Privacy policy ============== Draft for legal review. Not a final document. Last updated: 1 September 2026. Who processes what ------------------ The organization that contracts the service is the controller of their end users data. We are the processor: we process that data on their behalf and following their instructions. For the data of that organization team members —who signs in, with which email— we are the controller. What we store ------------- Conversations and their messages, the contact details of end users that the organization loads or that they provide themselves, attachments, and the knowledge base material. For each AI answer we store the model, the tokens and the cost, to be able to bill and so the organization knows what it is spending. What we do not store -------------------- Card data: the payment gateway handles it and it never passes through our systems. Technical logs contain neither credentials nor personal data: they are redacted before being written, by field name and by value shape. Rights ------ Any end user can ask the organization serving them for a copy of their data or its deletion. The organization resolves it from their panel, and the export is a file readable without us. Deletion removes what identifies the person and their files, and anonymises their messages: the conversation is also the organization support history. Retention --------- Each organization configures how long they keep things. Unconfigured, nothing is deleted. On cancellation, everything of theirs is deleted.