Legal
Privacy Policy
What we collect, why we have it, who else touches it, and how you get it back or removed. Written to be read, not to be survived.
Effective January 15, 2026 · Version 3.0
The short version
- Your company owns the content it connects. We process it on their instructions, not for our own purposes.
- We do not train shared models on your content, and we do not sell personal information.
- Retrieval respects the permissions of the person asking, so the model never sees more than they could.
- Data lives in the region chosen for your deployment, and can stay inside your own cloud subscription.
- You can ask what we hold, correct it, or have it deleted - and we will say plainly what we cannot delete and why.
The summary is a courtesy; the sections below are the document.
01Scope and our two roles
This policy explains how Bhogar handles personal information across our public website, our platform, and the support we provide around them. It applies to visitors to this site, to individuals whose companies use the platform, and to people who contact us.
We act in two distinct roles, and the difference matters for your rights and for who you should contact.
- Controller - our own business data
- For website analytics, marketing enquiries, account registration, billing, and support correspondence, we decide how the information is used. This policy governs that processing.
- Processor - your company’s content
- For the content your company connects to the platform and the conversations, documents, and workflow records created inside it, your company is the controller. We process it on their instructions under our Data Processing Agreement. If you are an employee or customer of a Bhogar customer, direct data requests to that company first.
02Information we collect
- Account information
- Name, work email, company, role, and authentication identifiers. Where your company uses single sign-on, we receive the identity attributes released by your identity provider rather than a password.
- Enquiry information
- What you send through our contact form or by email: name, work email, company, and your message. We use it to reply and to keep a record of the conversation.
- Usage and diagnostic data
- Which features are used, request timing, error traces, and coarse device and browser information. This is how we keep the platform reliable and find defects.
- Billing information
- Plan, entitlements, and invoicing details. Card data is handled by our payment processor; we do not store full card numbers.
- Customer content
- Documents, records, messages, and other material your company connects or creates in the platform, plus derived material such as embeddings and execution history. We process this as a processor, not for our own purposes.
- Website data
- Pages visited, referrer, and approximate location derived from IP address. Analytics that are not strictly necessary are governed by our cookie policy and your consent choices.
03How we use information
- Providing the platform: authenticating users, enforcing role and workspace permissions, running agents and workflows your company has configured, and retrieving the content a user is entitled to see.
- Reliability and security: monitoring, incident investigation, abuse and fraud prevention, and rate limiting.
- Support: answering questions and reproducing defects, using the minimum access required.
- Billing and administration: invoicing, entitlement management, and account records.
- Product improvement: aggregated and de-identified usage patterns that tell us which features are working. This never involves training shared models on your content.
- Communication: responding to enquiries and, where permitted, sending product updates you can unsubscribe from at any time.
Where the GDPR applies, we rely on contract performance for providing the platform, legitimate interests for security and product improvement, consent for non-essential cookies and marketing email, and legal obligation for records we are required to keep.
04AI processing, model providers, and training
The platform sends relevant context to a language model to produce an answer or to run an agent action. Three commitments govern that process.
- Retrieval is filtered by tenant and by the permissions of the requesting user before anything reaches a model, so a model is not given context the user could not open themselves.
- We do not use customer content to train shared or foundation models, and we do not sell it.
- Your company chooses the model providers. When it configures its own provider credentials - for example Azure OpenAI, OpenAI, Anthropic, Google, or Amazon Bedrock - inference is governed by the agreement your company holds with that provider.
Where the platform default provider is used instead, we contract for enterprise data handling terms that exclude training on submitted content. The current provider list is published with our Data Processing Agreement.
06International transfers and data location
Platform data is stored in the cloud region selected for your deployment. Where personal information moves across borders - for example when a support engineer in another country assists with an incident - we rely on the European Commission’s Standard Contractual Clauses or another approved transfer mechanism, together with technical measures such as encryption and access logging.
Companies with strict residency requirements can run the platform in their own cloud subscription so that content and model traffic remain inside their boundary.
07Retention
| Category | Retention |
|---|---|
| Account and workspace records | For the life of the account, then deleted or anonymised after termination |
| Customer content and indexes | While the source is connected; removed on disconnect, deletion request, or account termination |
| Conversation and execution history | Per your company’s configured policy |
| Diagnostic logs and telemetry | Time-bounded by the telemetry configuration for your deployment |
| Enquiry correspondence | Kept while it is useful for the relationship, then deleted on request |
| Billing records | As long as tax and accounting law requires |
Backups age out on their own cycle, so deletion propagates through them rather than instantly.
08How we protect information
- Encryption in transit and at rest using managed cloud key infrastructure.
- Tenant scoping enforced server-side on every request, including vector search.
- Role-based access and module entitlements, with multi-factor authentication available including WebAuthn.
- Secrets held in a managed vault and referenced by identifier, never embedded in configuration or prompts.
- Audit and execution history that records what ran, on whose behalf, and under which policy.
- Least-privilege internal access, reviewed periodically, with administrative actions logged.
Our trust centre describes the control model in more detail, including tenant isolation and deployment options.
09Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to processing based on legitimate interests, and to withdraw consent.
- For information we hold as controller - your account, enquiries, billing - email us and we will respond within the period required by applicable law, and within 30 days where the GDPR applies.
- For content held inside a customer tenant, contact that company. If a request reaches us first, we forward it and assist the customer in responding.
- You can unsubscribe from marketing email using the link in any message, and manage non-essential cookies through our cookie settings.
- If we cannot resolve a concern, you may complain to your local supervisory authority.
We do not charge for these requests, and exercising them does not affect your service.
10Automated processing
The platform generates suggestions and can execute workflow steps your company configures. It is designed so that consequential steps can require human approval, and every step is traceable. We do not make decisions about you that produce legal effects without human involvement.
11Children
The platform is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided information to us, contact us and we will delete it.
12Changes to this policy
We update this policy when our practices change. The effective date and version at the top of this document always reflect the current text. For material changes we notify account administrators by email or in-product notice before the change takes effect, and we keep prior versions available on request.
13Contact us
Privacy questions, data subject requests, and requests for our EU representative details go to privacy@bhogar.ai. If you are covered by a customer tenant, your company’s administrator is usually the faster route.
Questions about how we handle your data?
Privacy requests go to privacy@bhogar.ai. For content inside a customer tenant, contact your company administrator first.