Terug naar Trust Center
Geldig vanaf: 2026-10-04
Alleen in het Engels beschikbaar. Dit juridische document wordt in het Engels als gezaghebbende versie verstrekt. De interface van het Trust Center is vertaald naar uw taal.

Privacy Policy — ISMS Copilot

Overview

This Privacy Policy describes how ISMS Copilot ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our AI-powered compliance platform. This policy applies to all users of ISMS Copilot, including trial users, subscribers, and visitors to our website.

Effective Date: 2026-10-04. This Privacy Policy is updated regularly to reflect changes in our data processing practices and regulatory requirements.

Global Coverage: This policy covers both European (GDPR) and California (CCPA/CPRA) privacy requirements. EU users should focus on GDPR sections; California residents should also review the California Privacy Rights section.

Who This Is For

This Privacy Policy is for:

  • All ISMS Copilot platform users (compliance professionals, consultants, security teams)
  • Users of heyGRC, the Better ISMS GRC review product (heygrc.com and the heyGRC console at app.heygrc.com), including its optional Google Drive connection described under Google User Data below
  • Organizations evaluating ISMS Copilot for vendor risk assessments
  • Data Protection Officers conducting privacy reviews
  • Anyone seeking to understand how we handle personal information

Data Controller Information

ISMS Copilot is the data controller responsible for your personal information:

  • Name: ISMS Copilot (operated by Better ISMS EURL)
  • Jurisdiction: France (European Union)
  • Primary Data Location: Frankfurt, Germany (AWS EU-Central-1)
  • Privacy Contact: privacy@ismscopilot.com
  • Supervisory Authority: Commission Nationale de l'Informatique et des Libertés (CNIL)

Data Protection Officer

ISMS Copilot has not designated a Data Protection Officer as we do not meet the mandatory designation criteria under GDPR Article 37. For privacy inquiries, contact privacy@ismscopilot.com.

Information We Collect

Account Information

When you create an ISMS Copilot account, we collect:

  • Email address (for authentication and essential communications)
  • Password (hashed and encrypted, never stored in plain text)
  • Account creation and last login timestamps
  • User unique identifiers (UUIDs)

Conversation Data

When you use our AI compliance assistant, we process:

  • Your messages and queries
  • AI-generated responses
  • Conversation metadata (titles, timestamps, status)
  • Workspace configurations and custom instructions
  • Compliance-related content (policies, procedures, audit information you input)

Special category data (Article 9 GDPR, such as security incidents that reveal health, biometric, or other sensitive information) and personal data relating to criminal convictions and offences (Article 10 GDPR) are excluded from the default (non-ADP) AI routing path. If you need AI assistance with such data, enable Advanced Data Protection Mode, which routes your inputs to our EU-based enhanced-protection model. We do not automatically detect or filter special-category or criminal-offence content on the default path, so you are responsible both for having legal authority to process such data and for enabling Advanced Data Protection Mode before inputting it. See our Data Processing Agreement (§4.2) for the routing and safeguard details.

Uploaded Files

When you upload documents for analysis, we collect:

  • File content (PDF, DOCX, XLSX formats)
  • File names, sizes, and upload timestamps
  • Extracted document content and metadata
  • Document processing status

Slack Integration Data (heygrc bot)

If your organization is on a paid plan and an organization owner installs the heygrc Slack bot, we additionally process:

  • Slack workspace metadata captured during the OAuth install: workspace (team) ID, workspace name, bot user ID, and the ISMS Copilot user ID of the installer (for audit). The OAuth scope is bot-only — we do not request the workspace user directory, channel history, or file access.
  • An OAuth bot token issued by Slack, stored in an isolated slack_integration_secrets table with service-role-only access (encrypted at rest via the database infrastructure layer).
  • Message content of Slack messages addressed to the bot — direct messages or @heygrc channel mentions only. We do not read or store any message that is not addressed to the bot.
  • Slack user identifiers (slack_user_id) for the workspace member who sent each message addressed to the bot, recorded in the slack_threads mapping table for traceability.

The Slack integration is a paid-tier-only feature. Free / null-plan organizations cannot install the bot — the OAuth callback rejects the install with a "paid plan required" error.

Pull-Request Review Data (heyGRC GitHub App)

Note: this section describes heyGRC, our GitHub App that reviews pull requests for compliance. It is a separate product from the heygrc Slack bot described above (a Slack chat connector for ISMS Copilot). The two share a name but process different data.

If you install the heyGRC GitHub App on a repository, then each time a pull request is opened, updated, or a review is requested (by commenting /heygrc), we receive from GitHub and process, for the purpose of producing a compliance review:

  • The pull-request diff (the file patches, i.e. the changed lines of code), capped in size, together with the changed file paths and names.
  • Pull-request metadata: the pull-request number, its title, and its description.
  • An optional repository context file (.heygrc.md), if present in the repository, which you provide to describe your company context and the frameworks you care about.
  • Repository and account identifiers: your GitHub organization or account login, the repository name, and the GitHub App installation identifier.
  • Your organization's company profile and commitments entered in the heyGRC console, which are supplied to the model as review context.

We redact before the diff reaches any AI model. Whole files likely to contain secrets (for example .env files, private keys, credential files) are dropped and never sent, and secret-shaped content within a diff (private-key blocks, API keys and tokens, authorization headers, key/value secret assignments) is scrubbed. The same redaction is applied to the pull-request title and description, to the optional .heygrc.md file and to any /heygrc question. Model output is redacted again before it is posted or stored.

We do not keep your diff. The pull-request diff is used only to produce the review and is not persisted by us as a record. What we store is the review we write back: its summary and findings, each finding pointing at a file path and line and quoting the few changed lines it refers to and, where your organization links documents, short quotes from them, together with the pull-request number and commit identifier. The same review text is posted into your repository on GitHub, where it remains under your GitHub account's control. We do not fetch commit author names or e-mail addresses.

Replies to /heygrc questions. If you ask heyGRC a question under one of its inline findings, the question, the finding it is attached to and the code hunk that GitHub attaches to that comment are sent (redacted) to the AI model to draft the reply. We do not store the question or the reply.

Pricing and free allowances are described at heygrc.com/pricing.

Aevral

Aevral is the Better ISMS code security product at app.aevral.com. When you use Aevral, we collect your account details (email address, password or GitHub sign-in identity), your organization membership and role, team invitations you send (the invitee's email address), the GitHub login of the person who installed the Aevral GitHub App, billing identifiers from Stripe, and security logs. We process this as controller to provide the service (Article 6(1)(b) GDPR), keep accounting records (Article 6(1)(c)), and protect the service (Article 6(1)(f)).

For the repository content your organization authorizes Aevral to scan and review, we act as your organization's processor under the Data Processing Agreement (§1.7), not as controller, and it is not covered by this policy. Aevral's providers are on the Aevral sub-processor list.

If you connect an AI tool to Aevral through the Aevral MCP server, we keep a record of the connection (the tool's identifier, the organization you chose, whether it may start scans, and when it was created and last used) while it is connected and for 90 days after you disconnect it, then delete it. We also log each tool call (a category for the tool, the action, the organization and whether it succeeded, never the request or the results) for 90 days. At your instruction, Aevral sends the tool what it asks for from the organization you chose: the organization's GitHub account name and whether pull request reviews are on, repository names and visibility, scans (identifier, status, progress, commit, start time, summary) and their findings (title, severity, file and line, description, evidence and code excerpts, suggested fix), pull request reviews (repository, number, commit, review time) and their findings, and usage for the period (plan name, used and included counts, reset date). The tool's provider handles that data under your own agreement with that provider.

We keep Aevral account data for the life of the account, billing records as required for accounting, and security logs for as long as needed to protect the service. To access, correct, export or delete your Aevral data, email privacy@ismscopilot.com; the self-service export and deletion controls described in this policy apply to ISMS Copilot chat, not Aevral.

Payment Information

For premium subscriptions, we collect:

  • Stripe customer IDs and subscription IDs
  • Payment metadata (we never store full credit card numbers)
  • Billing events and invoice information
  • Subscription status and tier information

Payment card data is handled exclusively by Stripe, our PCI DSS Level 1 compliant payment processor. ISMS Copilot never stores or processes credit card numbers.

Analytics and Usage Data

To improve our service, we automatically collect:

  • User behavior events (page views, feature usage)
  • Session data and duration
  • Browser and device information
  • Error logs and performance metrics
  • User identifiers (UUID only) for error tracking in production (no email addresses or names)
  • IP addresses (anonymized)

Our analytics systems are configured with sendDefaultPii: false to prevent automatic collection of personally identifiable information. Conversation content and uploaded documents are never shared with analytics providers.

Email Communications Data

When you receive emails from us, we may collect:

  • Email engagement data (opens, clicks)
  • Subscription preferences
  • Unsubscribe status
  • Email delivery timestamps

How We Use Your Information

Service Delivery (Legal Basis: Contract Performance — Article 6(1)(b) GDPR)

  • Provide AI-powered compliance assistance
  • Authenticate your account and manage sessions
  • Process and store your conversations and uploaded files
  • Deliver features and functionality you've requested
  • Process subscription payments and manage billing

Service Improvement (Legal Basis: Legitimate Interest — Article 6(1)(f) GDPR)

  • Analyze platform usage to improve user experience
  • Monitor system performance and reliability
  • Identify and fix bugs and technical issues
  • Develop new features and capabilities

Security and Fraud Prevention (Legal Basis: Legitimate Interest — Article 6(1)(f) GDPR)

  • Detect and prevent unauthorized access
  • Monitor for suspicious activity or abuse
  • Protect platform integrity and user data
  • Respond to security incidents
  • Keep audit records of heyGRC API and console actions (see heyGRC Audit Records)
  • Process all chat messages through automated content moderation to detect prohibited content under our Acceptable Use Policy

Content Moderation

All chat messages are processed through Mistral AI's moderation API (model: mistral-moderation-latest, EU residency, zero retention) regardless of your Advanced Data Protection setting. Moderation is a two-stage pipeline: a fast classifier followed by a judge model that reviews borderline cases. Moderation runs on Mistral on every request to ensure consistent, EU-residency safety review.

We retain moderation outputs as follows:

  • For non-flagged messages: No moderation record is stored. The message is processed and discarded by the moderation pipeline.
  • For flagged messages: A moderation_events record is retained containing only metadata — the message identifier, the thread identifier, the abuse categories matched, and a timestamp. The full message content is not stored in the moderation record. This metadata is retained for up to 12 months for safety/audit purposes, after which it is automatically purged.
  • Thread deletion lock: When a message in a thread has been flagged, the thread is locked from user-initiated deletion to prevent destruction of abuse evidence. Customer Content within a flagged thread is still subject to deletion on a verified Article 17 erasure request submitted to privacy@ismscopilot.com (see "Right to Erasure" below); we evaluate each such request against the legitimate-interest balancing test under Article 17(3) and respond within 30 days.

Communications

We send different email types under different legal bases:

  • Transactional and account emails (password resets, security alerts, account activation, billing). Legal basis: Contract (Article 6(1)(b)) and Legal Obligation (Article 6(1)(c)).
  • Onboarding guidance, product education, and important service or legal updates. Legal basis: Legitimate Interest (Article 6(1)(f)). You can unsubscribe from non-essential messages at any time.
  • Marketing product-update newsletters. Legal basis: Consent (Article 6(1)(a)). Sent only to users who have opted in; withdraw any time via the unsubscribe link in every message.

Legal Compliance (Legal Basis: Legal Obligation — Article 6(1)(c) GDPR)

  • Retain billing records for tax and accounting requirements (7 years)
  • Respond to lawful requests from authorities
  • Comply with applicable data protection laws

ISMS Copilot never uses your data for marketing, advertising, or selling to third parties. Your conversations and uploaded documents are never used to train AI models.

How We Share Your Information

Third-Party Service Providers (Data Processors)

We share your information with trusted service providers who help us deliver the platform. The complete list of sub-processors, including the routing logic and contractual controls described below, is maintained in our Data Processing Agreement (DPA). Sub-processor changes are notified through our Trust Center and in-app changelog; a materially adverse change is additionally notified by at least 30 days' advance email and in-app notification, and a control-neutral change is notified by publication in the Trust Center and the customer-facing change log without an advance notice period. The criteria and process are defined in DPA §2.4. (Section updated 2026-07-21.)

Database and Storage (Always Active)

  • Supabase: Database and file storage (EU — Frankfurt, Germany)
  • AWS: Infrastructure (EU-Central-1, Frankfurt)
  • Backblaze: Encrypted offsite database backups, the newest 90 daily copies (EU, Amsterdam). Each copy is encrypted before upload and Backblaze never holds the key
  • GitHub (GitHub Actions): Runs the daily backup job that copies, encrypts and uploads the database (United States, EU-US Data Privacy Framework and Standard Contractual Clauses). The copy is unencrypted on GitHub's machine only while the job runs. We are moving this job to our EU infrastructure

AI Processing

How your AI requests are routed depends on one setting: whether Advanced Data Protection (ADP) Mode is enabled. ADP is the guaranteed EU, zero-retention path. With ADP off, your requests are served within a single vetted non-ADP envelope described below. Which specific provider serves a given request may vary by plan, by rollout, and over time, and we do not commit to a fixed per-request provider assignment. Your plan (Free, Essential, Plus, Standard, Pro, Business, or an app-managed Plus trial) does not change the outer limits of this envelope; current routing and the available provider subset may differ by plan. Each destination in the envelope meets our minimum non-ADP requirements (no training on your data, non-PRC jurisdiction, GDPR-aligned transfer mechanism), with the material retention and location differences shown below (Anthropic-served traffic has longer retention than the zero-retention OpenRouter allowlist). For paid plans (Plus and above) with ADP off, in the chat Fast and Think modes and the Beyond assistant, the current default destination is xAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint (zero data retention), with Anthropic Claude (Opus for Think, Sonnet for Fast) as the automatic failover; in any chat mode a non-ADP paid request may be served by any of the eight OpenRouter-allowlisted providers or Anthropic, and the destination may move between them over time (a control-neutral move within the disclosed envelope under DPA §2.4, publication-only).

Routing pathWhen it appliesAI providerLocationRetentionTraining
ADP enabled (any plan)ADP toggle ONMistral AIEU (Frankfurt)Zero retentionNo training
ADP off (any plan)ADP toggle OFF, any chat modexAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint is the current default for paid plans (Plus and above) in the Fast and Think chat modes and the Beyond assistant, with Anthropic Claude (Opus for Think, Sonnet for Fast) as the automatic failover. In any chat mode, a non-ADP paid request may be served by Anthropic Claude or any of the eight OpenRouter-allowlisted providers below (including xAI; the Essential subset is within this allowlist), and ISMS Copilot may move any cohort or mode between these destinations over time (a control-neutral move within the disclosed envelope under DPA §2.4, publication-only), with Mistral (EU) as the circuit-breaker failover described below. The specific provider may vary by plan, rollout, and over time.United States, or EU for the EU-based OpenRouter hosts (Inceptron in Sweden, Nebius in Netherlands); xAI is United States (OpenRouter-published provider footprint, per-request inference region not pinned via OpenRouter); see the complete per-provider region list in the DPA §3.1 (a default deployment posture, not contractual residency; inference region not pinnable via OpenRouter; use ADP for guaranteed EU). SCC; DPF (Article 45 adequacy) for Google Vertex.Anthropic-served traffic: inputs and outputs are ordinarily deleted within about 30 days; content its safety systems flag may be retained up to 2 years, and safety-classification scores up to 7 years; never used for training. OpenRouter-served traffic: zero retention (no persistent retention beyond serving the request; transient in-memory caching only). Enable ADP for zero retention everywhere.No training

About OpenRouter and the underlying providers (the non-ADP envelope). OpenRouter is a routing aggregator. We use OpenRouter so that requests can fail over automatically across a curated set of vetted hosts, increasing availability. A non-ADP request may route to any provider on the closed OpenRouter allowlist below (the seven glm-4.7 hosts plus xAI via the "xAI (ZDR)" endpoint for the Grok models); for paid plans (Plus and above) in the Fast and Think chat modes and the Beyond assistant the current default allowlist destination is xAI, and any allowlisted provider may serve any non-ADP paid mode (the destination may move within the allowlist over time, a control-neutral change under DPA §2.4). Essential-plan requests are restricted to a closed two-provider subset of that allowlist (Google Vertex and Cerebras). The same account-level controls below apply to every OpenRouter request regardless of plan:

  • Zero Data Retention is mandatory. Per OpenRouter's published policy, when ZDR is enabled at the account level, requests can only be routed to endpoints with a Zero Data Retention policy. Your conversation content is not persistently retained by any underlying provider beyond serving the request; a provider may hold it transiently in memory for the duration of processing, as is inherent to serving an inference request.
  • No training, ever. Both "Free Training Disallowed" and "Paid Training Disallowed" are set at the account level. Your data cannot be used to train any model.
  • No publication. "Free Publication Disallowed" is set; the model-publication channel is closed.
  • Closed OpenRouter allowlist. Only the following may serve our requests: Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, and Nebius (the seven hosts for the glm-4.7 model), plus xAI via the "xAI (ZDR)" endpoint for the Grok models. Each was selected after a privacy review, each confirms zero retention or no-training-on-customer-data in its published policies, and each maintains GDPR-aligned transfer mechanisms. For the OpenRouter allowlist the Standard Contractual Clauses operate at the underlying-provider layer through the OpenRouter aggregator (OpenRouter-intermediated); we do not sign separate direct SCCs with each underlying host. Google Vertex additionally holds EU-US Data Privacy Framework certification, which is an Article 45 adequacy mechanism, distinct from the Article 46 Standard Contractual Clauses relied on elsewhere. The allowlist was expanded from four to seven glm-4.7 hosts on 2026-05-25; xAI (already present on the account and already serving our public risk-analysis demo) was activated for paid Customer-Content and made the paid Fast/Think/Beyond default on 2026-07-21 (see the sub-processor change log).
  • PRC-jurisdiction providers blocked. Alibaba Cloud Int., Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, and Z.AI are all blocked at the OpenRouter account level. The control is jurisdiction-based: PRC-jurisdiction providers are blocked at the OpenRouter account level, and the allowlisted providers were selected to avoid PRC/Hong Kong infrastructure based on their published deployment documentation. Because OpenRouter does not expose per-provider region pinning, this is enforced through provider selection and the account-level blocklist rather than a guaranteed per-request inference region. It is a Schrems II-style supplementary measure aligned with EDPB Recommendations 01/2020.

Failover. Paid Fast/Think/Beyond failover. For the paid plans (Plus and above) Fast and Think chat modes and the Beyond assistant, which default to xAI via OpenRouter's "xAI (ZDR)" endpoint, if that route does not begin responding within a short pre-first-token timeout the request is re-served by Anthropic (Opus for Think, Sonnet for Fast); if Anthropic's circuit breaker is open, the request fails over to Mistral AI in Frankfurt (EU). The xAI attempt is zero-retention, so where a single request transits two destinations the first leg holds no persistent content. For non-ADP traffic served by Anthropic, if Anthropic is unavailable, requests automatically fail over to Mistral AI in Frankfurt. Mistral is also our circuit-breaker destination, so these users always reach an EU-compatible provider during outages. For OpenRouter-served traffic (any non-ADP plan), failover happens within the OpenRouter aggregator across the allowlisted providers (the Essential subset is Google Vertex and Cerebras; other non-ADP plans span the eight allowlisted providers); in all cases the OpenRouter account-level controls below apply. For a non-ADP request that is first attempted on an allowlisted OpenRouter provider, if that provider does not begin responding within a short timeout the attempt is aborted and the request is re-served by the failover non-ADP path: Anthropic (Opus for Think, Sonnet for Fast), or, if Anthropic's circuit breaker is open, Mistral in the EU. In that case the single request transits two disclosed destinations, with the OpenRouter attempt zero-retention (no persistent retention beyond serving the request) and the deepest fallback (Mistral, EU) zero-retention as well.

ADP as the EU-only opt-out. Enabling Advanced Data Protection Mode in your settings routes permitted AI processing to Mistral AI's confirmed Frankfurt, EU, zero-retention routes regardless of your plan. Authenticated web search is unavailable while ADP is enabled and fails closed, because Mistral's web search is not EU-only and not zero-retention: it runs on Mistral's stateful Conversations/Agents endpoint (which Mistral excludes from its zero-retention posture) and uses Brave (United States) as its web-search sub-processor. Beyond can still fetch an exact public page or document selected by the user through our EU Fly.io service; all subsequent AI processing remains on the ADP Mistral route. ADP remains the in-product control for users who require fully EU-based AI processing.

Where web search is available under your plan and organization policy, ISMS Copilot may search when you explicitly ask it to search or when a conservative intent check determines that your request requires current external information. A personal or organization-level Never search the web control prevents any search-provider request. The product shows when web evidence was used and provides source links; retrieval supplies the external fact set, while the AI uses that evidence and our separately maintained framework knowledge to reason and write the response. Citations improve traceability but do not guarantee that a source or generated answer is complete, current, or correct.

The processing is minimized by route:

  • Search-intent check: Mistral AI in the EU receives limited recent conversation text and returns a search/no-search classification. The classification call is zero-retention. It does not itself contact the web.
  • Launch retrieval route when ADP is off: the minimized query is sent to Mistral's web-search service. Mistral is used only to discover source URLs and return provider-attested URL references. We discard Mistral's generated search prose. Mistral's web search runs on Mistral's stateful Conversations/Agents endpoint, which Mistral excludes from its zero-retention posture, and Mistral engages Brave Search (Brave Software, Inc., United States) as Mistral's own web-search sub-processor. The minimized query therefore travels from Mistral (EU) to Brave (United States); this discovery step is not EU-only and not zero-retention, and standard, non-zero retention applies per the applicable Mistral/Brave provider terms. ISMS Copilot does not separately engage Brave for this launch route; Brave is engaged by Mistral. Our SSRF-hardened Fly.io service in the EU then fetches the referenced public pages directly and supplies bounded extracted text to the answering model. The selected websites receive ordinary outbound request metadata, such as our service IP, URL path/query, timing, and a neutral user agent. Authenticated web search fails closed when ADP is enabled.
  • Use by the existing answer model: bounded exact-fetched excerpts, source titles, and URLs are supplied as labeled request-scoped context to the answer provider already applicable to the conversation. They sit beside framework, memory, workspace, file, and user context. No additional semantic grounding model receives the complete draft.
  • Exact URL requests in Beyond: when you provide a specific public URL, the same EU Fly.io service fetches that exact page directly. Mistral discovery is not needed for the exact submitted page, although a company-research scope may separately discover independent sources.
  • Future Brave-direct route, not active: this is separate from Brave's launch role as Mistral's web-search sub-processor described above. The direct route (in which ISMS Copilot would call the Brave Search API itself, rather than reaching Brave via Mistral) is a dark candidate only. It is not the default, is not constructed or called by the launch route, and will remain disabled until at least 30 days after materially-adverse-change notice and founder contractual acceptance. If later approved, a bounded query derived only from the latest user request may be sent directly to Brave in the United States. We would not send files, memories, workspace context, account identifiers, or user/device identifiers. Queries would be limited to 400 characters and 50 words, with credentials and signed URLs rejected. Brave's standard API privacy notice states that query logs may be retained for up to 90 days. SCCs would apply, and Brave's published DPA excludes "Search Query Data" from its processor scope.

Mistral's generated search prose, raw discovery response, and fetched page text are used transiently and are not stored in conversation history, Beyond run records, detector telemetry, or application logs. The generated answer and its displayed source links follow your existing conversation-retention setting. Daily search counters store the user identifier, date, count, and update timestamp needed to enforce and maintain limits; they do not store the query or evidence.

Slack-originated requests. Messages sent to the heygrc Slack bot follow the same non-ADP envelope and ADP routing as web chat, governed by the organization's ADP setting: with ADP on (at the org level), Mistral (EU, zero retention); with ADP off, for paid organizations (Plus and above) the Fast and Think modes and Beyond default to xAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint (zero retention) with Anthropic as the automatic failover, and otherwise the destination may be Anthropic (standard commercial API terms) or the OpenRouter allowlist (zero retention, meaning no persistent retention beyond serving the request; the Essential-plan subset is Google Vertex and Cerebras). The org's ADP setting governs all Slack workspace users; an individual Slack workspace member cannot select their own routing.

Pull-request reviews and /heygrc replies (heyGRC GitHub App). heyGRC has its own routing and does not use the ISMS Copilot Advanced Data Protection toggle. Default path: the redacted diff, metadata and your organization's profile are sent through OpenRouter to a closed set of vetted hosts drawn from the allowlist above, pinned in each request to a named subset (currently Together AI and Fireworks AI in the United States and Inceptron in Sweden; the documented rollback set is Cerebras and Google Vertex in the United States), with zero data retention and no training enforced in every request (data_collection: deny, zdr: true) and PRC-jurisdiction hosts blocked at the account level. The reviewing model is an open-weights model developed by Z.AI (currently GLM-5.3 Flash; documented rollback GLM-4.7). Z.AI does not host these requests (its own inference endpoint is blocked at the account level, see above) and is not, on that basis, a recipient of your data. EU inference (organization setting): an organization owner can turn on "EU inference" in the heyGRC console. Reviews for that organization are then sent to Mistral AI on its EU regional endpoint (api.eu.mistral.ai) under the zero-retention and no-training settings of our Mistral account and Mistral's Data Processing Addendum, with no fallback to the default path: if the EU path is unavailable the review fails rather than being rerouted. The model served on the EU path is currently an open-weights model developed by Z.AI, hosted by Mistral; Z.AI does not receive these requests. /heygrc replies currently use the default path regardless of the EU setting. The review worker runs in the EU (Fly.io, Paris and Amsterdam) on both paths. Your code is not used to train any model on either path.

Content Moderation

All chat messages are processed through Mistral AI's moderation API (EU, zero retention) regardless of plan or ADP setting. See "Content Moderation" above for retention details.

Payment Processing

  • Stripe: Payment processing and subscription management (Global with EU DPA, PCI DSS Level 1 compliant)

Analytics and Monitoring

  • PostHog: Product analytics (EU — Frankfurt, Germany)
  • Sentry: Error tracking and monitoring (Germany). In production only, your user ID (UUID) is captured with error reports to enable faster troubleshooting. No email addresses, conversation content, or other personal information is sent.
  • Vercel: Web analytics and frontend hosting (GDPR-compliant)

Email Communications

  • SendGrid (Twilio): Transactional and legal update emails (United States with Standard Contractual Clauses)
  • Kit (ConvertKit): Onboarding and product update emails (United States with Standard Contractual Clauses)

You can unsubscribe from non-essential emails (product updates, onboarding sequences) at any time. Essential service notifications may still be sent as required by law or contract.

Document Processing

  • ConvertAPI: Document format conversion (EU endpoint, temporary processing only)
  • Fly.io: Backend API hosting, chat orchestration, and request-scoped exact-public-URL fetching (EU deployment)

Optional Integrations

  • Slack: Activated only if a paid-organization owner installs the heygrc bot. When activated, Slack acts as both a source (we receive messages addressed to the bot) and a destination (we post AI responses back to the workspace). Slack itself is also a sub-processor (United States) — the OAuth bot token sits in our database, and we exchange workspace metadata with Slack at install time and during message events. Transfer mechanism: Standard Contractual Clauses with Slack Technologies, Inc. The integration is org-scoped and can be uninstalled at any time from the Slack workspace's app management UI; uninstall hard-deletes all our integration records (token, workspace metadata, Slack-thread mappings) within seconds via the app_uninstalled event.
  • GitHub: Activated only if you install the heyGRC GitHub App on a repository. heyGRC retrieves pull-request data from your GitHub environment (signed webhooks and the GitHub API) and posts the review back into it as a check run, a review and comments. GitHub processes that data under your own agreement with GitHub; ISMS Copilot has no separate data-processing contract with GitHub and does not engage GitHub as a sub-processor. GitHub states that it is certified under the EU-U.S. Data Privacy Framework and relies on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for its own transfers. The App holds read access to repository contents, metadata and issues and write access to checks and pull requests only; it never has write access to your code. The integration is repository-scoped and can be uninstalled at any time from your GitHub settings. Uninstalling stops all processing immediately; we then delete your GitHub account name from our records, disable the repositories and release any plan inclusion. Stored reviews are handled as described under "Pull-Request Review Retention".
  • Google Drive (heyGRC): Activated only if an owner or admin of your heyGRC organization connects Google Drive. heyGRC then reads only the Drive files that this person chooses, either by picking them in Google's file picker or by opening them from Google Drive with Open with, then heyGRC. It compiles them into a linked-document pack, checks linked files once a day and re-reads only the ones that changed (a file that keeps changing is checked less often, down to once a week). We store an encrypted OAuth refresh token, the connecting Google account email and identifier, and the identifiers and change markers of the files chosen. Disconnecting in the heyGRC console asks Google to revoke access (unless the same Google account still connects another heyGRC organization) and deletes the stored token. See Google User Data below.

Google User Data (heyGRC Google Drive connection)

heyGRC's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements (see the Google Workspace API User Data and Developer Policy).

  • Who can connect and use it: only an owner or admin of your heyGRC organization can connect Google Drive, and only the person who connected can add files from Drive, from the Google account they connected.
  • Permissions we ask Google for: drive.file, which lets heyGRC open only the individual files that you pick in Google's file picker or open with heyGRC, and nothing else in your Drive; and, if the person who connected turns on Open with, drive.install, which only makes heyGRC appear in Google Drive's Open with menu for that account. drive.install does not let heyGRC see, list or open any file.
  • What we access: the files you choose (their content, name, type, size, and the modification time, checksum and version Google reports); the email address and account identifier of the Google account that connected; and, when you open a file with heyGRC, the file identifier and Google account identifier that Google sends with it. We cannot list, search, or open any other file in your Drive. heyGRC reads Google Docs and plain-text, Markdown and HTML files; Google Sheets, Google Slides, PDF and Word files are not supported yet. If someone other than the person who connected opens a file with heyGRC, heyGRC does not read or keep that file; it tells them to ask that person.
  • How we use it: only to provide the feature you turned on: to confirm that the file can be read and what type it is, to extract its text and compile it into your heyGRC linked-document review pack (clauses with verified quotes that heyGRC cites in your pull-request reviews), to check linked files once a day and re-read only the ones that changed (a file that keeps changing is checked less often, down to once a week), and to show who connected and manage the connection. heyGRC only reads your files. It never edits, moves, deletes, or changes the sharing of any file.
  • Who we share it with: the extracted text of the files you chose is sent to the AI model providers already listed in this policy for heyGRC review (the zero-data-retention OpenRouter provider set, or Mistral AI in the EU if your organization enabled EU inference), for inference only, to compile and apply your clauses. These providers do not retain it after processing and do not use it to train models. Short verified quotes from these files appear in the pull-request reviews (hosted by GitHub, Inc.) heyGRC posts to your private GitHub repositories where heyGRC is installed; on public repositories heyGRC refers to them only by subject. Our EU hosting and database providers (Fly.io and Supabase) process and store it on our behalf. We do not share Google user data with anyone else, except as required by law, or, with your prior explicit consent, as part of a merger, acquisition or sale of assets.
  • What we do not do: we do not sell Google user data. We do not use or transfer it for advertising, including retargeting, personalized or interest-based advertising, and we do not transfer it to advertising platforms, data brokers or information resellers. We do not use it to determine creditworthiness or for lending purposes. We do not use it, and do not let anyone else use it, to create, train, or improve any artificial intelligence or machine-learning model, whether a generalized model or a model personalized to you. Our staff do not read it, except with your permission for specific files, where needed for security (for example investigating a bug or abuse), to comply with applicable law, or for internal operations in aggregated and anonymized form.
  • How we store and protect it: the OAuth refresh token is encrypted with AES-256-GCM in an EU-hosted database table that only our backend can read, and is never logged or sent to an AI model. Short-lived access tokens are never written to a database or log: they are held in server memory until they expire (about an hour), and when you use Google's file picker, one is handed to your browser for that session. Extracted text and compiled clauses are stored in the EU. Extracted text is readable only by our backend; compiled clauses and their quotes are also shown to members of your heyGRC organization in the console and can be quoted in heyGRC's pull-request reviews (hosted by GitHub, Inc.) on your private GitHub repositories, as described above.
  • How long we keep it and how to delete it: we keep a linked document's extracted text and compiled clauses only while the document stays linked in your heyGRC console. When you remove the document, we delete its content. Quotes heyGRC has already posted in pull-request reviews stay in your GitHub repository, where you can edit or delete them. We delete the refresh token when you disconnect Google Drive in the heyGRC console, when the person who connected leaves your organization or loses the owner or admin role, and when your organization uninstalls heyGRC. Disconnecting stops all further reads; documents already linked keep their last extracted text until you remove them. Linked-document content is deleted about 30 days after your organization uninstalls heyGRC, by a daily purge job. Audit records of the connection (for example who disconnected and when; never a token or file content) follow the period in "heyGRC Audit Records" under Data Retention. You can also remove heyGRC's access at any time at https://myaccount.google.com/permissions. If you remove access there, we delete the stored token the next time heyGRC contacts Google. Questions or deletion requests: privacy@ismscopilot.com.

heyGRC Company Context (sent by your coding agent)

If an owner or admin of your heyGRC organization turns on the heyGRC context layer, your own coding agent (for example Claude Code, Cursor or Codex, running the heyGRC setup skill) reads your compliance platform and any documents you name, and sends heyGRC short "context objects": policy sections, controls with their framework mappings, vendors and third parties, risks, and descriptions of your data categories and processing activities. heyGRC does not connect to your compliance platform or to your Drive for this; your agent sends the data with a heyGRC API key that only an owner or admin can create.

  • Personal data: only what your own records contain, such as the name or role of a control owner or a vendor contact. The setup skill does not send who signed or approved a policy. Objects your source marks as secret are refused, and if a stored object is later marked secret, we erase its text from every stored version. Objects without a classification are accepted and treated as confidential (never quoted).
  • How we use it: we remove credentials (keys, tokens) from the text, store it in the EU with its version history, compile it into short rules with exact quotes, and use the rules that a pull request touches when we review it. Quotes in review comments follow your classification: public text on any repository, internal text only on repositories that are private when the review is posted; confidential and unclassified text is never quoted. heyGRC still uses those rules to reach a finding, so a finding may describe the rule's subject in its own words. Quotes already posted stay on GitHub if you later make the repository public.
  • Who we share it with: policy text is sent for compilation to the AI providers already listed for heyGRC review (the zero-data-retention OpenRouter provider set, or Mistral AI in the EU if your organization enabled EU inference). They do not keep it after processing and do not train on it. No new provider is involved. Quoted rules appear in your pull-request reviews on GitHub.
  • How long we keep it: The current revision of each object is kept while the organization is active. Items removed in the heyGRC console (a removed source, or an approved removal of an item deleted at the source) keep their current version for up to 12 months so they can be restored; their text is then erased (once no stored review cites it), or sooner at your organization's request (within 30 days) or about 30 days after your organization uninstalls heyGRC. An item deleted at the source stays in force, with its text, until an owner or admin approves the removal. A superseded revision is kept while a stored review cites it; its text is erased within a day of that review's deletion. A superseded revision that no review cites has its text erased 12 months after it was superseded, or once its rules are no longer in force if that is later (identifiers, hashes and timestamps kept). At your organization's request, we erase the text of named revisions within 30 days. This erasure does not reach review comments heyGRC has already posted on your GitHub pull requests; they stay in your repository, where you can edit or delete them. Everything else is deleted about 30 days after your organization uninstalls heyGRC, by the daily purge job; heyGRC audit records follow the period in "heyGRC Audit Records" under Data Retention. Records of held-change decisions (who decided, row state only) are kept on your organization's behalf for up to 12 months, or until the organization is deleted if that comes first. You can ask us to delete specific objects at privacy@ismscopilot.com.

We may disclose your information when required by law, or where necessary to protect life or safety, to:

  • Comply with legal processes (subpoenas, court orders)
  • Respond to lawful requests from government authorities
  • Report a credible threat to a person's life or safety, a suspected serious crime, or specific high-severity illegal content that meets our reporting threshold (such as child sexual abuse material or terrorism) to law enforcement, judicial authorities, or emergency services
  • Protect our rights, property, or safety
  • Prevent fraud or abuse of the platform

Where we disclose information on our own initiative to protect safety or to meet a legal reporting duty, rather than on a customer's instruction, we act as an independent controller for that disclosure. Such disclosures are rare, decided by a person, and limited to what is necessary.

No Sale of Personal Data

ISMS Copilot does not sell, rent, or trade your personal information to third parties for their marketing purposes.

International Data Transfers

Primary Data Storage

All ISMS Copilot database storage occurs in the European Union:

  • Location: Frankfurt, Germany (AWS EU-Central-1)
  • Provider: Supabase with AWS infrastructure
  • Coverage: All conversation history, uploaded files, and account data
  • Backups: a daily encrypted copy is kept in Backblaze B2 (EU). The job that makes it currently runs on GitHub Actions in the United States (see below)

Data Transfers Outside the EU

Some processing may be transferred to the United States with appropriate safeguards. We have conducted a Transfer Impact Assessment (TIA) covering all sub-processors that may process Customer Content outside the European Economic Area. Because OpenRouter does not pin the inference region, this covers the OpenRouter aggregator and each of the eight underlying providers in the closed allowlist, of which Inceptron (Inceptron AB, Sweden) and Nebius (Netherlands) are EU-based and the others (DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, and xAI) are US-based. For the paid Fast/Think/Beyond default (xAI via the "xAI (ZDR)" endpoint) we accept US-based inference under the underlying-provider Standard Contractual Clauses (Modules 2/3, Irish-law) with OpenRouter's Article 28(4) flow-down and the account-level controls as supplementary measures; a customer needing a guaranteed EU destination should enable Advanced Data Protection (Mistral, Frankfurt). The full TIA is available on request.

When Advanced Data Protection Mode is ON, AI processing and database storage occur within the EU. Two exceptions: email communications go to US-based providers (below), and the daily database backup job runs on GitHub Actions in the United States, where the database copy is unencrypted while the job runs (EU-US Data Privacy Framework and Standard Contractual Clauses).

When ADP is OFF (any plan):

  • AI requests are served within the non-ADP envelope. For paid plans (Plus and above) in the Fast and Think chat modes and the Beyond assistant, the current default is xAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint (US), with Anthropic Claude as the automatic failover; in any chat mode a non-ADP paid request may be served by Anthropic Claude (US) or any of the eight OpenRouter-allowlisted providers (including xAI, US-default for some and multi-region for others; the Essential-plan subset is restricted to Google Vertex and Cerebras), and ISMS Copilot may move any cohort or mode between these destinations over time (a control-neutral move within the disclosed envelope under DPA §2.4, publication-only), with Mistral (EU) as the circuit-breaker failover destination. Which provider serves a given request may vary by plan, rollout, and over time; based on their published deployment documentation, none was found to operate PRC or Hong Kong infrastructure, and PRC-jurisdiction providers are blocked at the OpenRouter account level. Transfer mechanisms: Anthropic-served traffic relies on its own SCCs; for the OpenRouter allowlist the SCCs operate at the underlying-provider layer through the OpenRouter aggregator (OpenRouter-intermediated), not direct SCCs we sign with each underlying host, and Google Vertex additionally holds EU-US Data Privacy Framework certification, which is an Article 45 adequacy mechanism, distinct from the Article 46 Standard Contractual Clauses; for OpenRouter-served traffic, the account-level controls (mandatory ZDR, training-disallowed, allowlist, PRC-blocklist) act as Schrems II-style supplementary measures. Anthropic-served traffic follows the retention shown in the AI Processing table above; OpenRouter-served traffic is zero-retention (no persistent retention beyond serving the request; transient in-memory caching only). The DPA §3.1 has the complete per-provider deployment-region detail and the OpenRouter region-pinning gap explanation. Customers needing contractual EU-only data residency for AI processing should enable Advanced Data Protection Mode (Mistral, EU), which bypasses this envelope entirely.

Email transfers (SendGrid, Kit) to the US occur regardless of ADP, protected by SCCs.

EU-Only Processing Options:

  • Enable Advanced Data Protection Mode for EU-only AI processing
  • For heyGRC, an organization owner can turn on EU inference in the heyGRC console (compliance reviews and linked-document and context compiles; /heygrc replies stay on the default path)
  • Unsubscribe from non-essential emails to minimize US transfers
  • Database storage always remains in the EU regardless of configuration

Data Retention

User-Controlled Retention

You control how long your data is retained:

  • Conversation history: 1 day to 7 years, or keep forever (configurable in Settings)
  • Uploaded documents: Linked to conversation retention settings
  • Automated deletion: Daily process removes expired data
  • Active accounts: Retained while account is active
  • Session tokens: Expire after inactivity period
  • Temporary chats: Automatically deleted after 30 days
  • Free-trial eligibility marker: If you start an app-managed free trial of a paid plan, we record that your account has used a trial (and the trial's end date). We keep this marker for the life of the account to prevent repeated free-trial abuse. Our legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in offering a one-time trial fairly; it is not treated as billing data, and it is deleted when your account is deleted (see After Account Deletion).

Pull-Request Review Retention (heyGRC GitHub App)

  • Diffs: not persisted as a record; used only to produce the review.
  • Reviews (summaries, findings, pull-request number and commit identifier): retained while the heyGRC App is installed, to power your console history and audit trail. After you uninstall the App from an organization, its reviews and remaining records are kept for 30 days and then deleted automatically, except heyGRC audit records, which are kept for up to 12 months from creation (see heyGRC Audit Records). Reinstalling the App later starts a new history. Removing a single repository from the App's scope stops reviews for it; its past reviews follow the organization. You can ask for earlier deletion at privacy@ismscopilot.com (completed within 30 days). Deleting your ISMS Copilot / heyGRC account deletes your organization's reviews with it.
  • Organization and installation records: the GitHub account name is deleted at uninstall; remaining records follow the 30-day window above, except heyGRC audit records, which are kept for up to 12 months from creation (see heyGRC Audit Records), and records we must keep for legal, tax or accounting purposes.

After Account Deletion

  • Personal data: Permanently deleted within 30 days, except heyGRC audit records (see heyGRC Audit Records below) and records your heyGRC organization keeps on its behalf, such as held-change decisions, which follow that organization's retention
  • Billing records: Anonymized and retained for 7 years (legal requirement for tax compliance)
  • Backup data: Overwritten within 90 days

Analytics and Logs

  • PostHog analytics: Up to 7 years (anonymized)
  • Sentry error logs: 90 days
  • Access logs: 30-90 days per infrastructure provider policies

Moderation Retention

  • Non-flagged messages: No moderation record stored.
  • Flagged messages: Metadata only (message ID, thread ID, abuse categories, timestamp — no message content) retained for up to 12 months, then automatically purged.

heyGRC Audit Records

Audit records of heyGRC API and console actions (who acted, when, which key and route, source IP address and user agent, and identifiers, hashes, counts and settings changed; never document content) are kept for up to 12 months from creation and then deleted automatically, including after your organization uninstalls heyGRC or your account is deleted. We keep them as controller for the security of the service (Art. 6(1)(f) GDPR), and show them to your organization's owners and members while it is active.

Data Security

Technical Security Measures

  • Encryption in transit: TLS 1.3 for all connections
  • Encryption at rest: Database and file storage encryption
  • Password security: Industry-standard hashing (irreversible)
  • Access control: Row-level security prevents unauthorized data access
  • Session management: Automatic timeout controls

Organizational Security Measures

  • Workspace isolation: Separate data for different projects/clients
  • User authentication: Required for all protected resources
  • MFA support: Multi-factor authentication available
  • Monitoring: Continuous error and security monitoring via Sentry
  • Incident response: 24-hour breach assessment and notification procedures

Data Minimization

  • Only essential data collected (email, messages, files)
  • No unnecessary demographic or contact information
  • Analytics configured to exclude PII
  • User-controlled retention periods

For detailed security documentation, visit our Trust Center or review our Register of Processing Activities (RoPA) for the per-activity Article 30 processing inventory.

Your Privacy Rights

Right to Access (Article 15 GDPR)

You have the right to access all personal data we hold about you.

How to exercise:

  • Log in to view conversations and files through the platform interface
  • For a complete data export, use the in-app data export tool in Settings → Data Protection (available to all plans)
  • We provide your data in JSON format (typically within 72 hours)

Right to Rectification (Article 16 GDPR)

You can update or correct your personal information.

How to exercise:

  • Update account settings through the Settings dialog (accessible via user menu)
  • For email address changes, contact privacy@ismscopilot.com
  • Changes are applied immediately for self-service updates

Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)

You can request complete deletion of your account and data.

How to exercise:

  • Use the in-app account deletion in Settings → Data Protection (self-service, available to all plans)
  • For deletion of specific content within a flagged thread (see "Content Moderation" above), email privacy@ismscopilot.com — we evaluate each request against the legitimate-interest balancing test under Article 17(3) and respond within 30 days
  • All data is permanently deleted within 30 days, except the records listed under Data Retention (heyGRC Audit Records, moderation metadata, anonymized billing records)

Account deletion is permanent and cannot be undone. All workspaces, conversations, and uploaded files will be permanently erased. Export any needed data before requesting deletion.

Right to Data Portability (Article 20 GDPR)

You can receive your data in a structured, machine-readable format.

How to exercise:

  • Use the in-app data export tool in Settings → Data Protection
  • Export is provided in JSON format
  • Export includes account information, conversations, and file metadata

Right to Restrict Processing (Article 18 GDPR)

You can request temporary suspension of data processing.

How to exercise: Email privacy@ismscopilot.com explaining the reason for restriction. We will respond within 30 days.

Right to Object (Article 21 GDPR)

You can object to certain types of data processing.

How to exercise: Email privacy@ismscopilot.com specifying what processing you object to. We will review and respond within 30 days.

Where processing is based on your consent (such as marketing product-update newsletters), you may withdraw consent at any time by clicking unsubscribe in any email or adjusting preferences in Settings. Withdrawal does not affect processing that occurred before withdrawal.

Right to Lodge a Complaint

You have the right to file a complaint with a supervisory authority:

Commission Nationale de l'Informatique et des Libertés (CNIL)

  • Website: https://www.cnil.fr/en
  • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Phone: +33 1 53 73 22 22

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional privacy rights.

While the CCPA's thresholds may not apply to Better ISMS for its own account data, we voluntarily extend the rights described in this section to California residents.

This section covers account data for all Better ISMS products: ISMS Copilot, heyGRC and Aevral. For content you authorize a product to process on your behalf (for example the repositories Aevral scans and reviews, or the Google Drive files heyGRC reads), where the CCPA/CPRA applies to your organization's processing, Better ISMS acts as a service provider, not as a business, and that content is governed by the Data Processing Agreement together with its United States State Privacy Laws section (§10). API request content is governed by the separate API Data Processing Agreement. As a service provider we do not sell or share that content, and we process it only on your organization's documented instructions. If your purchase process needs a countersigned copy of the DPA, contact privacy@ismscopilot.com.

Information We Collect (CCPA Categories)

In the past 12 months, we have collected the following categories of personal information from California residents:

  • Identifiers: Email addresses, account IDs, IP addresses (anonymized)
  • Commercial information: Subscription records, payment history, billing information
  • Internet or network activity: Usage data, session logs, feature interactions, error logs
  • Professional information: Content you input (policies, audit data, risk assessments). Content you authorize our products to process on your behalf follows the service-provider position described above, and is not collected for our own purposes
  • Inferences: Usage patterns derived from analytics (anonymized)

We do not collect sensitive personal information as defined by CCPA (e.g., Social Security numbers, driver's license numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, or union membership), with one exception: account login credentials (your email address together with your password), which we collect only to authenticate you and secure your account. OAuth sign-ins (GitHub, Google, Microsoft) never give us your password. This concerns the account data we collect ourselves. Content that customers authorize our products to process on their behalf (for example repository code, pull requests, Google Drive files) may incidentally contain sensitive personal information without our knowledge; where the CCPA/CPRA applies, we process that content as a service provider on the customer's documented instructions and do not collect it for our own purposes.

Business Purposes for Collection

We collect and use personal information for the following business purposes:

  • Providing the ISMS Copilot platform and AI compliance assistance
  • Processing payments and managing subscriptions
  • Authenticating and securing your account
  • Improving service quality and developing new features
  • Detecting and preventing fraud, security incidents, and abuse
  • Debugging and error tracking
  • Complying with legal obligations

Disclosure of Personal Information

We share personal information with the following categories of third parties for business purposes (AI routing follows the single non-ADP envelope described under "AI Processing" above; current routing and the available provider subset may differ by plan and ADP setting, see the full matrix):

  • Cloud service providers: Supabase, AWS (database and storage)
  • AI service providers: Anthropic (any non-ADP plan; the paid Fast/Think/Beyond failover), OpenRouter aggregator (any non-ADP plan, routing to one of the eight allowlisted underlying providers: Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius, and xAI via the "xAI (ZDR)" endpoint - xAI is the paid Fast/Think/Beyond default; the Essential subset is restricted to Google Vertex and Cerebras; see the "AI Processing" matrix above for the full posture per provider), or Mistral AI (ADP)
  • Payment processors: Stripe (payment processing)
  • Analytics providers: PostHog, Sentry, Vercel
  • Email service providers: SendGrid, Kit
  • Document processors: ConvertAPI, Fly.io

No Sale or Sharing: ISMS Copilot does not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

Your California Privacy Rights

Right to Know

You have the right to request that we disclose:

  • Categories of personal information we've collected about you
  • Categories of sources from which the information was collected
  • Business or commercial purpose for collecting the information
  • Categories of third parties with whom we share personal information
  • Specific pieces of personal information we've collected about you

Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations to retain billing records, moderation metadata for flagged content per our Acceptable Use Policy).

Right to Correct

You have the right to request correction of inaccurate personal information we maintain about you.

Right to Opt-Out

You have the right to opt out of:

  • Sale of personal information: Not applicable (we don't sell personal information)
  • Sharing for cross-context behavioral advertising: Not applicable (we don't engage in this practice)

Right to Limit Use of Sensitive Personal Information

Not applicable beyond the account-credential exception above: we do not use sensitive personal information for the purposes the CCPA limits.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights.

How to Exercise Your California Rights

Submit a request: Email privacy@ismscopilot.com with "CCPA Request" in the subject line. Specify which right you're exercising (Know, Delete, Correct).

Verification process: We will verify your identity by confirming your registered email address. For sensitive requests, we may require additional verification. You may designate an authorized agent to make requests on your behalf (we will require written authorization).

Response timeline:

  • Acknowledgment within 10 business days
  • Response within 45 days (may extend up to 90 days for complex requests)

California "Shine the Light" Law

Under California Civil Code Section 1798.83, California residents may request information about our disclosure of personal information to third parties for direct marketing purposes. ISMS Copilot does not disclose personal information to third parties for their direct marketing purposes.

Other US State Privacy Laws

For residents of states with comparable privacy laws (for example Virginia, Colorado, Connecticut, Utah), where such a law applies, the same position holds: for content you authorize our products to process on your behalf, we act as processor or service provider under your organization's instructions, and we do not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising or qualifying profiling as those laws define them. To exercise rights or ask a question, email privacy@ismscopilot.com. If we decline a request, we will say why and how to appeal; where the law provides, you may also contact your state attorney general.

Automated Processing

ISMS Copilot uses AI to assist with compliance content generation, but does not make automated decisions that produce legal effects or similarly significantly affect you under GDPR Article 22. All compliance decisions remain under your control. Content moderation flags are reviewed by humans before any account action is taken.

Cookies and Tracking

Essential Cookies

We use strictly necessary cookies for:

  • User authentication and session management
  • Security and fraud prevention
  • Platform functionality

Analytics Cookies

With your consent, we use analytics cookies to:

  • Understand platform usage patterns
  • Improve user experience
  • Monitor performance

We do not use advertising or marketing cookies. All analytics are configured to exclude personally identifiable information.

Privacy-First Analytics: PostHog operates in cookieless mode with in-memory persistence only. No cookies or browser storage are written to your device. Anonymous usage is tracked via privacy-preserving server-side hashing, and user profiles are created only for authenticated sessions.

Children's Privacy

ISMS Copilot is not intended for individuals under 16 years of age:

  • Our service is designed for compliance professionals and businesses
  • We do not knowingly collect data from children
  • If we discover underage use, we will terminate the account and delete the data

User Responsibilities

While ISMS Copilot provides GDPR-compliant infrastructure, you (as data controller for your own processing) are responsible for ensuring your use of the platform complies with applicable regulations.

You are responsible for:

  • Ensuring legal basis exists before uploading personal data
  • Configuring appropriate data retention periods for your organization
  • Maintaining separate workspaces for different clients or data categories
  • Informing individuals when their data is processed through ISMS Copilot
  • Including ISMS Copilot in your own data processing records
  • Conducting Data Protection Impact Assessments (DPIA) when processing high-risk data
  • Enabling Advanced Data Protection Mode before processing special category data (Article 9 GDPR) or criminal-offence data (Article 10 GDPR) with AI features, since such data is excluded from the default (non-ADP) AI routing path

Changes to This Privacy Policy

How We Notify You

When we update this Privacy Policy, we will:

  • Update the "Effective Date" at the top of this policy and publish the change in the Trust Center change log
  • Display in-app notification for changes to the products you use
  • For material changes, provide at least 30 days notice by email and in-app

Non-material changes (clarifications and additions that only strengthen protections) are published with a new "Effective Date" without advance notice, matching DPA §7.2.

Your Options

If you don't agree with changes:

  • Enable Advanced Data Protection Mode to keep AI processing within the EU regardless of routing changes
  • Request account deletion (self-service in Settings → Data Protection) before changes take effect
  • Export your data before the effective date
  • Email privacy@ismscopilot.com to discuss concerns or to formally object under your DPA where applicable

Contact Us

For privacy questions or rights requests, email privacy@ismscopilot.com. Include "Privacy Request" or "GDPR Request" in the subject for priority handling.

Response Times:

  • Acknowledgment: Within 24-48 hours
  • Full response: Within 30 days (typically within 72 hours)