Effective date: 2026-09-04 · Version: 2026.09 · Canonical location: https://www.piestar.com/privacy

Piestar, Inc. (“Piestar,” “we”) builds research program administration software — Piestar DPx and Piestar RFx — used by universities, research institutions, and consortia (each a “Customer”) to manage federally funded research programs. This notice explains what personal information we handle, why, and how we protect it. It covers the Piestar DPx and RFx services (the “Services”) and the piestar.com website.

1. Our role

For personal information entered into the Services, the Customer institution is the data controller and Piestar is a service provider (processor) acting on its documented instructions under a Master Subscription Agreement (MSA). We use Service data only to provide, secure, and support the Services. Institutional users’ questions about how their institution collects and uses their information should be directed to that institution; we assist institutions in responding.

For the piestar.com website and our own business contacts (sales, support, billing), Piestar acts as the controller.

2. Information we handle

Provided by Customers and their users through the Services

  • Account information: name, email address, institution, role, and login credentials (passwords are stored only as salted hashes).
  • Program and research administration data entered by institutions and their participants for reporting to federal sponsors, which may include participant names, contact details, positions, and demographic information that sponsors require institutions to report.
  • Content uploaded by users, such as proposals, reports, and supporting documents.

Collected automatically

  • Service activity logs: user identifier, timestamps, actions performed, and source IP address. Institution administrators can view activity logs for their own tenant within the Services.
  • Technical data needed to operate and secure the Services, such as browser type and session identifiers.
  • Website and Service analytics (see Section 7).

What we ask Customers not to provide. Under the MSA, the Services are not intended for Restricted Data — including protected health information, Social Security numbers, payment card numbers, and non-directory student education records — unless the Customer has contracted for services that support it.

3. How we use information

We use personal information only to:

  • provide, operate, secure, and support the Services;
  • communicate with users about their accounts and the Services (transactional and service messages, not marketing);
  • meet legal obligations and enforce our agreements;
  • improve the Services using anonymous and aggregated usage data, as permitted by the MSA.

We do not sell personal information, use it for advertising, or use Customer data to train artificial-intelligence models.

4. Sharing and subprocessors

We share personal information only with the parties below, each bound by contract to protect it and to use it solely to provide services to Piestar:

Subprocessor Purpose Location
Amazon Web Services Hosting, storage, backups, and AI processing (Amazon Bedrock) United States
Google Cloud Platform Off-site backup storage United States
Mailgun (Sinch) Transactional email delivery United States
HubSpot Customer support and account communications United States
Sentry Application error monitoring United States

Within the Services, information is visible to other users according to the institution’s configuration and the product-specific rules in Section 10. We disclose personal information to law enforcement or other third parties only when required by valid legal process, and we notify the affected Customer unless legally prohibited.

We do not transfer, store, or process Service data outside the United States.

5. Artificial intelligence features

The Services include optional AI-assisted features, available after a user accepts an in-application AI-use agreement, and institutions can disable them for their tenant. AI processing uses foundation models hosted on Amazon Bedrock inside Piestar’s AWS environment. Amazon Bedrock is configured for zero data retention: prompts and outputs are not stored by the model provider and are never used to train models. AI features operate with read-only access limited to the requesting user’s own tenant data, and their outputs are presented to the user for review.

6. Retention and deletion

Customer data is preserved for the lifetime of the Customer’s account unless an authorized user deletes it. At the end of a subscription, we return Customer data in a commercially reasonable format on request and delete it from our systems and backups on the Customer’s instruction or as the MSA provides. Because federal award cycles often span contract periods, many Customers instruct us to retain their data pending renewal; we do so only on their instruction. Activity logs are retained for the duration of the Customer relationship. Business contact information is retained while we have an ongoing relationship or a legitimate business need.

7. Cookies and analytics

The Services use cookies that are necessary to sign in and keep sessions secure. We also collect Service usage analytics — through Google Analytics and our own instrumentation — to understand how features are used and to improve them; this data is not used for advertising and is not shared with third parties for their own purposes. The piestar.com website uses Google Analytics and HubSpot to measure site usage and manage inquiries submitted through our forms. You can limit cookies through your browser settings; the Services require session cookies to function.

8. Security

We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit (TLS) and at rest, multi-factor authentication for administrative access, role-based access controls within the Services, continuous security monitoring, tested backups, and security awareness training for all personnel. Access to Customer data by Piestar personnel is limited to what is needed to support and operate the Services. Our security practices are documented for Customers in the Higher Education Community Vendor Assessment Toolkit (HECVAT), available on request.

If we determine that a security incident has affected a Customer’s personal information, we notify that Customer within two business days and cooperate with the Customer to meet applicable breach-notification laws.

9. Your rights and choices

Users of the Services can view and update their own account and profile information within the application. Requests to access, correct, export, or delete personal information held on behalf of an institution are handled with and through that institution, which we assist promptly. Where privacy law grants individuals rights directly against Piestar, we honor them in accordance with that law. To make a request or raise a concern, contact privacy@piestar.com; we investigate and respond to privacy complaints and disputes.

10. Service-specific disclosures

Piestar DPx. Program coordinators designated by the institution, and the delegates they authorize, can access participant information within their institution’s tenant for program management and sponsor reporting.

Piestar RFx. When a user publishes a solicitation, its abstract and solicitation details are shared publicly, including any personal information the user includes in them. When a user submits a proposal to a solicitation, the submission and the submitter’s account information are shared with the managers and reviewers of that solicitation.

11. Education records, children, and other notices

Where a Customer discloses education records to Piestar, Piestar acts as a “school official” with a legitimate educational interest under FERPA, uses the records only to provide the Services, and does not redisclose them except as the Customer directs or the law requires. The Services are intended for institutional users and are not directed to children under 13.

12. Changes to this notice

We update this notice when our practices change and record the version and effective date at the top. Material changes are communicated to Customers through their designated contacts before they take effect. Prior versions are available on request.

13. Contact

Piestar, Inc.
privacy@piestar.com P.O. Box 207, Manhattan, KS 66505