GERM Datahouse · Effective September 13, 2026

Privacy Policy

This policy describes how GERM Datahouse (the “Software”), operated by Salient Global Technologies Corp., handles data. The Software is private internal business software. It has no external users and no customers: the only people who use it are employees and authorized contractors of the Company, and the only business data it processes belongs to the Company.

1. What the Software does

GERM Datahouse consolidates the Company's own business records from the systems the Company already uses into a single internal database, so the Company can report on its own operations. It reads from those systems on a schedule. It does not write to them, and it does not modify records held in them.

2. Data sources and what is accessed

Access to each source is authorized by an administrator of the Company's own account for that service, using that service's standard authorization flow. No data is accessed from any account the Company does not own, and no data is passed from one source system into another — each is read independently into the Company's internal reporting database.

3. Why the data is used

Solely for the Company's internal reporting and analysis of its own business — financial reporting, project and inventory reporting, and operational dashboards used by Company staff. The data is not used for any other purpose.

4. Data the Software does not collect

  • No data belonging to any other business or third party.

  • No payment card numbers, card security codes, or cardholder data.

  • No personal data beyond the business contact details already present in the Company's own accounting and project records.

  • No end-consumer or website visitor data.

5. Where data is stored and who can reach it

Data is stored in databases running on infrastructure controlled by the Company on its internal network. The system is not published to the public internet and is not reachable from outside the Company's network.

Access is limited to authorized Company personnel and is role based: users are granted the minimum level of access needed for their work. Authentication is required for every request, and administrative functions are restricted to designated administrators.

6. Data sharing

Data is not sold, rented, or shared with any third party. It is not shared between customers, because the Software has no customers — it processes only the Company's own records for the Company's own benefit. Data is not used to produce aggregated or anonymized insights for anyone outside the Company.

Third-party service providers, including Intuit, receive only the API requests necessary to retrieve the Company's own data, in accordance with their terms.

7. Credentials and security

  • Authorization tokens for connected services are encrypted before being stored, with the encryption key held separately from the data.

  • Application credentials, including client identifiers and secrets, are held in server-side configuration. They are never exposed to a browser, never embedded in application code, and are excluded from version control.

  • The database holding authorization tokens is isolated on an internal network segment and is not reachable from the reporting or analytics layer.

  • Passwords and PINs are stored only as salted hashes, never in plain text.

  • Accounts lock automatically after repeated failed authentication attempts.

  • Errors and access are logged for troubleshooting; logs do not record credentials.

8. Retention

Business records are retained for as long as they are useful for the Company's reporting, consistent with the Company's records-retention practice and any applicable legal or tax obligation. Records deleted in a source system are marked as deleted rather than removed, so that historical reports remain accurate. Intermediate raw API responses are retained for a limited period and then purged automatically. Encrypted database backups are retained on a rolling schedule and then deleted.

9. Legal compliance

The Company handles this data in accordance with applicable data protection law, which may include the GDPR, CCPA, LGPD and PIPEDA to the extent they apply to the Company's activities.

10. Requests and questions

Individuals whose business contact details appear in the Company's records may request information about that data, or its correction or deletion, by contacting the address below. Requests are handled in accordance with applicable law and the Company's obligations to retain business and financial records.

11. Changes

This policy may be updated. The effective date above indicates when this version took effect.

12. Contact

info@sgtcorp.com
Salient Global Technologies
11252 Leo Ln
Dallas, TX 75229

Source Data Accessed Direction
Intuit QuickBooks Online Accounting records from the Company's own QuickBooks company file — customers, vendors, invoices, bills, payments, accounts, items and related transactions, via the QuickBooks Accounting API Read only
Other business systems operated by the Company Project, client, expense, inventory and related operational records from the Company's own accounts with the business software it uses Read only

Salient Global Technologies · Intuit and QuickBooks are registered trademarks of Intuit Inc. Used with permission.