Internet Backyard Inc. d/b/a gnomos Privacy Policy

Last Updated: August 27, 2026

This Privacy Policy explains how Internet Backyard Inc., doing business as gnomos (“gnomos,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal information when you visit our websites, use our platform or other services, communicate with us, apply for a position, or otherwise interact with our business (collectively, the “Services”). It also describes the privacy choices and rights that may be available to you.

gnomos provides a platform that helps business customers (“Customers”) and their affiliated operators (“Operators”) manage the billing, verification, and settlement of compute and power usage transactions with their customers and end users (“Tenants”).

1. Scope and Our Role

This Privacy Policy applies when gnomos determines the purposes and means of processing personal information, including information relating to website visitors, account administrators, business contacts, prospective customers, job applicants, and other individuals who interact directly with us.

When gnomos processes information on behalf of a Customer, Operator, or Tenant as a service provider or processor, including “Customer Data” as defined in our Master Services Agreement, the relevant Customer generally determines why and how that information is processed. That processing is governed by our agreement with the Customer, including any applicable data processing agreement, rather than solely by this Privacy Policy. Privacy requests concerning Customer Data should ordinarily be directed to the relevant Customer. We may separately process limited account, security, billing, compliance, and business contact information for our own purposes as described below.

A supplemental notice, product notice, contractual term, or just-in-time disclosure may apply to a particular Service or processing activity. If a supplemental notice conflicts with this Privacy Policy, the supplemental notice controls for that activity.

2. Personal Information We Collect

The personal information we collect depends on how you interact with us and the Services. It may include the following categories.

  • Contact and business information. Name, company, title, business address, email address, telephone number, state or other general location, and information about your relationship with a Customer, Operator, Tenant, vendor, partner, or other organization.
  • Account and authentication information. Username, account identifier, authentication information, single sign-on information, role, permissions, account settings, login records, and other information used to establish and administer access to the Services.
  • Identity and business verification information. Information used for know-your-customer, know-your-business, fraud-prevention, or compliance checks, which may include identity documents, identification numbers, images, business-formation records, beneficial ownership information, verification results, and related records.
  • Transaction and financial information. Billing contacts, invoices, payment and settlement information, transaction records, reconciliation information, financial-institution or payment-processor information, and related commercial records. Payment-card or bank-account information may be collected directly by our financial services providers.
  • Platform and operational information. Information associated with Customers, Operators, Tenants, facilities, sites, equipment, compute resources, workloads, meter readings, power usage, service utilization, transactions, and related operational events. Depending on the circumstances, this information may constitute Customer Data processed on behalf of a Customer.
  • Communications and support information. Messages, support requests, survey responses, feedback, correspondence, and other information you provide when you communicate with us.
  • Call and meeting information. Meeting metadata and, after appropriate notice or consent where required, transcripts, notes, summaries, and action items created through an AI-assisted notetaking service.
  • Device, network, and usage information. IP address, browser type, operating system, device manufacturer and model, unique identifiers, language settings, mobile carrier, general location, referring pages, pages viewed, access times, clicks, scrolling, navigation paths, and other interactions with the Services.
  • Security and audit information. Login activity, access and event logs, security telemetry, fraud or abuse indicators, and information used to investigate or prevent unauthorized activity.
  • Marketing information. Communication preferences and information about how you interact with our marketing communications.
  • Job applicant information. Contact information, professional credentials and skills, educational and employment history, resume information, interview materials, compensation expectations, references, and diversity information you choose to provide.
  • Inferences and derived information. Information derived from other information described in this section, such as usage trends, operational insights, risk indicators, and analytics.

3. Sources of Personal Information

We collect personal information from the following sources:

  • Directly from you, including when you create or administer an account, submit a form, communicate with us, participate in a meeting, apply for a position, or otherwise provide information to us.
  • From Customers, Operators, Tenants, and other authorized users of the Services.
  • Automatically from your device or browser through cookies, software development kits, session-replay technology, logs, and similar technologies.
  • From single sign-on providers. If you sign in using Google or another supported identity provider, we receive information needed to authenticate your account, such as your name, email address, and account identifier, subject to the provider’s settings and privacy policy.
  • From identity-verification providers. When you are invited to and actively use the platform, Persona or another provider may collect identity or business-verification information and provide us with verification results and related information needed to provide the Services.
  • From financial institutions, sponsor banks, payment processors, service providers, business partners, public sources, and other third parties, as permitted by law.

4. How We Use Personal Information

We may use personal information to:

  • Provide, operate, maintain, and improve the Services.
  • Create and administer accounts, authenticate users, manage roles and permissions, and provide customer support.
  • Facilitate billing, payment, settlement, reconciliation, and related transaction administration.
  • Measure, validate, analyze, and report compute, power, platform, and service usage.
  • Conduct identity and business verification and support fraud, abuse, security, sanctions, financial-crime, and other compliance controls, as applicable.
  • Communicate with you about the Services, respond to inquiries, and send administrative or transactional notices.
  • Understand use of the Services, diagnose technical issues, develop features, and improve user experience.
  • Create and use aggregated or de-identified information for lawful business purposes, including analytics, product development, and strategic planning.
  • Promote our business and manage communication preferences. We do not currently use personal information for cross-context behavioral advertising or targeted advertising.
  • Protect the Services, our Customers, users, and others. Enforce agreements, investigate suspected unlawful activity, and establish, exercise, or defend legal claims.
  • Comply with applicable laws, regulations, legal process, and contractual obligations.
  • Conduct corporate transactions, audits, risk management, business continuity, and other internal business operations.

5. Legal Bases for Processing

Where data protection law requires a legal basis, we process personal information when necessary to perform a contract or take steps at your request before entering into a contract. We also process information to comply with legal obligations, pursue our legitimate interests or those of another party, protect vital interests, perform a task in the public interest where applicable, or act with consent. Our legitimate interests include operating and securing the Services, administering customer and business relationships, improving our products, preventing fraud and abuse, and protecting our legal rights. Where processing is based on consent, you may withdraw consent at any time without affecting processing that occurred before withdrawal.

6. Artificial Intelligence and Automated Processing

gnomos uses artificial intelligence and AI-assisted technologies in connection with aspects of its Services and business operations. We maintain an AI governance program designed to support the responsible evaluation, use, and oversight of these technologies, taking into account considerations such as privacy, security, accuracy, appropriate human involvement, and applicable legal requirements. We may update our practices and this Privacy Policy as our use of AI and our governance program evolve.

We do not currently use automated decision-making or profiling in a manner that produces legal or similarly significant effects concerning individuals. If that changes, we will provide any notice, choice, or other protection required by applicable law.

7. Cookies, Analytics, and Session Replay

We use cookies and similar technologies to enable website functionality, remember preferences, understand how the Services are used, diagnose technical issues, protect the Services, and improve user experience.

We use analytics and session-replay technologies, including PostHog. These technologies may collect or reconstruct interactions with the Services, such as page views, clicks, scrolling, navigation paths, and time spent on pages. We use privacy controls designed to mask or exclude information that may be sensitive. PostHog’s processing is also governed by its applicable privacy terms.

Where required by applicable law, we obtain consent before using non-essential cookies and similar technologies. You may decline or withdraw that consent through our cookie settings, available through the link in the website footer. The affected technologies will remain disabled or stop collecting information after your choice takes effect. You may also use browser controls to block or delete cookies, although doing so may affect certain features of the Services.

8. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients for the purposes described in this Privacy Policy:

  • Customers, Operators, Tenants, and authorized users when disclosure is necessary to provide the Services or facilitate authorized platform activity.
  • Service providers supporting cloud hosting, infrastructure, information technology, customer support, communications, analytics, session replay, authentication, identity verification, AI-assisted transcription and productivity, security, monitoring, and other business functions.
  • Sponsor banks, regulated financial institutions, payment processors, and other financial services partners in connection with payment, billing, settlement, and related services. Current partner information may be identified in the Master Services Agreement or an applicable subprocessor list.
  • Professional advisers, including lawyers, auditors, accountants, bankers, and insurers, as appropriate for the services they provide.
  • Government authorities, law enforcement, courts, regulators, and other parties when we believe disclosure is required or appropriate to comply with law, protect rights or safety, prevent fraud or unlawful activity, or respond to legal process.
  • An acquirer, investor, lender, or other participant in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction.
  • Other parties at your direction, with your consent, or as otherwise disclosed when the information is collected.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We may use or disclose aggregated or de-identified information that cannot reasonably be used to identify you, subject to applicable law. Where required by law, we maintain de-identified information in de-identified form and do not attempt to reidentify it except as permitted to test our de-identification processes.

9. Sensitive Personal Information and Identity Verification

Some information processed in connection with identity, business, payment, security, or compliance functions may be considered sensitive personal information under applicable law. This may include government-issued identification information, account credentials, financial information, and information derived from identity-verification materials. Persona or another verification provider may collect certain verification information directly and provide gnomos with verification results and related information.

We use sensitive personal information only for purposes reasonably necessary and proportionate to provide the Services, verify identity or business status, administer transactions, protect accounts and systems, prevent fraud or unlawful activity, comply with law, or as otherwise permitted by applicable law. We do not use sensitive personal information to infer characteristics about individuals for unrelated purposes.

10. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, administer customer relationships and accounts, maintain transaction and tax records, protect security, resolve disputes, enforce agreements, and comply with legal obligations. Retention periods vary depending on the type of information and context in which it was collected.

In determining retention periods, we consider the amount, nature, and sensitivity of the information. We also consider the purposes for which it is processed, applicable contractual and legal requirements, security and fraud prevention needs, applicable limitation periods, and whether the information is subject to a dispute, investigation, audit, or legal hold. Identity verification materials, security and audit logs, analytics and session replay information, meeting transcripts and summaries, marketing records, applicant information, and transaction records may therefore be retained for different periods. When information is no longer required, we take reasonable steps to delete, de-identify, or securely dispose of it, subject to applicable law and technical limitations.

11. Data Security

We maintain technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, acquisition, use, alteration, disclosure, or destruction. Depending on the nature of the information and processing, these safeguards may include access controls and authentication, encryption, logging and monitoring, data minimization, retention controls, vendor-risk management, personnel safeguards, incident-response procedures, and periodic testing or assessment. No security measure is perfect or impenetrable, and we cannot guarantee absolute security.

12. International Data Transfers

We are based in the United States and may process and store personal information in the United States and other countries where we or our service providers operate. Those countries may have data protection laws that differ from the laws where you live. When we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country not recognized as providing an adequate level of protection, we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful safeguard, as applicable.

13. Your Privacy Choices

Marketing Communications

You may opt out of marketing emails at any time by using the unsubscribe link in the message or contacting us. We may continue to send administrative, transactional, security, or other non-marketing communications necessary to our relationship with you.

Account and Cookie Choices

You may update certain account information through the Services or by contacting us. You may manage non-essential cookies through our cookie settings as described above. Closing an account or requesting deletion may affect your ability to use the Services, and we may retain information as required or permitted by law or contract.

14. U.S. State Privacy Rights

Depending on where you live and subject to applicable exceptions, you may have the right to confirm whether we process your personal information. You may also have the right to access and obtain a copy of it, correct inaccuracies, delete it, obtain it in a portable format, opt out of its sale or use for targeted advertising, limit certain uses or disclosures of sensitive personal information, and appeal a decision regarding a privacy request. Some laws also provide a right to opt out of certain profiling. You may have the right not to receive discriminatory treatment for exercising a privacy right.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. To exercise an applicable right, contact us using the information in Section 20. Please describe your request and provide sufficient information for us to identify the relevant records. We will verify and respond to requests as required by applicable law. You may designate an authorized agent to act on your behalf, subject to applicable verification requirements. If we deny an appealable request, our response will explain how to submit an appeal.

California Shine the Light

California residents may request, once per calendar year and free of charge, information concerning certain disclosures of personal information to third parties for those parties’ direct marketing purposes during the preceding calendar year. Contact us to submit a request.

15. EEA, UK, and Swiss Privacy Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, applicable law may give you the right to access personal information, correct inaccurate information, request deletion, restrict processing, and object to processing based on legitimate interests or for direct marketing. You may also have the right to receive certain information in a portable format, withdraw consent, and lodge a complaint with a competent supervisory authority. You may have additional rights concerning decisions based solely on automated processing that produce legal or similarly significant effects. These rights are subject to applicable conditions and exceptions. To exercise a right, contact us using the information in Section 20.

16. Children’s Privacy

The Services are designed for businesses and are not directed to children under 18. We do not knowingly collect personal information through the Services from children under 13. If we learn that we have collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it.

17. Job Applicants and Business Contacts

If you apply for a position, we use applicant information to evaluate qualifications, conduct interviews and background or reference checks where permitted, communicate about the application, administer recruiting, meet legal obligations, and establish or defend legal claims. We may disclose applicant information to recruiting, background-check, technology, and professional-service providers and to authorities where required by law.

If you interact with us as a representative of a Customer, prospective customer, vendor, partner, or other organization, we use your information to administer the relationship, communicate with your organization, provide or receive services, conduct diligence, manage contracts and transactions, protect our business, and comply with law.

18. Third-Party Services and Social Media

The Services may contain links to third-party websites, applications, or services. This Privacy Policy does not govern the privacy, security, or other practices of third parties acting for their own purposes, and a link does not imply our endorsement. We also maintain pages on third-party social media platforms. If you interact with us there, we may receive information about that interaction. Information collected by the platform is governed by its own privacy policy.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the current version and update the “Last Updated” date above. If we make material changes, we may provide additional notice as required by applicable law, such as by posting a prominent notice on the Services or sending a notice to an email address associated with an account.

20. How to Contact Us

For questions, comments, or requests concerning this Privacy Policy or our privacy practices, contact us at:

Internet Backyard Inc., d/b/a gnomos 1209 Orange St Wilmington, DE 19801 Email: compliance@internetbackyard.com