Privacy Policy
What we do with your information, and what we never will.
The full notice: what we collect across our sites and products, how it is used, who sees it, how long we keep it, and how to reach us about any of it.
Effective September 20, 2026 · Last updated September 20, 2026
Limestone Technology Group (“Limestone,” “we,” “our,” or “us”) develops and operates software, automation, artificial intelligence, cloud, and related technology services for businesses and public-sector organizations.
LimestoneBiz and LimestoneGov are divisions and trade names of Limestone Technology Group. Limestone Technology Group is the entity responsible for the information practices described in this Privacy Policy.
This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Information through websites, software products, platforms, customer portals, web and mobile applications, support services, communications, AI-enabled functions, automation services, and other services owned or operated by Limestone or displaying this Privacy Policy, including the websites at limestonetg.com, limestonegov.com, limestonebiz.com, and partners.limestonetg.com.
Collectively, these are referred to in this Privacy Policy as the “Services.”
1. Relationship to customer agreements
For a customer that purchases or uses Limestone Products, capitalized terms including “Platform,” “Module,” “Products,” “Service,” “Service Order,” “Authorized Users,” “Licensed Users,” “Participants,” “Customer Data,” and “Customer Confidential Information” have the meanings stated in the applicable LimestoneBiz or LimestoneGov Master Services Agreement.
This Privacy Policy provides general public notice of Limestone’s information practices. It does not:
- order a Product or Module;
- amend a Master Services Agreement;
- modify a Service Order;
- replace a signed data-processing or regulated-data addendum; or
- create a customer-specific security, retention, or compliance commitment.
When Limestone processes Customer Data under a Master Services Agreement, the applicable signed amendment, Service Order, Master Services Agreement, schedules, and addenda govern that processing.
If this Privacy Policy conflicts with an applicable customer agreement concerning Customer Data, the applicable customer agreement controls to the extent of the conflict. Applicable privacy law continues to control where it cannot lawfully be modified by contract.
2. Limestone's privacy roles
Limestone handles Personal Information in two principal capacities.
2.1 Information controlled by Limestone
Limestone determines how Personal Information is used when we collect it for our own:
- websites;
- sales and demonstrations;
- customer and vendor relationships;
- billing and administration;
- support operations;
- security;
- recruiting;
- marketing communications; and
- general business operations.
For this information, Limestone generally acts as the business or controller responsible for the processing.
2.2 Customer Data
The applicable customer generally determines why and how Customer Data is collected and used through the Service.
“Customer Data” includes data, text, records, attachments, instructions, and other content submitted by or for a customer through the Service.
For Customer Data, Limestone generally acts as a service provider or processor. We process Customer Data according to:
- the customer's documented instructions;
- the applicable Service Order;
- the applicable Master Services Agreement and schedules;
- any signed addendum; and
- applicable law.
Customers determine what Customer Data is submitted, which Authorized Users may access it, and what customer-specific retention or disclosure requirements apply.
If your Personal Information was submitted to a Limestone Product by a customer, requests concerning that information should normally be directed to the customer. Limestone will assist the customer as required by the applicable agreement and law.
3. Personal Information we collect
“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked with an individual or household.
Personal Information does not include aggregated or de-identified information that cannot reasonably be linked to an individual, household, or identified customer.
Depending on how you interact with Limestone, we may collect the following categories.
3.1 Contact and professional information
This may include:
- name;
- organization;
- department;
- job title;
- business address;
- email address;
- telephone number; and
- other contact details.
3.2 Account and authentication information
This may include:
- account identifier;
- username;
- authentication records;
- organization affiliation;
- user role;
- assigned permissions;
- sign-in history; and
- multi-factor authentication status.
Passwords are stored in cryptographically protected (hashed) form, not as readable text.
3.3 Customer and transaction information
This may include:
- purchased Products and Modules;
- deployment name;
- implementation information;
- Licensed User counts;
- Participant access;
- subscription and service terms;
- billing contacts;
- invoices;
- payment status;
- support entitlements; and
- contract-related communications.
A third-party payment processor may collect payment-card information directly. Limestone may receive transaction identifiers and limited billing information without receiving complete payment-card numbers.
3.4 Customer Data
Depending on the Module and customer configuration, Customer Data may include:
- workflow and operational records;
- service requests, tickets, or cases;
- asset or equipment information;
- documents, images, and attachments;
- notes and communications;
- approvals and status information;
- user-submitted questions and responses;
- audit histories;
- AI prompts and instructions;
- AI-assisted output; and
- information supplied through customer-configured forms or integrations.
3.5 Support and communications information
When you contact Limestone, we may collect:
- the contents of the communication;
- attachments;
- support history;
- technical details;
- screenshots;
- affected user names;
- timestamps;
- reproduction steps;
- business impact; and
- related correspondence.
3.6 Telephone, voice, and messaging information
When you communicate with Limestone or a Limestone-operated service by telephone, voice assistant, text message, or a similar channel, we may collect:
- telephone number;
- date, time, and duration;
- routing information;
- audio or a call recording, when enabled;
- a transcript;
- information provided during the conversation;
- requested actions; and
- resulting emails, appointments, support requests, or other records.
We will provide notice of recording or automated processing when required by applicable law.
Unless separately disclosed and legally authorized, Limestone does not create voiceprints or use voice recordings to identify individuals through biometric matching.
3.7 AI interaction information
When an AI-enabled function is used, we may process:
- prompts and instructions;
- documents or records supplied as context;
- relevant Customer Data;
- generated responses;
- user corrections;
- feedback;
- technical logs; and
- actions requested or approved through the feature.
3.8 Device, usage, and technical information
We and our service providers may automatically collect:
- IP address;
- browser type;
- operating system;
- device type;
- language and regional settings;
- referring and exit pages;
- features accessed;
- session activity;
- timestamps;
- application performance;
- crash and diagnostic information;
- approximate location derived from an IP address; and
- security and audit logs.
3.9 Cookies and similar technologies
Our websites and applications may use cookies, local storage, software development kits, pixels, and similar technologies for:
- authentication;
- security;
- session management;
- preferences;
- service operation;
- performance measurement; and
- analytics.
3.10 Information from other sources
We may receive information from:
- your employer or organization;
- customer administrators;
- identity and authentication providers;
- customer-selected integrations;
- business partners and referrals;
- public sources;
- government records;
- security providers; and
- communications, analytics, or support vendors.
4. Sensitive and regulated information
Customers and users should minimize the Personal Information submitted through the Services.
Unless the parties first complete an appropriate written assessment, sign any required addendum, and confirm that the Service is properly configured, users must not submit specially protected or regulated information, including:
- protected health information;
- complete payment-card information;
- criminal-justice information;
- tax information subject to special safeguards;
- government-classified information;
- biometric identifiers;
- authentication secrets;
- export-controlled information; or
- other information subject to a specialized security or regulatory framework.
The standard LimestoneBiz and LimestoneGov agreements do not, by themselves, establish compliance with:
- HIPAA;
- PCI DSS;
- CJIS;
- FedRAMP;
- IRS Publication 1075;
- government-classified-data requirements; or
- a customer-specific security standard.
Additional assessment, configuration, and contractual terms may be required before regulated information is introduced.
5. How we use Personal Information
Limestone may use Personal Information to:
- provide, configure, host, operate, and maintain the Services;
- implement purchased Products and Modules;
- create and administer accounts;
- authenticate users and enforce permissions;
- process authorized transactions;
- provide support and training;
- investigate errors and incidents;
- monitor service reliability and availability;
- respond to inquiries and requests;
- communicate about services, renewals, security, and updates;
- process billing and maintain business records;
- provide AI-enabled functions;
- generate requested emails, summaries, records, or workflow actions;
- prevent fraud, abuse, unauthorized access, and security incidents;
- enforce applicable agreements;
- satisfy legal, contractual, accounting, and regulatory obligations;
- establish, exercise, or defend legal claims;
- improve the Services;
- develop features using aggregated or de-identified information;
- manage vendors and subprocessors; and
- accomplish another purpose disclosed when information is collected or authorized by the individual or customer.
For Customer Data, Limestone and its subprocessors process the information only as reasonably necessary to:
- provide the Service;
- secure the Service;
- support the Service;
- improve the Service;
- follow documented customer instructions;
- comply with applicable law; or
- enforce the applicable agreement.
Limestone may use aggregated and de-identified statistics that do not identify a customer, an individual, or Customer Confidential Information.
6. AI-enabled functions
6.1 AI processing
AI-enabled functions may classify, summarize, retrieve, draft, recommend, search, or otherwise assist with customer operations.
To perform these functions, Limestone may process prompts, instructions, Customer Data, documents, call transcripts, and other information supplied as context.
Limestone may use third-party AI and model providers as subprocessors.
6.2 Training of generally available models
Limestone will not knowingly use Customer Data to train a generally available AI model without the customer’s prior written consent.
Where commercially available and appropriate, Limestone will configure supported enterprise privacy controls for AI providers.
Limestone may use aggregated or de-identified information and voluntarily supplied feedback to improve its Services, provided the information does not identify the customer, an individual, or Customer Confidential Information.
6.3 Human review
AI output may be incomplete, inaccurate, or inappropriate for a particular situation. It does not replace qualified human judgment.
Customers and users are responsible for appropriate human review before relying on AI output for material:
- operational;
- safety;
- legal;
- employment;
- financial;
- regulatory; or
- public-sector decisions.
Users should not present AI output as verified fact without appropriate validation.
Limestone does not use AI-enabled functions to make decisions that produce legal or similarly significant effects about individuals without human review.
6.4 Restricted information
Users must not submit secrets or regulated information to an AI-enabled field unless Limestone and the applicable customer have approved that workflow.
7. AI-assisted telephone and messaging services
Limestone may use an AI-assisted agent to:
- answer calls;
- identify the purpose of a call;
- collect contact information;
- route a request;
- schedule follow-up;
- create a support or sales record;
- prepare or send a requested email;
- summarize a conversation; or
- initiate another authorized workflow.
When appropriate, callers will be informed that they are interacting with an automated or AI-assisted system.
When a call is recorded or transcribed, Limestone will provide notice or obtain consent as required by applicable law.
A caller who does not wish to continue with an AI-assisted interaction may request a person or use another available contact method.
8. How we disclose Personal Information
Limestone may disclose Personal Information in the following circumstances.
8.1 Service providers and subprocessors
Limestone may use subprocessors for:
- cloud hosting and storage;
- database and application infrastructure;
- identity and access management;
- AI and model services;
- monitoring and logging;
- cybersecurity;
- communications and support;
- voice, transcription, and messaging;
- email delivery;
- analytics;
- billing and payment processing;
- document signing; and
- professional and business services.
Limestone requires subprocessors that process Customer Data to maintain appropriate confidentiality and security obligations. Limestone remains responsible for its contractual obligations concerning its subprocessors.
A current list of Customer Data subprocessors is available on reasonable written request. Where commercially practicable, Limestone will notify an affected customer before adding a material new subprocessor that will process Customer Data.
8.2 Customer organizations and administrators
If you access a Service through an employer, government agency, or other organization, that customer and its authorized administrators may access:
- account information;
- Customer Data;
- usage activity;
- audit logs;
- permissions;
- communications; and
- other records associated with the customer's account.
8.3 Customer-selected integrations
Limestone may transmit information to an application, integration, or third-party service selected or enabled by the customer.
The third party’s privacy practices apply after it receives the information.
8.4 Legal, security, and safety purposes
Limestone may disclose information when reasonably necessary to:
- comply with law, regulation, subpoena, court order, or lawful government request;
- respond to public-records obligations applicable to a customer;
- protect Limestone, its customers, users, or others;
- investigate fraud, abuse, or a security incident;
- enforce an agreement; or
- establish, exercise, or defend legal claims.
Where legally permitted and reasonably practicable, Limestone may notify the affected customer before disclosing Customer Data in response to a legal demand.
8.5 Business transactions
Information may be disclosed in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction.
A successor will remain subject to applicable privacy and contractual obligations concerning transferred information.
8.6 At your direction
Limestone may disclose information when an individual or customer directs us to do so or provides appropriate consent.
9. Cookies, analytics, and advertising
Limestone may use essential cookies and similar technologies necessary for authentication, security, preferences, session management, and core functionality.
Today, the public websites at limestonetg.com, limestonegov.com, and limestonebiz.com set no cookies and use no analytics, advertising pixels, or third-party tracking scripts. If Limestone introduces analytics or other nonessential technologies, we will update this Privacy Policy and, where required by applicable law, request consent before activating them.
Cookie controls are also available through your browser. If nonessential cookies are introduced, Limestone will provide a cookie-preference tool where required by law. Blocking essential cookies may prevent portions of the Services, such as signing in to a customer portal, from functioning properly.
Limestone does not sell Personal Information for money or other valuable consideration.
Limestone does not share Personal Information for cross-context behavioral advertising.
If these practices change, Limestone will update this Privacy Policy and provide any legally required notice, consent, or opt-out mechanism.
Where required by law, Limestone will process legally recognized browser-based opt-out preference signals, such as the Global Privacy Control.
Some browsers transmit “Do Not Track” signals. Because no common industry standard for responding to them has been adopted, the Services do not currently respond to Do Not Track signals; Limestone does honor legally recognized opt-out preference signals, such as the Global Privacy Control, where required by law.
Limestone does not currently offer financial incentives in exchange for Personal Information.
10. Public-sector customers and records
LimestoneGov provides software and technology services to public-sector organizations.
Customer Data and Service records associated with a public-sector customer may be subject to:
- public-records laws;
- open-meeting and transparency requirements;
- government retention schedules;
- audit requirements;
- litigation holds;
- accessibility requirements;
- procurement requirements;
- archival obligations; or
- other laws governing public information.
The applicable public-sector customer determines whether a record must be retained, disclosed, corrected, restricted, exported, or deleted.
A public-sector customer should identify in its Service Order or a signed addendum:
- its adopted records-retention schedule;
- mandatory public-records requirements;
- audit requirements;
- accessibility requirements;
- security requirements;
- data-location requirements;
- breach-notification requirements; and
- other customer-specific legal obligations.
Limestone will retain and dispose of Customer Data and responsive Service records according to the identified schedule and applicable law, subject to the applicable agreement and technical limitations disclosed before execution of the Service Order.
Requests concerning records controlled by a government customer should normally be directed to that agency. Limestone will reasonably assist the agency as required by applicable law and agreement.
11. Data retention and return
Limestone retains Personal Information only as long as reasonably necessary to:
- provide and support the Services;
- fulfill the purposes described in this Privacy Policy;
- maintain security and audit records;
- follow customer instructions;
- comply with an agreement;
- satisfy legal, tax, accounting, and regulatory obligations;
- resolve disputes; and
- enforce agreements.
Customer Data is retained during the applicable service term and handled after expiration or termination according to the applicable customer agreement.
Unless a signed agreement states otherwise:
- access to the Service ends upon expiration or termination;
- a customer may request one commercially reasonable export of Customer Data in a commonly used format at any time before deletion;
- Limestone will not delete Customer Data earlier than sixty days after expiration or termination unless the customer requests earlier deletion or applicable law requires otherwise; and
- backup copies may remain until overwritten through ordinary retention cycles.
For a public-sector customer, the retention schedule identified in the Service Order or signed addendum may impose additional requirements.
After an applicable retention period, Personal Information is deleted, de-identified, or isolated from ordinary use, subject to backup cycles and legal obligations.
12. Data security
Limestone maintains administrative, technical, and organizational safeguards appropriate to the nature of the Services and information involved.
These safeguards may include:
- role-based access and least-privilege practices;
- unique administrative credentials;
- multi-factor authentication where supported;
- encryption in transit using current industry-standard transport protection;
- encryption at rest across Limestone's hosting infrastructure;
- logging and monitoring;
- vulnerability remediation and patching;
- personnel confidentiality obligations;
- backup and recovery practices;
- secure development practices; and
- documented incident-response procedures.
No transmission or storage system can guarantee absolute security.
Customers remain responsible for their own:
- access approvals;
- Authorized Users;
- endpoint protection;
- identity controls;
- credentials;
- retention requirements;
- user training; and
- prompt reporting of suspected credential compromise.
If you believe Personal Information has been accessed improperly, contact Limestone or your organization’s administrator promptly.
Where required by applicable law, Limestone will notify affected individuals and regulators of a qualifying security breach.
When a security incident affecting Customer Data is confirmed, Limestone’s default practice is to notify affected customers without unreasonable delay, targeting notice within 72 hours after confirmation.
Customer-specific security incident notification obligations are governed by the applicable Master Services Agreement, Schedule C, Service Order, and any signed addendum.
13. Privacy rights and requests
Depending on your residence and applicable law, you may have the right to:
- confirm whether Limestone processes your Personal Information;
- access Personal Information about you;
- correct inaccurate Personal Information;
- request deletion;
- obtain a portable copy of certain information;
- opt out of the sale of Personal Information;
- opt out of targeted advertising;
- opt out of qualifying automated profiling;
- withdraw consent for certain processing;
- limit certain uses of sensitive Personal Information;
- appeal the denial of a request; and
- exercise privacy rights without unlawful discrimination.
Because Limestone does not currently sell Personal Information or share it for cross-context behavioral advertising, certain opt-out requests may not require a change to our practices. We will nevertheless review and respond to valid requests as required by law.
13.1 How to submit a request
Submit privacy requests by email to privacy@limestonetg.com with the subject line Privacy Request.
Requests may also be mailed to:
Limestone Technology Group
Attn: Privacy
101 W Broadway Ave., Suite 280
Maryville, TN 37801
United States
Please provide enough information for us to identify the relevant records and understand the request.
13.2 Verification
Limestone may need to verify your identity before fulfilling a request.
Information collected for verification will be used only to evaluate and respond to the request.
If Limestone cannot verify a request or an applicable exception applies, we may deny or limit the request and provide the reason when required by law.
13.3 Requests involving Customer Data
If a request concerns Customer Data controlled by a Limestone customer, Limestone may direct the request to that customer.
Limestone will assist the customer as required by the applicable agreement and law.
13.4 Authorized agents
Where permitted by law, an authorized agent may submit a request on your behalf.
Limestone may request evidence of the agent’s authority and may verify your identity directly.
13.5 Appeals
If Limestone denies a privacy request, you may submit an appeal to privacy@limestonetg.com with the subject line Privacy Appeal.
Include the original request and explain why you believe the decision should be reconsidered.
Limestone will respond within the period required by applicable law.
14. California privacy disclosures
To the extent the California Consumer Privacy Act, as amended, applies to Limestone, this section supplements the remainder of this Privacy Policy for California residents.
During the preceding 12 months, Limestone may have collected:
- identifiers and contact information;
- customer and commercial information;
- internet and electronic-network activity;
- professional information;
- approximate location;
- audio, electronic, or visual information;
- account credentials;
- communications;
- Customer Data;
- sensitive information submitted through an approved workflow; and
- inferences generated to provide requested AI-enabled functionality.
The sources of this information are described in Section 3. The purposes are described in Section 5. Categories of recipients are described in Section 8.
Limestone does not use or disclose sensitive Personal Information for the purpose of inferring characteristics about an individual outside purposes permitted by applicable law.
Limestone does not knowingly sell or share the Personal Information of individuals under 16.
California residents may exercise applicable rights through the methods in Section 13.
15. Children's privacy
The general-audience Services are intended for organizations and adult business users. They are not directed to children under 13.
Limestone does not knowingly collect Personal Information directly from children under 13 through its general-audience websites or Services.
If Limestone learns that it collected Personal Information directly from a child under 13 without appropriate authorization, we will take reasonable steps to delete it.
A government, educational, or other customer may use a separately configured Service in a context involving minors. In that situation:
- the customer is responsible for identifying the applicable legal requirements;
- the customer is responsible for required notices and authority or consent;
- Limestone will process the information according to the applicable agreement and law; and
- additional contractual and technical safeguards may be required.
A parent or guardian who believes a child directly provided Personal Information to Limestone may contact privacy@limestonetg.com.
16. Third-party websites and services
The Services may contain links to third-party websites, applications, or services.
Limestone does not control and is not responsible for the privacy or security practices of third parties. We encourage users to review a third party’s privacy notice before providing information.
17. International processing
Limestone is based in the United States.
Personal Information may be processed in the United States and other locations where Limestone or its service providers operate.
Where required, Limestone will use appropriate contractual or legal mechanisms for international transfers.
Unless otherwise expressly agreed, the Services are designed primarily for organizations and users in the United States.
18. Changes to this Privacy Policy
Limestone may update this Privacy Policy to reflect changes in:
- the Services;
- Products and Modules;
- subprocessors;
- technology;
- legal requirements; or
- information practices.
When the policy is updated, Limestone will revise the “Last Updated” date.
If a change materially affects how previously collected Personal Information is used, Limestone will provide additional notice or obtain consent when required by law.
Limestone will not materially expand the use of previously collected Personal Information solely through a retroactive policy change where additional notice or consent is legally required.
Changes to this Privacy Policy do not amend an executed Service Order or Master Services Agreement. Contract amendments must follow the amendment process stated in the applicable agreement.
19. Contact Limestone
Questions, concerns, accessibility requests, and privacy inquiries may be directed to:
Limestone Technology Group
Attn: Privacy
101 W Broadway Ave., Suite 280
Maryville, TN 37801
United States
Privacy requests and appeals: privacy@limestonetg.com
General inquiries: hello@limestonetg.com
limestonetg.com