TELURE PRIVACY POLICY
Last Updated: 8/27/2026 Effective Date: 8/26/2026
TELURE LLC ("Telure," "we," "us") provides a software system of record used by climbing facilities to document inspections, equipment condition, and maintenance activity.
This Privacy Policy explains what personal information we handle, why, and what happens to it.
1. THE MOST IMPORTANT THING TO UNDERSTAND: WE ACT IN TWO DIFFERENT ROLES Almost every question about privacy in our Service depends on which of these two situations applies. ### 1.1 Information about our customers and their staff, where we decide how it is used When a climbing facility signs up for Telure, we collect information about that business and the individuals who administer the account. We decide how that information is used, and this Policy governs it directly. In privacy terminology, we are the controller of that information. ### 1.2 Information inside a facility's records, where the facility decides how it is used When a facility's staff record inspections, log incidents, take photographs, or enter equipment information, that content belongs to the facility. It may describe employees, members, guests, and program participants, including people who are minors. We store and process that content only on the facility's instructions and only to operate the Service for them. We do not decide what goes in, how long it is used for, or who else sees it. In privacy terminology, we are a processor or service provider, and the facility is the controller. ### 1.3 What this means if you are not our customer If you are a member, guest, program participant, parent, or employee of a climbing facility that uses Telure, and you want to know what information about you exists, correct it, or have it deleted, contact that facility, not us. They control it. We will support them in responding to you, but we cannot act on their records without their instruction. Section 10 explains how this works.
2. INFORMATION WE COLLECT AS CONTROLLER ### 2.1 Account information Business name, facility address, and facility characteristics. For each authorized user: name, email address, and job title or role. ### 2.2 Authentication information Credentials used to access the Service, stored in hashed form.
We do not collect, receive, store, or have access to any fingerprint, facial geometry, or other biometric identifier. Where a user unlocks the Service using a fingerprint or face scan, that verification happens entirely on the user's own device, and the device sends us only a cryptographic confirmation that it succeeded. No biometric data reaches us at any point.
2.3 Billing information
Subscription plan, billing contact, invoice and payment history. Payment card and bank account details are collected and stored by our payment processor, not by us. We never see or store a full card number or bank account number.
2.4 Support communications
Email, messages, and call notes exchanged when a user contacts us for support, and any information voluntarily included in them.
2.5 Technical and usage information
IP address, browser and device type, operating system, timestamps of access, pages and features used, and error and diagnostic logs. We use this to operate and secure the Service, diagnose failures, and understand which parts of the product are actually used.
2.6 Information from a facility's use of the Service
Aggregate operational signals such as how frequently checks are completed and whether an account has stopped logging activity. We use these to support customers and to identify facilities that may need help.
3. INFORMATION WE PROCESS ON BEHALF OF FACILITIES The following is entered into the Service by facility staff. We process it solely on the facility's behalf. ### 3.1 Records content Inspection entries and results, equipment registry information, corrective actions, notes, amendments, timestamps, and the identity of the staff member who made each entry. ### 3.2 Photographs Images captured by staff to document a failed inspection item or a hazard. These images may incidentally include identifiable people. ### 3.3 Incident reports Descriptions of incidents occurring at a facility. These may include names, ages, descriptions of injuries, accounts of what happened, witness information, and photographs. Where a facility runs youth programming, incident reports may describe minors. ### 3.4 Sensitivity We recognize that incident content and photographs are more sensitive than ordinary business records. We treat all facility records as confidential, apply the same security controls to all of it, and do not use any of it for any purpose other than operating the Service for the facility that created it.
4. WHAT WE DO NOT DO These are commitments, not descriptions of current practice that might change quietly.
We do not sell personal information. We have never done so and this Policy will not be changed to permit it without direct notice to every affected customer.
We do not share personal information for advertising purposes, cross-context behavioral advertising, or targeted advertising of any kind.
We do not use facility records to train machine learning models. The Service contains no machine learning component.
We do not use advertising cookies, tracking pixels, social media trackers, or third-party advertising SDKs.
We do not collect location data. The Service does not request or use device GPS, and we do not derive facility or user location from device signals.
We do not access facility member databases, payment systems, waivers, or check-in systems. The Service does not connect to them.
We do not read facility records except as described in Section 6.4.
5. PHOTOGRAPHS AND EMBEDDED METADATA Photographs taken on a phone commonly carry embedded metadata, including GPS coordinates, device identifiers, and capture timestamps.
Telure re-encodes every image on upload, which removes embedded metadata, including location. The record's own timestamps — when the observation was captured and when it reached our servers — are stored, displayed, and included in exports.
6. HOW WE USE INFORMATION AND WHEN WE DISCLOSE IT ### 6.1 Purposes To provide, operate, maintain, and secure the Service; to authenticate users and attribute entries; to send operational notifications, reminders, and alerts; to bill and collect fees; to provide support; to diagnose and fix defects; to detect and prevent abuse or security incidents; to improve the Service; and to comply with law. ### 6.2 Service providers We use a small number of third parties to operate the Service. Each has access only to what its function requires and is contractually restricted to processing on our instructions.
- Application hosting — cloud platform. Data involved: all Service traffic.
- Database and file storage — managed database and storage provider. Data involved: account data and facility records, including photographs.
- Payment processing — payment processor. Data involved: billing contact and payment details, which are held by the processor rather than by us.
- Transactional email — email delivery provider. Data involved: recipient address and message content.
- Error monitoring — application monitoring provider. Data involved: diagnostic and error data.
A current list of named providers is available at /legal/subprocessors and on request.
6.3 Legal process
If we receive a subpoena, court order, or other legal demand for facility records, we will, unless legally prohibited from doing so, notify the affected facility promptly and before producing anything, give them a reasonable opportunity to object or seek protection, and produce only what is required. We will not voluntarily disclose facility records to any third party absent legal compulsion or the facility's written authorization.
6.4 Our own access to facility records
Our personnel may access facility records only where necessary to resolve a support request the facility has raised, to investigate a defect or security incident, or where legally required. No Telure account, including administrative accounts, can edit or delete a submitted record entry. Support access happens through our infrastructure providers, which log access at the database level.
6.5 Business transfer
If Telure is acquired, merged, or sells substantially all of its assets, information may transfer as part of that transaction. The acquirer would be bound by the commitments in this Policy as to information collected before the transfer, and we would notify customers before any material change in how their information is handled.
6.6 Aggregated and de-identified information
We may produce aggregated statistics that do not identify any facility, individual, or record, and cannot reasonably be used to do so. We may use these to operate, analyze, and describe the Service.
6.7 Third-party access links generated by facilities
A facility may generate a scoped, time-limited link allowing an insurance broker, underwriter, or service vendor to view a defined subset of its records. That is a disclosure made by the facility, not by us. The facility decides whether to generate the link, what it exposes, to whom, and for how long.
7. MINORS ### 7.1 The Service is not for children Telure is a business tool. It is not directed to children, is not offered to children, and no one under 18 may hold an account or use the Service. We do not knowingly collect information directly from children. ### 7.2 Records may describe minors A facility's incident reports and program records may describe minors who participate in youth programming. That information is entered by the facility, about people who are not our users, and is controlled by the facility. We process it only on the facility's instruction. ### 7.3 Responsibility for that information The facility is responsible for having any notice, consent, or legal basis required to record information about a minor and to provide it to a service provider. Parents and guardians seeking access, correction, or deletion of information about their child should contact the facility directly. ### 7.4 If a child contacts us If we learn that we have collected information directly from a person under 18 through the Service, we will delete it. Contact us at legal@telure.co.
8. RETENTION ### 8.1 Facility records We retain a facility's records for as long as their subscription is active, and for one (1) year after termination. Export functionality remains available throughout that period, and we deliver a complete export on written request within ten (10) business days. After the one-year period, we may permanently delete their records. ### 8.2 Litigation holds Where a facility applies a litigation hold to a record set within the Service, we retain that record set until the hold is released, notwithstanding Section 8.1. ### 8.3 Account and billing information Account records and billing records are retained as long as required for tax, accounting, and legal purposes, typically seven years for transaction records. ### 8.4 Technical logs Access, error, and diagnostic logs are retained for no more than ninety (90) days and then deleted or de-identified. ### 8.5 Support communications Retained for as long as needed to provide support and maintain a service history, and then deleted on a routine schedule.
9. SECURITY We protect information using encryption in transit and at rest; individual credentials for every person who records work (a shared front-desk display can view, but cannot create a record without the individual PIN of the person doing the work); role-based access restrictions; database-level controls that prevent any user, including our own personnel, from altering or deleting a submitted record entry; infrastructure-level access logging; and access limited to personnel who need it.
We do not currently hold SOC 2, ISO 27001, or any equivalent third-party security certification. We say so plainly rather than implying otherwise.
No system is completely secure. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed by breach of our safeguards. If a breach affecting personal information occurs, we will notify affected customers and any regulators as required by applicable law, without undue delay.
10. YOUR RIGHTS AND CHOICES ### 10.1 If you administer a Telure account You may access and correct your account information within the Service, request a copy of the account information we hold about you, ask us to delete your account information subject to our legal and contractual retention obligations, and opt out of non-operational email. Operational messages such as alerts, reminders, security notices, and billing notices cannot be opted out of while an account is active, because they are part of the Service.
Contact legal@telure.co. We will respond within 30 days.
10.2 If you are described in a facility's records
Direct your request to the facility. They control that information. If you contact us instead, we will refer you to them and, where we can identify the facility, notify them of your request. We will not access, alter, or delete a facility's records in response to a request from someone who is not that facility, absent legal requirement.
10.3 State privacy rights
Residents of certain states have rights to know, access, correct, delete, and appeal, and to be free from discrimination for exercising them. Where those laws apply to us, we honor them. Where we act as a service provider to a facility, requests should go to that facility.
We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out from those activities is necessary.
10.4 Do Not Track and Global Privacy Control
We do not track users across third-party websites, so there is no cross-site tracking to disable. We do not respond differently to Do Not Track signals because we do not engage in the practices they address.
11. COOKIES AND SIMILAR TECHNOLOGIES We use cookies and local browser storage only to keep users signed in, maintain session state, remember interface preferences, and enable offline operation of the Service, which requires storing records on the device until they synchronize.
We do not use advertising cookies, third-party tracking cookies, or cross-site trackers. Because we use only strictly necessary and functional storage, we do not display a consent banner.
12. WHERE INFORMATION IS STORED Information is stored and processed in the United States. The Service is offered only to businesses in the United States and is not directed to individuals in the European Economic Area, the United Kingdom, or elsewhere outside the United States.
13. CHANGES TO THIS POLICY We may update this Policy. If a change materially affects how we handle personal information, we will notify account administrators by email at least 30 days before it takes effect. The "Last Updated" date at the top always reflects the current version, and prior versions are listed in the Version History at the end of this Policy.
14. CONTACT TELURE LLC 305 Danube St, Raleigh NC 27615 legal@telure.co
To exercise a right, ask a question, or report a concern about privacy or security, email legal@telure.co.
15. VERSION HISTORY Version 1.2 — August 27, 2026. Contact addresses moved to the telure.co domain (rights and privacy contact: legal@telure.co).
Version 1.1 — August 26, 2026. Aligned retention, credential, and image-metadata descriptions with the software as built; export after termination is delivered on request.
Version 1.0 — August 26, 2026. Initial publication.

