Privacy Policy
This Privacy Policy explains how Supera™, a product of Zolopreneur LLC - Supera PS ("Supera," "we," "us"), handles information in connection with our website (getsupera.com) and our bilingual performance-review service (the "Service").
Who is responsible for your data
For information entered by our business customers about their employees, the customer is the data controller and Supera acts as a processor that handles the data on the customer's behalf and instructions. For information you give us directly as a website visitor, Supera is the controller.
Information we collect
- Website inquiries: when you use our contact form, we collect the name, email, company, and message you provide.
- Account & service data: when a business uses Supera, we process account details and the information the business enters about its people — such as names, job positions, review content, goals, and acknowledgments.
- Contact details for notifications: email addresses and, where provided, mobile phone numbers used to deliver messages related to the Service. We encourage the account administrator to add a mobile number so we can send critical account, security, and delivery alerts; providing it is optional, and we keep a record of the choice made.
- Technical data: standard log and device information needed to operate and secure the Service.
How we use information
- To provide, secure, and improve the Service.
- To respond to inquiries you send us.
- To deliver transactional messages related to the Service (see below).
- To meet legal and security obligations.
- For product analytics on a business level — including understanding, in aggregate, where our paying customer companies are located, using the company's billing area (such as postal/ZIP code, city, and region), never an individual employee's location.
Text messages & WhatsApp
We encourage account administrators to add a mobile number so we can reach them about critical account, security, and delivery matters (for example, an email that could not be delivered). Providing it is optional. If an administrator adds a number but chooses email as their preferred channel, we use SMS or WhatsApp only for these critical, transactional notices — never for sales, marketing, or promotions.
Messaging consent & opt-out. If you or your employer provides a mobile number, we may send transactional messages by SMS or WhatsApp — such as one-time verification codes, review notifications, and reminders. Separately, if you submit our contact form and opt in with a phone number, we may send occasional product and launch updates. Message frequency varies with your activity. Message and data rates may apply. You can opt out at any time by replying STOP, and get help by replying HELP.
No mobile information is shared with third parties or affiliates for marketing or promotional purposes. We do not sell your personal information or share mobile phone numbers or SMS/messaging opt-in data with third parties for their own marketing. Any product or launch updates are sent only to recipients who explicitly opted in, and you can unsubscribe at any time by replying STOP.
How we share information
We share information only with service providers ("subprocessors") that help us run the Service (for example, cloud hosting, authentication, messaging delivery, and payment processing), under agreements that limit their use of the data. If your business chooses to enable an optional integration with a workplace-chat platform (such as Slack or Microsoft Teams), we share limited data with that platform — as a subprocessor, only for that business, and only to deliver the notifications and interactions the integration provides. We do not sell personal information. We may disclose information if required by law or to protect rights and safety.
Cookies
Supera keeps cookies to a minimum. We do not use advertising cookies, cross-site tracking cookies, or third-party trackers, and we do not sell or share your browsing activity. Our website analytics are cookieless — we measure page visits without placing tracking cookies on your device or identifying you. When you sign in to the Supera app, we use a single strictly-necessary cookie to keep you securely signed in, and our network provider may set essential security cookies to protect the site against bots and abuse. Because we use only strictly-necessary cookies and cookieless analytics, we do not display a cookie consent banner — there is nothing tracking you to consent to. You can control or delete cookies at any time in your browser settings; blocking the strictly-necessary sign-in cookie will prevent you from staying logged in. If we ever introduce advertising or analytics that use cookies, we will update this policy and, where the law requires it, ask for your consent first.
Security
We take the security of employee data seriously: AES-256 encryption at rest, TLS in transit, per-company data isolation with per-tenant encryption keys, MFA for administrators, and a tamper-evident audit log. The Service is built to SOC 2 and ISO 27001 control standards and runs on infrastructure that is itself SOC 2 and ISO 27001 certified. No system is perfectly secure, but security is a core priority.
Anonymous 360° feedback
When a business uses 360° feedback, responses are collected and presented in a way designed to protect the identity of the person giving feedback — including from administrators and co-administrators. Feedback is aggregated and shown only once enough responses have been received, so individual responses are not attributed to a specific reviewer. Administrator and co-administrator actions within the Service are recorded in a tamper-evident audit log.
Data retention & deletion
We keep information for as long as needed to provide the Service and meet legal obligations, and delete or de-identify it when no longer needed. Business customers can request deletion of their data.
Your choices & rights
Depending on your location, you may have rights to access, correct, or delete your personal information, or to object to certain processing (consistent with laws such as the CCPA and GDPR). Because much of the employee data is controlled by our business customers, we will direct or support such requests through the relevant customer where appropriate.
International data transfers
Supera is based in the United States and processes data on US-based infrastructure. Where we handle personal data from the EEA, the UK, or Switzerland, we rely on the EU Standard Contractual Clauses (and the UK and Swiss equivalents) together with strong technical safeguards — per-company encryption, no standing plaintext access, and per-company database isolation — to protect it. Business customers who need a signed Data Processing Agreement (DPA) or our current subprocessor list can request one at [email protected].
Age
The Service is intended for individuals 18 years of age or older. It is not directed to children.
Language
We provide this policy in English and Spanish for convenience. The English-language version is the official version; any translation is provided for information only.
Changes
We may update this policy from time to time. The "Last updated" date above reflects the most recent change.
Contact
Questions about this policy? Use the contact form on getsupera.com or email [email protected].