Scope
This policy applies to the NCASEAI website, accounts, workspaces, uploaded materials, generated reports, support interactions, and related product services. It does not govern third-party websites or services that publish their own policies.
Information We Collect
We collect information provided directly by users, generated through product use, and received from configured service providers.
- Account information such as name, email address, authentication identifiers, organization, role, and preferences.
- Workspace information such as research briefs, company names, market questions, configuration choices, comments, approvals, and collaboration records.
- Uploaded business information such as documents, URLs, notes, source material, and files selected for analysis.
- Generated reports, report sections, citations, revisions, exports, AI prompts, AI responses, and related job records.
- Technical and usage information such as device and browser details, IP-derived security logs, route activity, timestamps, errors, and product events.
- Support and contact information submitted through forms, email, meetings, or procurement discussions.
Cookies and Local Storage
NCASEAI uses essential cookies and browser storage for authentication, security, language, theme, session continuity, and product preferences. Analytics may be used to understand route usage and product reliability. A separate consent mechanism should be added before optional cookies or non-essential tracking are introduced where required by law.
How We Use Information
Information is used to provide and secure accounts, process requested research, generate and edit reports, operate collaboration and export features, monitor reliability, respond to support, prevent misuse, and improve the service. We do not use customer workspace content for unrelated advertising.
AI and Research Providers
Requested workflows may send relevant instructions, source excerpts, and report context to configured AI, retrieval, parsing, hosting, database, email, analytics, monitoring, or integration providers. The exact provider set depends on production configuration. Provider contracts, data-use settings, locations, and retention must be reviewed before sensitive or regulated information is processed.
Data Storage and Security
Production data is intended to be stored with access controls scoped to authenticated organizations. Credentials and provider keys are kept on the server. Security measures reduce risk but no online service can guarantee absolute security. See the Security page for current technical practices and limitations.
Retention
Account, workspace, report, source, operational, and backup data is retained only for the period needed to provide the service, meet contractual or legal duties, resolve disputes, protect security, and maintain legitimate business records. Final category-specific retention periods must be documented by [LEGAL COMPANY NAME] before public launch.
Sharing and International Processing
Information may be shared with authorized workspace members, service providers acting for NCASEAI, integration destinations configured by the user, professional advisers, authorities when legally required, or a successor in a permitted business transaction. Providers may process information outside the user’s country. Appropriate contractual and transfer safeguards should be documented for the final provider architecture.
User Rights and Choices
Depending on applicable law, users may have rights to access, correct, delete, restrict, object to, or export personal information and to withdraw consent where consent is the legal basis. Requests can be sent to [PRIVACY EMAIL]. Identity and authority may need to be verified before a request is completed.
Data Deletion
Users may request account or workspace deletion through [PRIVACY EMAIL] until an in-product deletion workflow is available. Some records may be retained where required for security, legal obligations, fraud prevention, dispute resolution, or backups that expire on a defined schedule.
Children’s Privacy
NCASEAI is a business service and is not directed to children. Accounts must not be created by anyone below the minimum age required to enter a binding contract in their jurisdiction. If child information is discovered, contact [PRIVACY EMAIL] so it can be reviewed and removed where appropriate.
Policy Updates
Material changes will be published on this page with a revised effective date. Additional notice may be provided through the product or account email where required. Continued use after an effective update is governed by applicable law and the notice provided.
Contact
Privacy questions and rights requests should be sent to [PRIVACY EMAIL] for [LEGAL COMPANY NAME], [REGISTERED ADDRESS].
