Legal
Privacy
What datafact.ai collects from visitors, and how customer data is handled in a DataFact deployment.
This website
datafact.ai is a static site. It sets no advertising cookies, runs no ad networks, and embeds no social tracking scripts.
It does use Google Analytics 4 to count visits and see which pages get read. Analytics storage is set to denied before the tag loads, so no analytics cookie is written unless consent is granted. IP addresses are anonymised. We use this only to understand which parts of the site are useful — there is no advertising, no remarketing, and no profile built about you.
Google Search Console is also verified for this domain. It reports aggregate search queries and crawl health; it does not place anything in your browser.
If you submit the contact form, the details you enter are used to reply to your enquiry. They are not added to a marketing list, and are not sold or shared.
Those submissions are stored in a managed Postgres database hosted by Supabase in the Asia Pacific (Tokyo) region. We store only what you type into the form, the time you sent it, and which page you sent it from — no IP address, no device information, no cookies.
Data inside a deployment
DataFact processes the documents and database records you connect to it. The platform is designed so that this content stays within the boundary you choose:
- On a subscription, your content sits in your own isolated workspace. It is not used to train models and is not shared with other customers.
- On-premise and private cloud deployments retain all content inside your own network.
- Questions, retrievals and answers are stored as the audit trail under your retention policy.
- Model serving can be configured to run entirely on infrastructure you control.
Where a deployment is configured to call an external model provider, the specific provider, region and retention terms are set out in the deployment agreement.
To be completed before launch
The following sections require counsel review and jurisdiction-specific drafting. They are listed here so the gap is explicit rather than hidden:
- Legal basis for processing and, where applicable, the identity of the data controller.
- Data subject rights and the process for exercising them.
- Sub-processor list and international transfer mechanisms.
- Retention periods per data category.
- Security incident notification commitments.
- Regional requirements for each market the site serves.
Contact
Questions about this policy: hello@datafact.ai