Privacy Policy

Last updated: July 24, 2026

1. Introduction

Pretorin ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our compliance automation platform.

By using Pretorin, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and password when you create an account
  • Organization Information: Company name, industry, size, and compliance goals
  • Compliance Data: Documents, evidence, and control implementations you upload or create
  • Communications: Messages you send to us for support or feedback

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on the platform, and interaction patterns
  • Device Information: Browser type, operating system, device type, and screen resolution
  • Log Data: IP address, access times, and referring URLs
  • Cookies: Session cookies for authentication and preferences

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process your compliance documentation and assessments
  • Personalize your experience and provide relevant recommendations
  • Analyze usage patterns to improve platform functionality
  • Communicate with you about updates, security alerts, and support
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information only in the following circumstances:

  • Service Providers: With trusted third parties who assist in operating our platform (hosting, analytics, support)
  • AI Model Providers: With the third-party model providers that power our AI features, as described in Section 6. You can disable this processing entirely — see Section 6.6
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly authorize us to share information

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication (MFA) for account access
  • Regular security audits and penetration testing
  • Access controls and audit logging
  • Secure data centers with SOC 2 compliance

While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

6. AI Processing of Your Data

Our platform uses artificial intelligence to help you draft and analyze compliance documentation. This section explains what that means for your data and how to turn it off. Section 19 of our Terms of Service covers the same ground in contractual terms.

6.1 What AI Processes

When you use an AI feature, the data relevant to that request is sent to a model provider to generate a response. Depending on the feature, that can include control requirement text and your implementation narratives, uploaded documents and evidence text, questionnaire and scoping answers, risk and vendor assessment data, and the messages you type into the AI assistant. AI features cover narrative and policy drafting, gap and posture analysis, evidence-to-control mapping, audit procedure suggestions, risk summarization, vendor scoring, accessibility conformance assessment, and semantic search over your own documents.

6.2 Third-Party Model Providers

AI processing is performed by third-party hosted model providers acting as our subprocessors. Currently these are OpenAI as the primary provider and Microsoft Azure OpenAI as a failover provider. A reserved open-weight tier reached through OpenRouter may be used for batch policy-document generation only; because that route reaches third-party-hosted model weights, we treat it as third-party data egress and hold it in reserve.

6.3 We Do Not Train Models on Your Data

We perform no model training or fine-tuning on your data. We operate no training pipelines, no training datasets, and no model checkpoints. Your data is used only to produce a response to a specific request you initiate. Our providers do not use content submitted through their APIs to train or improve their models under the terms applicable to our accounts.

On every request we instruct the provider not to store the request or response in provider-side application state. You should be aware that our primary provider may nonetheless retain request content transiently for abuse and misuse monitoring, currently for up to thirty (30) days, unless a zero-retention arrangement is separately approved and enabled for our account. We do not currently represent that a formal Zero Data Retention arrangement is in place. If your regulatory obligations require zero provider-side retention, contact us before submitting regulated content.

6.4 How Long AI-Related Data Is Kept

Retention differs by category, and these periods override the general retention statement in Section 7:

  • Prompt content and model output: transient. Not persisted in our application state, subject to the provider abuse-monitoring caveat above.
  • AI run audit metadata: retained on a rolling twelve (12) month target. This record holds the model and version, a prompt identifier, cryptographic (SHA-256) hashes of the input and output rather than the underlying text, the reported confidence value, the tool-call trace, and the chain of any human overrides.
  • Semantic search embeddings: retained for the life of your account or the life of the source record, and deleted when you delete the source document or evidence item, or when your organization is deleted.

6.5 Isolation Between Customers

Every AI request, retrieval operation, and audit record is scoped to a single organization. We do not share AI context, prompts, or embeddings across customers, and no customer's data is used to produce another customer's output.

6.6 Your Choices — Opting Out of AI

You can disable AI processing for your whole organization. Two channels are available:

  • Self-service setting: an organization owner or administrator can turn off AI feature processing under Settings → AI Feature Processing.
  • Written request: email [email protected] or use the contact form.

While your organization is opted out, no AI feature will send your data to a model provider, and the AI features described in Section 6.1 are unavailable to everyone in your organization. Non-AI functionality is unaffected. We give effect to a validated request within five (5) business days; the self-service setting normally takes effect within minutes. Every change is recorded in an immutable audit log. Opting out carries no penalty, price change, or loss of non-AI functionality, and you can re-enable AI at any time.

Short of opting out entirely, an owner or administrator can also choose which approved model backs your AI features under Settings → AI Models.

6.7 Human Review

No AI output is automatically applied to a compliance record. Every AI-produced artifact is created as a draft that someone in your organization must review and explicitly accept before it becomes part of your records, and that acceptance is captured in the audit log. Low-confidence outputs are additionally flagged and held back from streamlined approval and export.

6.8 Changes and Accountability

Our privacy lead, accountable to our chief executive, owns these AI disclosures and keeps them consistent across this policy and our Terms of Service. We review them before any release that changes how AI processes your data, and at least annually. Where a change is material to you, we will notify impacted customers at least thirty (30) days before it takes effect where feasible.

7. Data Retention

We retain your information for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time. Some information may be retained for legal, regulatory, or legitimate business purposes. AI-related data follows the more specific periods in Section 6.4.

8. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to certain processing activities
  • Withdraw Consent: Withdraw consent where processing is based on consent

8.1 How to Submit a Request

To exercise any of these rights, email us at [email protected] or use the contact form on our website. If you already have a Pretorin account, you can exercise the rights of access, portability, and erasure yourself at any time under Settings → Privacy & Data, where a data export is returned immediately and an account deletion can be requested directly.

We verify your identity before acting on a request, so that we do not disclose your personal data to someone else. Where we cannot verify a request, we will tell you in writing rather than leave the request unanswered.

8.2 Our Response Timeline and Format

  • Acknowledgement: we confirm receipt of your request in writing within 10 business days.
  • Substantive response: within 30 calendar days for requests under the GDPR or UK GDPR, and within 45 calendar days for requests under the CCPA or CPRA. Where no specific statutory deadline applies, we use 30 calendar days as our default.
  • When the clock starts: the response period begins on the date we receive a verifiable request — that is, when we have confirmed your identity, not the date of your first message.
  • Extensions: where the law permits and your request is complex, we may extend by a further 60 calendar days under the GDPR, or a further 45 calendar days under the CCPA. We will notify you in writing, with the reason, within the original response period.
  • How we respond: in writing by email, sent from [email protected] to the verified email address we hold for you. If your request reached us by post and we have no email address for you, we respond by post.
  • Format of the data: personal data provided in response to an access request is supplied in a commonly used electronic format. Data provided to satisfy the right to portability is delivered as structured, machine-readable JSON.
  • If we decline: where we deny a request in whole or in part, we tell you the specific basis for the denial and how to appeal or complain.

9. Cookies and Tracking

We use essential cookies for authentication and session management. We also use analytics tools to understand how users interact with our platform. You can control cookie preferences through your browser settings.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

11. Children's Privacy

Pretorin is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of Pretorin after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us through the contact form on our main website at www.pretorin.com.

For privacy requests specifically — including the rights described in Section 8 — email [email protected], which is monitored by our Privacy Lead.