1. Scope
This notice covers DueBrief’s marketing pages, accounts, workspaces, questionnaire and Trust Center features, transactional email, support, and public evidence-access flows. The final operating company identity must be inserted before launch.
2. Information we collect
- Account details such as name, work email, credentials, and workspace membership.
- Documents, answers, questionnaires, citations, exports, and Trust Center settings.
- Billing status and provider references, but not complete payment-card details.
- Security, audit, request, usage-count, and processing-timing information.
- Prospect work emails, named evidence requests, decisions, grants, and downloads.
3. How information is used
Information is used to provide and secure the service, process files and questionnaires, manage access, send essential messages, administer plans, respond to support and privacy requests, investigate abuse, meet deletion obligations, and measure product performance through content-minimized counts and timestamps.
4. AI processing
DueBrief sends a minimized question, eligible answer candidates, and necessary cited excerpts to its configured AI provider. Full document collections are not sent for each suggestion. Provider storage is disabled for supported calls, and provider terms must be verified before launch.
5. When information is shared
Information is shared with providers only for hosting, storage, email, payments, security scanning, and AI processing; with people a workspace authorizes; when required by law; or as part of a reviewed business transaction. DueBrief does not sell customer security documents or use them for advertising.
6. Retention and deletion
Active information is retained while needed to provide the service and meet legitimate operational or legal requirements. Product deletion removes active access immediately, and backup copies are scheduled for removal within 30 days. Final legal exceptions and retention periods require review before launch.
7. Security
DueBrief uses encryption in transit and at rest, private object storage, short-lived signed access, tenant-scoped authorization, PostgreSQL row-level security, malware scanning, governed audit records, and content-minimized logging. No service can guarantee absolute security.
8. Choices and privacy requests
Account information can be corrected through product settings. Authorized users can request account and workspace deletion in the product. Other access, correction, deletion, or retention questions can be submitted to privacy@duebrief.com; identity and authority must be verified first.
9. International processing and changes
DueBrief’s initial service is designed for a United States hosting region. Provider locations, transfer mechanisms, legal bases, regional disclosures, privacy rights, and the operating company’s address must be confirmed by qualified counsel before launch.
Contact
Questions can be sent to privacy@duebrief.com. The address must be verified and monitored before launch.