متاح بالإنجليزية فقط
تُنشر النصوص القانونية بالإنجليزية، والنسخة الإنجليزية هي النسخة المعتمدة. اطلب منا ترجمة إن احتجت إليها للمراجعة.
Legal
Privacy
What datafact.ai collects from visitors, what happens in a demo workspace, and how customer data is handled in a DataFact deployment.
This website
datafact.ai is a static site. It sets no advertising cookies, runs no ad networks, and embeds no social tracking scripts.
It does use Google Analytics 4 to count visits and see which pages get read. Analytics storage is set to denied before the tag loads, so nothing is written to your browser unless you consent. If you do consent, Google Analytics sets a cookie containing a pseudonymous identifier that tells one browser apart from another across visits, and your IP address is truncated before it is processed.
We call that identifier pseudonymous rather than anonymous deliberately. It carries no name, but it can single out a browser — and that is enough for it to count as personal information under both Chinese and European law. You can withdraw consent at any time; see Your rights.
Google Search Console is also verified for this domain. It reports aggregate search queries and crawl health; it does not place anything in your browser.
If you submit the contact form, the details you enter are used to reply to your enquiry. They are not added to a marketing list, and are not sold or shared.
Those submissions are stored in a managed Postgres database hosted by Supabase in the Asia Pacific (Tokyo) region. We store only what you type into the form, the time you sent it, and which page you sent it from — no IP address, no device information, no cookies.
Enquiries are kept for 24 months after we have dealt with them, so that we can pick up a conversation you resume later, and are deleted after that. You can ask us to delete yours sooner.
Demo workspaces
Try demo leads to a demo workspace hosted at app.datafact.ai. That workspace is a real DataFact environment, not a mock-up or a canned recording: whatever you put into it is processed by the same platform that runs a customer deployment.
Each visitor gets their own isolated workspace. It is created when you start and it is destroyed automatically 30 days after you last use it. Destruction removes the workspace and everything inside it — uploaded files, questions, retrievals and generated answers alike.
While a demo workspace exists, it holds:
- the documents and data you upload to it;
- the questions you ask, the passages retrieved, and the answers produced;
- a session identifier that keeps the workspace attached to your browser between visits, so you can come back to what you were doing. It is pseudonymous in exactly the sense described above — no name attached, but capable of singling out one visitor.
Demo content is not used to train models. It may be read by our engineers where that is necessary to diagnose a fault you have reported or to investigate abuse of the environment, and for no other purpose.
Please do not put real, confidential, personal or regulated data into a demo workspace.It exists so you can evaluate how the product behaves, and sample data does that job perfectly well. If you want to evaluate DataFact against your own live content, that is what a scoped trial or a private deployment is for — talk to us and we will set one up under an agreement that covers it properly.
Data inside a deployment
DataFact processes the documents and database records you connect to it. The platform is designed so that this content stays within the boundary you choose:
- On a subscription, your content sits in your own isolated workspace. It is not used to train models and is not shared with other customers.
- On-premise and private cloud deployments retain all content inside your own network.
- Questions, retrievals and answers are stored as the audit trail under your retention policy.
- Model serving can be configured to run entirely on infrastructure you control.
Where a deployment is configured to call an external model provider, the specific provider, region and retention terms are set out in the deployment agreement.
Your rights
You can ask us to show you what we hold about you, correct it, or delete it, and you can withdraw analytics consent at any time. Write to hello@datafact.ai and we will respond.
Two things we would rather state plainly than bury:
- Deleting a record from our live systems does not instantly erase it from encrypted backups. Those age out on their own cycle, and we do not restore deleted records from them.
- For a demo workspace we can only find you by the session identifier held in your browser — we do not know your name. If you no longer have that browser, we may genuinely be unable to locate your workspace. Where that happens we will tell you so directly rather than leave the request unanswered, and the workspace will still expire on its own schedule.
To be completed before launch
The following sections require counsel review and jurisdiction-specific drafting. They are listed here so the gap is explicit rather than hidden:
- Legal basis for processing and, where applicable, the identity of the data controller.
- Sub-processor list and international transfer mechanisms.
- Security incident notification commitments.
- Regional requirements for each market the site serves.
- Whether a personal information protection impact assessment is required for the demo environment, and whether the retention periods stated above are the ones counsel wants to commit to.
Contact
Questions about this policy: hello@datafact.ai