AutoFoundry Privacy Policy
Effective Date: July 24, 2026
Last Updated: July 24, 2026
1. Introduction and Scope
AutoFoundry LTD (“AutoFoundry,” “we,” “us,” or “our”) provides a business-to-business software platform that enables organizations to deploy and operate AI-assisted business workflows.
This Privacy Policy explains how AutoFoundry collects, uses, discloses, retains, and protects Personal Data when an individual:
- visits an AutoFoundry website;
- requests information or a demonstration;
- creates or uses an AutoFoundry account;
- uses an AutoFoundry application, assistant, integration, or service;
- communicates with AutoFoundry;
- participates in a trial, demonstration, or customer engagement; or
- otherwise interacts with AutoFoundry.
This Privacy Policy applies to website visitors, prospective customers, customer administrators, authorized users, business contacts, and other individuals whose Personal Data AutoFoundry processes for its own business purposes.
AutoFoundry currently offers its Services under United States law. This Privacy Policy is intended to address applicable United States privacy requirements. AutoFoundry does not represent that the Services are designed for, directed to, or compliant with the privacy laws of another country unless AutoFoundry has expressly agreed otherwise in writing.
When AutoFoundry processes information through the platform on behalf of a customer, the customer generally determines why and how that information is processed. In that situation, the customer acts as the controller or business, and AutoFoundry acts as its processor or service provider.
Customer Business Data processed on behalf of a customer is governed primarily by the customer’s agreement with AutoFoundry, including any applicable Data Processing Addendum.
This Privacy Policy does not govern the independent privacy practices of AutoFoundry customers, third-party websites, connected services, or other third parties acting outside their role as an AutoFoundry service provider.
2. Definitions
For purposes of this Privacy Policy:
“Customer Business Data”
“Customer Business Data” means information submitted, uploaded, connected, generated, stored, or otherwise processed through the Services by or on behalf of a customer or authorized user.
Customer Business Data may include business records, messages, documents, spreadsheets, images, audio, contracts, proposals, operational information, prompts, AI outputs, connected-service data, approvals, audit records, and other customer-controlled content.
“Personal Data”
“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual or household.
“Personal Data” includes “personal information,” “personal data,” and similar terms under applicable United States privacy laws.
“Sensitive Personal Data”
“Sensitive Personal Data” means Personal Data subject to heightened protection under applicable law, including certain government identifiers, account credentials, precise geolocation, health information, biometric identifiers, genetic data, financial-account credentials, contents of certain private communications, and information concerning protected personal characteristics.
“Services”
“Services” means AutoFoundry’s websites, software platform, AI assistants, applications, integrations, APIs, support services, and related offerings.
“Service Provider” or “Subprocessor”
A “Service Provider” or “Subprocessor” is a third party that processes information on AutoFoundry’s behalf to help provide, secure, maintain, or support the Services.
3. AutoFoundry’s Privacy Principles
AutoFoundry is designed around the following principles:
- collect and process only information reasonably necessary to provide, secure, support, and improve the Services;
- use Customer Business Data only to provide the Services requested or authorized by the customer;
- keep customers in control of their users, permissions, integrations, AI-provider configuration, and business workflows;
- not sell Personal Data or Customer Business Data;
- not share Personal Data for cross-context behavioral advertising;
- not use Customer Business Data for targeted advertising;
- not use Customer Business Data to train AutoFoundry general-purpose or foundation AI models;
- not knowingly enable an external AI provider to train its general-purpose models using Customer Business Data unless the customer has separately and expressly authorized that use;
- disclose when external AI providers may process Customer Business Data;
- use reasonable administrative, technical, contractual, and organizational safeguards appropriate to the nature of the information processed;
- maintain appropriate tenant, workspace, identity, permission, and approval boundaries; and
- provide customers and individuals with meaningful information about AutoFoundry’s data practices.
4. AutoFoundry’s Roles
AutoFoundry as a business or controller
AutoFoundry acts as a business or controller for Personal Data when AutoFoundry determines the purposes and means of processing.
This may include:
- website and visitor information;
- business contact information;
- account-registration information;
- customer relationship information;
- sales and demonstration information;
- support communications;
- billing and contract-administration information;
- service telemetry;
- security information;
- audit records; and
- information used to operate, protect, and improve AutoFoundry.
AutoFoundry as a service provider or processor
AutoFoundry generally acts as a service provider or processor when it processes Customer Business Data according to a customer’s instructions.
Customers are responsible for:
- determining whether they have a lawful basis or other authority to provide information to AutoFoundry;
- providing required notices to their employees, customers, vendors, contractors, and other individuals;
- obtaining any required permissions or consents;
- configuring users, permissions, integrations, retention settings, and AI providers appropriately;
- limiting Customer Business Data to information reasonably necessary for the intended workflow;
- avoiding unnecessary Personal Data in AI workflows;
- determining whether a particular workflow is appropriate for Sensitive Personal Data or regulated information;
- maintaining appropriate human review over consequential decisions and actions; and
- responding to privacy requests concerning Customer Business Data they control.
Individuals seeking to exercise rights concerning information controlled by an AutoFoundry customer should ordinarily contact that customer first.
5. Information AutoFoundry Collects
The information AutoFoundry collects depends on how an individual or organization interacts with the Services.
5.1 Account and business contact information
AutoFoundry may collect:
- name;
- business email address;
- business telephone number;
- employer or organization;
- job title or business role;
- account, workspace, tenant, or organization identifiers;
- authentication and identity-provider identifiers;
- account permissions;
- organization memberships;
- communication preferences; and
- billing or administrative contact information.
5.2 Customer Business Data
Customers and authorized users may submit, connect, or generate information through AutoFoundry, including:
- prompts, messages, questions, requests, and instructions;
- documents, spreadsheets, images, audio, and other files;
- records obtained from customer-authorized systems;
- contracts, proposals, pricing records, correspondence, and operational records;
- business processes, procedures, policies, and configuration information;
- AI-generated responses, summaries, recommendations, drafts, classifications, and analyses;
- proposed, approved, rejected, and executed actions;
- human approvals and review decisions;
- assistant instructions, settings, memory, context, and grounding information;
- conversation and session history;
- audit histories and activity records; and
- user feedback about platform results.
Customer Business Data may contain Personal Data when a customer or authorized user includes information concerning an employee, customer, supplier, contractor, applicant, representative, or other individual.
5.3 Connected-service information
When a customer authorizes an integration, AutoFoundry may receive information from the connected service as permitted by the customer’s configuration and the connected service’s authorization process.
This may include:
- messages;
- emails;
- documents;
- calendars;
- contacts;
- files;
- tasks;
- business records;
- connected-account identifiers;
- authorization scopes;
- integration settings;
- access or refresh tokens; and
- synchronization, status, and error information.
AutoFoundry uses connected-service information to provide, maintain, secure, troubleshoot, and support the authorized integration and related Services.
5.4 Technical, usage, and security information
AutoFoundry may automatically collect:
- Internet Protocol address;
- approximate location derived from an Internet Protocol address;
- browser and device type;
- operating system;
- referring page;
- pages, features, and functions used;
- session and device identifiers;
- timestamps;
- authentication events;
- access events;
- performance information;
- diagnostic and error information;
- security events;
- audit logs; and
- information used to identify abuse, fraud, unauthorized access, or service failures.
AutoFoundry does not intentionally collect precise geolocation through the public website unless that collection is separately disclosed.
5.5 Commercial and transaction information
AutoFoundry may collect:
- service-plan information;
- subscription information;
- transaction history;
- payment status;
- invoice information;
- contract information;
- account-administration records; and
- records of products or Services requested, purchased, or used.
Payment-card processing may be handled by a payment provider. AutoFoundry does not intend to directly store complete payment-card numbers unless expressly required and supported by an approved payment environment.
5.6 Communications and support information
AutoFoundry may collect information provided when an individual:
- requests a demonstration;
- contacts sales;
- contacts support;
- reports a problem;
- submits feedback;
- responds to a survey;
- communicates about a contract or account;
- participates in a customer call; or
- otherwise contacts AutoFoundry.
6. United States Personal Information Disclosures
The following table describes categories of Personal Data that AutoFoundry may have collected or processed during the preceding 12 months.
The table covers information AutoFoundry processes for its own purposes and information that may be present in Customer Business Data processed on behalf of a customer.
AutoFoundry does not necessarily collect every example listed from every individual.
Statutory category
Examples AutoFoundry may process
Sources
Business purposes
Categories of recipients
Identifiers
Name, business email, telephone number, Internet Protocol address, account ID, tenant ID, session ID, device identifier, authentication identifier
Individual, employer, customer administrator, identity provider, browser, connected service
Account administration, authentication, service delivery, communication, security, support
Customer administrators, infrastructure providers, identity providers, security providers
Customer-record information
Business contact details, address, signature, account information, correspondence, or other information included in business records
Individual, customer, connected service, uploaded content
Service delivery, customer support, contract administration, requested workflows
Customer-authorized users, service providers, AI providers where necessary for a requested workflow
Commercial information
Subscription, service plan, invoice, payment status, transaction history, contract history, and service usage
Customer, account administrator, billing provider, AutoFoundry systems
Billing, account management, customer service, financial recordkeeping
Billing providers, accountants, professional advisers, customer administrators
Internet or network activity
Browser type, device type, operating system, page views, feature use, access logs, session activity, diagnostic events, error records
Browser, device, AutoFoundry platform, security systems
Service operation, analytics, reliability, fraud prevention, troubleshooting, security
Hosting, monitoring, logging, security, and support providers
Approximate geolocation
General location inferred from an Internet Protocol address
Browser, device, security systems
Security, fraud prevention, localization, incident investigation
Security, hosting, and monitoring providers
Professional or employment-related information
Employer, organization, job title, business role, permissions, professional correspondence, and business records
Individual, employer, customer administrator, connected service, Customer Business Data
Account configuration, authorization, service delivery, requested business workflows
Customer-authorized users, service providers, AI providers where necessary
Audio, electronic, visual, or similar information
Uploaded images, audio files, documents, recordings, screenshots, messages, and electronic communications
Individual, customer, connected service, uploaded content
Requested workflows, support, transcription, analysis, documentation, auditability
Customer-authorized users, storage providers, AI providers where necessary
Inferences and AI-generated information
Classifications, summaries, recommendations, risk indicators, suggested actions, assistant outputs, or other conclusions generated from submitted information
AutoFoundry systems, configured AI models, Customer Business Data
Providing requested AI-assisted functions, review, decision support, workflow automation
Customer-authorized users and systems
Sensitive Personal Data
Account credentials; contents of customer-authorized messages or emails; and Sensitive Personal Data contained in Customer Business Data
Individual, customer, connected service, uploaded content
Authentication, security, or completion of a customer-authorized workflow
Identity providers, security providers, and approved processors necessary for the requested service
Other Personal Data
Information voluntarily supplied in a request, support communication, document, integration, or business workflow
Individual, customer, connected service
Purpose disclosed when collected or reasonably necessary to provide the requested service
Recipients reasonably necessary for the disclosed purpose
AutoFoundry does not sell any of these categories.
AutoFoundry does not share these categories for cross-context behavioral advertising.
AutoFoundry may disclose categories of Personal Data to service providers, subprocessors, AI providers, professional advisers, customer-authorized integrations, or government authorities for the purposes described in this Privacy Policy.
When AutoFoundry processes information solely on behalf of a customer, that processing is governed by the applicable customer agreement and the customer’s instructions.
7. Sources of Information
AutoFoundry may obtain information:
- directly from an individual;
- from an individual’s employer or organization;
- from customer administrators and authorized users;
- from customer-authorized connected services;
- automatically through the website or platform;
- from identity, security, infrastructure, billing, and support providers;
- from business partners or referral sources; and
- from publicly available business sources where permitted by law.
8. How AutoFoundry Uses Information
AutoFoundry may use Personal Data and Customer Business Data to:
- provide, operate, and maintain the Services;
- register and administer accounts;
- authenticate users;
- enforce permissions and organization boundaries;
- perform customer-requested workflows;
- generate AI-assisted outputs;
- connect customer-authorized services;
- route information to a customer-authorized AI provider;
- process and record proposed, approved, rejected, or executed actions;
- preserve conversation, session, artifact, and audit history;
- provide customer support;
- respond to communications;
- monitor availability, performance, and reliability;
- detect and prevent fraud, abuse, security incidents, and unauthorized access;
- troubleshoot and repair the Services;
- maintain audit, contractual, financial, and compliance records;
- communicate about accounts, service changes, incidents, or security matters;
- administer contracts, subscriptions, and billing;
- analyze service operation and user feedback;
- improve platform functionality and user experience using operational data, customer feedback, and appropriately aggregated or deidentified information;
- enforce agreements and policies;
- comply with legal obligations;
- establish, exercise, or defend legal claims; and
- protect AutoFoundry, customers, users, and others.
AutoFoundry does not use Customer Business Data to train AutoFoundry general-purpose or foundation AI models.
AutoFoundry may use aggregated or deidentified information for analytics, security, capacity planning, reliability, and product improvement.
AutoFoundry does not attempt to reidentify information maintained in deidentified form except as permitted by law to test whether deidentification methods remain effective.
9. AI Processing and Model Providers
9.1 How AI processing works
AutoFoundry may use artificial intelligence models to process Customer Business Data and generate customer-requested outputs.
Depending on the customer’s configuration, selected assistant, workflow, technical requirements, availability, and contractual arrangements, processing may be performed by:
- OpenAI;
- Anthropic;
- a locally hosted language model;
- a model operated in an AutoFoundry-controlled environment;
- a model operated in a customer-controlled environment; or
- another model provider approved through AutoFoundry’s provider-governance process.
When an external provider is used, AutoFoundry may send the provider the content, instructions, metadata, and contextual information reasonably necessary to perform the requested task.
The provider returns an output that AutoFoundry may:
- display to an authorized user;
- store as part of a conversation or artifact;
- route for human review or approval;
- use to support another customer-authorized workflow; or
- transmit to a customer-authorized connected service.
A locally hosted model may process information within AutoFoundry-controlled or customer-controlled infrastructure without sending the model request to an external model provider.
9.2 Customer control
Depending on the service plan, deployment, and configuration, customers may be able to control or restrict:
- which AI providers are enabled;
- which assistants may use each provider;
- which users may invoke an AI workflow;
- which systems and data sources an assistant may access;
- whether an external or locally hosted model is used;
- whether human approval is required;
- whether an AI-generated proposal may be executed;
- how conversations and artifacts are retained; and
- which integrations may receive an output.
9.3 Data minimization
AutoFoundry seeks to send an external AI provider only the content and context reasonably necessary to perform the requested task.
The exact information required depends on the workflow.
For example, reviewing a contract may require sending relevant contract text, while summarizing an email may require sending the email body and related context.
AutoFoundry may use filtering, truncation, selection, access controls, workflow constraints, or other measures to reduce unnecessary information.
Unless AutoFoundry has expressly represented otherwise in a customer agreement, AutoFoundry does not guarantee that every workflow automatically detects or removes all Personal Data before information is sent to an external AI provider.
9.4 Personal Data within business content
AutoFoundry AI workflows are intended primarily for business information.
AutoFoundry does not intentionally send account-profile information, billing information, authentication secrets, or Sensitive Personal Data to an AI provider merely because an individual has an AutoFoundry account.
However, Customer Business Data selected for an AI-assisted workflow may itself contain Personal Data.
For example, a customer-selected:
- email;
- message;
- contract;
- proposal;
- personnel document;
- supplier record;
- spreadsheet;
- calendar entry; or
- support record
may contain names, contact information, signatures, employment information, communications, or other information relating to an individual.
When a customer or authorized user requests AI processing of content containing Personal Data, the necessary content may be processed by the configured AI provider solely to provide the requested Service.
Customers should minimize Personal Data included in AI workflows.
9.5 Model training
AutoFoundry does not use Customer Business Data to train AutoFoundry general-purpose or foundation AI models.
AutoFoundry seeks to use external AI providers through commercial, enterprise, or application-programming-interface arrangements under which customer inputs and outputs are not used to train the provider’s general-purpose models by default.
AutoFoundry does not knowingly opt Customer Business Data into provider model-training, feedback, research, or data-sharing programs unless the customer has separately and expressly authorized that use.
Submitting feedback directly to an AI provider, enabling a provider feedback mechanism, or participating in a provider research program may be governed by separate terms and retention periods.
9.6 External AI-provider retention
“No model training” does not mean “no provider retention.”
Under standard commercial API configurations, an external AI provider may temporarily retain prompts, responses, related metadata, classifier results, or other customer content for purposes such as:
- abuse monitoring;
- fraud prevention;
- safety enforcement;
- system security;
- debugging;
- service operation;
- legal compliance; or
- investigation of suspected policy violations.
Standard provider configurations may include retention of inputs and outputs for up to 30 days.
Information associated with suspected policy violations, misuse investigations, legal obligations, or safety enforcement may be retained for longer periods.
Some provider features require persistent application storage. Depending on the provider and feature, files, threads, conversations, batches, vector stores, caches, assistant state, or similar objects may be retained until deleted or for another feature-specific period.
OpenAI currently states that API abuse-monitoring logs may be retained for up to 30 days by default and that certain API features store application state. OpenAI’s Zero Data Retention and Modified Abuse Monitoring controls require eligibility and approval and do not apply uniformly to every endpoint or feature.
Anthropic currently states that standard API inputs and outputs are generally deleted within 30 days, subject to contractual exceptions, legal requirements, and usage-policy enforcement. Anthropic’s Zero Data Retention arrangements require approval and may not apply to all products, beta features, files, caching, batch functions, third-party searches, or other persistent features.
Provider terms, features, and retention practices may change.
AutoFoundry configures provider use according to the applicable customer agreement, provider capabilities, and technical requirements.
9.7 Zero Data Retention
AutoFoundry may use Zero Data Retention, modified abuse-monitoring, regional processing, or similar provider controls when:
- the control is offered by the provider;
- AutoFoundry or the customer is eligible;
- the provider has approved the applicable account or project;
- the selected model and feature support the control;
- the control is technically compatible with the requested workflow; and
- the applicable customer agreement requires or authorizes its use.
AutoFoundry does not represent that Zero Data Retention applies to a customer, workflow, provider, model, endpoint, or feature unless that commitment is expressly stated in the applicable customer agreement, order form, service description, or written configuration confirmation.
A Zero Data Retention arrangement may still permit retention of limited safety results, system metadata, legal records, or information required to combat misuse or comply with law.
9.8 Regulated and high-risk workflows
Customers must not submit Sensitive Personal Data or regulated information to an AI workflow unless:
- the processing is necessary and lawful;
- the customer is authorized to provide the information;
- the applicable AutoFoundry service and deployment have been approved for that information;
- the configured provider has been approved for that information;
- any required written agreement is in place; and
- required technical, organizational, and human-review controls have been enabled.
9.9 Automated and consequential decisions
AutoFoundry is designed to support human-directed business workflows and approval-controlled execution.
AutoFoundry does not independently use Personal Data to make solely automated decisions producing legal or similarly significant effects concerning an individual.
Customers that configure AutoFoundry for employment, credit, insurance, housing, healthcare, legal, education, financial, or other consequential decisions are responsible for ensuring:
- appropriate human review;
- lawful authority;
- required notices;
- appropriate testing;
- accuracy review;
- anti-discrimination safeguards;
- an appeal or reconsideration process where required; and
- compliance with applicable law.
10. How AutoFoundry Discloses Information
AutoFoundry may disclose information to the following categories of recipients.
10.1 Customers and authorized users
Information associated with a customer account may be available to the customer’s administrators and authorized users according to their roles, permissions, and account configuration.
Customer administrators may be able to:
- access information;
- configure integrations;
- administer users;
- view activity;
- retain or delete information;
- export information; and
- manage account settings.
10.2 AI model providers
AutoFoundry may disclose necessary Customer Business Data to the external AI provider configured or authorized for a workflow.
The information disclosed depends on the requested task.
External AI providers may include OpenAI, Anthropic, and other approved providers.
10.3 Infrastructure and service providers
AutoFoundry may use service providers supporting:
- cloud and server infrastructure;
- networking;
- storage;
- backup and recovery;
- databases;
- identity and authentication;
- security monitoring;
- application monitoring;
- logging and error reporting;
- communications;
- customer support;
- billing and payment processing;
- document processing;
- software development;
- professional services; and
- other functions necessary to operate AutoFoundry.
These providers may process information only for the services they provide and subject to applicable contractual obligations.
10.4 Customer-authorized integrations
AutoFoundry may send information to a third-party system when a customer or authorized user directs AutoFoundry to perform an integration, synchronization, or action involving that system.
The third party’s privacy policy and the customer’s agreement with that third party govern the third party’s independent processing.
10.5 Professional advisers
AutoFoundry may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers when reasonably necessary for legitimate business, contractual, security, compliance, or legal purposes.
10.6 Legal and safety disclosures
AutoFoundry may disclose information when it reasonably believes disclosure is necessary to:
- comply with applicable law;
- respond to valid legal process;
- respond to a lawful government request;
- enforce an agreement;
- investigate fraud, misuse, abuse, or unauthorized activity;
- protect the security or integrity of AutoFoundry;
- protect the rights, property, or safety of AutoFoundry, customers, users, or others; or
- establish, exercise, or defend legal claims.
Where legally permitted and reasonably practicable, AutoFoundry seeks to notify an affected customer before disclosing Customer Business Data in response to a legal demand.
10.7 Corporate transactions
Information may be disclosed or transferred in connection with:
- a merger;
- acquisition;
- financing;
- reorganization;
- bankruptcy;
- sale of assets;
- due-diligence process; or
- similar corporate transaction.
Any successor will be required to process Personal Data consistently with applicable law and the commitments applicable to the transferred information.
11. Data Processing Addendum and Subprocessors
11.1 Data Processing Addendum
Business customers may request AutoFoundry’s standard Data Processing Addendum by contacting:
A customer may also request a Data Processing Addendum through its AutoFoundry account representative or established support channel.
The Data Processing Addendum may address:
- the parties’ controller and processor roles;
- processing instructions;
- confidentiality;
- information security;
- subprocessors;
- incident notification;
- deletion and return of Customer Business Data;
- audit and compliance information; and
- other processing obligations.
The applicable customer agreement and Data Processing Addendum control if they conflict with this Privacy Policy concerning AutoFoundry’s processing of Customer Business Data on the customer’s behalf.
11.2 Subprocessor information
AutoFoundry uses subprocessors to provide infrastructure, identity, security, communications, AI processing, monitoring, storage, support, and related functions.
A current list of material subprocessors is available upon request from:
AutoFoundry may add or replace subprocessors as the Services evolve.
Where required by an applicable Data Processing Addendum or customer agreement, AutoFoundry will provide advance notice of a material new or replacement subprocessor and an opportunity to object according to the applicable agreement.
An objection does not automatically prevent AutoFoundry from using the subprocessor. The parties will address objections according to the applicable customer agreement or Data Processing Addendum.
12. No Sale, Behavioral Advertising, or Financial Incentive
AutoFoundry does not sell Personal Data or Customer Business Data.
AutoFoundry does not share Personal Data for cross-context behavioral advertising.
AutoFoundry does not use Customer Business Data for targeted advertising.
During the preceding 12 months, AutoFoundry has not knowingly:
- sold Personal Data;
- shared Personal Data for cross-context behavioral advertising; or
- sold or shared the Personal Data of an individual under 16 years of age.
AutoFoundry does not provide a financial incentive or price difference in exchange for Personal Data.
Because AutoFoundry does not sell Personal Data or share it for cross-context behavioral advertising, AutoFoundry does not currently provide a “Do Not Sell or Share My Personal Information” link.
AutoFoundry will update this Privacy Policy and provide any required opt-out mechanism before beginning a practice that applicable law treats as a sale, targeted-advertising disclosure, or qualifying share.
13. Cookies and Similar Technologies
AutoFoundry may use cookies, local storage, session storage, and similar technologies to:
- maintain authenticated sessions;
- identify an authorized user;
- protect accounts;
- prevent fraud or abuse;
- preserve security settings;
- remember permitted preferences;
- maintain tenant or workspace context;
- route traffic;
- measure service reliability;
- troubleshoot errors; and
- maintain platform operation.
These technologies may include:
- strictly necessary session cookies;
- authentication cookies;
- security tokens;
- load-balancing or routing cookies;
- preference storage;
- tenant or workspace identifiers;
- local theme or display preferences;
- diagnostic identifiers; and
- limited operational analytics.
AutoFoundry does not use Customer Business Data for advertising cookies or cross-context behavioral advertising.
AutoFoundry may use analytics or performance technologies where enabled and permitted by law.
Where consent is legally required for a non-essential technology, AutoFoundry will request consent before using that technology.
Browser settings may allow an individual to block or delete cookies. Blocking essential technologies may prevent parts of the Services from operating correctly.
14. Data Retention
AutoFoundry retains information only for as long as reasonably necessary for the purposes for which it was collected, including to:
- provide the Services;
- comply with customer instructions;
- maintain security;
- preserve auditability;
- satisfy contractual commitments;
- comply with legal obligations;
- maintain financial records;
- resolve disputes; and
- enforce agreements.
Retention is generally determined as follows:
Customer Business Data
Customer Business Data is retained according to:
- customer configuration;
- the applicable customer agreement;
- any applicable Data Processing Addendum;
- the operational requirements of the selected workflow;
- lawful customer instructions; and
- applicable legal, security, audit, and backup requirements.
AI inputs and outputs
AI inputs and outputs may be retained by AutoFoundry when necessary to provide:
- conversation history;
- session continuity;
- artifacts;
- approvals;
- audit history;
- workflow history;
- support;
- troubleshooting; or
- another customer-enabled feature.
External AI providers may separately retain inputs, outputs, metadata, or application state as described in Section 9.
Connected-service information
Connected-service information is retained while necessary to provide and support the integration, subject to customer configuration, the applicable agreement, and the connected service’s requirements.
Authorization credentials may be retained while an integration remains authorized and may be deleted or invalidated when the integration is disconnected, subject to technical and legal requirements.
Account information
Account information is retained while the account or customer relationship remains active and afterward as reasonably necessary for:
- account closure;
- security;
- legal compliance;
- dispute resolution;
- fraud prevention;
- contractual administration; and
- enforcement.
Security, access, and audit records
Security, authentication, access, and audit records are retained for a period appropriate to:
- incident detection;
- investigation;
- accountability;
- contractual commitments;
- fraud prevention; and
- applicable law.
Support communications
Support communications are retained while necessary to resolve the matter and maintain an appropriate service and customer record.
Financial and contractual records
Contract, transaction, billing, accounting, and tax records are retained for legally required or reasonably necessary financial, audit, tax, insurance, and dispute periods.
Backups
Information contained in backups may remain until overwritten or deleted through AutoFoundry’s ordinary rolling backup, recovery, and disaster-recovery processes.
Information may be retained for longer when required by:
- law;
- legal process;
- a valid legal hold;
- security needs;
- fraud prevention;
- dispute resolution; or
- contractual obligations.
When a customer requests deletion or terminates the Services, AutoFoundry deletes or returns Customer Business Data as required by the applicable agreement, subject to lawful retention requirements, security records, legal holds, and ordinary backup expiration.
15. Security
AutoFoundry maintains a security program intended to protect information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Depending on the Service and deployment, safeguards may include:
- authentication controls;
- authorization and role-based access;
- tenant and workspace isolation;
- least-privilege access;
- encryption in transit;
- encryption at rest where applicable;
- secure credential and secret handling;
- network and infrastructure controls;
- logging and audit records;
- security monitoring;
- backups and recovery procedures;
- software-development practices;
- change-control practices;
- vulnerability and dependency management;
- incident-response procedures;
- employee and contractor confidentiality obligations; and
- review of service providers that process protected information.
Access to Customer Business Data is limited to authorized individuals and systems that require access to provide, secure, maintain, or support the Services or to comply with law.
No Internet transmission, storage system, AI system, or security program can guarantee absolute security.
Customers are responsible for:
- protecting credentials;
- using appropriate authentication controls;
- administering users and permissions;
- configuring integrations appropriately;
- limiting unnecessary data;
- reviewing AI-generated outputs;
- maintaining appropriate endpoint security; and
- promptly reporting suspected unauthorized access.
If AutoFoundry discovers a security incident affecting protected information, AutoFoundry will investigate and provide notifications as required by applicable law and contractual commitments.
16. United States Privacy Rights
Depending on an individual’s state of residence and applicable law, the individual may have the right to:
- confirm whether AutoFoundry processes Personal Data concerning the individual;
- access categories of Personal Data;
- access specific pieces of Personal Data;
- correct inaccurate Personal Data;
- request deletion of Personal Data;
- obtain a portable copy of certain Personal Data;
- obtain information about the categories of sources from which Personal Data was collected;
- obtain information about the purposes for which Personal Data was used;
- obtain information about categories of recipients;
- obtain a list of certain specific third parties to which Personal Data was disclosed;
- opt out of the sale of Personal Data;
- opt out of sharing for cross-context behavioral advertising;
- opt out of targeted advertising;
- opt out of certain profiling or automated decision-making;
- limit certain uses or disclosures of Sensitive Personal Data;
- question or obtain information concerning certain profiling decisions;
- appeal a decision concerning a privacy request;
- use an authorized agent where permitted;
- withdraw consent where processing relies on consent; and
- exercise privacy rights without unlawful discrimination or retaliation.
California law provides qualifying residents with rights concerning access, correction, deletion, sale, sharing, Sensitive Personal Information, and nondiscrimination. California disclosures may also require information about categories collected, sources, purposes, recipients, and disclosures during the preceding 12 months.
Minnesota law provides qualifying residents with rights that may include confirmation, access, correction, deletion, portability, opt-out rights, profiling information, appeals, and a list of specific third parties to which Personal Data was disclosed.
16.1 Exercising a privacy right
To submit a privacy request, email:
Use the subject line:
Privacy Request
A customer or authorized user may also submit a request through the established support channel available within the customer’s account.
A request should identify:
- the right the individual wishes to exercise;
- the individual’s name;
- the email address associated with the interaction or account;
- the organization associated with the information, if applicable;
- the state of residence; and
- sufficient information to allow AutoFoundry to locate and verify the relevant records.
AutoFoundry may request additional information reasonably necessary to verify identity, residence, authority, and the scope of the request.
Verification information will be used only to process, secure, and document the request.
AutoFoundry will respond within the period required by applicable law.
Where permitted by law, AutoFoundry may extend the response period and will provide notice of the extension and the reason for it.
AutoFoundry may deny or limit a request when permitted by law, including when AutoFoundry:
- cannot reasonably verify the request;
- cannot locate information concerning the requester;
- is required to retain the information;
- needs the information for security, fraud prevention, legal, contractual, or other exempt purposes;
- processes the information solely on behalf of a customer;
- determines that an exception applies; or
- determines that a request is manifestly unfounded, excessive, repetitive, or fraudulent.
16.2 Customer-controlled information
When AutoFoundry processes Personal Data solely on behalf of a customer, that customer controls the information.
AutoFoundry may:
- direct the individual to the applicable customer;
- notify the customer of the request; or
- assist the customer in responding according to the applicable agreement.
Users of an employer- or organization-managed account should ordinarily contact their organization’s administrator first.
16.3 Authorized agents
An authorized agent may submit a request where permitted by law.
AutoFoundry may require:
- proof that the individual authorized the agent;
- verification of the agent’s identity;
- verification of the individual’s identity; and
- information sufficient to validate the scope of the authorization.
16.4 Appeals
To appeal a decision concerning a privacy request, reply to the decision or email:
Use the subject line:
Privacy Appeal
The appeal should identify the original request, the decision being appealed, and the reason the individual believes the decision should be reconsidered.
AutoFoundry will review and respond to an appeal within the period required by applicable law.
Where required, AutoFoundry will provide information about how the individual may contact the appropriate state attorney general or other regulator.
16.5 Universal opt-out signals
Where required by applicable law, AutoFoundry recognizes qualifying browser-based universal opt-out preference signals for processing involving:
- a sale of Personal Data; or
- targeted advertising.
AutoFoundry does not currently sell Personal Data or process Personal Data for targeted advertising.
16.6 California “Shine the Light”
AutoFoundry does not disclose Personal Data to third parties for their own direct-marketing purposes in a manner requiring an opt-out under California’s “Shine the Light” law.
17. Sensitive and Regulated Information
Unless AutoFoundry has expressly approved the applicable Service, provider, deployment, and written agreement, customers must not submit:
- Social Security numbers or comparable government identifiers;
- driver’s-license or passport numbers;
- account passwords;
- private encryption keys;
- authentication secrets;
- complete payment-card information;
- financial-account credentials;
- protected health information subject to healthcare privacy laws;
- biometric identifiers used to uniquely identify an individual;
- genetic information;
- precise location information;
- highly sensitive financial information;
- information concerning an individual’s racial or ethnic origin;
- religious or philosophical beliefs;
- sexual orientation or sex life;
- citizenship or immigration status;
- union membership;
- criminal-history information; or
- other legally protected Sensitive Personal Data.
This restriction does not prohibit AutoFoundry from processing account credentials or integration tokens through systems specifically designed and approved for authentication or secret management.
AutoFoundry may block, quarantine, redact, restrict, or delete prohibited information when reasonably necessary to:
- protect the Services;
- enforce an agreement;
- comply with law;
- respond to a security issue; or
- prevent unauthorized or unsafe processing.
18. Children
AutoFoundry is a business service and is not directed to children.
Individuals under 18 years of age may not independently create or use an AutoFoundry account unless their use is expressly authorized by an organization and permitted by applicable law.
AutoFoundry does not knowingly collect Personal Data directly from children under 13 through its public website or Services.
Contact privacy@autofoundry.ai if you believe a child has provided Personal Data without appropriate authorization.
19. Data Processing Locations
AutoFoundry currently offers the Services under United States law.
AutoFoundry and its service providers may process information in the United States and in other locations where an approved provider operates infrastructure or personnel.
Customer Business Data may therefore be processed outside the customer’s state of residence.
AutoFoundry does not represent that all Customer Business Data remains within a particular state, region, or country unless a customer agreement or written service configuration expressly provides a geographic-processing commitment.
Customers requiring:
- United States-only processing;
- regional data residency;
- a particular cloud region;
- locally hosted model processing;
- Zero Data Retention;
- customer-controlled infrastructure; or
- another geographic or retention restriction
must obtain a written commitment applicable to the specific Service, provider, model, endpoint, and workflow.
20. Third-Party Services
AutoFoundry may contain links to or integrate with services AutoFoundry does not control.
A customer’s decision to connect, use, or direct information to a third-party service is governed by:
- the customer’s agreement with that provider;
- the provider’s privacy policy;
- the authorization granted by the customer; and
- the provider’s independent practices.
AutoFoundry is not responsible for the independent privacy, security, retention, or data-use practices of a third party acting outside its role as an AutoFoundry service provider or subprocessor.
21. Changes to This Privacy Policy
AutoFoundry may update this Privacy Policy to reflect changes in:
- the Services;
- AI providers;
- subprocessors;
- integrations;
- data practices;
- security practices;
- legal obligations; or
- business operations.
The “Last Updated” date identifies the latest revision.
If a change materially affects how AutoFoundry uses Personal Data or Customer Business Data, AutoFoundry will provide additional notice where required by law or contract.
Where required by law, AutoFoundry will provide affected individuals a reasonable opportunity to withdraw consent from materially different future processing of previously collected Personal Data.
AutoFoundry will not apply a materially expanded use of previously collected Personal Data where consent is legally required without first obtaining that consent.
22. Contact AutoFoundry
Questions, privacy requests, privacy appeals, Data Processing Addendum requests, and subprocessor-list requests may be sent to:
AutoFoundry LTD
Attn: Privacy
Business Mailing Address:
AutoFoundry LTD
9840 Conrad Avenue
Inver Grove Heights, MN 55076
Email: privacy@autofoundry.ai
United States
Customers may also contact their AutoFoundry account representative or use the established support channel available within their account.