1. Data we process
Account data (name, email, role, organization membership), company configuration data (industry, strategy, KPIs, business plan), uploaded documents and connected system data, and product usage and audit logs.
2. Purpose and legal basis
Data is processed to provide the contracted service, secure the platform, meet legal obligations, and improve reliability. We do not sell personal data or use it for advertising.
3. Organization isolation
Every record is scoped to an organization and protected by row-level access rules. Members of one organization cannot read another organization's data, and role-based permissions govern access inside an organization.
4. AI processing
Prompts and relevant company context are sent to AI model providers strictly to generate the requested output. Customer content is not used to train third-party foundation models.
5. Security
Encryption in transit and at rest, least-privilege access, authentication with session controls, audit logging of exports and administrative actions, and regular dependency and configuration scanning.
6. Retention and deletion
Data is retained for the life of the subscription. On written deletion request or 90 days after termination, customer content is deleted or irreversibly anonymized, except records we must keep by law.
7. Your rights
Subject to applicable law, individuals may request access, correction, export, restriction, or deletion of their personal data by contacting the organization administrator or us directly.
8. Sub-processors and transfers
We use vetted infrastructure and AI providers under contractual confidentiality and data-protection terms. Cross-border transfers use recognized safeguards.
