Privacy · Policy
Privacy policy
Our commitment to you on retention, residency, subprocessors, and breach response. The table below indexes the operational controls and the data they govern.
| Topic | Where we enforce it |
|---|---|
| Consent | Use the consent center to opt in or out per purpose. AI training is a separate opt-in. |
| Retention | A daily sweep honors per-(category, region) windows + active legal holds. |
| Data residency | Cross-border transfers without a published mechanism (SCC / BCR / adequacy) are refused. |
| Subprocessors | See the live roster. Each workspace must accept a published disclosure before transfer. |
| Breach response | 72-hour GDPR notification, 30-day worst-case state-law sweep. |
| Tenant offboarding | Approved admins move a workspace through REQUESTED → EXPORT_READY → DELETING → DELETED with a SHA-256-verified export + per-table receipt. |
Looking for a downloadable notice? See Privacy Notice or Data Processing Addendum.