IMPORTANT NOTICE
This Privacy Policy applies to Niwt, LLC and its DoDPOM defense budget intelligence platform services. This policy works together with our Terms of Service. Capitalized terms not defined here have the meanings in the Terms of Service.
Key Points
- ·We handle data as both Controller (our operations) and Processor (your platform data)
- ·U.S. businesses only - no EU/UK/Swiss users or data
- ·We do NOT sell personal information or use it for advertising
- ·We do NOT train AI models on your customer data
- ·Contact privacy@dodpom.com for any privacy requests
1. Scope and Roles
This Privacy Policy explains how Niwt, LLC ("Niwt" or the "Company") handles personal information in connection with the DoDPOM platform:
• Controller context (DoDPOM-Direct PI): our websites, sales/marketing operations, account administration, billing, support, and security operations we run for ourselves.
• Service Provider/Processor context (Customer Data): information we process on behalf of our business customers inside the Platform. In this context, the customer controls the data and directs our processing.
Capitalized terms not defined here have the meanings in the Terms of Service.
• Controller context (DoDPOM-Direct PI): our websites, sales/marketing operations, account administration, billing, support, and security operations we run for ourselves.
• Service Provider/Processor context (Customer Data): information we process on behalf of our business customers inside the Platform. In this context, the customer controls the data and directs our processing.
Capitalized terms not defined here have the meanings in the Terms of Service.
2. Geographic Scope and Data Processing
The Platform is available to businesses and professionals worldwide, subject to applicable export controls and sanctions (see ToS §27). The Platform is operated from the United States, and all data is stored and processed in the United States. By using the Platform, you acknowledge that your personal information will be transferred to and processed in the United States under U.S. law. If you access the Platform from outside the United States, you are responsible for compliance with local privacy and data protection laws applicable to your use.
3. What We Collect
3.1 DoDPOM-Direct PI (Controller)
Contact and account data (name, business email, phone), company details, billing/payment identifiers, authentication data (for DoDPOM accounts), support and communications, usage/telemetry of our sites and admin consoles, cookie/analytics data, and security logs.
3.2 Customer Data (Service Provider/Processor)
Data you input into the Platform, including search queries, pipeline notes, saved analyses, AI Analyst questions, and any derived Outputs. You, as Customer, determine the nature of this data and the access grants. We process it only as instructed to provide the Services.
3.3 Service/Usage Data and De-Identified Data
Operational telemetry, logs, performance metrics, and De-Identified Data created to operate, secure, and improve the Services.
3.4 No Children's Data
The Services are for business use and not directed to children under 13; Authorized Users must be 18+.
4. How We Use Information
4.1 For DoDPOM-Direct PI (Controller)
Provide and administer our sites and Services, communicate with you, process transactions, provide support, secure and protect against abuse, analyze and improve, and comply with law.
4.2 For Customer Data (Service Provider/Processor)
Provide, maintain, secure, support, and back up the Services, including processing search queries, generating AI responses, and storing pipeline notes. We do not sell Customer Data and do not use Customer Data for advertising. For non-Enterprise customers, aggregated and de-identified search patterns may be used to improve the Platform's domain ontology and search relevance (see ToS §10). For Enterprise-tier customers, Customer Data is not used to train models or ontologies that benefit other customers.
4.3 Service/Usage & De-Identified Data
Operate, secure, and improve the Services, capacity planning, and quality assurance. We will not attempt to re-identify De-Identified Data.
6. Third-Party Services and Integrations
The Platform uses third-party services for AI model inference (e.g., Amazon Bedrock), payment processing (Merchant of Record), and hosting infrastructure. When applicable, the third party's terms and privacy notices govern its handling of data. Subscription billing and payment data are processed by our Merchant of Record, not by the Company directly.
7. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information. No system is perfectly secure; we cannot guarantee absolute security. Security measures align with the ToS Security section.
8. Data Retention; Access, Export, and Deletion
We retain DoDPOM-Direct PI for as long as needed for the purposes above and as required by law. For Customer Data, access, export, retention, and deletion follow ToS §29 (Data Portability and Deletion) and any applicable DPA. After termination, we provide a retrieval window and then delete Customer Data from active systems, subject to backups/legal holds.
9. Your Privacy Requests
9.1 Where Niwt is Controller (DoDPOM-Direct PI)
You may request access, correction, deletion, or a copy of your DoDPOM-Direct PI, or opt-out of marketing. We will verify your identity and respond as required by applicable U.S. law.
9.2 Where Niwt is Service Provider/Processor (Customer Data)
For requests about Customer Data (including data tied to your employment—e.g., company email), contact your employer. We will assist the Customer in responding to the request as required by our DPA and applicable law.
9.3 Submission Channels
Email: privacy@dodpom.com. If we offer a web form, it will be linked on our site. You may authorize an agent as allowed by applicable law; we will verify both the agent and you.
10. California and Other U.S. State Privacy Laws
Niwt, LLC is a B2B provider. We do not sell or share personal information. If and when we meet a state law's applicability thresholds (e.g., CPRA, Colorado CPA, Virginia VCDPA, Connecticut, Utah), we will honor the rights provided by that law for DoDPOM-Direct PI (e.g., access, deletion, correction, appeal). For Customer Data, rights requests must be directed to the Customer (your employer). We do not discriminate for exercising rights permitted by law.
12. U.S. Hosting and Transfers
All data is stored and processed in the United States using Amazon Web Services (AWS) infrastructure in the us-east-1 region. If you access the Platform from outside the United States, your data will be transferred to the United States for processing. We do not currently operate data centers or store data outside the United States.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted to our site with an updated effective date. Your continued use after an update means you accept the revised Policy.
14. Contact Us
Last Updated: April 6, 2026
For questions about this Privacy Policy, please contact: privacy@dodpom.com