Privacy Policy
Draft — requires legal review before live launch
DRAFT — REQUIRES LEGAL REVIEW BEFORE LIVE LAUNCH. This is a working draft written for product completeness. It must be reviewed and finalized by a qualified legal adviser in your jurisdiction before production launch.
Who we are
This Service is operated by [Company legal name], [Registered address]. For privacy questions, contact [Data protection contact email — see Support panel in your account].
Information we collect
Account email and sign-in identifier; the business details and diagnostic answers you give during intake; the workflows, scores, analyses, explanations and implementation plans derived from those answers; payment confirmation and reference identifiers from our payment provider; and basic product usage/error events.
Why we collect it
To generate and store your analysis, grant access to what you purchased, provide support, maintain security, meet accounting obligations, and improve the product and methodology.
AI processing
Parts of your answers are sent to a third-party language model provider so they can be interpreted into structured workflow information; the prioritization/scoring itself is calculated by our own deterministic software, not by the language model. AI providers process this data under their own terms; [Placeholder — name of provider(s) and data processing agreement status to be confirmed before launch].
Payment processing
Payments are handled by our payment provider (Stripe). We receive confirmation of payment, amount and a reference identifier. We never receive or store your full card number.
Service providers
We use third-party infrastructure providers (hosting, database, authentication, AI inference, payments, email) to operate the Service. [Placeholder — final subprocessor list to be published before launch.]
Retention
Diagnostic answers, analyses and results are kept while your account is active. If you delete your account data, that content is removed; order and entitlement records are retained for accounting purposes with personal identifiers minimised. See your account for controls, and our data retention documentation for the underlying policy this describes.
Security
Data is stored in a managed database with row-level access rules so only your account can read your own assessments, analyses, orders and results. No system is perfectly secure; [Placeholder — formal security/compliance statements to be confirmed by counsel].
Your rights
You can request a copy of your data (data export, in your account) or ask us to delete your diagnostic and analysis data at any time. Depending on your jurisdiction you may have additional rights (e.g. access, correction, restriction, objection, portability, or lodging a complaint with a regulator). [Placeholder — jurisdiction-specific rights (e.g. GDPR/CCPA) to be finalized by legal counsel before launch.]
International transfers
Your information may be processed in countries other than your own. [Placeholder — transfer mechanism, e.g. standard contractual clauses, to be confirmed.]
Contact
Questions about this policy: [support email — see Support panel in your account].
Governing law
[Governing law / jurisdiction placeholder — to be confirmed by legal counsel.]