Sensory Bridges LLC
Master Product, Research, Privacy, Security & Workplace Policy Handbook
Effective date: August 21, 2026
Entity: Sensory Bridges LLC, a Tennessee limited liability company
Policy owner: Managing Member, with Privacy, Security, Research, and Human Resources leads
Legal and security notice: legal@sensorybridges.com
IMPORTANT USE NOTE. This handbook is an operating framework. It is not, by itself, a customer contract, employee contract, privacy notice, informed-consent form, business associate agreement, data-processing agreement, software license, or retroactive demand. Provisions intended to bind a customer, university, research partner, licensee, employee, contractor, investor, or meeting attendee must be placed in the appropriate signed agreement or conspicuous clickwrap and supported by a recorded manifestation of assent. Tennessee and Georgia counsel should confirm the entity facts, regulatory status, governing-law provisions, and all bracketed items before adoption.
Contents
1. Purpose, Scope, and Operating Principles
2. Document Hierarchy and Required Standalone Instruments
3. Definitions
4. Entity Separation and Intercompany Controls
5. Accounts, Eligibility, and Minors
6. Acceptable Use and Authorization Boundaries
7. Product Use, Wellness Positioning, and Safety
8. Active Participation, Outcomes, Returns, and Refunds
9. Customer Content, User Data, and Data Ownership
10. Privacy Governance and Notice Standards
11. Consumer and Data-Subject Requests
12. Children’s Privacy and School Deployments
13. Health, Accessibility, and Biometric Information
14. Research and Human-Subjects Protection
15. Meetings, Recordings, Notetakers, and Communications
16. Company Systems, Monitoring, and Personal Devices
17. Intellectual Property Ownership and Chain of Title
18. License From MMMmc and End-User License Rules
19. Trade Secrets, NDAs, and Confidentiality
20. Copyright, Trademark, Patent, and Infringement Response
21. Open Source, Third-Party Code, and AI Inputs
22. Security Program
23. Security Incident, One-Hour Internal Escalation, and Breach Notice
24. External Institutional Access, Mixed Systems, and UTC-Facing Protocol
25. Evidence Preservation and Legal Holds
26. Vendors, Subprocessors, and Data Transfers
27. Payment, Billing, Hardware, and Warranty
28. Disclaimers and Allocation of Risk
29. Limitation of Liability
30. User Responsibility and Indemnification
31. Dispute Notice and Mandatory Mediation
32. Attorneys’ Fees, Forensics, and Equitable Relief
33. Workforce: Equal Opportunity, Accommodation, and Anti-Harassment
34. Workforce: Classification, Pay, Time, Leave, and Remote Work
35. Workforce: Performance, Discipline, Complaints, and Separation
36. Personnel Files and Workforce Privacy
37. Confidentiality, Whistleblowing, and Protected Communications
38. Conflicts, Outside Activities, Gifts, and Research Integrity
39. Grants, Government Funding, and Sponsored Research
40. Records Retention and Destruction
41. Training, Audits, Enforcement, and Governance
42. Adoption and Acknowledgment
1. Purpose, Scope, and Operating Principles
This handbook establishes the minimum governance, privacy, security, research, product, workforce, intellectual-property, and dispute-management standards for Sensory Bridges LLC ("Sensory Bridges"). Sensory Bridges develops, assembles, tests, markets, supports, and deploys accessibility, self-regulation, education, wellness, research, and related tools, including the Brooks Band platform and associated applications, dashboards, firmware, data workflows, and services.
Sensory Bridges is the operating and commercialization entity. Under the intended structure described by management, MMMmc LLC is the intellectual-property holding, software-licensing, and consulting entity. Sensory Bridges may create or commission improvements, but ownership must be governed by executed invention-assignment, work-made-for-hire, and intercompany agreements. This handbook does not itself cure gaps in chain of title.
The Company will follow these principles:
- Collect and use only data reasonably necessary for disclosed purposes.
- Separate customer data, child data, education records, research records, workforce records, privileged material, and Company IP by role and purpose.
- Grant access by resource, purpose, user, time, and approved action; technical capability is not legal authorization.
- Preserve evidence without conducting unauthorized self-help on third-party systems.
- Respect user ownership of user-supplied content while obtaining only the license needed to provide the service.
- Protect trade secrets through documented reasonable measures, not labels alone.
- Make no unverified medical, scientific, patent, copyright-registration, security, or outcome claim.
- Apply consumer limitations, disclaimers, and remedies only to the extent permitted by nonwaivable law.
- Keep Sensory Bridges and MMMmc books, accounts, contracts, IP schedules, employees, systems, and liabilities separate.
2. Document Hierarchy and Required Standalone Instruments
When documents conflict, the following order controls unless a signed agreement expressly states otherwise: applicable law; court or regulator order; IRB-approved protocol and informed consent for research; signed enterprise order form and negotiated addendum; business associate agreement or data-processing agreement; end-user license or clickwrap terms; privacy notice and product-specific notice; this handbook; internal procedures.
The Company must publish or execute separate instruments for the following functions:
- Website Terms of Use and Acceptable Use Policy.
- Consumer Privacy Notice, Cookie Notice, and state-specific notices.
- Child and Parent Privacy Notice with verifiable parental-consent workflow when COPPA applies.
- School Data Privacy Addendum and FERPA data-use terms.
- HIPAA Business Associate Agreement when the Company is a business associate.
- Research protocol, IRB approval, informed consent/assent, authorization, and data-use agreement.
- Consumer subscription terms, hardware warranty, returns, and refund policy.
- Enterprise master services agreement, service-level terms, DPA, and security exhibit.
- MMMmc-to-Sensory Bridges intercompany IP license and development/assignment agreement.
- Employee confidentiality and invention-assignment agreement.
- Contractor services, confidentiality, work-made-for-hire, and invention-assignment agreement.
- Mutual or unilateral NDA for investors, vendors, partners, demonstrations, and due diligence.
- Meeting invitation notice and recording/notetaker consent.
- Vulnerability Disclosure Policy and DMCA notice-and-takedown process.
3. Definitions
Account means a user, administrator, service, cloud, email, repository, database, developer, recovery, machine, or identity-provider account used with Company Resources.
Active Participation means timely completion, to the extent reasonably possible, of the documented onboarding, baseline configuration, safety instructions, agreed usage schedule, required check-ins, device syncing, troubleshooting, and outcome measures stated for the purchased program. A disability-related limitation, approved accommodation, illness, emergency, service outage, or Company-caused barrier does not constitute nonparticipation.
Adverse Event means an event that may involve injury, health deterioration, safety risk, unexpected serious distress, or other event requiring safety review, regardless of product causation.
Documented Adverse Outcome means a material worsening in the specific outcome the program was designed to support, supported by reasonably reliable before-and-after information, reported promptly, and reviewed without requiring the customer to prove medical causation. It is distinct from an Adverse Event, which must be escalated immediately and may not be conditioned on refund eligibility.
Authorization means a current, express, resource-specific grant from a person with actual authority that identifies the permitted user, resource, data, purpose, action, and duration. Possessing credentials, receiving a link, holding an administrator role, attending a meeting, prior access, or benefiting from a misconfiguration does not alone establish Authorization.
Biometric Data means data treated as biometric information under applicable law. Audio, voice, movement, or behavioral information will not be labeled biometric unless the relevant definition and processing purpose are met; voiceprints or other identifiers used to identify a person receive heightened controls.
Child means a person under thirteen for COPPA purposes, or a minor under another applicable law or contract.
Company Data means information owned, licensed, controlled, administered, received, transmitted, or lawfully entrusted to Sensory Bridges, including customer, student, child, health, accessibility, research, grant, partner, investor, security, personnel, product, and business information. Storage on a Company Resource alone does not transfer ownership of third-party IP or personal information.
Company Materials means Company Data, Confidential Information, Company IP, documentation, prototypes, devices, credentials, repositories, models, designs, meeting records, and other protected assets.
Company Resource means an Account, device, website, application, API, SDK, repository, database, cloud tenant, server, storage location, backup, endpoint, network, domain, wearable, managed profile, or other computing or business resource owned, licensed, administered, or provided by Sensory Bridges.
Confidential Information means nonpublic information that is marked confidential or that a reasonable person would understand is confidential, including source and object code; GitHub, Replit, Webflow, deployment and development environments; system prompts, workflows, algorithms, model configurations, datasets and synthetic datasets; inventions and patent materials; hardware and firmware; customer, student, child, research, health, therapy, accessibility, grant, investor, personnel and security information; credentials and logs; meeting recordings and summaries; product roadmaps; pricing; forecasts; legal advice and attorney work product. It excludes information the recipient can document was lawfully known without restriction, independently developed without use of the information, rightfully received without duty, or publicly available without breach.
Consumer means an individual acting in a personal or household context.
Customer Content means content a customer or authorized user submits to the service. As between the customer and Sensory Bridges, the customer retains its ownership, subject to the limited service license in this handbook and the governing agreement.
De-identified Data means information processed so it cannot reasonably be linked to an identifiable person, supported by technical and contractual safeguards against re-identification. Pseudonymous data is not automatically de-identified.
Education Record has the meaning provided by FERPA and applicable state student-privacy law.
Personal Data means information linked or reasonably linkable to an identified or identifiable person, excluding information lawfully treated as de-identified or publicly available under the governing law.
Research means a systematic investigation designed to develop or contribute to generalizable knowledge or another activity governed by an IRB, sponsor, research agreement, or applicable research rule. Product analytics, quality assurance, and operations are not labeled Research merely to broaden use rights.
Security Incident means an actual or reasonably suspected compromise of confidentiality, integrity, availability, authentication, authorization, or lawful use of Company Data or Company Resources.
Service-Generated Data means security, diagnostic, performance, configuration, and usage telemetry created by operation of the service. It excludes the substantive content of communications unless clearly disclosed and lawfully processed.
Trade Secret means information meeting the applicable statutory definition because it derives independent economic value from not being generally known and is subject to reasonable measures to maintain secrecy.
Unauthorized Access means access without Authorization; beyond the approved resource, user, data, action, purpose, or time; after expiration or revocation; through credentials, impersonation, circumvention, interception, misconfiguration, or another unauthorized path; or for an undisclosed prohibited purpose.
Unauthorized Copy includes an unauthorized download, clone, fork, mirror, export, screenshot, recording, transcript, cache, embedding, backup, snapshot, replica, dataset, or reconstruction.
User means a customer, end user, employee, contractor, researcher, partner, attendee, administrator, or other person authorized to access a Company Resource or Company Material.
4. Entity Separation and Intercompany Controls
Sensory Bridges and MMMmc are separate legal entities. No person may state or imply that one entity is liable for the other, that their assets are interchangeable, or that a contract with one automatically binds the other.
The following controls are mandatory:
- Each contract, invoice, privacy notice, website, bank account, payroll account, insurance policy, repository, patent or copyright record, and license must identify the correct entity.
- Sensory Bridges may use MMMmc IP only under an executed intercompany license describing field, territory, exclusivity, sublicensing, source-code access, quality control, royalties, audit rights, data roles, improvements, termination, transition, and insolvency.
- Employees and contractors developing MMMmc-owned technology must execute assignments to the intended owner. Sensory Bridges must then assign covered rights under the intercompany development agreement.
- Hardware ownership, patent ownership, software ownership, trademarks, domain names, datasets, and improvements must be listed in separate schedules; labels such as “all Company IP” are not a substitute.
- Related-party payments must be documented, commercially reasonable, approved, and recorded. No commingling is permitted.
- Each entity must maintain its own legal hold, insurance, books, records, tax filings, capitalization, and minutes or written consents.
- Management must confirm whether Sensory Bridges has an exclusive or nonexclusive license and whether that license is limited to specified products or fields.
5. Accounts, Eligibility, and Minors
Public consumer accounts are not offered directly to children under thirteen unless the Company has implemented a product-specific COPPA program. An adult parent, guardian, school, clinician, or authorized organization may establish and manage a child-associated account only under the applicable consent and institutional agreement.
No one may misrepresent age, identity, authority, affiliation, ownership, or consent. Organizational administrators represent that they have authority to bind the organization and provision users. Administrators may control an organization-managed account and associated records only within the governing agreement; they do not acquire rights in a user’s unrelated personal account or device.
The Company will provide age-appropriate notices and, where required, obtain verifiable parental consent before collecting a Child’s Personal Data. Parents must be able to review, correct, delete, or withdraw further collection subject to narrow legal, safety, research, and recordkeeping exceptions. The service may be discontinued if the information is reasonably necessary to provide it and consent is withdrawn.
6. Acceptable Use and Authorization Boundaries
Users may access Company Resources only for the purpose, role, data, function, and period affirmatively authorized. Users must protect credentials, use multifactor authentication when offered, maintain supported software, report suspected compromise, and follow applicable law and institutional obligations.
Users must not:
- Access an Account, resource, environment, repository, branch, dataset, backup, record, or device without Authorization or exceed an Authorization boundary.
- Share, obtain, reuse, intercept, or test credentials, session tokens, API keys, OAuth grants, recovery methods, cookies, or device identities without Authorization.
- Create hidden accounts, forwarding rules, service principals, integrations, bots, webhooks, persistence, guest users, duplicate identities, or recovery mechanisms.
- Clone, fork, mirror, scrape, export, index, cache, reconstruct, or copy Company Materials except as the license expressly permits.
- Reverse engineer, decompile, disassemble, derive source code, bypass license controls, remove notices, or circumvent security, except to the limited extent a nonwaivable law permits despite contract restriction.
- Use Company Materials, prompts, outputs, workflows, or data to train, fine-tune, benchmark, validate, or build a competing model, product, dataset, or service without a signed license.
- Upload Company Data, Customer Content, Education Records, health data, research records, privileged information, or NDA material to an unapproved AI system, notetaker, storage service, or personal account.
- Intercept communications; record or transcribe without required notice and consent; impersonate another; falsify origin, timestamps, authorship, or attribution.
- Introduce malware; scan or test vulnerabilities outside the Vulnerability Disclosure Policy; interfere with availability; or evade rate, use, or safety limits.
- Delete, alter, conceal, fabricate, or destroy evidence, logs, metadata, source history, research records, personnel records, financial records, or legal holds.
- Use the service for unlawful discrimination, harassment, surveillance, exploitation of a Child, medical diagnosis without authorization, high-risk control, or infringement.
- Assist another person with prohibited conduct.
Potential violations may result in proportionate investigation, rate limiting, quarantine, credential rotation, access suspension, contract termination, preservation, notice, and lawful enforcement. The Company will avoid public attribution until supported by evidence.
7. Product Use, Wellness Positioning, and Safety
Unless a product-specific regulatory authorization expressly states otherwise, Sensory Bridges products are accessibility, education, self-regulation, research, or general-wellness tools. They are not a substitute for professional judgment and are not intended to diagnose, cure, mitigate, treat, or prevent disease. No employee may make medical-device, clinical-efficacy, therapeutic, or reimbursement claims without documented regulatory and legal approval.
Users must follow device, charging, fit, skin, accessibility, supervision, environment, and software instructions. Products must not be used as life-support, emergency-alert, sole supervision, restraint, punishment, or fail-safe systems. A qualified professional remains responsible for clinical, educational, employment, and safety decisions.
The Company will maintain complaint handling, adverse-event triage, corrective-action, recall, vulnerability, and regulatory-escalation procedures. Safety reports are accepted regardless of payment, participation, warranty, NDA, or dispute status. Reporting a safety issue does not waive any right.
Marketing must distinguish preliminary, internal, observational, pilot, and peer-reviewed evidence; identify population and limitations; and avoid guaranteeing outcomes.
8. Active Participation, Outcomes, Returns, and Refunds
Products require user, caregiver, educator, clinician, or administrator participation. Individual outcomes vary. The Company does not warrant a particular educational, behavioral, health, accessibility, employment, or financial result.
Unless a product-specific order form states otherwise, the following refund framework applies prospectively:
- Hardware returns require timely authorization, ordinary care, return of included components, and receipt within the published return window.
- Subscription fees are nonrefundable after the published trial period, except as required by law, for duplicate charges, or under the Outcome Review process.
- An Outcome Review refund may be considered when the purchaser documents Active Participation and a Documented Adverse Outcome, gives the Company a reasonable opportunity to troubleshoot or adjust the program where safe, and returns Company hardware.
- The Company will not require continued use after an Adverse Event or medically advised stop. Lack of further use after such instruction does not defeat Active Participation.
- Refund eligibility does not replace a hardware warranty, statutory withdrawal right, product-liability right, research-participant right, or other nonwaivable remedy.
- A refund decision will be based on objective criteria stated at purchase, not undisclosed discretion. Denials include a written reason and appeal route.
- A refund does not require a release of injury, privacy, research, discrimination, or third-party rights unless separately negotiated with counsel and lawful.
9. Customer Content, User Data, and Data Ownership
Customers retain ownership of Customer Content. They grant Sensory Bridges a limited, nonexclusive, worldwide license to host, copy, transmit, format, display, and otherwise process Customer Content only as necessary to provide, secure, support, and lawfully improve the contracted service, comply with instructions and law, and enforce the agreement. The license ends when the data is deleted from active systems, subject to documented backups, legal holds, security records, and lawful retention.
Sensory Bridges owns its service, software interfaces, configurations, documentation, analytics methods, and Service-Generated Data, subject to MMMmc’s underlying IP ownership and the intercompany license. The Company does not claim ownership merely because third-party content is stored on Company Resources.
Institutional customers may control Education Records or other organization-managed content. The data-processing agreement must identify controller/processor roles, access rights, export, retention, and deletion. Research data ownership and custody are governed by the protocol, consent, sponsor terms, and research agreement—not by a blanket website clause.
The Company may create aggregated or De-identified Data for security, quality, analytics, and research only if the process and contractual controls reasonably prevent identification and the use is consistent with notices, consent, and law. Re-identification is prohibited.
10. Privacy Governance and Notice Standards
The Company will maintain a data inventory and record of processing that identifies categories, sources, systems, purposes, legal bases or permissions, recipients, subprocessors, retention, security classification, responsible owner, and cross-border transfers.
Privacy notices will accurately disclose:
- Contact, account, profile, purchase, support, survey, research, device, app, usage, diagnostic, security, approximate location, audio, voice, movement, accessibility, health-related, and institutional data actually collected.
- Whether data comes from the individual, caregiver, school, clinician, device, integration, customer, public source, or service provider.
- Specific purposes, including account operation, personalization, safety, research, fraud prevention, support, billing, legal compliance, and rights protection.
- Categories of recipients and subprocessors; institution-administered visibility; user-directed sharing; and business transfers.
- Retention criteria and material product-specific periods.
- Consumer rights, verification, authorized agents, appeals, and non-discrimination.
- Whether data is sold, shared for cross-context advertising, used for targeted advertising, or used for profiling; the Company will not state “we do not sell” unless verified across cookies, SDKs, analytics, and integrations.
- AI, automated decision support, model-training, biometric, research, child, student, and health-data practices.
- International transfers and applicable safeguards.
Materially new purposes require updated notice and consent where required. Policies are prospective and will not be represented as retroactively authorizing prior access or use.
11. Consumer and Data-Subject Requests
The Company will provide a documented channel for access, correction, deletion, portability, opt-out, consent withdrawal, appeal, and complaint requests. Requests will be acknowledged promptly and completed within the applicable legal period. A 45-day response target applies where Tennessee law governs and the Company is subject to it; extensions and appeals will be handled as the statute permits.
Identity verification must be proportionate to the request and may not collect excessive new data. The Company will not disclose another person’s data, trade secrets, security-sensitive information, privileged material, or information prohibited from release. Denials must identify the basis and appeal route. Requests under a school-controlled or employer-controlled account may be directed to the controlling institution.
Deletion may be limited by legal holds, research integrity, grant, safety, fraud, security, accounting, warranty, defense-of-claims, and other lawful obligations. Restricted data must be isolated from ordinary use.
12. Children’s Privacy and School Deployments
When a service is directed to Children or the Company has actual knowledge it collects a Child’s Personal Data online, the Company must implement a COPPA program before collection. The program includes a child-specific privacy notice, direct parental notice, verifiable parental consent, data minimization, parent rights, service-provider diligence, security, and a finite retention schedule.
School authorization may support collection only where COPPA permits the school to consent for an educational context and the use is limited to that context. Commercial profiling, advertising, unrelated research, or use beyond the school’s authority requires separate legal analysis and consent.
For FERPA-regulated deployments, the written agreement must specify whether Sensory Bridges is a school official under direct control or a studies/audit recipient; permit access only for legitimate educational interests; prohibit redisclosure and commercial use; require security and deletion; address parent/student requests; and support the institution’s disclosure records. The Company does not claim that it is itself directly regulated by FERPA in every relationship.
No child or student data may be used to train a general model, create advertising profiles, or infer sensitive traits unless specifically authorized by law, contract, notice, and consent. Education Records must be separated from general product analytics.
13. Health, Accessibility, and Biometric Information
HIPAA applies only when the Company is acting as a covered entity or business associate with respect to protected health information. A signed Business Associate Agreement is required before receiving PHI on behalf of a covered entity. Consumer wellness data outside HIPAA may still be subject to the FTC Act, the FTC Health Breach Notification Rule, state privacy laws, biometric laws, contract, and Company promises.
Sensitive health, therapy, disability, accommodation, voice, and movement data receive heightened access, encryption, logging, minimization, and retention controls. Raw audio will not be collected, retained, or described as destroyed on-device unless engineering has verified the actual architecture. Product documentation must distinguish audio feature extraction from recording and voice identification.
Before processing a voiceprint or other biometric identifier, the Company must determine applicable state law, provide the required notice, obtain written consent where required, publish a retention/destruction schedule, prohibit sale or profit where required, and contractually control vendors. Ordinary audio is not automatically a biometric identifier, but it remains sensitive.
The Company will maintain an accessibility channel and use WCAG 2.2 AA as a design target where feasible, with testing by people with disabilities, keyboard and screen-reader support, captioning, contrast, focus, error identification, and alternative formats. Accommodation requests will be handled individually and without retaliation.
14. Research and Human-Subjects Protection
Research involving human participants may begin only after a qualified determination of whether IRB review, exemption, or other oversight is required. Where 45 C.F.R. Part 46, FDA rules, sponsor terms, or institutional policies apply, the Company will follow the approved protocol and document continuing review, amendments, deviations, adverse events, unanticipated problems, training, and closure.
Informed consent must explain purpose, procedures, risks, benefits, alternatives, privacy, data use, recording, AI/notetakers, compensation, injury information where applicable, voluntary participation, withdrawal, contacts, retention, future use, commercial profit, return of results, and limits on confidentiality. Children require parental permission and age-appropriate assent when required.
Research participation must be voluntary. Declining or withdrawing may not affect employment, education, care, access to ordinary services, grades, or benefits except where the intervention cannot continue without necessary data. Research data may not be silently repurposed for product development, model training, marketing, or employment decisions.
The Company will not characterize ordinary customer communications or every recorded meeting as Research. If communications are to be used for generalizable research, the protocol, notice, consent, and data governance must authorize that use.
External research transfers require a data-use agreement covering purpose, permitted users, security, publication review for confidentiality—not suppression of valid results—re-identification prohibition, incident notice, return/deletion, and sponsor/IRB obligations.
15. Meetings, Recordings, Notetakers, and Communications
Nonpublic product, research, investor, technical, legal, personnel, partner, and strategy meetings are confidential when the invitation, governing agreement, or circumstances reasonably provide notice. Confidentiality is not created merely by declaring every later communication confidential.
The Company may use an approved human or automated notetaker or record a meeting only under this protocol:
- The invitation provides conspicuous advance notice of the tool, operator, purposes, recipients, retention, and how to object.
- The meeting begins with contemporaneous notice. Where one-party consent is insufficient or the participants’ locations are uncertain, affirmative consent is obtained from every participant.
- A participant may request no recording. When feasible, the Company will disable recording, offer an unrecorded alternative, or provide a written summary. If recording is essential for accessibility, research, compliance, or the service, that fact and lawful basis must be explained before participation.
- Unapproved bots, phone bridges, transcribers, screen recorders, or AI assistants are prohibited.
- Recordings containing legal advice, therapy, health, education, research, Child, personnel, or grant information receive role-based access and purpose-specific retention.
- Recording is paused for privileged, highly sensitive, or off-record discussions when appropriate.
Sensory Bridges owns the particular recording, transcript, summary, and notes it creates as a business record, subject to MMMmc’s underlying IP, the speaker’s rights in pre-existing material, privacy rights, research consent, institution-owned data, and the governing contract. Participation does not transfer a speaker’s unrelated IP or waive privilege.
Meeting records may be used for documentation, accessibility, quality, security, and product improvement as disclosed. Use for Research or model training requires separate authorization where applicable. Participants may not redistribute, publish, upload, or use Company meeting records outside the authorized purpose.
16. Company Systems, Monitoring, and Personal Devices
After required notice and to the extent permitted by law, Users have no expectation of personal privacy in Company Accounts, Company-owned devices, Company-managed work profiles, Company networks, Company repositories, Company business communications, Company Data, and security/audit records generated by Company Resources.
Authorized personnel may proportionately monitor, log, review, preserve, and investigate Company Resources for security, continuity, legal compliance, research integrity, offboarding, support, contract enforcement, and protection of Company or third-party data. Emergency access must be documented and reviewed.
The Company does not claim an unrestricted right to search a personal device or unrelated personal account. If a personal system connects to Company Resources, authenticates to an Account, contains Company Data, uses Company credentials, or is reasonably believed to contain incident evidence, the Company may revoke access, preserve Company-side logs, require return/deletion and an accounting, request a limited inspection by consent, or seek lawful process. Actual access requires written consent, a valid BYOD/MDM agreement, or lawful process and must minimize unrelated personal and privileged content.
Users may not store Company Data in personal email, cloud, messaging, repository, AI, transcription, removable media, or backup services without written approval. The Company is not responsible for preserving personal data stored contrary to policy, but this does not eliminate nonwaivable security, privacy, or notice duties after the Company learns regulated data is present.
17. Intellectual Property Ownership and Chain of Title
Copyright attaches to an original work of authorship when fixed in a tangible medium, subject to statutory limits. Registration is not the source of copyright, but timely registration may be required for suit and may affect statutory damages and attorneys’ fees. No employee may claim that every idea is copyrighted or that registration exists without checking the copyright schedule.
Patent inventorship is determined by law and cannot be changed by contract; ownership may be assigned. “Patent pending” may be used only for a product or process actually covered by a pending application. The Company will maintain a confidential invention disclosure and patent schedule showing inventors, owners, assignments, filing numbers, status, countries, deadlines, public disclosures, and government or sponsor rights.
All employees and contractors must disclose covered inventions, preserve records, execute assignments, and cooperate with filings. Agreements must identify pre-existing materials and exclude inventions protected by applicable employee-invention law. Work-made-for-hire language is supplemented by a present assignment of rights.
The Company will maintain an asset register for the Brooks Band hardware and app, firmware, dashboards, source repositories, datasets, algorithms, Mirror Match, Founders Lab, AVVOF, GFOD, calculators, prototypes, and future unfiled IP. Listing an item does not establish ownership; each entry must include author/inventor, date, evidence, owner, agreements, funding, university-resource use, open-source components, and license status.
18. License From MMMmc and End-User License Rules
Sensory Bridges may distribute or provide MMMmc software only within its signed intercompany license. End users receive only the limited rights stated in an accepted license; software is licensed, not sold.
Unless a signed order form states otherwise, an end-user license is personal or organization-limited, nonexclusive, nontransferable, nonsublicensable, and limited to object-code use for the paid term and authorized purpose. No source, patent, trademark, research, or trade-secret license arises by implication, estoppel, viewing, testing, employment, grant participation, demonstration, or access.
Revocation and suspension are categorized for enforceability:
- Free, demo, beta, evaluation, repository-review, or courtesy access may be revoked at any time, with or without cause, subject to nonwaivable law and preservation duties.
- Paid access may be suspended immediately for security risk, unlawful use, infringement, nonpayment, confidentiality breach, or material violation, with notice and cure when reasonably safe and required.
- A paid license may be terminated for cause under the agreement. Termination without customer breach must follow the contract and may require notice, transition, or a pro-rata refund; the Company will not promise a paid term and simultaneously reserve an illusory right to cancel without consequence.
- Revocation ends use rights but does not authorize destruction of evidence, erase accrued obligations, or override lawful retention.
Upon termination, the user must stop use, return hardware as required, remove software, return or securely delete Company Materials subject to legal hold, and certify compliance if the agreement requires it.
19. Trade Secrets, NDAs, and Confidentiality
The Company will use reasonable measures to protect each asserted Trade Secret: need-to-know access; role separation; MFA; encryption; private repositories; logging; approved devices; confidentiality agreements; labeling; training; visitor and meeting controls; controlled exports; vendor diligence; offboarding; and a trade-secret schedule identifying the secret without public overdisclosure.
Confidentiality obligations apply only to covered information and include lawful exclusions and compelled-disclosure procedures. A recipient must use Confidential Information only for the permitted purpose, protect it with at least reasonable care, limit access, report suspected loss, and return or destroy it on request subject to law and preservation.
Trade-secret obligations survive while the information remains a Trade Secret. Other confidentiality obligations survive for the period stated in the agreement. Nothing prohibits protected whistleblowing, reporting to government, discussing wages or working conditions where protected, responding to lawful process, or using the federal trade-secret whistleblower immunity in 18 U.S.C. § 1833(b).
20. Copyright, Trademark, Patent, and Infringement Response
Users may not reproduce, distribute, adapt, publicly display, perform, remove notices from, or create derivatives of protected Company Materials except as licensed. Fair use, reverse-engineering exceptions, interoperability rights, and other nonwaivable rights are preserved.
The Company will maintain a DMCA agent if it qualifies for the safe harbor, a repeat-infringer policy, a compliant notice/counter-notice workflow, and a process for trademark and patent complaints. Takedown decisions must preserve evidence and avoid knowingly false claims.
For proven infringement, misappropriation, unauthorized access, or breach, the Company may seek the remedies actually authorized by contract and law, including injunction, impoundment, return, destruction, accounting, actual loss, infringer’s profits, unjust enrichment, reasonable royalty, statutory damages where available, exemplary damages where statutory conditions are met, and attorneys’ fees where recoverable.
No handbook may impose an automatic punitive “high cost” unrelated to anticipated loss. A separately negotiated business agreement may use reasonable liquidated damages only after counsel confirms that actual damages are difficult to estimate and the amount is a reasonable forecast rather than a penalty. Copyright materials should accurately state that statutory damages can range by work and willfulness under 17 U.S.C. § 504, not promise an automatic award.
21. Open Source, Third-Party Code, and AI Inputs
All software releases require a software bill of materials and review of open-source, source-available, model, font, media, SDK, dataset, and third-party license terms. Copyleft, attribution, notice, source-offer, patent, field-of-use, and redistribution obligations must be documented before release.
No employee may paste Confidential Information, third-party code, education records, health data, research data, or privileged content into a generative-AI service without approval. AI-assisted code must receive human review for ownership, security, license, provenance, bias, accessibility, and reliability. The Company does not represent AI output as exclusively human-created and does not guarantee noninfringement.
22. Security Program
The Company will maintain a risk-based written security program aligned to the NIST Cybersecurity Framework and, where applicable, the NIST Privacy Framework. Controls include asset inventory, data classification, least privilege, MFA, secure configuration, encryption in transit and at rest appropriate to risk, secrets management, logging, vulnerability management, secure development, code review, backups, recovery testing, vendor management, incident response, and workforce training.
Specific algorithm names or versions such as “AES-256” or “TLS 1.3” will be promised publicly only when engineering verifies universal implementation. Security statements must describe controls accurately and must not guarantee absolute security.
Source repositories require organization ownership, protected branches, peer review, signed releases where feasible, dependency scanning, secret scanning, token rotation, audit logs, and export restrictions. Personal repository mirrors are prohibited.
The Company will maintain a Vulnerability Disclosure Policy with authorized testing scope, safe-harbor language approved by counsel, prohibited methods, reporting instructions, response targets, and no promise of bounty unless a program exists.
23. Security Incident, One-Hour Internal Escalation, and Breach Notice
Any workforce member, contractor, bound administrator, or vendor who knows or reasonably suspects a Security Incident must notify legal@sensorybridges.com and the designated security contact immediately and no later than one hour after discovery. This is an internal/contractual escalation target, not a representation that every third party or stranger is legally bound.
The initial report should identify known persons, times and time zones, Accounts, devices, IP addresses, credentials, access paths, files, records, repositories, queries, copies, changes, deletions, recipients, integrations, forwarding, persistence, and locations. The reporter must not investigate by entering another person’s system.
Within twenty-four hours of discovery, the incident lead should, as appropriate:
1. Stop or contain unauthorized access within Company control.
2. Preserve relevant evidence and metadata without avoidable alteration.
3. Record chain of custody, hashes, tenant/object/correlation/session IDs, IPs, user agents, and retention settings.
4. Identify affected data owners, controllers, research institutions, customers, and licensors.
5. Engage counsel, insurer, forensics, and law enforcement when appropriate.
6. Assess contractual and statutory notice, including Tennessee breach law, HIPAA, the FTC Health Breach Notification Rule, COPPA, education, biometric, research, and other state laws.
7. Document decisions and follow-up actions.
The Company will notify affected persons, controllers, regulators, and others within the period and in the manner required by law or contract. The handbook does not replace statutory analysis and does not guarantee that an unrelated third party will provide a one-hour notice or twenty-four-hour inventory unless that party accepted such a contract.
24. External Institutional Access, Mixed Systems, and UTC-Facing Protocol
This protocol applies prospectively to universities, schools, research institutions, customers, and other external administrators, including any University of Tennessee unit, when they access, host, connect to, receive, or control Company Materials.
Before access, the parties must create an Authorization Matrix identifying owner, administrator, data controller, processor, credential issuer, user, resource, permitted purpose, permitted dates, approval, technical permission, revocation, export rights, recipients, and return/deletion. Institutional authority over its own tenant does not automatically establish authority over unrelated personal accounts, Company Resources, private devices, privileged communications, or third-party confidential information.
Contracts should require:
- Resource- and purpose-limited access; named approvers; logging; notice; and segregation of institution data from Company and personal data.
- Compliance with the institution’s own acceptable-use, authorization, copyright, license, incident-response, research, personnel, and conflict policies.
- Prompt notice of suspected unauthorized access and a verified inventory of files viewed, searched, copied, exported, modified, deleted, shared, restored, or retained.
- Preservation of native logs, metadata, search terms, approvals, recipients, integrations, devices, and legal holds.
- No review or use of privileged or work-product material; immediate sequestration, nonwaiver, recipient identification, and neutral review if discovered.
- No model training, product development, publication, commercialization, or secondary research using Company Materials without a signed license and required consent.
- Return, deletion subject to preservation, access cutoff, downstream notice, and signed certification.
- Cooperation with lawful breach, research, sponsor, partner, data-subject, and regulatory obligations.
UT System Policy IT0002 recognizes broad monitoring and access rights on UT resources but also limits users to authorized purposes, requires respect for IP and privacy, restricts unlicensed copying, and states that certain access to connected non-UT systems or systems containing UT data requires approval or legitimate grounds. UT IT0122 requires incident tracking, forensic-evidence protection, containment, recovery, and communication. These policies may be relevant evidence or contract standards; Sensory Bridges does not adopt them as admissions and cannot use this handbook to bind UT retroactively.
25. Evidence Preservation and Legal Holds
When litigation, an administrative dispute, a claim, a research inquiry, or a material incident is reasonably anticipated, counsel or an authorized legal-hold lead will issue a scoped hold. Relevant deletion, overwriting, backup rotation, log expiry, messaging retention, source-history rewriting, and device disposal must be suspended.
Custodians must preserve native records and metadata, avoid annotations that alter originals, identify locations and custodians, and cooperate with lawful collection. Legal holds are confidential but do not permit concealment, falsification, or unauthorized access.
Return or deletion demands must distinguish evidence that must be preserved from operational copies that should be returned or deleted. Where privilege or unrelated personal content is present, the Company will consider a neutral examiner, special master, filtering protocol, hash inventory, and Federal Rule of Evidence 502 protections.
26. Vendors, Subprocessors, and Data Transfers
Before a vendor processes Company Data, the business owner and privacy/security leads must evaluate service need, data categories, security, privacy, location, subcontractors, AI/model use, deletion, portability, incident history, financial stability, and contract terms.
Contracts must include confidentiality, purpose limitation, least access, security, incident notice, cooperation, return/deletion, audit or assessment rights, subprocessor flow-down, legal-process notice where lawful, and allocation of controller/processor duties. Vendors handling PHI, Education Records, Child data, research data, biometrics, payment information, or privileged material require specialized review.
Sensory Bridges is not liable for the independent acts of an unrelated third party outside its reasonable control to the fullest extent permitted by law. That provision does not excuse Sensory Bridges’ own breach, misrepresentation, nonwaivable duty, legally attributable vendor conduct, unreasonable security, unlawful disclosure, or notification duty.
27. Payment, Billing, Hardware, and Warranty
Prices, taxes, renewal, hardware ownership, replacement fees, shipping, return windows, cancellation, and subscription term must be disclosed before purchase. Auto-renewal requires the notice and cancellation mechanism required by applicable law. No employee may route Company payments through a personal account.
Hardware warranties must identify duration, coverage, exclusions, repair/replacement process, and legal rights. Disclaimers may not negate nonwaivable consumer warranties. Beta and research devices require separate terms and inventory controls.
Chargebacks, billing disputes, refunds, and collections must be documented. Access may be limited for nonpayment after required notice, but safety records, legally required exports, and consumer rights must remain available as required.
28. Disclaimers and Allocation of Risk
To the fullest extent permitted by law, services are provided “as is” and “as available,” and Sensory Bridges disclaims implied warranties of merchantability, fitness for a particular purpose, title, and noninfringement. These disclaimers do not apply where prohibited, to express warranties in an order form, or to a hardware warranty that cannot lawfully be disclaimed.
Sensory Bridges does not warrant uninterrupted operation, error-free software, exact sensor measurements, successful outcomes, compatibility with every device, or the accuracy of third-party or AI output. Users must maintain appropriate backups and professional oversight.
The Company is not responsible for third-party platforms, integrations, content, institutions, networks, devices, or unauthorized actors, except to the extent responsibility is imposed by law or a signed agreement. Connecting an integration directs data sharing described at setup and subjects the user to the third party’s terms.
29. Limitation of Liability
To the fullest extent permitted by law, Sensory Bridges and its affiliates, licensors, and suppliers will not be liable under the governing consumer or standard online agreement for indirect, incidental, special, exemplary, punitive, or consequential damages; lost profits, revenue, goodwill, business opportunity, or data; substitute-service cost; or third-party conduct.
Sensory Bridges’ aggregate liability arising from the specific product, service, subscription, or license will not exceed the amount the claimant actually paid to Sensory Bridges for that affected product, service, subscription, or license during the twelve months before the event. If applicable law does not permit a zero-dollar cap, the minimum amount required by that law applies.
The cap and exclusions do not apply to the extent prohibited by law and must be reviewed for death or personal injury, fraud, gross negligence, willful misconduct, nonwaivable product liability, statutory privacy or consumer rights, infringement by the Company, confidentiality obligations, and separately negotiated enterprise indemnities. Each entity’s liability is separate; payments to MMMmc are not automatically payments to Sensory Bridges.
30. User Responsibility and Indemnification
In an enterprise or other properly assented agreement, the customer will defend and indemnify Sensory Bridges against third-party claims to the extent arising from the customer’s unlawful Customer Content, violation of another’s rights, unauthorized instructions, misuse, or breach by its administrators or end users. Consumer indemnities must be narrowly applied and are subject to nonwaivable law.
Sensory Bridges controls the defense with qualified counsel, may not settle an indemnified claim by admitting fault or imposing nonmonetary obligations on the indemnifying party without consent, and must mitigate. The indemnified party will give prompt notice and reasonable cooperation. Indemnity does not cover Sensory Bridges’ own negligence, willful misconduct, breach, or legal violation to the extent prohibited.
31. Dispute Notice and Mandatory Mediation
Before filing a covered contractual claim, the claimant must send a detailed written notice to legal@sensorybridges.com identifying the parties, agreement, facts, dates, requested relief, and supporting records. The parties will select a mutually acceptable mediator within ten business days and use good-faith efforts to hold the first confidential mediation session within thirty calendar days after receipt of the notice. The parties may extend the date by written agreement if mediator availability requires it.
Mediation is a condition precedent only to the extent enforceable. It does not bar emergency injunctive relief, preservation orders, account-security relief, administrative charges, regulator or law-enforcement reports, small-claims rights that cannot be waived, or a filing needed to preserve a limitations period. Any limitations tolling should be confirmed in a signed writing.
Unless the signed contract states otherwise, mediation involving Sensory Bridges will occur remotely or in Hamilton County, Tennessee, and Tennessee law governs without depriving a Consumer of mandatory protections. If mediation does not resolve the dispute within forty-five days after the first session, either party may pursue available relief. Arbitration applies only if a separate conspicuous agreement contains it.
32. Attorneys’ Fees, Forensics, and Equitable Relief
A party proven by final judgment, arbitral award, written admission, or settlement to have materially breached an accepted confidentiality, authorization, security, return, preservation, or IP provision must reimburse reasonable, documented, causally related forensics, containment, restoration, notification, expert, mediation, court, and attorneys’ fees to the extent authorized by contract or law.
The Company may seek temporary, preliminary, and permanent equitable relief for actual or threatened trade-secret misappropriation, infringement, unauthorized access, evidence destruction, or misuse where legal standards are met. The handbook does not eliminate the need to prove entitlement.
An automatic $25,000 legal-fee advance or unlimited fee-shifting solely on the Company’s accusation is not adopted. Counsel may negotiate a reasonable escrow or advancement provision in a business-to-business agreement after an admission, neutral finding, or defined trigger; the amount must be tied to expected loss and enforceability.
33. Workforce: Equal Opportunity, Accommodation, and Anti-Harassment
Sensory Bridges prohibits unlawful discrimination, harassment, and retaliation based on any status protected by applicable law. Hiring, pay, assignments, training, discipline, leave, promotion, and separation will be based on lawful criteria.
The Company will engage in a timely, good-faith interactive process for disability, pregnancy, religion, and other legally protected accommodation requests. Medical information is collected only as permitted, stored separately with restricted access, and disclosed only as authorized or required. Requesting accommodation, reporting discrimination, using protected leave, participating in an investigation, or raising security/research concerns will not be treated as misconduct.
Coverage thresholds for ADA, FMLA, Title VII, Tennessee, Georgia, and local law differ. The Company will provide rights required by applicable law even if a generic handbook summary is incomplete. FMLA rights, if the Company is covered and the employee is eligible, are administered under a separate leave policy.
34. Workforce: Classification, Pay, Time, Leave, and Remote Work
Every worker must be classified based on actual duties and relationship, not title. Nonexempt employees must record all time, receive required minimum wage and overtime, take lawful breaks, and may not work off the clock. Contractors require a signed agreement and may not be managed in a manner inconsistent with classification.
Pay frequency, deductions, expenses, commissions, bonuses, benefits, and leave will be documented. Final pay will follow governing law. No manager may withhold earned wages as an IP, equipment, confidentiality, or damages remedy.
Remote work is not a waiver of accommodation rights or a guarantee of permanence. Approved remote workers must use secure systems, protect confidential calls and screens, maintain safe workspaces, report time and incidents, and return Company Materials. Medical and family-leave conflicts must be handled under the applicable accommodation and leave process.
35. Workforce: Performance, Discipline, Complaints, and Separation
The Company may use coaching, warning, performance plans, suspension, or termination depending on severity; progressive discipline is not guaranteed unless a signed agreement says otherwise. Employment is at will to the extent lawful and expressly acknowledged; this handbook is not an employment contract.
Employees must receive the allegations and relevant nonprivileged information needed to respond fairly before material discipline where practicable. Decision-makers will document evidence, consistency, accommodations, protected activity, conflicts, and the basis for action. Complaints about discrimination, retaliation, pay, security, research, grants, privacy, or ethics must be routed outside the accused manager when necessary.
Separation includes prompt access revocation, credential rotation, device and record inventory, preservation, return of property, lawful final pay, benefits notices, confidentiality reminder, and an opportunity to identify personal or third-party material. Offboarding must not delete evidence or commingle entity assets.
36. Personnel Files and Workforce Privacy
The Company will maintain accurate personnel records and a separate restricted medical/accommodation file. Access is limited by role and legitimate need. Employees may request access or correction as provided by law and policy. Release requires authorization or lawful process, with redaction of Social Security, bank, medical, leave, family, and other confidential information.
Personnel retention will follow a schedule based on payroll, tax, discrimination, leave, safety, benefits, immigration, litigation, and contract requirements. “Permanent” retention is not the default for all private-company records merely because a university policy uses that period.
Monitoring notices, applicant/employee privacy notices, background checks, biometrics, location tracking, and recording require separate legal review.
37. Confidentiality, Whistleblowing, and Protected Communications
Employees and contractors must protect Company and third-party Confidential Information. This duty does not prohibit communications protected by the National Labor Relations Act, whistleblower laws, anti-retaliation laws, government-reporting rights, subpoena, protected concerted activity, or 18 U.S.C. § 1833(b).
Attorney-client communications and attorney work product must be restricted, labeled where appropriate, and segregated from general personnel and project files. If potentially privileged material is inadvertently received, personnel must stop substantive review, notify counsel, sequester copies, identify recipients, and follow counsel’s nonwaiver and return instructions.
Therapy, health, medical, accommodation, research-participant, and child communications receive purpose-specific access and may not be used in employment or commercial decisions except as lawfully authorized.
38. Conflicts, Outside Activities, Gifts, and Research Integrity
Employees, officers, researchers, and contractors must disclose actual or potential conflicts involving outside employment, consulting, ownership, investors, university roles, family relationships, vendors, grants, publications, and IP. Disclosure is not automatic prohibition. The Company will use written management plans, recusal, data separation, independent review, or other proportionate controls.
No person may use institutional, grant, sponsor, employer, customer, or Company resources outside authorization. Publications and presentations require confidentiality, participant privacy, sponsor, and IP review but may not suppress lawful whistleblowing or research-integrity reporting.
39. Grants, Government Funding, and Sponsored Research
Grant and sponsored-research activities must follow the award, budget, cost principles, reporting, subrecipient, conflict, effort, procurement, records, publication, data, and IP requirements that actually apply. Federal awards may require 2 C.F.R. Part 200 controls, sponsor-specific invention reporting, and government rights.
The Company will not assume that receiving or participating in a grant transfers all IP to a university, sponsor, or Company. Agreements and law control. Pre-existing IP, project IP, data, deliverables, inventions, open-source obligations, publication, confidentiality, and commercialization must be addressed before work begins.
Suspected research misconduct, financial impropriety, unauthorized access, participant risk, or sponsor noncompliance must be reported without retaliation and preserved.
40. Records Retention and Destruction
The Company will adopt a schedule by record category, legal requirement, business need, and sensitivity. Illustrative categories include corporate and IP chain-of-title records; tax and finance; contracts; personnel; research; child and education data; product and safety; source control; security logs; support; recordings; marketing consent; and privacy requests.
No category is retained indefinitely by default. IP ownership and corporate records may require very long or permanent retention; raw personal, child, health, biometric, and audio data should have short, purpose-based periods. Backups follow documented cycles and are not used for ordinary processing after deletion.
Destruction must be secure, documented where material, and suspended by legal hold, regulatory, safety, sponsor, or research obligation.
41. Training, Audits, Enforcement, and Governance
Personnel receive role-based onboarding and annual training covering security, privacy, children, research, accessibility, harassment, accommodation, conflicts, IP, open source, recording, incident response, and legal holds. Privileged or high-risk roles receive additional training.
The Company will perform periodic access reviews, data-map reviews, vendor reviews, incident exercises, backup tests, policy audits, and IP-chain-of-title audits. Findings must have owners and remediation dates.
Violations are investigated impartially and addressed proportionately. The Company will not use this policy to manufacture assent, backdate ownership, retaliate, access third-party systems without authority, or make public accusations unsupported by native evidence.
42. Adoption and Acknowledgment
This handbook becomes effective only after written adoption by Sensory Bridges’ authorized governing body and completion of counsel review. Adoption should identify superseded policies, effective date, responsible officers, distribution, training, and version control.
Acknowledgment. I acknowledge receipt of this handbook, understand that it is not an employment contract or a grant of ownership, and agree to follow the policies applicable to my role. I understand that customer, license, confidentiality, research, and invention obligations arise from the applicable signed agreements and law.
Name: ______________________________ Role: _______________________________ Signature: __________________________ Date: _______________________________
