Scope
This Privacy Policy describes how Decidian collects, uses, shares, retains, and protects personal information across our website, intelligence platform, RAG + API services, and professional engagements.
How we collect, use, retain, and protect information across the Decidian platform and engagements.
This Privacy Policy describes how Decidian collects, uses, shares, retains, and protects personal information across our website, intelligence platform, RAG + API services, and professional engagements.
We collect (a) information you provide directly — name, business email, organization, and inquiry context submitted through forms; (b) information generated through use — authentication identifiers, API request metadata, audit and replay records of decision packets; and (c) information collected automatically — IP address, device and browser type, and aggregate analytics.
We use information to deliver and secure the platform, authenticate users, operate RAG and API surfaces, generate decision packets and audit records, respond to inquiries, fulfill contractual obligations, monitor calibration and reliability, and meet legal and regulatory requirements.
Where applicable (including under GDPR and UK GDPR), we process personal data on the basis of contract performance, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.
Content you submit through Decidian — including source documents, prompts, RAG corpora, and decision-context inputs — is treated as confidential client data. It is processed under the engagement's data processing terms, is not used to train shared models, and is segregated by tenant.
We engage a limited set of sub-processors for hosting, observability, and authentication. A current list is available on request and is provided in writing to enterprise customers under their data processing addendum.
Where personal data is transferred across jurisdictions, we rely on appropriate safeguards including Standard Contractual Clauses and equivalent mechanisms.
We retain information only as long as necessary to provide the service, satisfy audit and replay obligations agreed with the client, and comply with legal requirements. Decision packets and audit trails are retained per the engagement's retention schedule.
We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, role-based access controls, least-privilege provisioning, audit logging, and incident response procedures. No system is perfectly secure; we work to reduce risk continuously.
Subject to applicable law, you may request access to, correction of, deletion of, or restriction on the processing of your personal information, and may object to certain processing. To exercise these rights, contact us using the details below.
Decidian is an enterprise service. It is not directed to children and we do not knowingly collect personal information from children.
We may update this Policy to reflect changes in our service, legal requirements, or operational practices. Material changes will be communicated through the platform or via email to enterprise customers.
Privacy inquiries may be directed to privacy@decidian.tech or via our Contact page.