Ennijo Privacy Policy

Effective Date: September 4, 2026
Last Updated: September 4, 2026

Ennijo is a relationship management and customer relationship management platform designed to help real estate professionals build, maintain, and strengthen relationships with the people in their businesses.

Ennijo is provided by 29in5 LLC, doing business as Ennijo ("Ennijo," "we," "us," or "our").

We believe your relationships are yours. We process information to provide Ennijo and help you manage those relationships. We do not treat the people in your CRM as Ennijo leads simply because their information is stored in Ennijo.

This Privacy Policy explains how we collect, use, disclose, store, and protect Personal Information when you visit an Ennijo website, create or use an Ennijo account, use Ennijo features, connect an authorized third-party service, communicate with us, or otherwise interact with Ennijo.

This Privacy Policy should be read together with our Terms of Service and, where applicable, our Data Processing Addendum.

1. Key Definitions

For purposes of this Privacy Policy:

"Ennijo" or the "Service" means the Ennijo web application, Ennijo websites, and related customer-facing features, tools, integrations, and support services provided by 29in5 LLC.

"Customer" means the person, team, brokerage, company, or other organization that subscribes to or is authorized to use Ennijo.

"Authorized User" means an individual permitted by a Customer to access that Customer's Ennijo account.

"CRM Contact" means a prospect, client, past client, referral partner, vendor, professional contact, sphere contact, or other individual whose information a Customer places into Ennijo.

"CRM Contact Data" means Personal Information relating to a CRM Contact that is entered, imported, synchronized, received, or otherwise maintained through Ennijo.

"Customer Data" means information submitted to or generated through a Customer's use of Ennijo, including CRM Contact Data.

"Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to an individual.

Scope of This Policy

This Privacy Policy describes processing for Ennijo features that are generally available to Customers. Optional or separately licensed modules may involve additional processing, which is described in the terms applicable to those modules.

2. Types of Information We Process

Account Data

Account Data is information relating to Customers and Authorized Users.

This may include:

Payment card details are collected and processed by Stripe. Ennijo does not receive or store full payment card numbers.

CRM Contact Data

CRM Contact Data may include:

Customers determine which individuals they place into Ennijo, what information they maintain about those individuals, and how that information is used.

Usage and Technical Data

When you use Ennijo or visit our websites, we may automatically collect information such as:

Support and Communications Data

If you contact Ennijo for support, submit feedback, participate in training, complete a form, respond to a survey, or otherwise communicate with us, we may retain the information you provide and our communications with you.

3. Our Role When Processing Information

Our legal role may differ depending on the information being processed.

Information Ennijo Processes for Its Own Business

For information such as Account Data, billing information, website information, security information, and support communications, Ennijo generally determines why and how the information is processed.

Depending on applicable law, Ennijo may be considered a controller, business, or similar responsible party for that information.

CRM Contact Data

For CRM Contact Data, Ennijo generally processes information on behalf of the Customer.

The Customer determines:

Depending on applicable law, the Customer may be considered the controller or business, and Ennijo may be considered the processor or service provider.

Additional terms relating to this processing may be contained in Ennijo's Data Processing Addendum.

4. CRM Contacts Are Not Ennijo Leads

A person does not become an Ennijo prospect, marketing lead, or sales opportunity simply because an Ennijo Customer stores that person's information in the CRM.

Ennijo does not independently market Ennijo products or third-party products to an individual solely because that individual appears in a Customer's CRM.

Ennijo does not claim ownership of CRM Contact Data.

As between Ennijo and the Customer, the Customer retains its rights in CRM Contact Data, subject to the limited rights Ennijo needs to provide, operate, secure, maintain, and support the Service.

5. How We Collect Information

We may collect information:

Directly From Customers and Users

For example, when you:

Through Authorized Integrations

Where a Customer or its administrator authorizes Ennijo to access another service, we may receive or process information from that service as necessary to provide the authorized Ennijo functionality.

Automatically

We may collect technical and usage information through our application infrastructure, servers, security systems, cookies, and similar technologies.

From Service Providers

We may receive information from companies that help us provide services such as hosting, authentication, security, communications, billing, and customer support.

6. How We Use Information

We may use Personal Information to:

We may use Account Data to communicate with current and prospective Customers about Ennijo products and services, subject to applicable law.

We do not use CRM Contact Data to independently solicit or market to our Customers' CRM Contacts.

7. Artificial Intelligence

Ennijo uses artificial intelligence to assist Customers with relationship management and productivity.

Current AI-assisted functionality may include:

Ennijo currently uses Anthropic as its artificial intelligence service provider.

Depending on the feature being used, Ennijo may transmit limited CRM Contact Data to Anthropic so that the requested feature can be provided.

Information used by AI-assisted coaching features may include information such as:

Where possible, Ennijo designs AI features to limit unnecessary transmission of Personal Information. For example, certain coaching functions may identify whether a telephone number or email address exists without sending the actual telephone number or email address to the AI provider.

Customers should understand that free-text fields, including notes and activity summaries, may contain information entered by Authorized Users. Customers should not place highly sensitive Personal Information into those fields.

AI Training

Ennijo does not sell CRM Contact Data to artificial intelligence providers.

Ennijo accesses Anthropic's services under commercial terms that provide that customer content submitted through those commercial services is not used to train Anthropic's general-purpose foundation models.

Ennijo does not authorize CRM Contact Data to be used for third-party general-purpose model training.

AI Provider Retention

Information transmitted to Anthropic is processed and retained in accordance with Anthropic's applicable commercial terms and data-processing commitments.

Anthropic's retention practices operate separately from Ennijo's own retention periods described in Section 15.

If Ennijo changes AI providers or materially changes how AI providers process Customer Data, we will update our practices and disclosures as appropriate.

Accuracy

AI-generated suggestions may contain errors, omissions, or incomplete information.

Customers remain responsible for reviewing AI-generated suggestions before relying on them or using them in communications with another person.

8. Google Workspace Integration

Ennijo may integrate with Google Workspace for Customers that use Google Workspace email.

Where enabled, these integrations may be authorized by the Customer's Google Workspace administrator rather than separately authorized by each individual Authorized User.

Ennijo may use a Google service account with administrator-approved domain-wide delegation to access only the Google Workspace permissions reasonably necessary to provide the authorized functionality.

Ennijo's use of information received through Google APIs is subject to the Google API Services User Data Policy, including applicable Limited Use requirements.

Gmail Activity

Where Gmail activity logging is enabled by a Customer's Google Workspace administrator, Ennijo may access limited information relating to recently sent email for the purpose of recording relevant relationship activity in the CRM.

The Gmail activity feature currently accesses limited message header information, including:

The Gmail activity logging workflow does not access or store the body of the email.

Where an email can be matched to a CRM Contact, Ennijo may store an activity entry associated with that contact, including the email subject.

Although Ennijo accesses the subject through email message headers, subject lines may themselves contain Personal Information, including client names, property addresses, transaction details, or other information.

Stored subject lines become part of that CRM Contact's relationship activity and may be included in activity information used by AI-assisted features described in Section 7.

Limited Use of Google User Data

Ennijo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.

Google user data is used only to provide or improve authorized user-facing Ennijo features.

Google user data is not used by Ennijo to develop, train, or improve generalized artificial intelligence or machine learning models.

Google user data is not used for advertising.

Google user data is not sold.

Google user data is not transferred except as permitted by Google's applicable policies and as reasonably necessary to:

Ennijo personnel do not access Google user data except where such access is permitted and reasonably necessary for purposes such as:

Ennijo does not receive or store an Authorized User's Google Workspace password as part of this integration.

Access provided through domain-wide delegation is controlled by the Customer's Google Workspace administrator. A Customer may remove or modify that authorization through its Google Workspace administrative controls.

9. Customer Responsibilities for CRM Contact Data

Customers are responsible for determining whether they have the legal right to collect, store, use, and communicate with individuals whose information they place into Ennijo.

Customers are responsible for complying with applicable:

Customers are responsible for obtaining any consent required before sending regulated communications.

Ennijo providing a feature does not establish that a Customer has legal permission to contact a particular individual.

Customers are responsible for honoring applicable:

10. Information Customers Should Not Store in Ennijo

Ennijo is a relationship CRM. It is not designed to serve as a secure repository for highly sensitive identity, medical, financial, or authentication records.

Unless Ennijo expressly authorizes a particular use, Customers should not intentionally enter or upload information such as:

Customers should use appropriate purpose-built systems for highly sensitive documents and financial information.

11. Cookies, Analytics, and Website Technology

Ennijo currently does not use third-party behavioral analytics, advertising pixels, or session-recording tools within the Ennijo CRM application.

We may collect technical logs through our hosting and infrastructure providers as reasonably necessary to:

Certain Ennijo-related websites may load third-party technical resources such as web fonts. When a browser requests a resource directly from a third party, that third party may receive technical information such as the visitor's IP address.

Opt-Out Preference Signals

Ennijo does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising.

Because we do not currently engage in those activities, there is no targeted advertising activity for an opt-out preference signal, such as Global Privacy Control, to apply to.

If our practices change, we will honor recognized opt-out preference signals to the extent required by applicable law and will update this Privacy Policy.

We may change the technologies we use as Ennijo develops.

If we introduce material tracking, targeted advertising, or behavioral analytics practices, we will update this Privacy Policy and provide any consent or opt-out mechanisms required by applicable law.

12. How We Share Personal Information

We may disclose Personal Information in the following circumstances.

Service Providers and Subprocessors

We use companies that help us operate, secure, and provide Ennijo.

Current categories of service providers include:

Current core providers supporting the Ennijo application include:

Ennijo's public-facing and training-related services may additionally use:

These providers may receive information that individuals submit through the applicable forms or registration processes. They do not receive CRM Contact Data maintained inside the Ennijo application solely by virtue of providing those services.

These providers may process Personal Information only as necessary to perform services for Ennijo or as otherwise permitted by applicable law and their agreements with us.

A current list of Ennijo's subprocessors is maintained at:

https://ennijo.com/subprocessors

We may add, remove, or replace subprocessors as the Service develops.

Where required by applicable law or our Data Processing Addendum, we will provide appropriate notice of subprocessor changes.

Payment Processing

Ennijo uses Stripe as its payment processor for subscriptions and invoices.

Payment card details are submitted to and processed by Stripe. Ennijo does not receive or store full payment card numbers.

Stripe's independent processing of Personal Information is subject to its applicable privacy practices.

Customer-Authorized Services

If a Customer directs Ennijo to interact with another service or authorizes an integration, information may be transmitted as necessary to provide the requested functionality.

Information received by an independent third-party service may then be governed by that service's own privacy practices.

Legal Requirements

We may disclose information if we reasonably believe disclosure is necessary to:

Where legally permitted and appropriate, we may notify the affected Customer before disclosing Customer-controlled information.

Business Transactions

If 29in5 LLC or Ennijo is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar business transaction, information may be disclosed or transferred as part of that transaction.

Any successor receiving Personal Information will remain subject to applicable privacy obligations.

13. We Do Not Sell Personal Information

Ennijo does not sell Personal Information.

This includes both Account Data and CRM Contact Data.

Ennijo does not provide CRM Contact Data to third parties so those third parties can independently market to the Customer's contacts merely because those contacts are stored in Ennijo.

Certain privacy laws define terms such as "sale" or "sharing" more broadly than ordinary usage.

If Ennijo engages in activity that constitutes a sale or sharing under an applicable privacy law, we will provide any required notices and opt-out rights.

14. Aggregated and De-Identified Information

We may create aggregated or de-identified information that cannot reasonably be used to identify an individual.

We may use such information for purposes such as:

Where required by law, we will maintain de-identified information in de-identified form and will not attempt to re-identify it except as permitted by law.

15. Data Retention

We retain Personal Information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to contractual and legal requirements.

Active Accounts

Customer Data is generally retained while the Customer's account remains active.

After Cancellation

When a Customer cancels Ennijo, account access may first be suspended rather than immediately deleted.

Customer Data will remain available for possible reactivation or export for 30 days following cancellation.

During that period, a Customer may export Customer Data using Ennijo's in-application export tools or may contact us at support@ennijo.com for assistance.

After the initial 30-day period, Ennijo will begin deleting Customer Data from active production systems.

Ennijo intends to complete deletion of Customer Data from active production systems no later than 60 days after cancellation, unless longer retention is:

This deletion commitment applies to Customer Data stored as part of the Ennijo Service, including CRM Contact Data, related activity records, and Gmail-derived activity records maintained in the CRM.

Database Backups

Ennijo currently uses Supabase Pro infrastructure, under which daily database backups are retained for up to 7 days.

Information deleted from active production systems may therefore remain in database backups for up to 7 additional days before aging out through the normal database backup lifecycle.

If the underlying Supabase project is permanently deleted, associated database backups are also permanently deleted.

If Ennijo later changes its infrastructure, backup configuration, service plan, or backup technology, retention periods may change. We will update our practices and disclosures where appropriate.

AI Provider Retention

Information transmitted to our AI provider is processed and retained according to the provider's applicable commercial terms and data-processing commitments, as described in Section 7.

Those retention practices operate separately from Ennijo's own retention periods.

Operational Logs

Technical and security logs may be retained separately from the primary database for periods reasonably necessary to operate, secure, troubleshoot, and protect Ennijo.

We seek to minimize unnecessary Personal Information in operational logs.

16. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Information from unauthorized:

Safeguards may include:

Payment card details are processed by Stripe and full payment card numbers are not stored on Ennijo's systems.

No online service can guarantee absolute security.

Customers are responsible for:

17. Security Incidents

If we become aware of a security incident affecting Personal Information, we will investigate and take reasonable steps to contain and remediate the incident.

Where required by applicable law or contract, we will notify affected Customers, individuals, regulators, or other appropriate parties.

Where Ennijo processes CRM Contact Data on behalf of a Customer, additional security incident obligations may be governed by our Data Processing Addendum.

18. International Data Transfers

Ennijo is based in the United States.

Personal Information may be processed or stored in the United States or other countries where Ennijo's authorized service providers operate.

Those countries may have privacy laws different from those in an individual's home jurisdiction.

Where applicable law requires additional safeguards for international transfers, Ennijo may use recognized transfer mechanisms including:

Additional transfer provisions may be included in our Data Processing Addendum.

19. European Economic Area and United Kingdom Privacy Rights

Where the European Union General Data Protection Regulation, United Kingdom GDPR, or similar privacy laws apply, individuals may have rights including:

These rights may be subject to limitations or exceptions under applicable law.

Lawful Bases

Where applicable law requires a lawful basis for processing, Ennijo may rely on one or more of the following:

For CRM Contact Data processed on behalf of a Customer, the Customer is generally responsible for establishing the lawful basis for collecting and using that information.

Requests Concerning CRM Contact Data

If Ennijo processes your information only because you are contained in a Customer's CRM, that Customer is generally responsible for responding to your privacy request.

If you submit a request directly to Ennijo concerning Customer-controlled CRM Contact Data, we may refer the request to the appropriate Customer or assist that Customer as required by applicable law and contract.

20. United States State Privacy Rights

Residents of certain U.S. states may have additional privacy rights.

Depending on applicable law, those rights may include:

Not every right applies to every individual, company, or type of information.

When Ennijo Acts as a Service Provider

When Ennijo processes CRM Contact Data solely on behalf of a Customer, applicable privacy law may require an individual to submit a request to that Customer rather than directly to Ennijo.

In such cases, Ennijo will provide reasonable assistance to the Customer as required by applicable law and our agreements.

California

California residents may have rights under the California Consumer Privacy Act, as amended, where that law applies.

These may include rights to:

Ennijo does not sell Personal Information.

21. Privacy Requests

To request access, correction, deletion, or another applicable privacy right concerning information for which Ennijo is responsible, contact us at:

Privacy Email: privacy@ennijo.com

Mail:

29in5 LLC
4648 S Biltmore Ln
Madison, WI 53718
United States

We may need to verify your identity before completing certain requests.

Authorized agents may submit requests where permitted by law, subject to appropriate verification.

If your request concerns CRM Contact Data controlled by an Ennijo Customer, we may refer you to that Customer or work with the Customer to address the request.

We may retain information relating to privacy requests when necessary to demonstrate compliance with legal obligations.

22. Marketing Communications

You may opt out of promotional emails from Ennijo by using the unsubscribe method included in the communication or by contacting us.

Even after opting out of promotional communications, we may continue sending non-promotional communications relating to:

23. Children's Privacy

Ennijo is intended for business use by adults.

Ennijo is not directed to children under 18, and we do not knowingly create Ennijo accounts for children under 18.

Customers should not intentionally use Ennijo to store sensitive Personal Information about children unless such processing is lawful, necessary, and expressly supported by Ennijo.

If we learn that Personal Information has been collected in violation of applicable children's privacy law, we will take reasonable steps to address it.

24. Third-Party Websites and Services

Ennijo may contain links to or integrations with third-party websites and services.

We are not responsible for the independent privacy, security, or data practices of those third parties.

Customers should review the privacy practices of third-party services before connecting them to Ennijo or transmitting Personal Information to them.

25. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

When we make material changes, we will take reasonable steps to provide notice.

Notice may include:

The current version posted by Ennijo will control from its stated effective date.

26. Contact Us

If you have questions about this Privacy Policy or Ennijo's privacy practices, contact us:

Ennijo
29in5 LLC
4648 S Biltmore Ln
Madison, WI 53718
United States

Privacy: privacy@ennijo.com

Support: support@ennijo.com

Our Privacy Principle

Your relationships are yours.

Ennijo processes your data to help you manage those relationships, not to turn them into ours.