Privacy Policy
Effective date: [EFFECTIVE DATE] · Last updated: [DATE]
[PLACEHOLDERS] must be completed. Do not rely on this document
until this notice is removed.
1. Scope
This Privacy Policy explains how [LEGAL ENTITY NAME] ("we", "us") collects, uses, and protects information in connection with the xcube platform and APIs (the "Service"). It supplements, and is incorporated into, our Terms of Service.
2. Information We Process
- Account information — name, email, and organization membership, provided via our authentication provider when you sign up or are invited.
- Customer Data — the messages, documents, and knowledge bases you submit to the Service, and embeddings/derived indexes created to provide retrieval features.
- Usage and operational data — request metadata, model and token usage, billing measurements, IP address, and logs used to operate, secure, meter, and improve the Service.
3. How We Use Information
We process information to provide the Service (including chat and retrieval over your knowledge bases), to authenticate users, to meter and bill usage, to enforce limits and prevent abuse, to maintain security, and to comply with law. We do not sell your personal information.
4. Tenant Isolation
Customer Data is segregated per organization. Access controls and row-level security are used so that one organization's data is not exposed to another.
5. Model Processing & Subprocessors
To generate responses and embeddings, prompts and relevant context are sent to model providers and infrastructure subprocessors that operate on our behalf. [LIST OF SUBPROCESSORS / MODEL PROVIDERS AND REGIONS — to be completed.] For on-premise deployments, processing occurs within the customer's environment as configured.
6. Data Retention
Customer Data is retained while your account is active and as needed to provide the Service. Conversation-scoped uploads may be deleted when the associated conversation is deleted. [SPECIFIC RETENTION PERIODS AND DELETION SLAs — to be completed.]
7. Security
We use technical and organizational measures including encryption in transit, access controls, tenant isolation, and secret encryption at rest for integration credentials. No method of transmission or storage is perfectly secure.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. [HOW TO EXERCISE RIGHTS / DPO CONTACT / LEGAL BASES (e.g. GDPR) — to be completed.]
9. International Transfers
[CROSS-BORDER TRANSFER MECHANISMS, IF APPLICABLE — to be completed.]
10. Changes
We may update this Policy; material changes will be communicated through the Service or by other reasonable means.
11. Contact
Privacy questions: [PRIVACY CONTACT EMAIL].