Read me Page help ↗
Free Consultation
Legal

Privacy Policy

1. Who we are

autogovern.io (“autogovern”, “we”, “us”) provides AI governance and risk-management software and advisory services, including this website and the Governance Workbench at autogovern.io/app. The data controller is autogovern.io Governance Systems Inc. [ ● registered address ]. For any privacy question, contact info@autogovern.io.

2. Information we collect

We collect only what we need to run the service and respond to you:

Information you give us

Information collected automatically

3. Data you analyse in the Workbench

Several Workbench tools (for example the Fairness Scanner, Drift & Data-Quality analysis, the Document Gap Scanner, the Shadow AI and Model File scanners, and the on-page Governance & Risk assessors) run entirely in your browser. The datasets, documents, model files, contract text and prompts you analyse are never uploaded to us — they are read, parsed and scored on your own device and never leave it. Keeping raw data on your device is a deliberate design choice and it holds regardless of the settings below.

Private assessment saving

Assessment cloud auto-save is off by default. You can enable it separately or press Save privately. Saved assessments are excluded from training. Signed-in assessments belong to your organization; anonymous assessments require the owning browser's HttpOnly cookie. Clearing that cookie removes your access to anonymous saved work. An assessment ID alone does not grant access.

The intake classifier sends your answers to our server for obligation mapping even when auto-save is off. Hosted and AI-assisted tools may also send their inputs to our server or an external model provider; check each tool's data-handling label. Browser-only dataset analysis does not upload your source files.

Optional improvement and training summaries

Optional tool-run summaries are off by default and independent of saving. If you enable summaries, we receive the tool name, score/band, compact result rollup, system name/risk tier and browser identifiers for product improvement. A separate training checkbox controls whether those summaries may also be used for training. This excludes raw uploaded datasets, documents and model files. Turning the option off stops future summaries; it does not retract records already sent. Full saved assessments are not made available for training by this option.

Sharing and public benchmarks

Saving does not create a public link. The Dossier can create a separate, read-only summary link containing only the system name, risk tier, score and dates. Anyone holding that link can view the summary for the selected 1–30 days. Creating a replacement invalidates the prior link; Revoke summary link ends access immediately. Intake answers, contact details and detailed findings are not included. Downloaded copies cannot be recalled.

Public assessment benchmarks require a separate opt-in on the saved assessment. Organizational effectiveness benchmarks retain their separate organization-level opt-in. Disabling participation excludes the record from future aggregate queries; it cannot recall published copies of earlier reports.

Retention and deletion

Automatically saved assessments have identifying fields removed after 90 days by the retention job. Assessments deliberately saved remain until deleted. The Dossier's Delete saved assessment removes the source assessment's intake, findings, contact information and scores and revokes its summary link. An empty reference record remains for linked audit artifacts. Separately issued passports, other artifacts and downloaded copies are not deleted by this action; revoke passports separately. Optional tool-run records have identifying fields removed after 90 days.

Existing anonymous assessments that predate ownership cookies are locked because ownership cannot be verified from their old IDs. Organization members retain access to their organization's saved assessments. These changes do not withdraw separately published signed artifacts.

Trust Passports

Issuing a passport is a separate disclosure: its attestation can be read by anyone with the verification link. Public directory listing is a separate opt-in. A valid cryptographic signature establishes issuer and integrity; it does not certify accuracy, safety or legal compliance. Reviewer identity and accreditation are not independently verified by AutoGovern.

Separately, three tools (Model Risk Management, Fair Lending and FS AI RMF) save only to your browser’s local storage and never contact our server at all.

Our downloadable scanner, Aegis, runs fully offline and sends nothing to us by default. If you explicitly choose to upload a report (the opt-in -submit option), the scan results are stored under an anonymous, randomly-generated install identifier that contains no host or personal information.

4. How we use information

We do not sell your personal data, and we do not use it for third-party advertising.

Where GDPR applies, we rely on: consent (e.g. when you submit a form or save an assessment); contract (to deliver a service you requested); legitimate interests (to secure and improve the platform, balanced against your rights); and legal obligation where required.

6. Sharing & subprocessors

We share personal data only with the subprocessors below, under appropriate agreements. This is the complete list — we do not use any subprocessor not named here:

We may also disclose information where required by law, or as part of a corporate transaction, subject to this policy. See our Data Processing Addendum for the contractual terms governing subprocessors.

7. Cookies & local storage

autogovern.io does not use third-party advertising or cross-site tracking cookies. We use strictly-necessary browser storage (such as localStorage for your theme preference) to make the site work. Your browser settings let you clear this at any time.

8. Retention

We keep personal data only as long as needed for the purposes above. [ ● retention periods below are a starting template — confirm with counsel before relying on them]:

To request deletion of your data before these periods elapse, email info@autogovern.io; see §10 for your rights.

9. International transfers

Our providers may process data outside your country, including outside the UK/EEA. Where they do, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

10. Your rights

Subject to applicable law (including UK/EU GDPR and, for California residents, the CCPA/CPRA), you may request to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise any right, email info@autogovern.io. You also have the right to complain to your local data-protection authority.

11. Security

Measures we actually have in place today:

We do not currently hold a SOC 2, ISO 27001, or similar third-party security certification, and we have not commissioned an independent penetration test. If you need either as part of a procurement process, contact info@autogovern.io to discuss our roadmap. No method of transmission or storage is perfectly secure, but we work to protect your information.

12. Incident notification

[ ● notification timelines below are a starting template — confirm the exact commitment with counsel]: If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will: (a) investigate and contain it without undue delay; (b) notify affected customers by email as soon as reasonably possible, and in any case within 72 hours of confirming the incident, where required by applicable law (e.g. UK/EU GDPR Art. 33); and (c) provide a description of the incident, the data categories affected, and the remediation steps taken or planned. Notification timing may be adjusted where a law-enforcement or regulatory authority instructs us to delay disclosure.

13. Children

autogovern.io is a business tool and is not directed to children under 16. We do not knowingly collect their data.

14. Changes

We may update this policy from time to time. We will revise the “last updated” date above and, where appropriate, notify you of material changes.

15. Contact

Questions or requests: info@autogovern.io.