What we collect, what we never do with it, where it lives, and how long we keep it. Written to be read rather than to be survived.
Written to be read, not survived.
01What we collect
Account data you give us: name, work email, organisation name and role. Authentication material is stored as a hash, never as a recoverable value.
Operational data your workspace generates: records created in applications you build, flow run history, and the audit trail of actions taken by people and agents.
Technical data: coarse IP-derived region and a hashed user agent, retained for security investigation. We do not store raw IP addresses against your account.
02What we do not do
We do not use customer content to train, fine-tune or evaluate models. Inference runs against zero-retention endpoints and prompt content is excluded from provider logging.
We do not sell personal data, and we do not share it with advertising networks.
We do not place analytics or marketing cookies before you consent to them.
03Where data lives
Your organisation is pinned to a region when it is created and routed there for the life of the account. Failover is within-region-family and never moves data across a regulatory boundary without a signed instruction.
Sub-processors are listed in the data processing agreement, which is provided during procurement and updated with 30 days' notice before any addition.
04How long we keep it
Audit evidence is retained for the period your plan specifies, defaulting to 365 days and configurable upward on enterprise agreements.
Deleted records are soft-deleted so audit evidence stays resolvable, then hard-deleted on the retention schedule.
On termination, a full export of records, flow definitions and audit evidence is available in open formats for 90 days, after which the tenant is destroyed.
05Your rights
Access, rectification, erasure, restriction, portability and objection, exercised through your workspace administrator or directly by contacting us.
Where we act as processor rather than controller, we will route your request to the controlling organisation and support them in answering it.
06Contact
Privacy questions and rights requests: privacy@smartatom.ai. Security disclosures: security@smartatom.ai, acknowledged within one business day.
This document is a working draft written to the correct structure. It has not been reviewed by counsel and must be replaced with approved text before publication.
