Back to Trust Center
Effective: 2026-07-23

Privacy Policy — ISMS Copilot

Overview

This Privacy Policy describes how ISMS Copilot ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our AI-powered compliance platform. This policy applies to all users of ISMS Copilot, including trial users, subscribers, and visitors to our website.

Effective Date: 2026-07-23. This Privacy Policy is updated regularly to reflect changes in our data processing practices and regulatory requirements.

Global Coverage: This policy covers both European (GDPR) and California (CCPA/CPRA) privacy requirements. EU users should focus on GDPR sections; California residents should also review the California Privacy Rights section.

Who This Is For

This Privacy Policy is for:

  • All ISMS Copilot platform users (compliance professionals, consultants, security teams)
  • Organizations evaluating ISMS Copilot for vendor risk assessments
  • Data Protection Officers conducting privacy reviews
  • Anyone seeking to understand how we handle personal information

Data Controller Information

ISMS Copilot is the data controller responsible for your personal information:

  • Name: ISMS Copilot (operated by Better ISMS EURL)
  • Jurisdiction: France (European Union)
  • Primary Data Location: Frankfurt, Germany (AWS EU-Central-1)
  • Privacy Contact: privacy@ismscopilot.com
  • Supervisory Authority: Commission Nationale de l'Informatique et des Libertés (CNIL)

Data Protection Officer

ISMS Copilot has not designated a Data Protection Officer as we do not meet the mandatory designation criteria under GDPR Article 37. For privacy inquiries, contact privacy@ismscopilot.com.

Information We Collect

Account Information

When you create an ISMS Copilot account, we collect:

  • Email address (for authentication and essential communications)
  • Password (hashed and encrypted, never stored in plain text)
  • Account creation and last login timestamps
  • User unique identifiers (UUIDs)

Conversation Data

When you use our AI compliance assistant, we process:

  • Your messages and queries
  • AI-generated responses
  • Conversation metadata (titles, timestamps, status)
  • Workspace configurations and custom instructions
  • Compliance-related content (policies, procedures, audit information you input)

Special category data (Article 9 GDPR, such as security incidents that reveal health, biometric, or other sensitive information) and personal data relating to criminal convictions and offences (Article 10 GDPR) are excluded from the default (non-ADP) AI routing path. If you need AI assistance with such data, enable Advanced Data Protection Mode, which routes your inputs to our EU-based enhanced-protection model. We do not automatically detect or filter special-category or criminal-offence content on the default path, so you are responsible both for having legal authority to process such data and for enabling Advanced Data Protection Mode before inputting it. See our Data Processing Agreement (§4.2) for the routing and safeguard details.

Uploaded Files

When you upload documents for analysis, we collect:

  • File content (PDF, DOCX, XLSX formats)
  • File names, sizes, and upload timestamps
  • Extracted document content and metadata
  • Document processing status

Slack Integration Data (heygrc bot)

If your organization is on a paid plan and an organization owner installs the heygrc Slack bot, we additionally process:

  • Slack workspace metadata captured during the OAuth install: workspace (team) ID, workspace name, bot user ID, and the ISMS Copilot user ID of the installer (for audit). The OAuth scope is bot-only — we do not request the workspace user directory, channel history, or file access.
  • An OAuth bot token issued by Slack, stored in an isolated slack_integration_secrets table with service-role-only access (encrypted at rest via the database infrastructure layer).
  • Message content of Slack messages addressed to the bot — direct messages or @heygrc channel mentions only. We do not read or store any message that is not addressed to the bot.
  • Slack user identifiers (slack_user_id) for the workspace member who sent each message addressed to the bot, recorded in the slack_threads mapping table for traceability.

The Slack integration is a paid-tier-only feature. Free / null-plan organizations cannot install the bot — the OAuth callback rejects the install with a "paid plan required" error.

Payment Information

For premium subscriptions, we collect:

  • Stripe customer IDs and subscription IDs
  • Payment metadata (we never store full credit card numbers)
  • Billing events and invoice information
  • Subscription status and tier information

Payment card data is handled exclusively by Stripe, our PCI DSS Level 1 compliant payment processor. ISMS Copilot never stores or processes credit card numbers.

Analytics and Usage Data

To improve our service, we automatically collect:

  • User behavior events (page views, feature usage)
  • Session data and duration
  • Browser and device information
  • Error logs and performance metrics
  • User identifiers (UUID only) for error tracking in production (no email addresses or names)
  • IP addresses (anonymized)

Our analytics systems are configured with sendDefaultPii: false to prevent automatic collection of personally identifiable information. Conversation content and uploaded documents are never shared with analytics providers.

Email Communications Data

When you receive emails from us, we may collect:

  • Email engagement data (opens, clicks)
  • Subscription preferences
  • Unsubscribe status
  • Email delivery timestamps

How We Use Your Information

Service Delivery (Legal Basis: Contract Performance — Article 6(1)(b) GDPR)

  • Provide AI-powered compliance assistance
  • Authenticate your account and manage sessions
  • Process and store your conversations and uploaded files
  • Deliver features and functionality you've requested
  • Process subscription payments and manage billing

Service Improvement (Legal Basis: Legitimate Interest — Article 6(1)(f) GDPR)

  • Analyze platform usage to improve user experience
  • Monitor system performance and reliability
  • Identify and fix bugs and technical issues
  • Develop new features and capabilities

Security and Fraud Prevention (Legal Basis: Legitimate Interest — Article 6(1)(f) GDPR)

  • Detect and prevent unauthorized access
  • Monitor for suspicious activity or abuse
  • Protect platform integrity and user data
  • Respond to security incidents
  • Process all chat messages through automated content moderation to detect prohibited content under our Acceptable Use Policy

Content Moderation

All chat messages are processed through Mistral AI's moderation API (model: mistral-moderation-latest, EU residency, zero retention) regardless of your Advanced Data Protection setting. Moderation is a two-stage pipeline: a fast classifier followed by a judge model that reviews borderline cases. Moderation runs on Mistral on every request to ensure consistent, EU-residency safety review.

We retain moderation outputs as follows:

  • For non-flagged messages: No moderation record is stored. The message is processed and discarded by the moderation pipeline.
  • For flagged messages: A moderation_events record is retained containing only metadata — the message identifier, the thread identifier, the abuse categories matched, and a timestamp. The full message content is not stored in the moderation record. This metadata is retained for up to 12 months for safety/audit purposes, after which it is automatically purged.
  • Thread deletion lock: When a message in a thread has been flagged, the thread is locked from user-initiated deletion to prevent destruction of abuse evidence. Customer Content within a flagged thread is still subject to deletion on a verified Article 17 erasure request submitted to privacy@ismscopilot.com (see "Right to Erasure" below); we evaluate each such request against the legitimate-interest balancing test under Article 17(3) and respond within 30 days.

Communications

We send different email types under different legal bases:

  • Transactional and account emails (password resets, security alerts, account activation, billing). Legal basis: Contract (Article 6(1)(b)) and Legal Obligation (Article 6(1)(c)).
  • Onboarding guidance, product education, and important service or legal updates. Legal basis: Legitimate Interest (Article 6(1)(f)). You can unsubscribe from non-essential messages at any time.
  • Marketing product-update newsletters. Legal basis: Consent (Article 6(1)(a)). Sent only to users who have opted in; withdraw any time via the unsubscribe link in every message.

Legal Compliance (Legal Basis: Legal Obligation — Article 6(1)(c) GDPR)

  • Retain billing records for tax and accounting requirements (7 years)
  • Respond to lawful requests from authorities
  • Comply with applicable data protection laws

ISMS Copilot never uses your data for marketing, advertising, or selling to third parties. Your conversations and uploaded documents are never used to train AI models.

How We Share Your Information

Third-Party Service Providers (Data Processors)

We share your information with trusted service providers who help us deliver the platform. The complete list of sub-processors, including the routing logic and contractual controls described below, is maintained in our Data Processing Agreement (DPA). Sub-processor changes are notified through our Trust Center and in-app changelog; a materially adverse change is additionally notified by at least 30 days' advance email and in-app notification, and a control-neutral change is notified by publication in the Trust Center and the customer-facing change log without an advance notice period. The criteria and process are defined in DPA §2.4. (Section updated 2026-07-21.)

Database and Storage (Always Active)

  • Supabase: Database and file storage (EU — Frankfurt, Germany)
  • AWS: Infrastructure (EU-Central-1, Frankfurt)

AI Processing

How your AI requests are routed depends on one setting: whether Advanced Data Protection (ADP) Mode is enabled. ADP is the guaranteed EU, zero-retention path. With ADP off, your requests are served within a single vetted non-ADP envelope described below. Which specific provider serves a given request may vary by plan, by rollout, and over time, and we do not commit to a fixed per-request provider assignment. Your plan (Free, Essential, Plus, Standard, Pro, Business, or an app-managed Plus trial) does not change the outer limits of this envelope; current routing and the available provider subset may differ by plan. Each destination in the envelope meets our minimum non-ADP requirements (no training on your data, non-PRC jurisdiction, GDPR-aligned transfer mechanism), with the material retention and location differences shown below (Anthropic-served traffic has longer retention than the zero-retention OpenRouter allowlist). For paid plans (Plus and above) with ADP off, in the chat Fast and Think modes and the Beyond assistant, the current default destination is xAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint (zero data retention), with Anthropic Claude (Opus for Think, Sonnet for Fast) as the automatic failover; in any chat mode a non-ADP paid request may be served by any of the eight OpenRouter-allowlisted providers or Anthropic, and the destination may move between them over time (a control-neutral move within the disclosed envelope under DPA §2.4, publication-only).

Routing pathWhen it appliesAI providerLocationRetentionTraining
ADP enabled (any plan)ADP toggle ONMistral AIEU (Frankfurt)Zero retentionNo training
ADP off (any plan)ADP toggle OFF, any chat modexAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint is the current default for paid plans (Plus and above) in the Fast and Think chat modes and the Beyond assistant, with Anthropic Claude (Opus for Think, Sonnet for Fast) as the automatic failover. In any chat mode, a non-ADP paid request may be served by Anthropic Claude or any of the eight OpenRouter-allowlisted providers below (including xAI; the Essential subset is within this allowlist), and ISMS Copilot may move any cohort or mode between these destinations over time (a control-neutral move within the disclosed envelope under DPA §2.4, publication-only), with Mistral (EU) as the circuit-breaker failover described below. The specific provider may vary by plan, rollout, and over time.United States, or EU for the EU-based OpenRouter hosts (Inceptron in Sweden, Nebius in Netherlands); xAI is United States (OpenRouter-published provider footprint, per-request inference region not pinned via OpenRouter); see the complete per-provider region list in the DPA §3.1 (a default deployment posture, not contractual residency; inference region not pinnable via OpenRouter; use ADP for guaranteed EU). SCC; DPF (Article 45 adequacy) for Google Vertex.Anthropic-served traffic: inputs and outputs are ordinarily deleted within about 30 days; content its safety systems flag may be retained up to 2 years, and safety-classification scores up to 7 years; never used for training. OpenRouter-served traffic: zero retention (no persistent retention beyond serving the request; transient in-memory caching only). Enable ADP for zero retention everywhere.No training

About OpenRouter and the underlying providers (the non-ADP envelope). OpenRouter is a routing aggregator. We use OpenRouter so that requests can fail over automatically across a curated set of vetted hosts, increasing availability. A non-ADP request may route to any provider on the closed OpenRouter allowlist below (the seven glm-4.7 hosts plus xAI via the "xAI (ZDR)" endpoint for the Grok models); for paid plans (Plus and above) in the Fast and Think chat modes and the Beyond assistant the current default allowlist destination is xAI, and any allowlisted provider may serve any non-ADP paid mode (the destination may move within the allowlist over time, a control-neutral change under DPA §2.4). Essential-plan requests are restricted to a closed two-provider subset of that allowlist (Google Vertex and Cerebras). The same account-level controls below apply to every OpenRouter request regardless of plan:

  • Zero Data Retention is mandatory. Per OpenRouter's published policy, when ZDR is enabled at the account level, requests can only be routed to endpoints with a Zero Data Retention policy. Your conversation content is not persistently retained by any underlying provider beyond serving the request; a provider may hold it transiently in memory for the duration of processing, as is inherent to serving an inference request.
  • No training, ever. Both "Free Training Disallowed" and "Paid Training Disallowed" are set at the account level. Your data cannot be used to train any model.
  • No publication. "Free Publication Disallowed" is set; the model-publication channel is closed.
  • Closed OpenRouter allowlist. Only the following may serve our requests: Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, and Nebius (the seven hosts for the glm-4.7 model), plus xAI via the "xAI (ZDR)" endpoint for the Grok models. Each was selected after a privacy review, each confirms zero retention or no-training-on-customer-data in its published policies, and each maintains GDPR-aligned transfer mechanisms. For the OpenRouter allowlist the Standard Contractual Clauses operate at the underlying-provider layer through the OpenRouter aggregator (OpenRouter-intermediated); we do not sign separate direct SCCs with each underlying host. Google Vertex additionally holds EU-US Data Privacy Framework certification, which is an Article 45 adequacy mechanism, distinct from the Article 46 Standard Contractual Clauses relied on elsewhere. The allowlist was expanded from four to seven glm-4.7 hosts on 2026-05-25; xAI (already present on the account and already serving our public risk-analysis demo) was activated for paid Customer-Content and made the paid Fast/Think/Beyond default on 2026-07-21 (see the sub-processor change log).
  • PRC-jurisdiction providers blocked. Alibaba Cloud Int., Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, and Z.AI are all blocked at the OpenRouter account level. The control is jurisdiction-based: PRC-jurisdiction providers are blocked at the OpenRouter account level, and the allowlisted providers were selected to avoid PRC/Hong Kong infrastructure based on their published deployment documentation. Because OpenRouter does not expose per-provider region pinning, this is enforced through provider selection and the account-level blocklist rather than a guaranteed per-request inference region. It is a Schrems II-style supplementary measure aligned with EDPB Recommendations 01/2020.

Failover. Paid Fast/Think/Beyond failover. For the paid plans (Plus and above) Fast and Think chat modes and the Beyond assistant, which default to xAI via OpenRouter's "xAI (ZDR)" endpoint, if that route does not begin responding within a short pre-first-token timeout the request is re-served by Anthropic (Opus for Think, Sonnet for Fast); if Anthropic's circuit breaker is open, the request fails over to Mistral AI in Frankfurt (EU). The xAI attempt is zero-retention, so where a single request transits two destinations the first leg holds no persistent content. For non-ADP traffic served by Anthropic, if Anthropic is unavailable, requests automatically fail over to Mistral AI in Frankfurt. Mistral is also our circuit-breaker destination, so these users always reach an EU-compatible provider during outages. For OpenRouter-served traffic (any non-ADP plan), failover happens within the OpenRouter aggregator across the allowlisted providers (the Essential subset is Google Vertex and Cerebras; other non-ADP plans span the eight allowlisted providers); in all cases the OpenRouter account-level controls below apply. For a non-ADP request that is first attempted on an allowlisted OpenRouter provider, if that provider does not begin responding within a short timeout the attempt is aborted and the request is re-served by the failover non-ADP path: Anthropic (Opus for Think, Sonnet for Fast), or, if Anthropic's circuit breaker is open, Mistral in the EU. In that case the single request transits two disclosed destinations, with the OpenRouter attempt zero-retention (no persistent retention beyond serving the request) and the deepest fallback (Mistral, EU) zero-retention as well.

ADP as the EU-only opt-out. Enabling Advanced Data Protection Mode in your settings routes permitted AI processing to Mistral AI's confirmed Frankfurt, EU, zero-retention routes regardless of your plan. Authenticated web search is unavailable while ADP is enabled and fails closed, because Mistral's web search is not EU-only and not zero-retention: it runs on Mistral's stateful Conversations/Agents endpoint (which Mistral excludes from its zero-retention posture) and uses Brave (United States) as its web-search sub-processor. Beyond can still fetch an exact public page or document selected by the user through our EU Fly.io service; all subsequent AI processing remains on the ADP Mistral route. ADP remains the in-product control for users who require fully EU-based AI processing.

Where web search is available under your plan and organization policy, ISMS Copilot may search when you explicitly ask it to search or when a conservative intent check determines that your request requires current external information. A personal or organization-level Never search the web control prevents any search-provider request. The product shows when web evidence was used and provides source links; retrieval supplies the external fact set, while the AI uses that evidence and our separately maintained framework knowledge to reason and write the response. Citations improve traceability but do not guarantee that a source or generated answer is complete, current, or correct.

The processing is minimized by route:

  • Search-intent check: Mistral AI in the EU receives limited recent conversation text and returns a search/no-search classification. The classification call is zero-retention. It does not itself contact the web.
  • Launch retrieval route when ADP is off: the minimized query is sent to Mistral's web-search service. Mistral is used only to discover source URLs and return provider-attested URL references. We discard Mistral's generated search prose. Mistral's web search runs on Mistral's stateful Conversations/Agents endpoint, which Mistral excludes from its zero-retention posture, and Mistral engages Brave Search (Brave Software, Inc., United States) as Mistral's own web-search sub-processor. The minimized query therefore travels from Mistral (EU) to Brave (United States); this discovery step is not EU-only and not zero-retention, and standard, non-zero retention applies per the applicable Mistral/Brave provider terms. ISMS Copilot does not separately engage Brave for this launch route; Brave is engaged by Mistral. Our SSRF-hardened Fly.io service in the EU then fetches the referenced public pages directly and supplies bounded extracted text to the answering model. The selected websites receive ordinary outbound request metadata, such as our service IP, URL path/query, timing, and a neutral user agent. Authenticated web search fails closed when ADP is enabled.
  • Use by the existing answer model: bounded exact-fetched excerpts, source titles, and URLs are supplied as labeled request-scoped context to the answer provider already applicable to the conversation. They sit beside framework, memory, workspace, file, and user context. No additional semantic grounding model receives the complete draft.
  • Exact URL requests in Beyond: when you provide a specific public URL, the same EU Fly.io service fetches that exact page directly. Mistral discovery is not needed for the exact submitted page, although a company-research scope may separately discover independent sources.
  • Future Brave-direct route, not active: this is separate from Brave's launch role as Mistral's web-search sub-processor described above. The direct route (in which ISMS Copilot would call the Brave Search API itself, rather than reaching Brave via Mistral) is a dark candidate only. It is not the default, is not constructed or called by the launch route, and will remain disabled until at least 30 days after materially-adverse-change notice and founder contractual acceptance. If later approved, a bounded query derived only from the latest user request may be sent directly to Brave in the United States. We would not send files, memories, workspace context, account identifiers, or user/device identifiers. Queries would be limited to 400 characters and 50 words, with credentials and signed URLs rejected. Brave's standard API privacy notice states that query logs may be retained for up to 90 days. SCCs would apply, and Brave's published DPA excludes "Search Query Data" from its processor scope.

Mistral's generated search prose, raw discovery response, and fetched page text are used transiently and are not stored in conversation history, Beyond run records, detector telemetry, or application logs. The generated answer and its displayed source links follow your existing conversation-retention setting. Daily search counters store the user identifier, date, count, and update timestamp needed to enforce and maintain limits; they do not store the query or evidence.

Slack-originated requests. Messages sent to the heygrc Slack bot follow the same non-ADP envelope and ADP routing as web chat, governed by the organization's ADP setting: with ADP on (at the org level), Mistral (EU, zero retention); with ADP off, for paid organizations (Plus and above) the Fast and Think modes and Beyond default to xAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint (zero retention) with Anthropic as the automatic failover, and otherwise the destination may be Anthropic (standard commercial API terms) or the OpenRouter allowlist (zero retention, meaning no persistent retention beyond serving the request; the Essential-plan subset is Google Vertex and Cerebras). The org's ADP setting governs all Slack workspace users; an individual Slack workspace member cannot select their own routing.

Content Moderation

All chat messages are processed through Mistral AI's moderation API (EU, zero retention) regardless of plan or ADP setting. See "Content Moderation" above for retention details.

Payment Processing

  • Stripe: Payment processing and subscription management (Global with EU DPA, PCI DSS Level 1 compliant)

Analytics and Monitoring

  • PostHog: Product analytics (EU — Frankfurt, Germany)
  • Sentry: Error tracking and monitoring (Germany). In production only, your user ID (UUID) is captured with error reports to enable faster troubleshooting. No email addresses, conversation content, or other personal information is sent.
  • Vercel: Web analytics and frontend hosting (GDPR-compliant)

Email Communications

  • SendGrid (Twilio): Transactional and legal update emails (United States with Standard Contractual Clauses)
  • Kit (ConvertKit): Onboarding and product update emails (United States with Standard Contractual Clauses)

You can unsubscribe from non-essential emails (product updates, onboarding sequences) at any time. Essential service notifications may still be sent as required by law or contract.

Document Processing

  • ConvertAPI: Document format conversion (EU endpoint, temporary processing only)
  • Fly.io: Backend API hosting, chat orchestration, and request-scoped exact-public-URL fetching (EU deployment)

Optional Integrations

  • Slack: Activated only if a paid-organization owner installs the heygrc bot. When activated, Slack acts as both a source (we receive messages addressed to the bot) and a destination (we post AI responses back to the workspace). Slack itself is also a sub-processor (United States) — the OAuth bot token sits in our database, and we exchange workspace metadata with Slack at install time and during message events. Transfer mechanism: Standard Contractual Clauses with Slack Technologies, Inc. The integration is org-scoped and can be uninstalled at any time from the Slack workspace's app management UI; uninstall hard-deletes all our integration records (token, workspace metadata, Slack-thread mappings) within seconds via the app_uninstalled event.

We may disclose your information when required by law, or where necessary to protect life or safety, to:

  • Comply with legal processes (subpoenas, court orders)
  • Respond to lawful requests from government authorities
  • Report a credible threat to a person's life or safety, a suspected serious crime, or specific high-severity illegal content that meets our reporting threshold (such as child sexual abuse material or terrorism) to law enforcement, judicial authorities, or emergency services
  • Protect our rights, property, or safety
  • Prevent fraud or abuse of the platform

Where we disclose information on our own initiative to protect safety or to meet a legal reporting duty, rather than on a customer's instruction, we act as an independent controller for that disclosure. Such disclosures are rare, decided by a person, and limited to what is necessary.

No Sale of Personal Data

ISMS Copilot does not sell, rent, or trade your personal information to third parties for their marketing purposes.

International Data Transfers

Primary Data Storage

All ISMS Copilot database storage occurs in the European Union:

  • Location: Frankfurt, Germany (AWS EU-Central-1)
  • Provider: Supabase with AWS infrastructure
  • Coverage: All conversation history, uploaded files, and account data

Data Transfers Outside the EU

Some processing may be transferred to the United States with appropriate safeguards. We have conducted a Transfer Impact Assessment (TIA) covering all sub-processors that may process Customer Content outside the European Economic Area. Because OpenRouter does not pin the inference region, this covers the OpenRouter aggregator and each of the eight underlying providers in the closed allowlist, of which Inceptron (Inceptron AB, Sweden) and Nebius (Netherlands) are EU-based and the others (DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, and xAI) are US-based. For the paid Fast/Think/Beyond default (xAI via the "xAI (ZDR)" endpoint) we accept US-based inference under the underlying-provider Standard Contractual Clauses (Modules 2/3, Irish-law) with OpenRouter's Article 28(4) flow-down and the account-level controls as supplementary measures; a customer needing a guaranteed EU destination should enable Advanced Data Protection (Mistral, Frankfurt). The full TIA is available on request.

When Advanced Data Protection Mode is ON, core data processing (database and AI) occurs within the EU. Email communications to US-based providers still occur with Standard Contractual Clauses in place.

When ADP is OFF (any plan):

  • AI requests are served within the non-ADP envelope. For paid plans (Plus and above) in the Fast and Think chat modes and the Beyond assistant, the current default is xAI (Grok) via OpenRouter's "xAI (ZDR)" endpoint (US), with Anthropic Claude as the automatic failover; in any chat mode a non-ADP paid request may be served by Anthropic Claude (US) or any of the eight OpenRouter-allowlisted providers (including xAI, US-default for some and multi-region for others; the Essential-plan subset is restricted to Google Vertex and Cerebras), and ISMS Copilot may move any cohort or mode between these destinations over time (a control-neutral move within the disclosed envelope under DPA §2.4, publication-only), with Mistral (EU) as the circuit-breaker failover destination. Which provider serves a given request may vary by plan, rollout, and over time; based on their published deployment documentation, none was found to operate PRC or Hong Kong infrastructure, and PRC-jurisdiction providers are blocked at the OpenRouter account level. Transfer mechanisms: Anthropic-served traffic relies on its own SCCs; for the OpenRouter allowlist the SCCs operate at the underlying-provider layer through the OpenRouter aggregator (OpenRouter-intermediated), not direct SCCs we sign with each underlying host, and Google Vertex additionally holds EU-US Data Privacy Framework certification, which is an Article 45 adequacy mechanism, distinct from the Article 46 Standard Contractual Clauses; for OpenRouter-served traffic, the account-level controls (mandatory ZDR, training-disallowed, allowlist, PRC-blocklist) act as Schrems II-style supplementary measures. Anthropic-served traffic follows the retention shown in the AI Processing table above; OpenRouter-served traffic is zero-retention (no persistent retention beyond serving the request; transient in-memory caching only). The DPA §3.1 has the complete per-provider deployment-region detail and the OpenRouter region-pinning gap explanation. Customers needing contractual EU-only data residency for AI processing should enable Advanced Data Protection Mode (Mistral, EU), which bypasses this envelope entirely.

Email transfers (SendGrid, Kit) to the US occur regardless of ADP, protected by SCCs.

EU-Only Processing Options:

  • Enable Advanced Data Protection Mode for EU-only AI processing
  • Unsubscribe from non-essential emails to minimize US transfers
  • Database storage always remains in the EU regardless of configuration

Data Retention

User-Controlled Retention

You control how long your data is retained:

  • Conversation history: 1 day to 7 years, or keep forever (configurable in Settings)
  • Uploaded documents: Linked to conversation retention settings
  • Automated deletion: Daily process removes expired data
  • Active accounts: Retained while account is active
  • Session tokens: Expire after inactivity period
  • Temporary chats: Automatically deleted after 30 days
  • Free-trial eligibility marker: If you start an app-managed free trial of a paid plan, we record that your account has used a trial (and the trial's end date). We keep this marker for the life of the account to prevent repeated free-trial abuse. Our legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in offering a one-time trial fairly; it is not treated as billing data, and it is deleted when your account is deleted (see After Account Deletion).

After Account Deletion

  • Personal data: Permanently deleted within 30 days
  • Billing records: Anonymized and retained for 7 years (legal requirement for tax compliance)
  • Backup data: Overwritten within 90 days

Analytics and Logs

  • PostHog analytics: Up to 7 years (anonymized)
  • Sentry error logs: 90 days
  • Access logs: 30-90 days per infrastructure provider policies

Moderation Retention

  • Non-flagged messages: No moderation record stored.
  • Flagged messages: Metadata only (message ID, thread ID, abuse categories, timestamp — no message content) retained for up to 12 months, then automatically purged.

Data Security

Technical Security Measures

  • Encryption in transit: TLS 1.3 for all connections
  • Encryption at rest: Database and file storage encryption
  • Password security: Industry-standard hashing (irreversible)
  • Access control: Row-level security prevents unauthorized data access
  • Session management: Automatic timeout controls

Organizational Security Measures

  • Workspace isolation: Separate data for different projects/clients
  • User authentication: Required for all protected resources
  • MFA support: Multi-factor authentication available
  • Monitoring: Continuous error and security monitoring via Sentry
  • Incident response: 24-hour breach assessment and notification procedures

Data Minimization

  • Only essential data collected (email, messages, files)
  • No unnecessary demographic or contact information
  • Analytics configured to exclude PII
  • User-controlled retention periods

For detailed security documentation, visit our Trust Center or review our Register of Processing Activities (RoPA) for the per-activity Article 30 processing inventory.

Your Privacy Rights

Right to Access (Article 15 GDPR)

You have the right to access all personal data we hold about you.

How to exercise:

  • Log in to view conversations and files through the platform interface
  • For a complete data export, use the in-app data export tool in Settings → Data Protection (available to all plans)
  • We provide your data in JSON format (typically within 72 hours)

Right to Rectification (Article 16 GDPR)

You can update or correct your personal information.

How to exercise:

  • Update account settings through the Settings dialog (accessible via user menu)
  • For email address changes, contact privacy@ismscopilot.com
  • Changes are applied immediately for self-service updates

Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)

You can request complete deletion of your account and data.

How to exercise:

  • Use the in-app account deletion in Settings → Data Protection (self-service, available to all plans)
  • For deletion of specific content within a flagged thread (see "Content Moderation" above), email privacy@ismscopilot.com — we evaluate each request against the legitimate-interest balancing test under Article 17(3) and respond within 30 days
  • All data is permanently deleted within 30 days

Account deletion is permanent and cannot be undone. All workspaces, conversations, and uploaded files will be permanently erased. Export any needed data before requesting deletion.

Right to Data Portability (Article 20 GDPR)

You can receive your data in a structured, machine-readable format.

How to exercise:

  • Use the in-app data export tool in Settings → Data Protection
  • Export is provided in JSON format
  • Export includes account information, conversations, and file metadata

Right to Restrict Processing (Article 18 GDPR)

You can request temporary suspension of data processing.

How to exercise: Email privacy@ismscopilot.com explaining the reason for restriction. We will respond within 30 days.

Right to Object (Article 21 GDPR)

You can object to certain types of data processing.

How to exercise: Email privacy@ismscopilot.com specifying what processing you object to. We will review and respond within 30 days.

Where processing is based on your consent (such as marketing product-update newsletters), you may withdraw consent at any time by clicking unsubscribe in any email or adjusting preferences in Settings. Withdrawal does not affect processing that occurred before withdrawal.

Right to Lodge a Complaint

You have the right to file a complaint with a supervisory authority:

Commission Nationale de l'Informatique et des Libertés (CNIL)

  • Website: https://www.cnil.fr/en
  • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Phone: +33 1 53 73 22 22

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional privacy rights.

Information We Collect (CCPA Categories)

In the past 12 months, we have collected the following categories of personal information from California residents:

  • Identifiers: Email addresses, account IDs, IP addresses (anonymized)
  • Commercial information: Subscription records, payment history, billing information
  • Internet or network activity: Usage data, session logs, feature interactions, error logs
  • Professional information: Compliance-related content you input (policies, audit data, risk assessments)
  • Inferences: Usage patterns derived from analytics (anonymized)

We do not collect sensitive personal information as defined by CCPA (e.g., Social Security numbers, driver's license numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, or union membership).

Business Purposes for Collection

We collect and use personal information for the following business purposes:

  • Providing the ISMS Copilot platform and AI compliance assistance
  • Processing payments and managing subscriptions
  • Authenticating and securing your account
  • Improving service quality and developing new features
  • Detecting and preventing fraud, security incidents, and abuse
  • Debugging and error tracking
  • Complying with legal obligations

Disclosure of Personal Information

We share personal information with the following categories of third parties for business purposes (AI routing follows the single non-ADP envelope described under "AI Processing" above; current routing and the available provider subset may differ by plan and ADP setting, see the full matrix):

  • Cloud service providers: Supabase, AWS (database and storage)
  • AI service providers: Anthropic (any non-ADP plan; the paid Fast/Think/Beyond failover), OpenRouter aggregator (any non-ADP plan, routing to one of the eight allowlisted underlying providers: Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius, and xAI via the "xAI (ZDR)" endpoint - xAI is the paid Fast/Think/Beyond default; the Essential subset is restricted to Google Vertex and Cerebras; see the "AI Processing" matrix above for the full posture per provider), or Mistral AI (ADP)
  • Payment processors: Stripe (payment processing)
  • Analytics providers: PostHog, Sentry, Vercel
  • Email service providers: SendGrid, Kit
  • Document processors: ConvertAPI, Fly.io

No Sale or Sharing: ISMS Copilot does not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

Your California Privacy Rights

Right to Know

You have the right to request that we disclose:

  • Categories of personal information we've collected about you
  • Categories of sources from which the information was collected
  • Business or commercial purpose for collecting the information
  • Categories of third parties with whom we share personal information
  • Specific pieces of personal information we've collected about you

Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations to retain billing records, moderation metadata for flagged content per our Acceptable Use Policy).

Right to Correct

You have the right to request correction of inaccurate personal information we maintain about you.

Right to Opt-Out

You have the right to opt out of:

  • Sale of personal information: Not applicable (we don't sell personal information)
  • Sharing for cross-context behavioral advertising: Not applicable (we don't engage in this practice)

Right to Limit Use of Sensitive Personal Information

Not applicable — we do not collect or use sensitive personal information as defined by CCPA.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights.

How to Exercise Your California Rights

Submit a request: Email privacy@ismscopilot.com with "CCPA Request" in the subject line. Specify which right you're exercising (Know, Delete, Correct).

Verification process: We will verify your identity by confirming your registered email address. For sensitive requests, we may require additional verification. You may designate an authorized agent to make requests on your behalf (we will require written authorization).

Response timeline:

  • Acknowledgment within 10 business days
  • Response within 45 days (may extend up to 90 days for complex requests)

California "Shine the Light" Law

Under California Civil Code Section 1798.83, California residents may request information about our disclosure of personal information to third parties for direct marketing purposes. ISMS Copilot does not disclose personal information to third parties for their direct marketing purposes.

Automated Processing

ISMS Copilot uses AI to assist with compliance content generation, but does not make automated decisions that produce legal effects or similarly significantly affect you under GDPR Article 22. All compliance decisions remain under your control. Content moderation flags are reviewed by humans before any account action is taken.

Cookies and Tracking

Essential Cookies

We use strictly necessary cookies for:

  • User authentication and session management
  • Security and fraud prevention
  • Platform functionality

Analytics Cookies

With your consent, we use analytics cookies to:

  • Understand platform usage patterns
  • Improve user experience
  • Monitor performance

We do not use advertising or marketing cookies. All analytics are configured to exclude personally identifiable information.

Privacy-First Analytics: PostHog operates in cookieless mode with in-memory persistence only. No cookies or browser storage are written to your device. Anonymous usage is tracked via privacy-preserving server-side hashing, and user profiles are created only for authenticated sessions.

Children's Privacy

ISMS Copilot is not intended for individuals under 16 years of age:

  • Our service is designed for compliance professionals and businesses
  • We do not knowingly collect data from children
  • If we discover underage use, we will terminate the account and delete the data

User Responsibilities

While ISMS Copilot provides GDPR-compliant infrastructure, you (as data controller for your own processing) are responsible for ensuring your use of the platform complies with applicable regulations.

You are responsible for:

  • Ensuring legal basis exists before uploading personal data
  • Configuring appropriate data retention periods for your organization
  • Maintaining separate workspaces for different clients or data categories
  • Informing individuals when their data is processed through ISMS Copilot
  • Including ISMS Copilot in your own data processing records
  • Conducting Data Protection Impact Assessments (DPIA) when processing high-risk data
  • Enabling Advanced Data Protection Mode before processing special category data (Article 9 GDPR) or criminal-offence data (Article 10 GDPR) with AI features, since such data is excluded from the default (non-ADP) AI routing path

Changes to This Privacy Policy

How We Notify You

When we update this Privacy Policy, we will:

  • Send email notification to your registered email address
  • Display in-app notification upon next login
  • Update the "Effective Date" at the top of this policy
  • Provide at least 30 days notice for material changes

Your Options

If you don't agree with changes:

  • Enable Advanced Data Protection Mode to keep AI processing within the EU regardless of routing changes
  • Request account deletion (self-service in Settings → Data Protection) before changes take effect
  • Export your data before the effective date
  • Email privacy@ismscopilot.com to discuss concerns or to formally object under your DPA where applicable

Contact Us

For privacy questions or rights requests, email privacy@ismscopilot.com. Include "Privacy Request" or "GDPR Request" in the subject for priority handling.

Response Times:

  • Acknowledgment: Within 24-48 hours
  • Full response: Within 30 days (typically within 72 hours)