Legal
Privacy Policy
Effective date: 2026-07-27
1. Introduction and scope
Maz Innovation Inc., a Delaware corporation with its principal place of business in Chicago, Illinois ("MAZ," "we," "us," or "our"), operates the mazinc.com website (the "Site") and the COCO platform (coco.mazinc.com, api.mazinc.com) (together, the "Service") — an AI-assisted analytics platform for private-equity and advisory work. This Privacy Policy describes the information we collect, how we use and protect it, and the rights available to you.
Our two roles. For personal information relating to Site visitors and Service account holders, MAZ acts as the data controller (or "business" under U.S. state privacy laws). For the business content our clients upload to COCO ("Customer Data"), MAZ acts strictly as a data processor / service provider on the client's behalf: the client controls that data, and we process it only on the client's documented instructions and as described in our agreement with the client.
Important notice regarding Customer Data. Where we process Customer Data on a client's behalf, that processing is governed by our written agreement with the client, not by this Policy. If you are an individual whose information is contained in Customer Data, please direct privacy inquiries to the organization that engaged us (see Section 10); we will assist that organization in responding as our agreement requires.
2. Information we collect
Information you provide to us:
- Account data — name, work email address, organization, and role.
- Communications — information you include when you contact us by email or through the Site (name, email address, message contents).
- Customer Data — files and content that clients upload to COCO (for example, financial spreadsheets and business documents) and the analyses derived from them. Customer Data may include confidential financial information concerning portfolio companies or other businesses.
Information collected automatically:
- Usage and device data — IP address, browser and device type, pages viewed, actions taken, timestamps, and security logs generated in the ordinary operation of the Service.
We do not collect information from third-party data brokers, and we do not use the Service to build advertising profiles.
3. Cookies and tracking
The Service uses only essential cookies — those required for authentication, session integrity, and site function. We do not use advertising cookies, cross-site tracking cookies, or third-party web analytics.
Do Not Track. Because we do not track users across third-party sites, the Service does not respond differently to browser "Do Not Track" signals — there is no tracking to disable.
4. How we use information
We use the information described above to:
- Provide and operate the Service — authenticate users, run analyses, generate reports, and maintain accounts;
- Protect the Service — detect, prevent, and respond to fraud, abuse, security incidents, and unauthorized access;
- Support and communicate — respond to inquiries and send administrative and service notices;
- Improve the Service — in aggregated or diagnostic form only, as described in Section 11. We do not use Customer Data to train AI models; and
- Comply with law — meet our legal and regulatory obligations and enforce our agreements.
5. AI processing
COCO uses artificial intelligence to analyze uploaded data and generate narrative commentary. Deterministic figures are computed by MAZ's own software. Narrative commentary is produced using Anthropic Claude models hosted on Amazon Bedrock, operating entirely within MAZ's own AWS environment. Customer content is processed inside AWS solely to generate output for the client that uploaded it. It is not transmitted to Anthropic or to any third-party AI provider, and it is not used to train any AI model — ours or anyone else's.
6. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose information only:
- To subprocessors — vetted service providers that host and deliver the Service under written contracts that limit their use of the data to providing services to us:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, database, encrypted file storage, and AI inference (Amazon Bedrock) | United States |
| Vercel | Application and website delivery (CDN) | United States |
- For legal reasons — where required by law, subpoena, or other legal process, or where reasonably necessary to protect the rights, property, or safety of MAZ, our clients, or others; and
- In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, in which case we will provide notice where required by law and require the successor to honor this Policy.
7. Where information is stored; international visitors
Customer Data and account data are stored in the United States (AWS, US-East region), encrypted in transit and at rest.
The Service is operated from the United States and is intended for use by businesses located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your jurisdiction.
8. Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy:
- Account data — for the life of the account and as needed thereafter to comply with our legal obligations, resolve disputes, and enforce agreements.
- Customer Data — for the duration of the client engagement. We delete Customer Data within 30 days of engagement termination, or earlier on the client's instruction, unless a longer period is required by law.
- Backups — encrypted backups age out on our standard 30-day cycle.
9. Security and incident notification
We protect information using administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit and at rest, role-based access controls, network filtering (WAF), centralized secrets management, security logging, and independent penetration testing. MAZ is pursuing SOC 2 attestation.
No method of transmission or storage is completely secure. If we become aware of a security incident affecting personal information or Customer Data, we will notify affected clients and individuals without undue delay, consistent with our contractual commitments and applicable law.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a portable copy of your personal information; to restrict or object to certain processing; and — for California residents — to know the categories of information we collect and to opt out of "sale" or "sharing" of personal information (we do neither). We will not discriminate against you for exercising any of these rights.
California notice at collection. In the preceding 12 months we have collected the following categories of personal information: identifiers (name, work email, organization), internet or network activity (usage and device data described in Section 2), and professional or employment-related information (role, organization). We collect them for the purposes described in Section 4. We do not collect sensitive personal information as defined by the CCPA, and we do not sell or share personal information.
How to exercise your rights. Submit requests to privacy@mazinc.com. We will verify your identity before acting on a request — typically by confirming control of the email address associated with your account — and respond within the timeframe required by applicable law. You may use an authorized agent to submit a request on your behalf; we will require proof of the agent's authorization. If we decline a request, you may appeal by replying to our decision, and we will explain the outcome of the appeal.
Customer Data. Where personal information is contained in Customer Data, MAZ processes it on the client's instructions. Individuals should direct requests concerning Customer Data to the relevant client (the controller); we will assist the client in responding as our agreement requires.
11. De-identified and aggregated information
We may create and use de-identified or aggregated information (for example, overall usage statistics) to operate, secure, and improve the Service. We maintain such information without attempting to re-identify it, and we do not use Customer Data to create statistics or insights for any other client or third party.
12. Third-party sites
The Site may contain links to third-party websites. This Policy does not apply to those sites, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policy of any site you visit.
13. Children
The Service is a business tool. It is not directed to children and is not intended for use by anyone under 18 years of age, and we do not knowingly collect personal information from children.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we will post the revised version with a new effective date, and for material changes we will provide additional notice (such as email to account holders) before the changes take effect.
15. Contact us
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | privacy@mazinc.com |
| Security matters | security@mazinc.com |
| General inquiries | hello@mazinc.com |
Mailing address: Maz Innovation Inc., 233 S Wacker Dr, Suite 4400, Chicago, IL 60606, USA.