Legal
Privacy Policy
Last updated 31 August 2026
This policy explains what data we collect, why we collect it, and the controls available to you. It covers the website, the platform and our professional services.
Data we collect
Account data such as name, email address, job title and organisation details. Workspace data such as domains, prompts, competitors, crawl records and reports. Enquiry data submitted through demo, contact and services forms.
Usage data including feature events used to operate the service, enforce plan limits and improve the product. We do not build advertising profiles from product events.
How we use data
To provide the platform, run crawls and analyses you request, enforce plan limits, deliver reports and notifications, provide support, and communicate about your account or trial.
To process and respond to enquiries submitted through the website, including routing them to the correct team within our organisation.
Lawful bases
Where European data protection law applies, we rely on performance of the contract with your organisation, legitimate interests in operating and improving the service, and consent where we ask for it explicitly.
Consent can be withdrawn at any time through the controls described in this policy.
Data separation
Organisation data is isolated at the database level using row level security. Members can only access records belonging to organisations where they are authorised.
Demonstration data is never mixed with your organisation's records, and every metric is labelled with its source so a report can never overstate what is connected.
Processors
We use infrastructure, payment and email providers to operate the service. Provider API keys and secrets are held server-side only and are never exposed to the browser.
We select processors that provide appropriate safeguards for the data they handle and we share only the minimum data each processor needs.
International transfers
Data may be processed in regions where our infrastructure providers operate. Where required, transfers are made under appropriate safeguards, including standard contractual clauses.
Security
Access is protected by authentication and server-side authorisation on every privileged action. Secrets never reach the browser, and organisation boundaries are enforced by database policies rather than interface logic.
Retention
Workspace data is retained while your organisation is active, including after a trial expires, so that it remains available if you subscribe.
You may request deletion of an organisation and its data from organisation settings, and we honour deletion requests within the period required by applicable law.
Your rights
Depending on your jurisdiction you may request access, correction, export or deletion of personal data, object to or restrict processing, and lodge a complaint with a supervisory authority.
Contact us at privacy@authorityos.com and we will respond within the period required by applicable law.
Children
The platform is intended for professional use by organisations. We do not knowingly collect personal data from children, and we will delete any such data brought to our attention.
Changes to this policy
We will update this policy as the product and legal requirements evolve. Material changes will be communicated through the platform or by email before they take effect.
This document is a plain-language summary prepared for the platform and is not legal advice. Have your counsel review it before commercial launch.
