Skip to content

Legal

Privacy Notice

What DueBrief collects, why it is needed, where providers help, and how account and workspace data can be managed.

Status
Pre-launch draft
Last updated
August 2, 2026

1. Scope

This notice covers DueBrief’s marketing pages, accounts, workspaces, questionnaire and Trust Center features, transactional email, support, and public evidence-access flows. The final operating company identity must be inserted before launch.

2. Information we collect

  • Account details such as name, work email, credentials, and workspace membership.
  • Documents, answers, questionnaires, citations, exports, and Trust Center settings.
  • Billing status and provider references, but not complete payment-card details.
  • Security, audit, request, usage-count, and processing-timing information.
  • Prospect work emails, named evidence requests, decisions, grants, and downloads.

3. How information is used

Information is used to provide and secure the service, process files and questionnaires, manage access, send essential messages, administer plans, respond to support and privacy requests, investigate abuse, meet deletion obligations, and measure product performance through content-minimized counts and timestamps.

4. AI processing

DueBrief sends a minimized question, eligible answer candidates, and necessary cited excerpts to its configured AI provider. Full document collections are not sent for each suggestion. Provider storage is disabled for supported calls, and provider terms must be verified before launch.

5. When information is shared

Information is shared with providers only for hosting, storage, email, payments, security scanning, and AI processing; with people a workspace authorizes; when required by law; or as part of a reviewed business transaction. DueBrief does not sell customer security documents or use them for advertising.

6. Retention and deletion

Active information is retained while needed to provide the service and meet legitimate operational or legal requirements. Product deletion removes active access immediately, and backup copies are scheduled for removal within 30 days. Final legal exceptions and retention periods require review before launch.

7. Security

DueBrief uses encryption in transit and at rest, private object storage, short-lived signed access, tenant-scoped authorization, PostgreSQL row-level security, malware scanning, governed audit records, and content-minimized logging. No service can guarantee absolute security.

8. Choices and privacy requests

Account information can be corrected through product settings. Authorized users can request account and workspace deletion in the product. Other access, correction, deletion, or retention questions can be submitted to privacy@duebrief.com; identity and authority must be verified first.

9. International processing and changes

DueBrief’s initial service is designed for a United States hosting region. Provider locations, transfer mechanisms, legal bases, regional disclosures, privacy rights, and the operating company’s address must be confirmed by qualified counsel before launch.

Contact

Questions can be sent to privacy@duebrief.com. The address must be verified and monitored before launch.