Privacy

Privacy policy, in plain view.

How we collect, use, retain, and protect information across the Decidian platform and engagements.

Data Path
1
CollectScope-limited, purpose-bound
2
ProcessEncrypted in transit & at rest
3
RetainDocumented per engagement
4
DeleteOn request, on schedule
Last updated: July 24, 2026

Scope

This Privacy Policy describes how Decidian collects, uses, shares, retains, and protects personal information across our website, intelligence platform, RAG + API services, and professional engagements.

Information we collect

We collect (a) information you provide directly — name, business email, organization, and inquiry context submitted through forms; (b) information generated through use — authentication identifiers, API request metadata, audit and replay records of decision packets; and (c) information collected automatically — IP address, device and browser type, and aggregate analytics.

How we use information

We use information to deliver and secure the platform, authenticate users, operate RAG and API surfaces, generate decision packets and audit records, respond to inquiries, fulfill contractual obligations, monitor calibration and reliability, and meet legal and regulatory requirements.

Legal bases

Where applicable (including under GDPR and UK GDPR), we process personal data on the basis of contract performance, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.

Client data and confidentiality

Content you submit through Decidian — including source documents, prompts, RAG corpora, and decision-context inputs — is treated as confidential client data. It is processed under the engagement's data processing terms, is not used to train shared models, and is segregated by tenant.

Sub-processors

We engage a limited set of sub-processors for hosting, observability, and authentication. A current list is available on request and is provided in writing to enterprise customers under their data processing addendum.

International transfers

Where personal data is transferred across jurisdictions, we rely on appropriate safeguards including Standard Contractual Clauses and equivalent mechanisms.

Retention

We retain information only as long as necessary to provide the service, satisfy audit and replay obligations agreed with the client, and comply with legal requirements. Decision packets and audit trails are retained per the engagement's retention schedule.

Security

We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, role-based access controls, least-privilege provisioning, audit logging, and incident response procedures. No system is perfectly secure; we work to reduce risk continuously.

Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or restriction on the processing of your personal information, and may object to certain processing. To exercise these rights, contact us using the details below.

Children

Decidian is an enterprise service. It is not directed to children and we do not knowingly collect personal information from children.

Changes

We may update this Policy to reflect changes in our service, legal requirements, or operational practices. Material changes will be communicated through the platform or via email to enterprise customers.

Contact

Privacy inquiries may be directed to privacy@decidian.tech or via our Contact page.