ARTICLE 50 HUB

Privacy Policy

Last approved: Pending configuration · Version 1.0

Loading records…

What we collect

We collect account, organisation, system, content metadata and evidence that you choose to submit. We minimise personal data and do not use customer content to train models without separate, explicit permission.

Purpose and legal basis

We process data to provide the service, protect accounts, maintain audit records, meet contractual obligations and improve reliability.

Optional AI assistance

AI Copilot is disabled unless configured by the service operator. When a user requests a workflow, only the explicitly selected system, evidence file, content asset, rule or deterministic Evidence Pack input is sent to the disclosed Qwen / Alibaba Cloud Model Studio workspace. The API key remains server-side. Outputs require item-level human confirmation before any governed field, task, alert or report-summary record is written. AI run records, source references, output hashes and human decisions are retained with the workspace and included in exports and deletion workflows.

Retention and deletion

Active workspace records remain available until the organisation deletes them. Invalidated evidence attachments are purged after the selected retention period while their integrity metadata remains in the audit trail. Saved public checker reports are retained for 30 days by default and first-party product events for 90 days by default. Organisation deletion removes workspace records, organisation-linked product events, stored attachments and orphaned user accounts.

Security and processors

Data is encrypted in transit and production storage must be encrypted at rest. Access controls, MFA, malware scanning, integrity-checked backups and tenant isolation protect customer data. Current hosting and subprocessor information is published below.

Your rights

Account owners can export organisation data and permanently delete the organisation from Settings. Contact the service operator for access, correction or objection requests.

Cookies

The service uses a strictly necessary secure session cookie for authentication. Optional first-party product analytics are disabled until the visitor opts in. If accepted, a session-scoped identifier is stored in session storage and expires when the browser session ends. Declining does not affect the service. No advertising or cross-site tracking cookies are used.