Skip to content

Legal

Privacy Policy

What we collect, why we have it, who else touches it, and how you get it back or removed. Written to be read, not to be survived.

Effective January 15, 2026 · Version 3.0

The short version

  • Your company owns the content it connects. We process it on their instructions, not for our own purposes.
  • We do not train shared models on your content, and we do not sell personal information.
  • Retrieval respects the permissions of the person asking, so the model never sees more than they could.
  • Data lives in the region chosen for your deployment, and can stay inside your own cloud subscription.
  • You can ask what we hold, correct it, or have it deleted - and we will say plainly what we cannot delete and why.

The summary is a courtesy; the sections below are the document.

01Scope and our two roles

This policy explains how Bhogar handles personal information across our public website, our platform, and the support we provide around them. It applies to visitors to this site, to individuals whose companies use the platform, and to people who contact us.

We act in two distinct roles, and the difference matters for your rights and for who you should contact.

Controller - our own business data
For website analytics, marketing enquiries, account registration, billing, and support correspondence, we decide how the information is used. This policy governs that processing.
Processor - your company’s content
For the content your company connects to the platform and the conversations, documents, and workflow records created inside it, your company is the controller. We process it on their instructions under our Data Processing Agreement. If you are an employee or customer of a Bhogar customer, direct data requests to that company first.

02Information we collect

Account information
Name, work email, company, role, and authentication identifiers. Where your company uses single sign-on, we receive the identity attributes released by your identity provider rather than a password.
Enquiry information
What you send through our contact form or by email: name, work email, company, and your message. We use it to reply and to keep a record of the conversation.
Usage and diagnostic data
Which features are used, request timing, error traces, and coarse device and browser information. This is how we keep the platform reliable and find defects.
Billing information
Plan, entitlements, and invoicing details. Card data is handled by our payment processor; we do not store full card numbers.
Customer content
Documents, records, messages, and other material your company connects or creates in the platform, plus derived material such as embeddings and execution history. We process this as a processor, not for our own purposes.
Website data
Pages visited, referrer, and approximate location derived from IP address. Analytics that are not strictly necessary are governed by our cookie policy and your consent choices.

03How we use information

  • Providing the platform: authenticating users, enforcing role and workspace permissions, running agents and workflows your company has configured, and retrieving the content a user is entitled to see.
  • Reliability and security: monitoring, incident investigation, abuse and fraud prevention, and rate limiting.
  • Support: answering questions and reproducing defects, using the minimum access required.
  • Billing and administration: invoicing, entitlement management, and account records.
  • Product improvement: aggregated and de-identified usage patterns that tell us which features are working. This never involves training shared models on your content.
  • Communication: responding to enquiries and, where permitted, sending product updates you can unsubscribe from at any time.

Where the GDPR applies, we rely on contract performance for providing the platform, legitimate interests for security and product improvement, consent for non-essential cookies and marketing email, and legal obligation for records we are required to keep.

04AI processing, model providers, and training

The platform sends relevant context to a language model to produce an answer or to run an agent action. Three commitments govern that process.

  • Retrieval is filtered by tenant and by the permissions of the requesting user before anything reaches a model, so a model is not given context the user could not open themselves.
  • We do not use customer content to train shared or foundation models, and we do not sell it.
  • Your company chooses the model providers. When it configures its own provider credentials - for example Azure OpenAI, OpenAI, Anthropic, Google, or Amazon Bedrock - inference is governed by the agreement your company holds with that provider.

Where the platform default provider is used instead, we contract for enterprise data handling terms that exclude training on submitted content. The current provider list is published with our Data Processing Agreement.

05When we share information

We share personal information only in the following circumstances.

  • Service providers and subprocessors that host, secure, or support the platform, under written terms that limit them to our instructions. Categories and roles are listed in the DPA.
  • Model providers, to produce the response or action a user requested, as described above.
  • Your own company: administrators can see workspace membership, audit history, and usage attributable to their tenant.
  • Professional advisers, auditors, or acquirers in a corporate transaction, under confidentiality obligations.
  • Authorities, where we are legally compelled. We assess each request, push back on overbroad demands, and notify the affected customer unless prohibited from doing so.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

06International transfers and data location

Platform data is stored in the cloud region selected for your deployment. Where personal information moves across borders - for example when a support engineer in another country assists with an incident - we rely on the European Commission’s Standard Contractual Clauses or another approved transfer mechanism, together with technical measures such as encryption and access logging.

Companies with strict residency requirements can run the platform in their own cloud subscription so that content and model traffic remain inside their boundary.

07Retention

Default retention. Customer-configurable periods override these.
CategoryRetention
Account and workspace recordsFor the life of the account, then deleted or anonymised after termination
Customer content and indexesWhile the source is connected; removed on disconnect, deletion request, or account termination
Conversation and execution historyPer your company’s configured policy
Diagnostic logs and telemetryTime-bounded by the telemetry configuration for your deployment
Enquiry correspondenceKept while it is useful for the relationship, then deleted on request
Billing recordsAs long as tax and accounting law requires

Backups age out on their own cycle, so deletion propagates through them rather than instantly.

08How we protect information

  • Encryption in transit and at rest using managed cloud key infrastructure.
  • Tenant scoping enforced server-side on every request, including vector search.
  • Role-based access and module entitlements, with multi-factor authentication available including WebAuthn.
  • Secrets held in a managed vault and referenced by identifier, never embedded in configuration or prompts.
  • Audit and execution history that records what ran, on whose behalf, and under which policy.
  • Least-privilege internal access, reviewed periodically, with administrative actions logged.

Our trust centre describes the control model in more detail, including tenant isolation and deployment options.

09Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to processing based on legitimate interests, and to withdraw consent.

  • For information we hold as controller - your account, enquiries, billing - email us and we will respond within the period required by applicable law, and within 30 days where the GDPR applies.
  • For content held inside a customer tenant, contact that company. If a request reaches us first, we forward it and assist the customer in responding.
  • You can unsubscribe from marketing email using the link in any message, and manage non-essential cookies through our cookie settings.
  • If we cannot resolve a concern, you may complain to your local supervisory authority.

We do not charge for these requests, and exercising them does not affect your service.

10Automated processing

The platform generates suggestions and can execute workflow steps your company configures. It is designed so that consequential steps can require human approval, and every step is traceable. We do not make decisions about you that produce legal effects without human involvement.

11Children

The platform is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided information to us, contact us and we will delete it.

12Changes to this policy

We update this policy when our practices change. The effective date and version at the top of this document always reflect the current text. For material changes we notify account administrators by email or in-product notice before the change takes effect, and we keep prior versions available on request.

13Contact us

Privacy questions, data subject requests, and requests for our EU representative details go to privacy@bhogar.ai. If you are covered by a customer tenant, your company’s administrator is usually the faster route.

Questions about how we handle your data?

Privacy requests go to privacy@bhogar.ai. For content inside a customer tenant, contact your company administrator first.