123Exec
HomePlatformPricingAbout
See plans See it in action

Privacy Policy

How EPIQ Development, Inc. handles information in the 123Exec platform. Effective date: August 27, 2026. Version 1.1.

1. Who We Are and What This Covers

This Privacy Policy explains how EPIQ Development, Inc. ("Company," "we," "us"), the operator of the 123Exec platform ("123Exec" or the "Service"), collects, uses, shares, and protects information. It applies to the Service and to our related websites and communications. It works alongside our Terms and Conditions; capitalized terms not defined here have the meaning given there.

123Exec is a business tool. Most of the information in it belongs to the client companies that use it. This Policy describes both the information those companies and their people put into the Service and the information we collect automatically when the Service is used.

This Privacy Policy applies to our Service, websites, communications, and related online features. It does not apply to third-party websites, services, or integrations that we do not own or control, even if they are linked from or accessible through the Service. Customer organizations are responsible for their own privacy notices, permissions, legal bases, consents, and compliance obligations for information they submit to or process through the Service.

2. Information We Collect

Information you and your team provide:

  • Account and contact details, such as name, work email, company, and role.

  • Customer Data, meaning the business information you enter or generate in the Service: assessments, company goals, KPIs, financial figures, revenue and pipeline data, initiatives, strategy inputs, meeting and one-on-one notes, and leadership and 360 review inputs.

  • Communications you send us, such as support requests and feedback.

Information collected automatically when the Service is used:

  • Usage and device data, such as pages viewed, features used, actions taken, approximate location from IP address, browser and device type, and timestamps. We collect this through our product-analytics provider, PostHog. These events are attributed to your company, not to you as a named individual, and we do not build individual user profiles from them. Analytics do not load until you accept them through our consent banner.

  • Referral attribution data. If a coach or partner referred you to the Service, a first-party cookie set by Rewardful records that referral for up to 60 days. This cookie does not load until you accept it through our consent banner.

  • Cookies and similar technologies used to keep you signed in, remember preferences, and support the analytics and referral attribution described above. Section 7 describes these in detail. You can also control cookies through your browser, though some features may not work without them.

  • Acceptance records. When you accept our Terms and Conditions or this Privacy Policy, we record which version you accepted, the date and time, your account and company, your IP address and browser, and how you accepted. We keep the full text of every version we publish, so we can always show exactly what you agreed to. These records exist to perform and evidence our contract with you. They are not analytics, they are not optional, and they are not covered by the consent banner.

We do not use session replay or session recording. We do not record, reconstruct, or play back how you move through the interface.

Information from others: If a coach or partner refers or sets up your account, we may receive your contact and account details from them, and our payment processor provides us with billing status (never full card numbers).

We do not intentionally collect government identifiers, full payment card numbers, or health information. Please do not submit those to the Service.

Sensitive personal information: The Service is not intended to collect or process sensitive personal information unless we expressly agree otherwise in writing. You should not submit the following categories of information to the Service unless your organization has confirmed that the submission is lawful, authorized, necessary, and appropriate:

  • government-issued identifiers, such as Social Security numbers, driver's license numbers, passport numbers, or national identification numbers;

  • full payment card numbers, bank account credentials, or financial account login credentials;

  • protected health information, medical records, disability information, or health insurance information;

  • biometric identifiers or biometric templates;

  • precise geolocation information unrelated to ordinary business use;

  • information about children or minors;

  • special-category or sensitive information, including information revealing racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, health data, sex life, or sexual orientation;

  • consumer credit, background check, or eligibility information regulated by specialized laws;

  • legally privileged, highly confidential, or third-party proprietary information that you are not authorized to submit; or

  • passwords, access credentials, authentication tokens, or secrets.

If you believe sensitive information has been submitted to the Service in error, please contact us promptly so we can evaluate appropriate steps, which may include deletion, restriction, or other remedial measures.

Customer compliance and regulated data: 123Exec is a business software platform. Customers are responsible for determining whether the Service is appropriate for their intended use and for complying with laws, regulations, industry standards, employment obligations, confidentiality obligations, and internal policies that apply to the information they submit to or process through the Service.

Unless we expressly agree in writing, the Service is not designed to process regulated or highly sensitive information, such as protected health information, consumer credit information, government identifiers, financial account credentials, biometric information, children's information, legally privileged materials, or information subject to specialized laws or industry rules. Customers should not submit such information unless they have confirmed that their use of the Service is lawful, authorized, and appropriate.

If a customer uses the Service in a regulated environment, including financial services, employment, human resources, leadership assessments, coaching, or professional advisory contexts, the customer remains responsible for any disclosures, consents, notices, recordkeeping, retention, supervision, or other compliance obligations that apply to its own use of the Service and Customer Data.

3. Our Role: Processor and Service Provider

For Customer Data submitted to the Service by or on behalf of a customer organization, that customer is generally the controller, business, or other legally responsible entity that determines the purposes and means of processing. We process Customer Data on behalf and in support of the customer as a processor, service provider, or contractor, as those terms are defined under applicable privacy laws.

For information we collect and use for our own business purposes, such as account registration information, billing status, support communications, website interactions, security logs, product analytics, and administrative records, we act as a controller, business, or similar responsible entity.

Where we process Customer Data on behalf of a customer, we will use it only to provide, maintain, secure, support, and improve the Service; comply with law; enforce our agreements; prevent fraud or abuse; and as otherwise instructed or authorized by the customer. We do not sell Customer Data, and we do not use Customer Data for cross-context behavioral advertising.

If required by applicable law or contract, we will enter into a data processing agreement or similar addendum with the customer.

4. How We Use Information

We use information to:

  • Provide, operate, secure, and maintain the Service, including authentication, access control, and fraud and abuse prevention.

  • Provide support and respond to your requests.

  • Understand how the Service is used and improve its features, content, reliability, and usability.

  • Produce aggregated and anonymized insights across all clients, for example how much companies using 123Exec tend to grow or improve their margins and leadership scores. These insights are combined and stripped of identifying detail so they do not reveal any individual company, and we may use them internally and in our marketing. We do not present one client's raw figures to anyone.

  • Bill for the Service and manage your subscription.

  • Credit the coach or partner who referred you.

  • Communicate with you about the Service, including service and security notices, and, where permitted, product news you can opt out of.

  • Comply with law and enforce our Terms.

5. Website-Use Restrictions and Acceptable Use

You may use the Service, our websites, and related materials only for lawful business purposes and in accordance with our Terms and this Privacy Policy. You may not use the Service or our websites to:

  • interfere with, disrupt, impair, overload, or compromise the operation, integrity, availability, or security of the Service;

  • attempt to circumvent authentication, access controls, rate limits, security measures, or technical restrictions;

  • access, collect, scrape, harvest, copy, or extract information from the Service or our websites by automated means, including bots, spiders, crawlers, scripts, or similar tools, except as expressly permitted by us in writing;

  • collect information about other users or customers except as authorized by your company's account permissions;

  • upload or submit unlawful, infringing, misleading, malicious, or unauthorized content; or

  • use the Service in a way that would violate applicable law, third-party rights, or contractual obligations.

We may suspend, restrict, or terminate access to the Service or our websites if we believe a user has violated these restrictions, threatens the security or integrity of the Service, or creates legal, operational, or security risk.

6. Artificial Intelligence Features, Human Review, and Automated Decisions

Some Service features use artificial intelligence ("AI") or machine learning technologies to generate summaries, guidance suggestions, comparisons, or other outputs based on information submitted to or available within the Service. These features are intended to assist users and do not replace professional judgement, legal, financial, employment, compliance, or other expert advice.

AI-generated outputs may be incomplete, inaccurate, outdated, or inappropriate for a particular situation. Users are responsible for reviewing AI outputs before relying on, sharing, or acting on them.

We do not use AI features to make decisions that produce legal or similarly significant effects about individuals, such as employment, credit, housing, insurance, benefits, or eligibility decisions. Customers and users should not use AI outputs as the sole basis for decisions about individuals.

Unless expressly authorized by us in writing, users should not submit sensitive personal information, regulated information, confidential third-party information, or information they are not authorized to process into AI features. Our current AI provider is Anthropic. Under Anthropic's Commercial Terms of Service, Anthropic may not train models on customer content submitted through its services, and Anthropic's Data Processing Addendum governs its handling of that content. Information sent to AI providers is limited to what is reasonably necessary to provide the applicable feature.

7. Cookies and Analytics

We use cookies and similar technologies to operate the Service, to remember your preferences, to understand how the Service is used, and to credit the coach who referred a client.

Consent comes first. Nothing outside the strictly necessary category loads until you have answered our consent banner. Analytics and referral attribution are not loaded first and explained afterwards; they do not run at all unless you accept them. Accept and Decline are presented with equal prominence, and you can change your choice at any time using the Cookies link in the footer. Your choice is recorded in your browser's local storage rather than in a cookie.

The technologies we use fall into the following categories:

  • Strictly necessary technologies, which support login, authentication, account security, fraud prevention, load balancing, and core Service functionality. These do not require consent, and the Service will not work without them.

  • Preference technologies, which remember choices such as account settings, interface preferences, and other configuration details.

  • Analytics technologies, provided by PostHog, which help us understand which client companies are active and which parts of the Service they use, so we can improve performance, usability, and the features that matter most. Analytics events are attributed to the customer organization, not to a named or identified individual, and we do not create individual person profiles from them. The question we are answering is which companies use which parts of the tool, not what any one person does.

  • Referral attribution technologies, provided by Rewardful. Where a coach or partner referred you to the Service, a first-party cookie records that referral for up to 60 days, so the referring coach is credited.

We do not use session replay or session recording, and we do not intend to. We do not record, reconstruct, or play back how you navigate the interface.

We do not use cookies for advertising, and we do not permit third parties to use cookies on the Service for cross-context behavioral advertising.

You may also control cookies through your browser settings. Declining or disabling non-essential technologies will not prevent you from using the Service, although disabling strictly necessary technologies through your browser may affect its availability, security, or functionality.

8. How We Share Information

We do not sell your personal information. We share information only as follows:

  • Service providers (subprocessors) that help us run the Service under contract. As of the effective date of this Policy these are:

    • Supabase, database and authentication, hosted on Amazon Web Services in us-east-1, Northern Virginia;

    • Netlify, hosting and scheduled functions, us-east-2, Ohio;

    • Stripe, payment processing, United States;

    • Anthropic, AI features, United States;

    • PostHog, company-level product analytics, United States; and

    • Rewardful, referral attribution, Canada.

Each may process information only to provide its service to us. The current list, and the region each provider operates in, is maintained in our Subprocessor List.

  • Within your own company, according to the roles and permissions your administrators set.

  • With a coach, only if your company has allowed it. Where a coach introduced you to the Service, or your company adds one, that coach can see your information only after the person who leads your company explicitly allows it. Allowing is a deliberate choice, it is never on by default, and it can be withdrawn at any time from the Coach access screen, which takes effect immediately. An allowed coach has read-only access at the company level: goals, KPIs, initiatives, strategy, meeting items, the team roster, company financials, and a summary of the leadership team showing each leader's name, role and a single overall readiness score. A coach does not see any individual's assessment detail, 360 feedback, self-assessment comments, or one-on-one notes.

  • For legal reasons, such as to comply with law, respond to lawful requests, or protect the rights, safety, and security of our users, the public, or the Company.

  • In a business transfer, such as a merger, acquisition, or sale of assets, in which case we will continue to protect the information and notify you as required.

Third party websites and external links: The Service and our websites may contain links to third-party websites, applications, services, resources, or content that we do not own or control. These links are provided for convenience and informational purposes only. We do not endorse, control, or assume responsibility for the content, privacy practices, security practices, products, services, or policies of any third-party website or service.

When you visit or interact with a third-party website or service, your information is governed by that third party's privacy policy and terms, not this Privacy Policy. We encourage you to review the privacy and security practices of any third-party site or service before providing information to it.

9. Data Retention and Deletion

We retain information for as long as reasonably necessary to provide, secure, maintain, and improve the Service; comply with legal, accounting, tax, audit, and contractual obligations; resolve disputes; enforce agreements; and protect against fraud, abuse, or security threats. Your subscription is month to month; when you cancel, access continues through the end of the paid period. After your access ends, you may request a copy of your Customer Data within thirty (30) days and we will provide it in a commercially reasonable electronic format. After that period we may delete or de-identify Customer Data, subject to law and our routine backup cycles. Aggregated and anonymized insights that no longer identify you may be retained.

Subject to applicable law, contract, and technical limitations, we generally retain categories of information as follows:

  • Account information: for the life of the account and for a reasonable period after cancellation or termination.

  • Customer data: while the customer account is active and for the post-cancellation export period described in this Policy, after which it may be deleted, de-identified, or retained only as required by law, contract, backup cycles, or legitimate business needs.

  • Billing and transaction records: for the period required for tax, accounting, audit, and legal compliance. Our payment processor retains transaction records for the period its own legal obligations require, which is generally longer than our own retention period and is not within our control.

  • Support communications: for as long as needed to provide support, maintain business records, improve the Service, and address disputes or legal obligations.

  • Security logs and audit records: for a limited period reasonably necessary for security, fraud prevention, troubleshooting, legal compliance, and incident investigation.

  • Acceptance records and published document versions: for as long as the agreement is in force and for as long afterwards as any related legal or contractual obligation requires. Published versions and the acceptances recorded against them cannot be altered or deleted, because a record of agreement that could be edited later would not evidence anything.

  • Analytics data: for a limited period reasonably necessary to understand and improve the Service, unless a longer retention period is required for security, legal, or operational reasons. Analytics data is company-level and contains no session recordings and no individual person profiles.

  • Referral attribution data: the referral cookie expires 60 days after it is set. The record of which coach referred a company is retained for the life of that business relationship.

  • Database backups: our database is protected by point-in-time recovery with a rolling seven-day window. Recovery points older than seven days expire automatically.

  • Aggregated, anonymized, or de-identified information: may be retained without time limit if it no longer identifies, and cannot reasonably be used to identify, a customer, company, user, or individual.

Deletion may not be immediate from all systems due to technical constraints, backup cycles, legal holds, fraud prevention, dispute resolution, or compliance obligations.

10. How We Protect Information

We maintain administrative, technical, and organizational safeguards appropriate for a platform of this kind, including encryption of data in transit, database-level isolation of each company's data, required multi-factor authentication, role-based access, change logging, backups, and abuse protections. As explained in our Terms, no method of transmitting or storing data is completely secure, and we cannot guarantee absolute security. Security is also a shared responsibility: please protect your credentials and use the safeguards we provide.

Security incidents and breach notification: We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, misuse, or destruction. However, no system or method of transmission or storage is completely secure.

If we become aware of a security incident involving personal information or Customer Data, we will investigate and take steps we believe are appropriate under the circumstances. Where required by applicable law or contract, we will notify affected customers, users, regulators, or other parties. Notice may be provided by email, through the Service, or by other legally permitted means.

Customers are responsible for maintaining accurate administrator and security contact information so that we can provide timely notices when required.

11. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to opt out of certain uses, and to be free from discrimination for exercising these rights. California residents have rights under the California Consumer Privacy Act, including the right to know, delete, and correct, and the right to opt out of the sale or sharing of personal information; as noted, we do not sell personal information. If the GDPR applies to you, you also have rights to object to or restrict certain processing and to lodge a complaint with a supervisory authority.

Because much of the information in the Service is controlled by your employer or the company that owns the account, we may direct certain requests to that company, and we will assist them as required. To make a request or ask a question, contact us using the details in Section 16. We will verify your request as the law requires before acting on it.

12. Children

The Service is intended for businesses and their personnel and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us and we will take appropriate steps to remove it.

13. Where Information Is Handled

We are based in the United States, and the Service is operated from the United States. Most of our service providers store and process information in the United States, and the region each one operates in is listed in our Subprocessor List.

We do not represent that every provider processes information exclusively within the United States. Some providers are organized outside the United States, or have personnel outside the United States who may access information in the course of operating, supporting, or securing their service. Our referral attribution provider, Rewardful, is a Canadian company.

We and our service providers may therefore process, store, access, or transfer information in the United States and in other jurisdictions where we or they operate. These jurisdictions may have data protection laws that differ from those in your country, state, or region. Where we engage a provider that processes information outside the United States, we do so under contract terms requiring it to protect that information consistently with this Policy and applicable law.

14. International Data Transfers

Where applicable law requires a transfer mechanism for personal information transferred from the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions with cross-border transfer requirements, we will rely on appropriate safeguards, which may include standard contractual clauses, data processing agreements, adequacy decisions, supplementary measures, or another lawful transfer mechanism.

You may contact us using the information in this Privacy Policy to request more information about the safeguards we use for international transfers, where applicable.

15. Changes to This Policy

We may update this Policy from time to time. If we make a material change, we will post the updated Policy with a new effective date and, where appropriate, notify you through the Service or by email. Your continued use of the Service after the effective date means you accept the updated Policy.

16. How to Contact Us

For privacy questions or requests about this Privacy Policy or our privacy practices you may contact us at:

EPIQ Development, Inc.

Attn: Privacy Contact

Email: info@123exec.com

Phone: 858-361-0013

Please include enough information for us to understand and verify your request. If your request relates to information controlled by your employer, company, or another customer organization, we may direct your request to that organization or work with that organization to respond, as applicable.

123Exec

Great companies aren't complicated. They're consistent. Run yours, as easy as 1-2-3.

Product
PlatformPricingAbout
The recipe
1 · Coach2 · Operator3 · Strategist
Get started
See it in actionBook a call
© 2026 EPIQ Development, Inc. All rights reserved. · Terms · Privacy · Subprocessors CoachOperatorStrategist