LogiRootLogiRootAI Governance Platform

LogiRoot Privacy & Data Handling Policy

Effective date: June 9, 2026

This policy describes how LogiRoot AI Inc. ("LogiRoot," "we," "us") collects, stores, uses, shares, retains, and protects information when you use the LogiRoot platform and visit our website. It is written to be read — if anything is unclear, contact us at the address below.


1. Information We Collect

Account information. When you create a LogiRoot account, we collect your email address (used for sign-in and service communications) and your organization's name and subscription details provided through AWS Marketplace.

Governance evaluation content. When your systems submit AI actions to LogiRoot for governance evaluation, we process the content of those requests in order to apply your policies and return a decision. This content is provided by you and may contain whatever your systems include in it.

Operational metadata. We collect service usage and operational data (such as request volumes, timestamps, decision outcomes, and error states) needed to operate, secure, and support the platform.

Support communications. If you contact support, we keep the correspondence.

What we do not collect. We do not collect or process payment information. All billing is handled by AWS Marketplace; LogiRoot never sees your payment details.

2. How We Store It

All customer data is stored on Amazon Web Services infrastructure in the United States. Data is encrypted in transit (TLS) and encrypted at rest using AWS-managed key services. Each customer's data is logically isolated per tenant; access requires authentication, and administrative access is restricted and logged.

3. How We Use It

We use the information described above solely to provide the service: applying your governance policies, producing your audit evidence, operating and securing the platform, providing support, and communicating with you about your account and the service. We do not sell your data. We do not use your governance evaluation content for advertising, and we do not use customer content to train machine-learning models.

4. How We Share It

We do not sell or rent customer data. We share data only with the service providers necessary to operate the platform (such as Amazon Web Services for infrastructure and our transactional email provider for sign-in messages), each bound to use it only to provide their service to us; and where required by law, legal process, or to protect the rights, safety, and security of LogiRoot, our customers, or others. If a legal demand for your data is not legally prohibited from disclosure, we will make reasonable efforts to notify you before producing it.

5. How Long We Keep It (Retention)

Evaluation content is retained according to your subscription tier's retention window, after which its content is automatically removed on a daily schedule. The decision record itself is retained; the underlying content is not.

Audit evidence records are retained as long as your account requires them. These records are designed for integrity: they contain decision outcomes and cryptographic fingerprints rather than the underlying evaluated content, and the fingerprints cannot be reversed to reveal that content.

Account information is retained for as long as your account is active and as required afterward for legal, tax, and accounting purposes.

6. Backups

Customer data is backed up using AWS-managed automated backups, encrypted at rest, and retained for 14 days, after which backups expire automatically. Deleted data ages out of backups as those backups expire.

7. Data Deletion and Your Rights

You may request deletion of your data at any time by contacting us. Upon a verified request, we delete your stored evaluation content and account information within 30 days, subject to legal retention obligations.

One honest carve-out: the integrity-protected audit evidence record is designed to be tamper-evident and is not retroactively editable — that is its purpose. However, these records do not contain your evaluated content or readable personal information; they contain decision outcomes and irreversible cryptographic fingerprints. Deleting your stored content removes the readable data; the evidence record proves only that evaluations occurred and what was decided.

Depending on your jurisdiction (including under GDPR and CCPA/CPRA), you may have rights to access, correct, delete, export, or restrict the processing of your personal information. We honor verified requests consistent with applicable law. We do not discriminate against you for exercising these rights.

8. Security

We protect customer data with encryption in transit and at rest, per-tenant isolation, authenticated access, restricted and logged administrative access, and tamper-evident audit records. No system is perfectly secure, but security is the product we sell, and we hold our own infrastructure to the standard we offer our customers.

9. Security Incidents

Our commitment to you: if we confirm a security incident affecting your data, we will notify affected customers without undue delay, consistent with applicable law and any contractual commitments, and will share what happened, what data was involved, and what we are doing about it.

Reporting to us: if you believe you have found a security vulnerability or incident involving LogiRoot, contact security@logirootai.com. Our vulnerability disclosure policy, including our PGP key, acknowledgment timeline, and safe-harbor terms, is published at logirootai.com/security.

10. Children

LogiRoot is a business service. It is not directed to children, and we do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this policy as the service evolves. We will post changes on this page with an updated effective date, and for material changes we will notify customers by email.

12. Contact

LogiRoot AI Inc. Email: privacy@logirootai.com Security: security@logirootai.com Support: support@logirootai.com