Use the contact page for legal, privacy, or procurement follow-up.
How account, organisation, workflow, and contact-request data are handled.
This notice covers the public pages, signup and verification flows, onboarding, customer-team access, billing posture, and the authenticated pricing workflow service.
Who is responsible for the data
For provider-run account, security, billing, and public-contact data, the service provider acts as controller for the information it needs to run and secure the service. For customer workflow data uploaded into the product, the customer will usually act as controller and the provider will usually act as processor or service provider under the commercial agreement.
- The exact contracting entity and any agreed data-processing terms are set out in the applicable proposal, order form, renewal, or DPA.
- This notice is intended to work alongside those commercial documents rather than replace them.
What data is processed
The service may process identity data, customer-organisation data, uploaded workflow files, review activity, billing metadata, audit trails, and public contact requests.
- Identity data includes name, email address, password hash, verification state, MFA state, and session records.
- Organisation data includes company details, memberships, invites, settings, seeded reasons, and plan access.
- Operational data includes uploaded files, review decisions, exports, and audit or security-event records.
Why the data is used
Personal data is used to authenticate users, run the workflow service, separate customer data, provide support, manage trials and billing posture, comply with legal obligations, and investigate misuse or incidents.
- Security controls include email verification, password reset, login throttling, MFA, audit records, and security-event logging.
- Public contact requests are stored so evaluation, procurement, legal, privacy, or implementation questions can be handled.
- Optional public-site analytics is kept off until configured and consented to.
Retention, sharing, and transfers
Data is retained only as long as it is needed for service delivery, support, legal obligations, incident investigation, and commercial record keeping. Infrastructure, delivery, and support providers may process data where needed to host, secure, or support the service.
- Customer data is not sold.
- International transfers, where they apply, should be supported by an appropriate transfer mechanism under the governing agreement and applicable law.
Rights and contact routes
Where applicable, individuals may request access, correction, deletion, restriction, objection, or portability. Identity verification may be required before action is taken.
- Customer users should normally also notify their Admin Review user for organisation-specific data-rights requests.
- Public privacy or data-rights requests can be submitted through the contact route using the data-rights topic.
Route legal, privacy, or procurement questions through the same product host.
The public contact route is the intake path for rollout, compliance, data-rights, and commercial follow-up.