Privacy Policy
Effective September 8, 2026 · Version 2026-09-08
This Privacy Policy explains how AI Assurance Hub LLC ("we", "us") collects, uses, discloses, and protects personal information in connection with AI Assurance Hub (the "Service").
1. Our role
For personal information relating to account holders and visitors, we act as a business/controller. For personal information that our customers upload into their governance workspace, we act as a service provider/processor and process it only on the customer’s documented instructions, as described in our Data Processing Addendum.
2. Information we collect
- Account data — name, work email, hashed password, and organization details you provide.
- Authentication & security data — sign-in timestamps, IP address, and browser/user-agent for active sessions (used for security and audit).
- Customer content — the AI use cases, tools, policies, evidence and related records you enter, which may contain personal data you choose to include.
- Communications — notification and email preferences, and messages you send us.
- Billing data — where billing is enabled, payment details are collected and processed by our payment processor; we do not store full card numbers.
- Newsletter subscriptions — if you opt in on our website, your email address and the page you subscribed from, used to send occasional guides and product updates.
- Website analytics — cookieless, aggregate data about visits to our public website: the pages viewed and the referring domain, plus a daily-rotating, non-reversible hash of your IP address and browser used only to estimate unique visitors. It is not a persistent identifier and is not linked to your identity.
We do not use third-party advertising or cross-site tracking technologies.
3. How we use information
- To provide, secure, and operate the Service;
- To authenticate users and prevent fraud or abuse;
- To send transactional and (per your preferences) notification emails;
- To send occasional newsletter and product-update emails to people who opt in (you can opt out at any time by contacting us);
- To measure aggregate traffic to our public website and improve it;
- To maintain an append-only audit trail of governance actions;
- To comply with legal obligations and enforce our terms.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. Disclosure of information
We disclose personal information to service providers that process it on our behalf under contract (see our Subprocessors list), and where required by law or to protect rights and safety. We do not disclose customer content except on the customer’s instructions or as legally required.
5. Data retention
We retain account and customer content for as long as your account is active and as needed to provide the Service. On account closure, customer content is purged after a short grace period, subject to backups aging out and any records we must retain for legal or audit purposes. Audit logs are append-only and retained for their configured retention period.
6. Security
We use industry-standard safeguards, including encryption in transit (TLS), encryption of particularly sensitive fields at rest (e.g. multi-factor secrets), strong password hashing, strict per-tenant data isolation, least-privilege access, security headers, and an audit trail. No method of transmission or storage is 100% secure.
7. Your privacy rights
Depending on your jurisdiction (including California/CPRA, Virginia, Colorado, Connecticut, Utah and other US states), you may have rights to access, correct, delete, and obtain a portable copy of your personal information, and to appeal a decision. Because we do not sell or share personal information for advertising, no opt-out of sale/sharing is required.
Account holders can download a copy of their personal data and request deletion of their account from within the app under Security & privacy. You may also contact us at [email protected]. If your personal data was entered by an organization using the Service, please direct your request to that organization (the controller); we will assist them as their processor.
8. Cookies
We use only strictly necessary, first-party cookies to keep you signed in and to remember your active organization. These are functional and cannot be disabled while using the Service. We do not use advertising cookies. Our public-website analytics are cookieless — we measure aggregate traffic without setting cookies or storing persistent identifiers (see “Information we collect”).
9. International users
The Service is operated from the United States and data is processed there. If you access the Service from outside the US, you consent to that processing. Where personal data originates in the EU/EEA/UK, additional terms and safeguards apply as agreed in the DPA.
10. Children
The Service is a business tool not directed to children and is not intended for anyone under 16.
11. Changes
We may update this Policy; material changes will be reflected by the version and effective date above.
12. Contact
Questions or requests: [email protected].