Last updated: July 24, 2026
Pretorin ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our compliance automation platform.
By using Pretorin, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
We use the information we collect to:
We do not sell your personal information. We may share your information only in the following circumstances:
We implement industry-standard security measures to protect your data:
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
Our platform uses artificial intelligence to help you draft and analyze compliance documentation. This section explains what that means for your data and how to turn it off. Section 19 of our Terms of Service covers the same ground in contractual terms.
When you use an AI feature, the data relevant to that request is sent to a model provider to generate a response. Depending on the feature, that can include control requirement text and your implementation narratives, uploaded documents and evidence text, questionnaire and scoping answers, risk and vendor assessment data, and the messages you type into the AI assistant. AI features cover narrative and policy drafting, gap and posture analysis, evidence-to-control mapping, audit procedure suggestions, risk summarization, vendor scoring, accessibility conformance assessment, and semantic search over your own documents.
AI processing is performed by third-party hosted model providers acting as our subprocessors. Currently these are OpenAI as the primary provider and Microsoft Azure OpenAI as a failover provider. A reserved open-weight tier reached through OpenRouter may be used for batch policy-document generation only; because that route reaches third-party-hosted model weights, we treat it as third-party data egress and hold it in reserve.
We perform no model training or fine-tuning on your data. We operate no training pipelines, no training datasets, and no model checkpoints. Your data is used only to produce a response to a specific request you initiate. Our providers do not use content submitted through their APIs to train or improve their models under the terms applicable to our accounts.
On every request we instruct the provider not to store the request or response in provider-side application state. You should be aware that our primary provider may nonetheless retain request content transiently for abuse and misuse monitoring, currently for up to thirty (30) days, unless a zero-retention arrangement is separately approved and enabled for our account. We do not currently represent that a formal Zero Data Retention arrangement is in place. If your regulatory obligations require zero provider-side retention, contact us before submitting regulated content.
Retention differs by category, and these periods override the general retention statement in Section 7:
Every AI request, retrieval operation, and audit record is scoped to a single organization. We do not share AI context, prompts, or embeddings across customers, and no customer's data is used to produce another customer's output.
You can disable AI processing for your whole organization. Two channels are available:
While your organization is opted out, no AI feature will send your data to a model provider, and the AI features described in Section 6.1 are unavailable to everyone in your organization. Non-AI functionality is unaffected. We give effect to a validated request within five (5) business days; the self-service setting normally takes effect within minutes. Every change is recorded in an immutable audit log. Opting out carries no penalty, price change, or loss of non-AI functionality, and you can re-enable AI at any time.
Short of opting out entirely, an owner or administrator can also choose which approved model backs your AI features under Settings → AI Models.
No AI output is automatically applied to a compliance record. Every AI-produced artifact is created as a draft that someone in your organization must review and explicitly accept before it becomes part of your records, and that acceptance is captured in the audit log. Low-confidence outputs are additionally flagged and held back from streamlined approval and export.
Our privacy lead, accountable to our chief executive, owns these AI disclosures and keeps them consistent across this policy and our Terms of Service. We review them before any release that changes how AI processes your data, and at least annually. Where a change is material to you, we will notify impacted customers at least thirty (30) days before it takes effect where feasible.
We retain your information for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time. Some information may be retained for legal, regulatory, or legitimate business purposes. AI-related data follows the more specific periods in Section 6.4.
Depending on your location, you may have the following rights:
To exercise any of these rights, email us at [email protected] or use the contact form on our website. If you already have a Pretorin account, you can exercise the rights of access, portability, and erasure yourself at any time under Settings → Privacy & Data, where a data export is returned immediately and an account deletion can be requested directly.
We verify your identity before acting on a request, so that we do not disclose your personal data to someone else. Where we cannot verify a request, we will tell you in writing rather than leave the request unanswered.
We use essential cookies for authentication and session management. We also use analytics tools to understand how users interact with our platform. You can control cookie preferences through your browser settings.
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
Pretorin is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of Pretorin after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact us through the contact form on our main website at www.pretorin.com.
For privacy requests specifically — including the rights described in Section 8 — email [email protected], which is monitored by our Privacy Lead.