AlignyxGhost Core V2
Legal index
Privacy notice

Privacy Policy

Privacy notice covering account data, workspace content, AI processing, deletion, security, subprocessors, and individual rights.

Effective
July 28, 2026
Updated
July 28, 2026
Owner
[Your LLC Legal Name]

Scope and role

This Privacy Policy describes how [Your LLC Legal Name] collects, uses, discloses, retains, and protects information in connection with Ephemeral Workspace™. It is an attorney-review draft and must be conformed to actual providers, data flows, jurisdictions, and customer contracts before launch.

For most customer workspace content, the customer is expected to act as controller or business, and the provider acts as processor or service provider under customer instructions. For account, billing, security, marketing, and service-administration data, the provider may act as an independent controller.

Information collected

We may collect account identifiers, organization membership, authentication metadata, billing status, plan and entitlement metadata, workspace settings, lifecycle policies, support requests, device and browser metadata, security events, audit metadata, payment processor references, and customer-configured content.

Workspace content may include messages, files, whiteboards, meeting notes, document annotations, semantic outputs, decisions, exports, and related metadata. The product architecture is designed to minimize raw-content persistence, but exact retention depends on customer settings, enabled providers, legal holds, backup windows, deletion state, and live infrastructure configuration.

How information is used

Information is used to provide, secure, bill, maintain, improve, debug, support, audit, and administer the Service; enforce policy and capability controls; process AI requests when enabled; verify deletion workflows; prevent abuse; comply with law; and communicate with account administrators.

Security, audit, deletion, evidence, and billing records should be metadata-only where the architecture requires it. They should not contain raw workspace content, prompts, model outputs, payment card numbers, credentials, private keys, or secret values.

AI processing

AI features may send minimized or redacted content to configured AI providers only through server-side controls where implemented. Customers are responsible for confirming that AI processing is appropriate for their content, legal basis, confidentiality commitments, and provider configuration.

Unless a signed agreement says otherwise, AI outputs are not professional advice, legal determinations, compliance certifications, or security certifications.

Sharing and subprocessors

Information may be shared with subprocessors and infrastructure providers that support hosting, authentication, database, storage, payment processing, email, AI processing, malware scanning, KMS/HSM, monitoring, logging, security, support, and deletion verification.

We may also disclose information to comply with law, respond to valid legal process, enforce agreements, protect rights and safety, investigate abuse, complete business transactions, or with customer direction or consent.

Retention and deletion

The Service is designed around configurable retention, expiration, cryptographic destruction, deletion orchestration, verification, and receipt boundaries. Retention periods vary by content type, workspace policy, customer configuration, legal hold, provider behavior, backup window, dispute, security need, and legal obligation.

Some metadata may be retained after content deletion to support billing, security, audit integrity, non-reconstructive deletion evidence, fraud prevention, tax, accounting, dispute, legal, and compliance obligations.

Security

The Service is designed with access controls, tenant isolation, encryption, policy enforcement, audit metadata, rate limiting, malware scanning, secret boundaries, managed-key contracts, and independent verification adapters. No system can be guaranteed perfectly secure.

Security concerns may be sent to security@example.com. Do not include secrets, customer content, private keys, exploit payloads that cause harm, or third-party personal data in unsolicited reports.

Privacy rights

Depending on location and role, individuals may have rights to access, correct, delete, port, restrict, object to, or opt out of certain processing. Many workspace-content requests must be directed to the customer organization that controls the workspace.

Privacy requests may be sent to privacy@example.com. We may need to verify identity, authority, organization membership, and whether the request relates to provider-controlled data or customer-controlled workspace data.

California and U.S. state notices

If applicable, the production policy should identify categories of personal information collected, sources, purposes, categories of recipients, retention criteria, sale/share status, sensitive-information use, and methods for exercising state privacy rights.

This draft does not assume that the provider sells personal information or shares it for cross-context behavioral advertising. If analytics, advertising, or data enrichment tools are added, this notice must be updated before launch.

Regulated data

The Service is not intended for protected health information, consumer health data, children's data, payment card storage, export-controlled technical data, classified information, biometric identification, or other specially regulated data unless the provider has expressly agreed in writing and the required legal, security, and operational controls are active.

No HIPAA Business Associate Agreement, GLBA addendum, FERPA addendum, CJIS terms, government cloud terms, or sector-specific compliance terms are implied by use of the Service.

International transfers

Information may be processed in the United States and other jurisdictions where providers operate. Before launch, counsel should add the appropriate international-transfer language, standard contractual clauses, data transfer impact assessment references, and regional hosting commitments if offered.

Customers are responsible for selecting workspaces, providers, regions, and contractual terms that match their transfer and residency obligations.

Children

The Service is intended for business and professional users and is not directed to children. Users should not submit children's personal information unless expressly authorized by a signed agreement and applicable law.

If we learn that a child has provided personal information outside an approved customer-controlled context, we will take appropriate steps consistent with applicable law.

Changes and contact

This Privacy Policy may be updated as product, providers, law, or business practices change. The effective date is July 28, 2026; the last update is July 28, 2026.

Questions may be sent to privacy@example.com.

These pages are protective attorney-review drafts. They should be reviewed, jurisdiction-adjusted, and approved by counsel before public launch, paid subscriptions, or regulated customer use.