Privacy policy
Effective [DATE]. Last updated [DATE].
This is a starting draft written to match the product as built. It is not legal advice and has not been reviewed by a lawyer. Every [BRACKETED] value needs filling, and several statements below are claims only you can confirm. Delete this notice when the document is reviewed.
1. Who this covers
This policy explains how [LEGAL ENTITY NAME] ("Vexum", "we") handles personal information on vexumai.com and in the Vexum service. It covers visitors to the site, people at customer organizations who use the service, and prospects who contact us.
2. Two different roles
For our own site, marketing and account records, we decide how information is used and act as controller. For the records inside a customer's workspace, including anything read from their connected systems, the customer decides and we act as processor on their instructions under our agreement with them. If you work at a customer organization and want your information corrected or deleted from a workspace, ask your organization first; we will support them in responding.
3. What we collect
You give us: name, work email, company, role and anything you write when you book a call, email us, or set up an account.
The service records: who signed in, what they viewed, what steps ran, what was retrieved and what was decided, with timestamps. This audit trail is a product feature, not analytics, and it necessarily identifies the people who acted.
Customer content: procedures, drawings, inspection results, travellers, complaints and similar records supplied by a customer or read from their connected systems. These may incidentally contain names, such as an inspector or an approver.
Technical: IP address, device and browser information, and pages viewed on the site.
4. Why we use it
To provide and secure the service; to keep the audit trail our customers rely on; to authenticate users and enforce permissions; to answer enquiries and run pilots; to invoice; to detect abuse and debug faults; and to meet legal obligations. Where the law requires a legal basis, ours is performance of a contract, our legitimate interest in operating and securing the service, consent where we ask for it, and compliance with law.
5. AI models
The service sends the material an investigation needs to language models in order to read documents and prepare work. We use [NAMED MODEL PROVIDERS] under agreements that [CONFIRM: prohibit training on submitted content and set a zero or short retention window]. We do not use customer content to train our own models [CONFIRM, then state plainly]. Ask us for the current list of model providers and their terms.
6. Connected systems are read-only
Where a customer connects a quality, engineering or ERP system, the connection has read access only. We read what an investigation needs and we do not write to, alter or delete anything in the source. Credentials are held encrypted and used only to perform those reads.
7. Who else sees it
We share personal information with service providers who help us run the service, under contract and only for that purpose: hosting [PROVIDER], model providers [PROVIDERS], email [PROVIDER], scheduling [PROVIDER], error monitoring [PROVIDER]. We also disclose where the law requires it, and to an acquirer in a merger or sale, in which case this policy continues to apply until replaced. We do not sell personal information and we do not share it for cross-context behavioural advertising.
8. How long we keep it
Customer content and the audit trail are kept for the life of the workspace, and for [N] days after termination so the customer can export, then deleted or de-identified. Enquiries and marketing records are kept for [N] months after the last contact. Backups roll off within [N] days. Invoicing records are kept as long as tax law requires.
9. Security
We encrypt data in transit and at rest, restrict access to the people who need it, log administrative action, and review access periodically. Our current certifications and posture are [STATE ACCURATELY, OR SAY WHAT IS IN PROGRESS]. No system is perfectly secure; if a breach affects your information we will notify you and any regulator as the law requires.
10. Where it is processed
We process information in [REGIONS]. Where information leaves its region of origin we rely on [TRANSFER MECHANISM, e.g. Standard Contractual Clauses]. Deployment inside a customer's own environment is available where data cannot leave a plant or a country.
11. Your rights
Depending on where you live you may have the right to access, correct, delete or port your personal information, to object to or restrict processing, and to withdraw consent. Write to [PRIVACY EMAIL] and we will respond within the period the law allows. We will not treat you differently for exercising a right. If you are in the UK or EU you may also complain to your supervisory authority.
12. Cookies
The site uses cookies necessary to make it work and to keep you signed in. [STATE ANY ANALYTICS OR EMBEDDED SCHEDULING COOKIES, AND WHETHER A CONSENT BANNER IS REQUIRED IN YOUR MARKETS]. Booking a call loads a third-party scheduling widget, which sets its own cookies under its own policy.
13. Children
The service is for business use. We do not knowingly collect information from anyone under 16, and we will delete it if we learn that we have.
14. Changes
We will post any revised policy here with a new effective date, and will tell customers directly about material changes.
15. Contact
Privacy questions and requests: [PRIVACY EMAIL]. Postal: [REGISTERED ADDRESS]. [EU / UK REPRESENTATIVE, IF REQUIRED].