Privacy Policy

Last updated: April 25, 2026

1. Who we are

Gladius BDC ("Gladius", "we", "us") is an AI-powered business development service for automotive dealerships, operated by Gladius Inc. We provide automated lead response and appointment-setting software that integrates with dealer CRMs, telephony providers, and billing systems.

2. What data we process

To operate the service we process two categories of data:

  • Dealer account data — names, business addresses, email addresses, phone numbers, billing details, store configuration, AI persona settings, and the contents of conversations between the AI and consumers.
  • Consumer lead data — names, phone numbers, email addresses, vehicle interest, conversation messages, appointment records, and TCPA consent records. We process this data on behalf of, and at the direction of, the dealer.

3. How we use it

  • To deliver the AI conversation, scheduling, and reporting features the dealer has subscribed to.
  • To send transactional emails and SMS the dealer has authorized (e.g., appointment confirmations, follow-ups).
  • To improve the AI engine using anonymized and aggregated patterns. Individual conversation contents are not used to train any third-party model.
  • To provide customer support and to investigate operational issues.
  • To comply with legal obligations, including TCPA, CCPA, and applicable state-level consumer protection laws.

4. Sharing

We share data only with the sub-processors required to run the service: Anthropic (LLM inference), Twilio (SMS delivery), Resend (email delivery), Stripe (billing), Clerk (authentication), Supabase (data storage), Vercel (hosting), and Upstash (queue/cache). We do not sell consumer data. We do not use consumer data for advertising.

5. TCPA compliance

Every outbound SMS or call placed by Gladius is gated by hardcoded TCPA logic — express written consent, federal/state DNC checking, dealer-timezone quiet hours, and opt-out keyword detection (STOP, UNSUBSCRIBE, OPT-OUT). Dealers are responsible for the accuracy of consent records they submit. Gladius retains consent records and opt-out logs for a minimum of four years.

6. Your rights

If you are a consumer whose data was processed on behalf of a Gladius dealer, you may:

  • Reply STOP to any SMS to opt out of further messages.
  • Request access, correction, or deletion of your data by emailing privacy@gladiusbdc.com. We will route your request to the appropriate dealer if needed.
  • California residents have additional rights under the CCPA. EU residents have rights under GDPR — contact us using the same email above.

7. Retention

Conversation data is retained for the life of the dealer's subscription plus 90 days, or longer where required by law (e.g., TCPA consent records). Closed-account data is purged after 90 days unless the dealer requests an export.

8. Security

Production data is encrypted in transit (TLS 1.2+) and at rest. API keys and secrets are managed through Vercel's encrypted environment. Access to dealer data is restricted to engineering personnel under a documented incident-response policy.

9. Children

Gladius is not directed to anyone under 18 and does not knowingly collect data from children.

10. Changes

We will post material changes to this policy on this page and notify dealers by email at least 30 days before they take effect.

11. Contact

Questions? Email privacy@gladiusbdc.com or call (813) 442-0253.

// ONE ROOFTOP PER REGION · FOUNDER CELL 813-442-0253