until that obligation ends.


11. How we protect information

Germinate operates its hosting environments in Amazon Web Services. Client environments are provisioned in the region appropriate to that client: US West (Oregon) for United States clients, with backup redundancy in US East (N. Virginia), and Asia Pacific (Sydney) for Australian clients. Our safeguards include:

  • encryption of data in transit and at rest;
  • multi-factor authentication on administrative access, with access limited by role to personnel who require it;
  • logically separated environments for development, staging, and production, and logical separation between clients;
  • logging and monitoring of administrative access and system activity;
  • encrypted backups with defined retention, tested restoration procedures, and backups held in the same region as the environment they protect;
  • written confidentiality obligations and security training for personnel with data access; and
  • continuous monitoring of our security controls through a compliance automation platform, as part of an active SOC 2 readiness program.

We are working toward SOC 2 Type II attestation and have not yet completed an audit. We are happy to complete security questionnaires and discuss our controls with clients and prospective clients under NDA.

No system is perfectly secure, and we cannot guarantee absolute security. If a security incident affects personal information we control, we will notify affected individuals and regulators as applicable law requires. Where an incident affects data we process for a client, we notify that client without undue delay so they can meet their own obligations.


12. Location of data and international transfers

Website information. Germinate is a United States company. Information you send us through this website is processed in the United States. If you contact us from outside the United States, your information will be transferred to and processed here, which may not provide the same level of legal protection as your home jurisdiction.

Client hosting environments. Data residency for client environments is set per client, as described in Section 11 — United States regions for US clients, and Asia Pacific (Sydney) for Australian clients. Australian client data, including backups, remains in the Asia Pacific (Sydney) region and is not replicated to the United States. Where a client has a data residency requirement, it is recorded in that client's agreement.

Administrative access. Germinate personnel are located in the United States. Where a client environment is hosted outside the United States, our personnel may access it from the United States to deliver the hosting, maintenance, and support services that client has engaged us for. Storing data in a region does not by itself keep it from being accessed by our personnel elsewhere, and we would rather say so plainly than imply otherwise.

Transfer mechanisms. Where we process personal data subject to the GDPR or UK GDPR on a client's behalf, transfers are governed by the Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, as incorporated into our Data Processing Agreement. Where we process personal information subject to the Australian Privacy Act 1988 (Cth), our obligations to the disclosing entity are set out in our agreement with that client.


13. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding the information we hold as a controller — that is, the website information described in Section 3:

  • Know and access — confirm whether we process your personal information and obtain a copy;
  • Correct — have inaccurate information corrected;
  • Delete — have your information deleted, subject to exceptions where we must retain it;
  • Portability — receive your information in a portable format;
  • Opt out — of targeted advertising, sale, or profiling with significant effects (we do none of these);
  • Object or restrict — where the GDPR or UK GDPR applies;
  • Withdraw consent — where we relied on consent; and
  • Non-discrimination — we will not treat you differently for exercising any of these rights.

How to make a request

Email privacy@germinateapps.com with the subject line "Privacy Request," and tell us what you would like us to do. You may also write to us at the address in Section 16.

We will verify your identity before acting, using information we already hold. We do not ask for additional sensitive information to verify a request. An authorized agent may submit a request on your behalf with written authorization, and we may contact you to confirm it.

We respond within 45 days. If we need more time, we will tell you within that period and may extend once by a further 45 days.

If we decline

If we decline your request, we will tell you why. You may appeal by replying to our decision with the word "Appeal." A different reviewer will consider it and respond within 45 days. If we deny the appeal, we will give you a way to contact the Oregon Department of Justice or your state's attorney general. Residents of the EEA or UK may also complain to their supervisory authority.


14. Children

This website is directed to businesses and is not intended for children. We do not knowingly collect personal information from anyone under 13, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided us information through this website, contact us and we will delete it.

Some applications Germinate hosts for clients may serve minors. Where that is the case, the client operating the application is responsible for parental consent and for compliance with COPPA, FERPA, and applicable state law. Our obligations to that client are set out in our agreement with them.


15. Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date at the top. If a change materially affects how we handle personal information, we will post a prominent notice on this page for at least 30 days. Material changes are not applied retroactively to information already collected without notice.


16. Contact us

Germinate, LLC
525 3rd St Ste 200
Lake Oswego, OR 97034
United States

Privacy requests: privacy@germinateapps.com
General: hello@germinateapps.com
Phone: (503) 828-1828


Our Work

  • Case Studies
  • The Greenhouse
  • Testimonials

About

  • About Us
  • Process
  • Define & Design

Contact

  • Contact Us
  • 1 (503) 828-1828
  • hello@germinateapps.com
  • 525 3rd St Ste 200
    Lake Oswego, OR 97034
  •  
Germinate

© 2026 Germinate LLC  |  Terms of Service  |  Privacy Policy