Privacy Policy

... ...

Effective Date: 05.28.2026 · Last Updated: 05.28.2026 Version 1.0 
Contains: Part I — Privacy Policy | Part II — Cookie Policy 
Issued by: CuraeSoft Corporation, 39 Beta Court, San Ramon, CA 94583

PART I — PRIVACY POLICY

This Privacy Policy describes how CuraeSoft Corporation (“CuraeSoft,” “we,” “us,” “our”) collects, uses, shares, and protects information in connection with coAmplifi Pro and our websites. It applies whether you are using a single-Workspace coAmplifi Pro subscription or your organization participates in a Vendor Management (W2W) connection. If you do not agree with this Privacy Policy, please do not access or use the Services. 

California Notice of Collection: We collect the categories of Personal Information described in Section 5 for the business and commercial purposes described in Sections 6 and 7. To learn more about exercising your California privacy rights, please review Section 14. 

Notice to All Users: CuraeSoft does not sell your Personal Information and does not share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals. See Sections 7 and 14 for details.

2. Definitions

  • Authorized User. An individual whom a Customer has granted permission to access the Services. 
  • Client Hiring Firm. A Customer that initiates or maintains a Vendor Management connection in which it engages a Vendor Firm. 
  • Connected Customer. A Customer with which another Customer has an active Vendor Management connection. Each Connected Customer remains an independent controller of Customer Data inside its own Workspace; CuraeSoft is the processor for both Connected Customers with respect to Customer Data crossing the Shared Info Bridge. 
  • Cookie Policy. Part II of this Notice, governing tracking technologies.
  • Customer. An organization with an active subscription to coAmplifi Pro. 
  • Customer Data. Content and information submitted to the Services by Authorized Users. Customer Data submitted to the Shared Info Bridge is owned by the Customer that submitted it; the Connected Customer receives access but does not acquire ownership. 
  • CuraeSoft / We / Us / Our. CuraeSoft Corporation, a California corporation, and its affiliates. 
  • Other Information. All information CuraeSoft collects, generates, or receives that is not Customer Data — account information, usage data, log data, device data, location data, cookie data, and additional information described in Section 5. 
  • Personal Information / Personal Data. Information associated with an identified or identifiable individual. 
  • Sensitive Personal Information. Personal Information meeting the heightened-protection threshold under applicable law, including CCPA / CPRA. CuraeSoft does not currently collect Sensitive Personal Information from Authorized Users. 
  • Services. coAmplifi Pro and any associated mobile and desktop applications. 
  • Shared Info Bridge. The information pathway between two connected Workspaces in a Vendor Management connection. The Shared Info Bridge is the only data exchange between connected Workspaces. 
  • Vendor Firm. A Customer that accepts a Vendor Management connection invitation from a Client Hiring Firm. 
  • Vendor Management / W2W. The Workspace-to-Workspace bridge feature of coAmplifi Pro. 
  • Vendor Work. An assignment created by a Client Hiring Firm within a Vendor Management connection. 
  • Workspace. The unique domain or instance of the Services configured for a Customer. 

3. Controller and Processor Roles

3.1 Single-Workspace Context

The Customer is the controller of Customer Data inside its Workspace. CuraeSoft is the processor of that Customer Data and the controller of Other Information. 

3.2 Vendor Management (W2W) Context

Where a Customer participates in a Vendor Management connection, each Connected Customer is the controller of Customer Data on its own side of the Shared Info Bridge. CuraeSoft is the processor for both Connected Customers with respect to Customer Data crossing the Shared Info Bridge. CuraeSoft remains the controller of Other Information in W2W contexts, including connection metadata, consent-acknowledgment records, and Vendor Work lifecycle events. 

3.3 CuraeSoft Entity

CuraeSoft Corporation, a California corporation, with principal place of business at 39 Beta Court, San Ramon, CA 94583, is the controller of Other Information and the processor of Customer Data for all Authorized Users. 

4. Cookie Policy

CuraeSoft uses cookies and similar tracking technologies on the Websites and Services. The collection, use, and management of cookies is described in Part II of this Notice (Cookie Policy), incorporated into this Privacy Policy by reference. CuraeSoft honors Global Privacy Control (GPC) signals as required by California Civil Code §1798.135(b)(1) and 11 CCR §7025. 

5. Information We Collect

5.1 Customer Data — Single-Workspace Context

In a single-Workspace context, Authorized Users submit Customer Data — messages, files, project entries, and audit-log notes — when using the Services. Customer Data is owned by the Customer, not by the individual Authorized User. CuraeSoft processes Customer Data only as instructed by the Customer or as required by applicable law. 

5.2 Customer Data — Vendor Management (W2W) Context

Where the Customer participates in a Vendor Management connection, certain Customer Data is submitted to the Shared Info Bridge for cross-tenant collaboration. The Shared Info Bridge may contain Vendor Work assignment information; vendor-reported progress and time entries; shared files; and Change Log entries. Customer Data not submitted to the Shared Info Bridge is not visible to the Connected Customer. 

5.3 Other Information

CuraeSoft collects, generates, and receives the following categories of Other Information: 

  • Account and workspace information. Email address, name, password, organizational role, profile picture, domain, and other account-setup details. 
  • Usage information — Services metadata. Workspaces, projects, vendor-work assignments, and features the Authorized User views or interacts with. 
  • Usage information — Log data. IP address, prior page URL, browser type and settings, date and time of access, browser configuration and plugins, and language preferences. 
  • Usage information — Device information. Type of device, operating system, device settings, application IDs, unique device identifiers, and crash data. 
  • Location information. Approximate location derived from IP address. CuraeSoft does not collect precise geolocation. 
  • Cookie information. See Part II (Cookie Policy). 
  • Third-Party Services information. Information from third-party applications a Customer permits Authorized Users to connect to the Services. 
  • Contact information. Contact information an Authorized User chooses to import. May be revoked through in-product settings. 
  • Third-party data. Data about organizations, industries, customer lists, Website visitors, and marketing campaigns from affiliates, partners, or others. 
  • Additional information provided to CuraeSoft. Information from focus groups, contests, events, feedback, job applications, certification programs, support requests, and social-media interactions. 
  • W2W connection metadata (W2W context only). Connection identifiers and state; consent-acknowledgment records; Vendor Work lifecycle events; and bridge file-upload events. 

6. How We Use Your Information

6.1 Customer Data

CuraeSoft processes Customer Data as instructed by the Customer, including through the Customer’s use of Services functionality. In a W2W context, Customer Data crossing the Shared Info Bridge is processed by CuraeSoft on behalf of both Connected Customers, each as a separate controller with respect to its own side of the bridge. 

6.2 Legal Compliance

CuraeSoft processes Other Information to comply with legal obligations, including accessing, preserving, or disclosing information pursuant to valid legal requests. In a W2W context, where such a request implicates information that crossed the Shared Info Bridge, CuraeSoft will notify both Connected Customers where lawful and feasible. 

6.3 Legitimate Interests

CuraeSoft processes Other Information in pursuit of legitimate interests including: providing, updating, maintaining, and protecting the Services; developing and improving features; investigating and preventing security issues and abuse; and communicating with Authorized Users and Customers about the Services. 

6.4 Performance of the Customer Agreement

CuraeSoft processes account information and usage information to perform the Customer Agreement — providing the Services, authenticating users, enforcing subscription limits, and billing the Customer. 

6.5 Consent

Where CuraeSoft processes Other Information on the basis of consent, you may withdraw consent at any time through in-product settings or by emailing 

coamplifi-support@curaesoft.com. 

6.6 Vendor Management (W2W) Data

When you or your Customer participates in a Vendor Management (W2W) connection: only data explicitly shared through the Shared Info Bridge is accessible to the Connected Customer; each Customer Organization is the controller of the data it submits to the Bridge; CuraeSoft processes Bridge data as a service provider under CCPA / CPRA; CuraeSoft does not combine Bridge data from one connection with data from another connection; and each Customer is responsible for having appropriate inter-organization agreements with the other Connected Customer. 

7. How We Share and Disclose Information

CuraeSoft does not sell Personal Information. CuraeSoft does not share Personal Information for cross-context behavioral advertising. 

7.1 Customer Instructions

CuraeSoft shares and discloses information in accordance with the Customer’s instructions, including any applicable terms in the Customer Agreement. 

7.2 Displaying the Services

Information submitted to the Services may be displayed to other Authorized Users in the same or connected Workspaces. In a W2W context, certain profile information may be displayed to Authorized Users of the Connected Customer solely to enable identification of the counterparty. 

7.3 Customer Access

Workspace Admins and Authorized Users may access, modify, or restrict access to information within the bounds of their assigned permissions. 

7.4 Sub-processors

CuraeSoft engages third-party sub-processors to support delivery of the Services. CuraeSoft will provide at least 30 days’ advance notice of sub-processor additions that materially affect the categories of Personal Information processed. 

7.5 Stripe — Payment Processing

Payment information is processed by Stripe under its own privacy policy. Stripe is an independent controller. See Section 9. 

7.6 Professional Advisers, Corporate Affiliates, and Business Changes

CuraeSoft may share information with professional advisers acting as service providers and with corporate affiliates. In the event of a merger, acquisition, bankruptcy, reorganization, or similar transaction, some or all information may be shared or transferred, subject to standard confidentiality arrangements. 

7.7 Aggregated or De-identified Data

CuraeSoft may disclose aggregated or de-identified information for any purpose. CuraeSoft will not attempt to re-identify de-identified information. 

7.8 Law Enforcement and Regulators

CuraeSoft may disclose information if it reasonably believes disclosure is required by applicable law, regulation, or legal process. 

7.9 Safety and Enforcement

CuraeSoft may share information to protect rights, property, or safety — including to enforce contracts or policies, investigate illegal activity or fraud, or prevent imminent bodily harm. 

7.10 With Consent

CuraeSoft may share information with third parties when it has your consent or as otherwise permitted in this Privacy Policy.

8. Data Retention

8.1 Customer Data — Single-Workspace Context

CuraeSoft retains Customer Data in accordance with the Customer’s instructions, including any applicable terms in the Customer Agreement. Customers may customize their retention settings. 

8.2 Customer Data — W2W Context

In a W2W context, Customer Data submitted to the Shared Info Bridge is retained per the same retention controls each Connected Customer applies to its own Workspace. 

8.3 Other Information

CuraeSoft retains Other Information for as long as necessary for the purposes described in the Data Retention & Deletion Schedule. W2W connection metadata and consent acknowledgment records are retained for the timeframes specified in that Schedule. After the applicable retention 

period, CuraeSoft deletes or anonymizes personal information. Where deletion is not immediately possible (for example, data stored in backup archives), CuraeSoft isolates the data from further processing and deletes it when deletion becomes technically feasible. For further detail on Customer Data retention under the Data Processing Addendum, contact coamplifi-support@curaesoft.com. 

9. Stripe Payment Processing

9.1 Stripe as Independent Controller

Payment information is collected, processed, and stored by Stripe, Inc. (“Stripe”) under its own Privacy Policy at stripe.com/privacy. Stripe is an independent controller; CuraeSoft does not act as a processor of Stripe’s payment data and does not store, process, or transmit cardholder data through coAmplifi. 

9.2 What CuraeSoft Receives from Stripe

CuraeSoft receives from Stripe: a tokenized payment reference, billing address, the last four digits, expiration date, and card brand for receipt display, transactional outcome, and limited fraud-related metadata. CuraeSoft does not receive or store the full primary account number, card verification value (CVV), or magnetic-stripe data. 

9.3 What Stripe Receives from CuraeSoft

CuraeSoft provides Stripe with: the Customer’s billing email, subscription tier, charge amount, and currency. 

10. Security

CuraeSoft takes the security of your information seriously and works to protect it from loss, misuse, and unauthorized access or disclosure. In a W2W context, CuraeSoft enforces the Shared Info Bridge data-isolation boundary technically; cross-tenant data exposure is treated as a critical-severity event and triggers notification to both Connected Customers within applicable legal timeframes. Suspected security vulnerabilities should be reported through the Vulnerability Disclosure Policy. 

11. Changes to This Privacy Policy

CuraeSoft may change this Privacy Policy from time to time. Material changes that alter your privacy rights will receive additional notice by email to the administrative contact on the account. Each version is assigned a version number and effective date. 

12. International Data Transfers 

coAmplifi Pro is currently a US-only product. Information collected through the Services is processed in the United States. When CuraeSoft expands internationally, this Privacy Policy will be updated to describe safeguards for cross-border transfers, expected to include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, and other applicable transfer mechanisms. 

13. Data Retention, Anonymization, and Backup Processing

For CuraeSoft’s deletion, anonymization, and backup-archive practices with respect to personal information, see Section 8.3 above. 

14. Your California Privacy Rights

(a) Your California Privacy Rights. If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you specific rights regarding your personal information: 

(i) Know. Request that we disclose the categories of personal information we collected about you; the categories of sources; the business or commercial purpose; the categories of third parties to whom we disclose it; and the specific pieces of personal information we have collected about you. 

(ii) Delete. Request that we delete personal information we have collected from you, subject to certain exceptions. 

(iii) Correct. Request that we correct inaccurate personal information we maintain about you. 

(iv) Opt out of sale or sharing. Opt out of the sale or sharing of your personal information for cross-context behavioral advertising. 

(v) Limit sensitive personal information. Request that we limit our use and disclosure of sensitive personal information to the purposes authorized by CPRA §1798.121. See Section 14.6 (Limit the Use of My Sensitive Personal Information) below. 

(vi) Non-discrimination. We will not discriminate against you for exercising any of these rights. 

(b) How to submit a request. To submit a CCPA / CPRA rights request, contact us at: coamplifi-support@curaesoft.com or in writing at CuraeSoft Corporation, 39 Beta Court, San Ramon, CA 94583, Attn: Privacy. We will verify your identity before processing your request. 

(c) Response timeline. We will respond to your request within forty-five (45) days of receipt. If we require additional time, we will notify you within the initial 45-day period and may extend our response by an additional forty-five (45) days with written explanation. 

(d) Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require written proof of the agent’s authority and may verify your identity directly. 

14.1 Categories of Personal Information Collected

CuraeSoft collects the following from Authorized Users, Customers, analytics providers, and third-party services: 

  • Identifiers and contact information (name, email, employer, IP address); • Commercial information (subscription tier, transactional history); 
  • Internet or electronic-network-activity information (log data, device information, usage metadata, and W2W connection metadata in W2W contexts); 
  • Financial information (limited to billing address and tokenized payment reference — no cardholder data); 
  • Approximate geolocation information (derived from IP address); 
  • Professional or employment-related information (role within the Customer); and • Inferences drawn from the above categories. 

14.2 No Sale or Sharing for Targeted Advertising

CuraeSoft does not sell Personal Information as defined under California Civil Code §1798.140(ad), and does not share Personal Information for cross-context behavioral advertising. 

Do Not Sell or Share My Personal Information. Under CCPA / CPRA, you have the right to opt out of the sale or sharing of your personal information. To opt out: Click [Do Not Sell or Share My Personal Information] or enable a Global Privacy Control (GPC) signal in your browser. We treat GPC signals as valid opt-out requests. You may also submit an opt-out request to coamplifi-support@curaesoft.com. 

14.3 California Consumer Rights

California consumers have the right to: know the categories or specific pieces of Personal Information CuraeSoft has collected; delete Personal Information, subject to statutory exceptions; correct inaccurate Personal Information; opt out of any sale or sharing; limit the use and disclosure of Sensitive Personal Information; and not be discriminated against for exercising these rights. 

14.4 How to Exercise California Rights

Submit a request by email to: coamplifi-support@curaesoft.com. CuraeSoft will verify the request using account information. Where the request implicates Personal Information that crossed the Shared Info Bridge in a W2W context, CuraeSoft will coordinate with the relevant Connected Customer as described in Section 16. 

14.5 Global Privacy Control

CuraeSoft honors Global Privacy Control (GPC) signals as required by California Civil Code §1798.135(b)(1) and 11 CCR §7025 for opt-out of any sharing activity based on cookie identifiers. 

14.6 Limit the Use of My Sensitive Personal Information

Under CPRA §1798.121, you have the right to direct us to limit our use and disclosure of sensitive personal information to uses that are necessary to perform the Services or as otherwise permitted by CPRA. CuraeSoft uses sensitive personal information only to the extent necessary to provide the Services. To request that we limit any additional use, contact us at coamplifi-support@curaesoft.com. 

15. Your Other US State Privacy Rights

15.1 Covered States

As of the effective date of this Privacy Policy, comprehensive privacy laws are in effect in Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Texas, Florida, Oregon, Tennessee, Montana, New Hampshire, New Jersey, Delaware, Maryland, Minnesota, Rhode Island, Nebraska, and Kentucky. CuraeSoft will treat residents of additional states as having equivalent rights from those states’ effective dates. 

15.2 Rights Available

Across these state laws, residents generally have the right to access, delete, correct, and port their Personal Information; to opt out of targeted advertising, sale, and certain profiling; and to appeal a denied request. 

15.3 How to Exercise Rights

Email coamplifi-support@curaesoft.com and CuraeSoft will respond within the timeframe required by applicable state law, typically 45 days. 

15.4 Appeals

Where applicable state law provides an appeal right, residents may appeal a denied request to coamplifi-support@curaesoft.com. CuraeSoft will respond to appeals within 60 days. If the appeal is denied, the resident may contact the relevant state Attorney General. 

16. Your General Privacy Rights

Subject to legal exemptions, you may have the right to request access to your Personal Information, to update, delete, or correct it, to receive a portable copy, to opt out of certain processing, or to object to processing based on legitimate interests. You can exercise many of these rights through in-product settings. If in-product settings are insufficient, contact the Customer who controls your Workspace. If the Customer cannot assist, contact CuraeSoft at coamplifi-support@curaesoft.com. 

17. Data Protection Authority

coAmplifi Pro is currently a US-only product. CuraeSoft has not designated a Data Protection Officer within the meaning of GDPR Article 37, nor an EU Representative under GDPR Article 27. When CuraeSoft expands internationally, a DPO will be designated and an EU Representative will be appointed, with contact details reflected in the Privacy Policy. 

18. Limitation of Liability

18.1 Excluded Damages

EXCEPT FOR THE EXCLUSIONS IN SECTION 18.3, IN NO EVENT WILL CURAESOFT BE LIABLE TO YOU FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, COVER, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUES, BUSINESS INTERRUPTION, LOST BUSINESS OPPORTUNITIES, LOSS OF DATA, OR LEGAL FEES OR COSTS ARISING OUT OF OR RELATED TO THIS PRIVACY POLICY OR YOUR USE OF THE SERVICES, REGARDLESS OF THE THEORY OF LIABILITY, AND REGARDLESS OF WHETHER CURAESOFT HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. 

18.2 Aggregate Cap

EXCEPT FOR THE EXCLUSIONS IN SECTION 18.3, CURAESOFT’S TOTAL CUMULATIVE LIABILITY TO YOU ARISING OUT OF OR RELATED TO THIS PRIVACY POLICY OR YOUR USE OF THE SERVICES IS LIMITED TO ONE HUNDRED U.S. DOLLARS (USD $100.00) IN THE AGGREGATE (THE “CAP”). 

18.3 Exclusions from Cap and Excluded Damages

The exclusions in Section 18.1 and the Cap in Section 18.2 do not apply to: (a) liability that cannot be limited under applicable law, including liability under FOSTA-SESTA (47 U.S.C. §230(e)(5); 18 U.S.C. §1591; 18 U.S.C. §2421A) as further described in Section 19; liability to data subjects under any Data Protection Law to the extent it cannot be contractually limited; liability for death or personal injury caused by negligence where such liability cannot be limited by contract; and any other liability that applicable law prohibits from being limited or excluded by contract; (b) liability arising from CuraeSoft’s gross negligence or willful misconduct; (c) liability arising from CuraeSoft’s fraud or fraudulent misrepresentation; or (d) liability arising from CuraeSoft’s intentional breach of its data protection obligations under this Privacy Policy, which liability is capped at three (3) times the Cap in Section 18.2, subject in all cases to an absolute ceiling equal to the limits of CuraeSoft’s then-current cyber liability insurance coverage (the “Confidentiality Super-Cap”), and is not subject to the excluded damages in Section 18.1; or (e) Customer’s obligation to pay Fees and Taxes due under the Customer Terms. 

18.4 Duty to Mitigate.

You have a duty to take reasonable steps to mitigate your damages upon becoming aware of any event or circumstance that has given or may give rise to a claim under this Privacy Policy. 

18.5 Basis of the Bargain.

You acknowledge that the limitations of liability in this Section 18 reflect a reasonable allocation of risk and are an essential element of the basis of the bargain between you and CuraeSoft. The limitations apply notwithstanding any failure of essential purpose of any limited remedy and regardless of whether any party has been advised of the possibility of such damages. 

18.6 Anti-Stacking.

The Cap in Section 18.2 (including the Confidentiality Super-Cap in Section 18.3) is consolidated with any Cap in the Customer Terms or User Terms of Service such that aggregate liability of CuraeSoft for the same underlying facts is the single higher Cap, not the sum. 

19. FOSTA-SESTA Carve-Out

Nothing in this Privacy Policy is intended to or shall be construed to release, waive, or limit any claim arising under 18 U.S.C. §1591 or 18 U.S.C. §2421A as enacted or amended by FOSTA-SESTA (Pub. L. 115-164), to the maximum extent required by 47 U.S.C. §230(e)(5). 

20. Application of Consumer Law

coAmplifi Pro is a workplace tool intended for use by businesses and organizations and not for consumer purposes. To the maximum extent permitted by law, you acknowledge that consumer laws do not apply to your use of the Services. If consumer laws apply and cannot otherwise be 

lawfully excluded, nothing in this Privacy Policy will restrict, exclude, or modify any statutory warranties, guarantees, rights, or remedies that you have under those consumer laws.

21. Survival

Sections 18 (Limitation of Liability), 19 (FOSTA-SESTA Carve-Out), 21 (Survival), 22 (Governing Law and Dispute Resolution), and 23 (General Provisions) survive any termination or expiration of your use of the Services or your relationship with CuraeSoft.

22. Governing Law, Jury Trial Waiver, and Dispute Resolution

22.1 Governing Law and Venue

This Privacy Policy and any disputes arising out of or related to it will be governed exclusively by the laws of the State of Delaware, without regard to conflicts-of-laws rules. Subject to Section 22.3, the state and federal courts of New Castle County, Delaware will have exclusive jurisdiction. 

22.2 Jury Trial Waiver

YOU AND CURAESOFT EACH KNOWINGLY AND IRREVOCABLY WAIVE ANY RIGHT TO TRIAL BY JURY IN ANY ACTION, PROCEEDING, OR COUNTERCLAIM ARISING OUT OF OR RELATING TO THIS PRIVACY POLICY OR YOUR USE OF THE SERVICES, TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW. 

22.3 Binding Arbitration Agreement and Class Action Waiver

Pre-Arbitration Notice. Before initiating arbitration, the party asserting a Dispute must provide written notice to the other party specifying in reasonable detail the nature of the Dispute and the relief sought. The parties agree to negotiate in good faith for sixty (60) days. Notices of Dispute to CuraeSoft must be sent to legal@curaesoft.com

(a) Agreement to Arbitrate. Except for equitable relief, TROs, and IP enforcement litigation, You and CuraeSoft agree that any dispute, claim, or controversy arising out of or relating to this Privacy Policy, your use of the Services, or CuraeSoft’s collection, use, or disclosure of your information (each a “Dispute”) will be resolved by final and binding individual arbitration administered by the AAA under its Commercial Arbitration Rules and, where applicable, its Consumer Arbitration Rules. The Federal Arbitration Act (9 U.S.C. §§1–16) governs. 

(b) CLASS ACTION AND COLLECTIVE ACTION WAIVER. YOU AND CURAESOFT EACH AGREE THAT ANY DISPUTE WILL BE BROUGHT IN AN INDIVIDUAL CAPACITY ONLY 

AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, MULTI-CUSTOMER, REPRESENTATIVE, OR PRIVATE ATTORNEY GENERAL ACTION OR PROCEEDING. IF THIS WAIVER IS HELD UNENFORCEABLE WITH RESPECT TO ANY CLAIM, THEN THAT CLAIM (AND ONLY THAT CLAIM) WILL BE SEVERED AND ADJUDICATED IN A COURT OF COMPETENT JURISDICTION UNDER SECTION 22.1, AND ALL OTHER CLAIMS WILL REMAIN SUBJECT TO ARBITRATION. 

(c) Arbitrator Bound by Limitation of Liability. The arbitrator is bound by the limitation of liability in Section 18, including the Cap in Section 18.2, the Confidentiality Super-Cap in Section 18.3, and the excluded damages in Section 18.1, and may not award damages in excess of the Cap or Super-Cap or award any category of damages excluded by Section 18.1, except for any liability that under Section 18.3 cannot be limited or excluded by contract. (d) Costs and Fee Shifting. CuraeSoft will reimburse Your AAA filing fee for Disputes under USD 75,000 that are not mass arbitrations. CuraeSoft will pay all AAA administrative and arbitrator fees for such Disputes. If CuraeSoft’s last written settlement offer is lower than the arbitrator’s award, CuraeSoft pays the greater of the award or USD $1,000.00 plus Your reasonable attorneys’ fees. The arbitrator may award costs against either party for frivolous claims. 

(e) Mass Arbitration. If 5 or more similar Disputes are filed within 365 days by the same law firm or organization, AAA’s Mass Arbitration Supplementary Rules apply. The parties will select 3 bellwether cases, stay the remainder pending resolution, and engage in 60-day mediation before stayed cases may proceed. 

(f) Confidentiality. Arbitration proceedings, documents, and awards are confidential except as required by law, to enforce an award, to counsel/accountants/insurers under confidentiality obligations, or with both parties’ written consent. 

(g) Severability. If any portion of this Section 22.3 other than the Class Action Waiver in subsection (B) is held unenforceable, that portion will be severed and the remainder will continue in effect. If the Class Action Waiver is held unenforceable in its entirety, this Section 22.3 will be void and any Dispute will proceed in court under Section 22.1.

23. General Provisions

23.1 Notices.

Notices to CuraeSoft must be sent to coamplifi-support@curaesoft.com. Notices are deemed received the day after sending. 

23.2 Modifications.

CuraeSoft may modify this Privacy Policy from time to time. Material modifications take effect on the date stated in the notice. Non-material modifications take effect on posting. 

23.3 Waiver.

No failure or delay by either party in exercising any right under this Privacy Policy constitutes a waiver of that right. 

23.4 Severability.

If any provision of this Privacy Policy is held by a court of competent jurisdiction or arbitrator to be unenforceable, the provision will be modified to be enforceable to the maximum extent that preserves its intent. 

23.5 Entire Agreement.

This Privacy Policy, together with Part II (Cookie Policy) and any terms incorporated by reference, constitutes the entire agreement between you and CuraeSoft with respect to the privacy of your information.

24. Version Control

Each version of this document is dated and archived. 

Revision 
#
Details of Change Issuance / 
Revision 
date
Reason for 
Change
Changes 
Done By
Changes 
Approved 
By
01  Issuance  05.28.2026  Issuance  ISO  CRO

25. Contact

coamplifi-support@curaesoft.com

CuraeSoft Corporation · 39 Beta Court, San Ramon, CA 94583 · Attn: Privacy 

By clicking “I Agree” and/or continuing to use the Services, You: (1) acknowledge that you have read and agree to this Privacy Policy; (2) consent to receive all related records and disclosures electronically under the federal E-Sign Act (15 U.S.C. §7001) or California UETA (Cal. Civ. Code §1633.1); (3) acknowledge that your electronic action constitutes your legally binding acknowledgment; (4) confirm you have the hardware and software to access and retain these records; (5) understand you may withdraw consent to electronic delivery by emailing coamplifi-support@curaesoft.com; (6) represent that you are at least 18 years old; (7) acknowledge that you can read, write, and understand the English language; and (8) confirm that you have the legal authority to bind yourself and, where applicable, the organization you represent.

PART II — COOKIE POLICY

This Cookie Policy explains how CuraeSoft Corporation (“CuraeSoft,” “we,” “us”) uses cookies and similar technologies on coamplifi.com and related CuraeSoft websites (the “Sites”) and within coAmplifi Pro (the “Services”). This Cookie Policy is Part II of the coAmplifi Privacy and Cookie Notice. Capitalized terms used but not defined here have the meanings given in Part I. 

C.1. Scope

This Cookie Policy applies to the Sites and the Services. It does not apply to third-party applications or integrations that connect to the Services through coAmplifi APIs. Marketing cookies are used on the Sites only and are never deployed within the authenticated Services product. 

C.2. Definitions

  • Consent Management Platform (CMP). A software service that collects, records, and manages your cookie-preference selections and enables or disables specific cookie categories accordingly. 
  • Cookie. A small text file placed by a website on your device. References to “cookies” in this policy also include similar technologies — web beacons, single-pixel GIFs, browser local storage and session storage, SDK telemetry in mobile applications, and mobile-device advertising identifiers — where used for similar purposes. 
  • Persistent Cookie. A Cookie that remains on your device until it expires or you delete it. 
  • Session Cookie. A Cookie that is deleted when you close your browser. 
  • Sites. coamplifi.com and related domains operated by CuraeSoft, including marketing pages, the blog, and the help center. 
  • Third-Party Cookie. A Cookie set by a domain other than the domain you are browsing. 

C.3. What Is a Cookie?

Cookies are small text files sent by us to your computer or mobile device that enable Sites and Services features and functionality. Session Cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent Cookies last until you or your browser delete them or until they expire. Other similar technologies include single-pixel GIFs (also called web beacons), browser local storage and session storage, SDK telemetry, and mobile-device advertising identifiers. 

C.4. Do We Use Cookies?

Yes. CuraeSoft uses cookies and similar technologies on both the Sites and the Services. We use both Session Cookies and Persistent Cookies. Some cookies are associated with your account and personal information in order to remember that you are signed in and which Workspaces you are signed in to. Other cookies are not tied to your account but are unique and allow CuraeSoft to carry out analytics, security, and similar functions. 

C.5. How We Use Cookies

The table below summarizes the categories of cookies we use, where each is used, and typical retention periods. 

Category  Purpose  Where Used  Type
Authentication  Identify the signed-in user; route to the correct Workspace; support multi-factor authentication. Sites + 
Services
Session and 
Persistent
Security  Fraud detection; CSRF protection; session integrity; suspicious-login detection. Sites + 
Services
Session and 
Persistent
Preferences  Language; accessibility; 
communication preferences; 
recently-viewed content.
Sites + 
Services
Persistent
Performance / Analytics Understand how the Sites and Services are used; identify where to invest engineering effort. Analytics in the Services are scoped to operating, securing, and improving the Services — not for advertising. Sites + 
Services 
(scoped)
Persistent
Marketing  Deliver marketing campaigns and track campaign performance. Not used in the Services. Sites only  Persistent
Third-Party 
Analytics
Aggregated site analytics. Not used in the Services. Sites only  Persistent

C.6. Vendor Management (W2W) Cookie Considerations

C.6.1 Cookie Isolation Across Connected Customers

Cookies set in one Customer’s Workspace are scoped to that Customer’s Workspace and to the Authorized User who is signed in. Cookies do not propagate from one Connected Customer’s Workspace to another through the Shared Info Bridge. 

C.6.2 Bridge Data and Cookies

Shared Info Bridge data flows are not carried in cookies. The substantive Bridge data flows through authenticated API endpoints and is not stored client-side in cookies. 

C.7. Third-Party Cookies

The Sites use a limited number of Third-Party Cookies, primarily for analytics. Third-Party Cookies are limited to the Sites; the Services do not use Third-Party Cookies for marketing, advertising, or cross-context behavioral advertising. 

C.8. Advertising Cookies

CuraeSoft and its marketing partners use cookies and other ad technologies on the Sites to operate marketing campaigns more effectively and to measure campaign performance. These technologies are limited to the Sites and are not used in the Services. To opt out of interest-based advertising from participating ad servers, use the Digital Advertising Alliance opt-out tool at optout.aboutads.info or the Network Advertising Initiative opt-out tool at optout.networkadvertising.org. 

C.9 Managing Cookie Preferences

You have multiple ways to control how cookies are used on the Sites. 

Browser controls. Most browsers allow you to view, manage, delete, and block cookies through their settings menu. You can also configure your browser to alert you before a cookie is stored. Because these controls are browser-specific, the steps differ across Chrome, Safari, Firefox, Edge, and others; instructions are available in each browser’s help documentation. Blocking Strictly Necessary cookies may prevent the Sites from functioning correctly. 

Cookie Preference Banner. When you first visit the Sites — and at any time thereafter via the “Cookie Settings” link in the Sites’ footer — you are presented with a cookie preference banner. Consistent with the symmetry-in-choice principle reflected in CPRA Regulations (11 CCR §7004), the banner presents three options of equivalent prominence (identical color, size, and font weight): 

  • Accept All — permits the Sites to use all cookie categories described in Section C.5, including Analytics, Marketing, and Third-Party cookies. 
  • Reject All — blocks all non-essential cookies. Strictly Necessary cookies (authentication, session management, security) remain active because the Sites cannot function without them. 
  • Manage Preferences — opens a secondary panel where you can enable or disable each non-essential cookie category individually (Functional, Analytics, Marketing, Third-Party). 

Persistence and re-prompt. Your selection is recorded and persists until you change it, clear your browser cookies, or a material change to this Cookie Policy triggers a re-prompt (see Section C.12). Non-essential cookies are not loaded until you have made an affirmative selection; closing the banner without choosing does not constitute consent. 

Account-level controls. If you are signed into a CuraeSoft account, your cookie preferences for the browser are also recorded against your account record where you have opted out of “sale” or “sharing” under Section C.11. 

C.10 Do Not Track Signals

The Sites and the Services do not collect Personal Information about your online activities in a manner that “Do Not Track” (“DNT”) signals are designed to address. As a result, DNT signals do not currently alter CuraeSoft’s data collection or use practices. This disclosure is provided pursuant to California Business and Professions Code §22575(b)(7). For affirmative tracking controls that CuraeSoft does honor, see Section C.9 (cookie preferences) and Section C.11 (Global Privacy Control). 

Functionality. When the Sites detect a DNT header in your browser request, no behavioral change occurs and no separate DNT-specific notice is presented. The cookie preference banner described in Section C.9 is displayed unchanged, and you may use those controls to exercise the cookie choices CuraeSoft does honor. 

C.11 Global Privacy Control

CuraeSoft recognizes the Global Privacy Control (“GPC”) signal as a valid request to opt out of the “sale” or “sharing” of Personal Information within the meaning of California Civil Code §1798.135(b)(1), 11 CCR §7025, and analogous provisions of other US state privacy laws. When a GPC signal is received from your browser, CuraeSoft treats it as a properly authenticated opt-out request and applies the opt-out to the browser and, where you are signed in, to your CuraeSoft account. 

Functionality. When the Sites detect a GPC header in your browser request: 

  • The cookie preference banner described in Section C.9 is displayed with Marketing, Analytics, and Third-Party Cookie categories pre-set to “off.” Strictly Necessary cookies remain enabled because the Sites cannot function without them. 
  • A confirmation indicator is shown adjacent to the banner: “Global Privacy Control detected — sale/sharing opt-out applied.” 
  • If you are signed into a CuraeSoft account at the time the GPC signal is received, the opt-out is applied to your account record and persists across the browsers and devices on which you subsequently sign in. 
  • To override the GPC default for any non-essential category, open the “Manage Preferences” panel (Section C.9) and toggle that category on. The override is recorded as your affirmative consent for that category on that browser and does not change the account-level opt-out for other categories. 
  • The GPC opt-out is logged with timestamp, browser fingerprint (where available), and account ID (where signed in) to provide audit evidence of the opt-out being honored. 

C.12 Changes to This Cookie Policy

CuraeSoft may update this Cookie Policy from time to time. Material updates — including new cookie categories, new Third-Party Cookie providers, or new purposes of use — will be notified by email to the Customer’s administrative contact and through in-product notification at least thirty (30) days before they take effect. Non-material updates take effect on publication. Prior versions remain available in the Terms & Policy Archives at coamplifi.com. 

Functionality.

  • For material changes — adding a cookie category, adding a Third-Party Cookie provider, adding a processing purpose, or reducing user control — notice is delivered through three channels at least thirty (30) days before the effective date: (i) email to each Customer’s administrative contact; (ii) a banner on the Sites linking to the redlined version; and (iii) an in-product notification within coAmplifi Pro. 
  • For material changes that affect cookie consent specifically — the cookie preference banner re-prompts on first visit after the effective date. Non-essential cookies are not loaded until a new selection is made; Strictly Necessary cookies continue to operate. 
  • For non-material changes — typo fixes, contact-information updates, clarifications, formatting — the updated Cookie Policy is published with no banner re-prompt. ● Prior versions are archived at coamplifi.com/legal/privacy/archive for at least seven (7) years, with a redline of each version against the version that immediately preceded it. 

C.13. Version Control

Each version of this document is dated and archived. 

Revision 
#
Details of Change Issuance / 
Revision 
date
Reason for 
Change
Changes 
Done By
Changes 
Approved 
By
01  Issuance  05.28.2026  Issuance  ISO  CRO

C.14. Contact

coamplifi-support@curaesoft.com

CuraeSoft Corporation · 39 Beta Court, San Ramon, CA 94583 · Attn: Privacy © 2026 CuraeSoft Corporation. All rights reserved.