Privacy Policy

    Privacy Policy
    Effective Date: September 16th, 2026

    1. Introduction

    Understand Tech Inc. ("Understand.tech", "we", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services (the "Site" or "Platform"), when you order or use an AI-in-a-Box appliance, and how we handle data retrieved through third-party integrations and AI features.

    This Policy applies to:

    • Visitors to our website,

    • Registered users of the Platform (including free, Explorer, Business and Enterprise accounts),

    • Customers who order and operate AI-in-a-Box appliances, and

    • End users who interact with AI assistants, portals or workflows hosted on the Platform by our customers.

    If you use the Platform on behalf of a company or organization, you confirm that you have authority to do so.

    2. Who Is Responsible for Processing Your Personal Data?

    Understand Tech Inc., a Delaware corporation, 100 Church St, Rm 800, New York, NY 10007-2621, United States, is the data controller for personal data processed in connection with the Platform and our website.

    Where your contract is with our French entity, Understand Consulting Group EURL (Frontignan, France), that entity is the controller for your account, billing and support data, and Understand Tech Inc. acts on its behalf for Platform operations. Both entities apply this Policy.

    For certain activities (e.g., R&D, infrastructure operations), our affiliates and service providers act as processors or sub-processors on our behalf. Where required by law, we enter into data processing agreements with these parties.

    If you are a Business or Enterprise customer, additional data protection terms may apply under a separate Data Processing Agreement (DPA) or Enterprise Agreement.

    3. What Personal Data Do We Collect?

    We collect and process the following categories of data, depending on how you use the Platform:

    3.1 Account Data

    • Email address

    • Name or display name

    • Profile picture (optional)

    • Account and notification preferences

    • Organization / company name (if provided)

    • Role or job title (if provided)

    3.2 Authentication & Authorization Data

    • Credentials or tokens for third-party services you connect (e.g., OAuth tokens, API keys, access/refresh tokens)

    • SSO-related identifiers (where Single Sign-On is configured by your organization)

    3.3 Billing, Order & Transaction Data (Paid Plans)

    • Billing contact details (name, email, company, billing address, VAT or tax ID)

    • Subscription plan, orders, quotes, purchase orders and billing history

    • Payment-related identifiers from our payment processor (Stripe): payment method type, card brand and last four digits, payment status. We do not store full card numbers; card data is entered on and processed by Stripe under its own privacy policy.

    • Wire transfer details as they appear on bank statements (payer name, bank reference)

    3.4 AI-in-a-Box Order & Delivery Data

    If you order an AI-in-a-Box appliance we also process:

    • Shipping and installation site address and the name, email and phone number of the delivery and on-site contacts

    • Appliance serial number and the link between the appliance and your account

    • Information required for export-control and sanctions screening: company legal name, country, ownership information and end-use statements where requested

    • Warranty and return records (failure reports, replacement shipments, return confirmations)

    3.5 User Files & Documents

    Data you choose to upload or link, including (as applicable):

    • Files uploaded directly to the Platform (e.g., PDFs, Office documents, spreadsheets, images, audio)

    • Data and documents from connected services:

    • Google Drive

    • OneDrive / SharePoint

    • GitHub

    • Azure DevOps

    • Jira

    • Confluence

    • AWS S3

    • Notion

    • Salesforce and other CRM systems

    • Public or private websites (if you use the web crawler)

    • Metadata about those files (e.g., filenames, sizes, paths, last modified dates)

    3.6 AI Interaction Data

    • Prompts and questions you or your end users submit

    • AI-generated responses and artifacts (reports, decks, summaries)

    • Feedback and ratings on responses (optionally encrypted)

    • Workflow executions and node-level logs (e.g., which nodes ran, success/failure, timestamps)

    3.7 Usage & Device Data

    • IP address

    • Browser type, language, and version

    • Device type and operating system

    • Page views and interactions (clicks, navigation, timestamps)

    • Session identifiers, login timestamps, and error logs

    • Aggregated usage metrics (e.g., number of Prompts, assistants, workflows, training data volume)

    3.8 Support & Communication Data

    • Emails and tickets you send to support@understand.tech

    • Messages exchanged through our support or feedback channels

    • Information you provide during demos, onboarding, setup sessions, or account reviews

    • Content you choose to show us during a remote support session

    4. AI-in-a-Box Appliances: Data Stays on Your Premises

    AI-in-a-Box appliances run the Understand Tech platform entirely on hardware installed at your site. For these deployments:

    • Documents, prompts, AI responses, embeddings, logs and configuration are processed and stored on the appliance, inside your network. They are not transmitted to Understand Tech.

    • The appliance can operate fully offline. Updates are delivered as signed packages that you or our engineers install; installing an update does not send your content to us.

    • Optional telemetry (appliance health, software version, usage counters, without document or prompt content) can be enabled by your administrators and disabled at any time. It is off by default in air-gapped mode.

    • We access the appliance only during a support session you open, or when you ship a unit to us for replacement. Before returning an appliance you may wipe its storage using the procedure we provide; on receipt we erase all storage and, on request, issue a certificate of data destruction.

    • If your administrators enable access to public LLM APIs from the appliance, prompts sent to those providers are processed under the provider's terms; this is your configuration choice.

    For AI-in-a-Box customers, Understand Tech therefore processes only the account, order, delivery, billing, screening and support data described in Sections 3.1 to 3.4 and 3.8. You are the controller of all personal data processed on the appliance.

    5. Data Source Integrations

    We support integrations with several third-party services. Data is only accessed after explicit user or admin authorization.

    5.1 Services with Persistent Access

    For the following services, once you connect them, we may maintain access (via tokens) to keep assistants and knowledge bases up to date until you revoke access or disconnect:

    • Google Drive

    • OneDrive / SharePoint

    • Salesforce (per-user OAuth, where enabled)

    We use such access to:

    • Index and embed content you select

    • Refresh content periodically (depending on your configuration)

    • Synchronize records you configure (e.g., CRM opportunities) in both directions

    5.2 Services with Limited / On-Demand Access

    For the following services, we typically access data only during active actions (e.g., when you create or update an AI assistant or workflow, or run a specific node):

    • GitHub

    • Azure DevOps

    • Jira

    • Confluence

    • AWS S3

    • Notion

    • Other HTTP/REST or custom JSON API data sources you configure

    We access only the repositories, spaces, buckets, projects, or paths you configure.

    5.3 Revoking Access

    You can revoke access at any time:

    • From within the Platform (disconnecting an integration), and/or

    • Via the third-party platform (e.g., Google Account settings, Microsoft consent dashboard, GitHub / Atlassian / Notion / Salesforce security settings).

    Once revoked, we can no longer fetch new data from that service, though we may retain previously ingested content and embeddings as part of your AI assistants and knowledge bases, until you delete them.

    6. Use of Google Workspace APIs

    Our application uses the following Google Drive API scopes:

    • https://www.googleapis.com/auth/drive.readonly

    • https://www.googleapis.com/auth/drive.metadata.readonly

    These scopes allow us to read and analyze files on your Google Drive for the sole purpose of creating AI assistants and workflows based on content you've authorized us to process.

    We comply fully with the Google API Services User Data Policy, including the Limited Use requirements:

    • We do not use your Google Drive data to train or improve any AI or ML models.

    • We do not share or sell your Google Drive data.

    • We only process content to generate AI responses and knowledge bases for your own use and for the operation of assistants you configure.

    • You may revoke access at any time.

    • Access to your Google Drive is granted only after your explicit consent and remains active only while connected.

    • All content access is governed by strict internal security and access control mechanisms.

    Disclosure: The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    7. Website Crawling and User Responsibility

    We offer functionality that lets you crawl websites and create AI assistants based on publicly available web content.

    You are solely responsible for:

    • Ensuring that you have the right to crawl the website

    • Respecting the site's robots.txt, terms of use, and intellectual property rights

    • Ensuring that you do not ingest content that you are not authorized to process or share

    Understand.tech assumes no responsibility or liability for unauthorized web crawling or for any breaches of third-party terms caused by your use of this feature.

    8. Use of AI/ML APIs and Models

    We use AI/ML providers and models (SaaS and, where applicable, self-hosted or on-premise):

    • For SaaS LLMs (e.g., OpenAI, Anthropic, Google, Mistral, or the Understand Tech partner AI API), we use enterprise modes or configurations that disable data logging and training by the provider.

    • For self-hosted, private-cloud and AI-in-a-Box LLMs, your data does not leave the environment you control, except for the minimal telemetry or logs you configure.

    This ensures:

    • Your prompts and documents are not used to train general-purpose foundation models.

    • Providers do not retain your content beyond what is needed to deliver the response (subject to their enterprise terms).

    • Optional encryption (including ephemeral key-based or public-key encryption) may be applied to chat logs and feedback stored in our databases.

    Specific terms for Business and Enterprise customers may be detailed in your Order Form, Enterprise Agreement or DPA.

    9. Why We Process Your Data (Purposes & Legal Bases)

    We process your data for the following purposes:

    9.1 Service Provision and Account Management

    • To create and manage your account

    • To authenticate you and provide secure access

    • To run AI assistants, workflows, and knowledge bases you configure

    • To integrate with third-party data sources you connect

    • To process orders, deliver and install appliances, and manage warranty replacements

    9.2 Billing and Payments

    • To invoice you, collect payments by card or wire, manage renewals and handle overage billing

    • To detect and prevent payment fraud, together with our payment processor

    9.3 Legal Compliance and Screening

    • To perform export-control and sanctions screening before accepting orders, especially for AI-in-a-Box appliances, as required by U.S. and EU law

    • To keep accounting, tax and customs records

    9.4 Customer Support and Communication

    • To respond to support requests and technical issues

    • To notify you about important service updates, security alerts, renewals, or policy changes

    • To communicate about your subscription, orders and billing

    9.5 Service Improvement and Analytics

    • To understand how the Platform is used (in aggregate and pseudonymized forms)

    • To improve performance, UX, and features

    • To detect abuse, anomalies, and security risks

    9.6 Marketing (B2B)

    • To send you product updates, invitations to events, or relevant content (within B2B context) where allowed by law and your preferences.

    • You can opt out of marketing communications at any time by using the unsubscribe link or contacting us.

    Legal Bases (for EEA/UK Users): Depending on the context, we process your data based on:

    • Contract performance (Art. 6(1)(b) GDPR): to provide the Platform, deliver appliances and related services.

    • Legitimate interests (Art. 6(1)(f) GDPR): e.g., for security, service improvement, limited B2B marketing, and fraud detection, where these do not override your rights.

    • Consent (Art. 6(1)(a) GDPR): where required, for certain cookies, marketing, or optional integrations.

    • Legal obligation (Art. 6(1)(c) GDPR): where we must retain or disclose data under applicable law, including export-control, sanctions, tax and accounting rules.

    10. Cookies and Similar Technologies

    We use cookies and similar technologies to:

    • Authenticate and keep you logged in

    • Maintain session state and security

    • Measure usage and performance (analytics)

    • Improve user experience

    You can disable cookies via your browser settings, but this may limit certain functionalities (e.g., login, persistent sessions). Where required by law, we will present a cookie banner or preferences manager to obtain your consent for non-essential cookies.

    11. Automated Processing and Profiling

    We use automated processing to:

    • Generate responses from AI models based on your prompts and selected data

    • Execute workflows and apply rules you configure

    • Screen orders against sanctions and denied-party lists; any match is reviewed by a person before an order is declined

    We do not perform automated decision-making that produces legal or similarly significant effects without human involvement. The Platform is a tool to assist humans; final decisions remain with you and your organization.

    12. Data Sharing

    We do not sell or trade your personal data.

    We only share your personal data with:

    12.1 Infrastructure and Subprocessors

    • Cloud hosting providers (e.g., AWS)

    • Storage, database, and search infrastructure

    • AI/ML providers (e.g., OpenAI, Anthropic, self-hosted LLMs), in configurations that disable training and logging

    • Payment processing (Stripe) and banking providers

    • Monitoring, logging, and analytics tools

    • Email and communication providers

    These providers act as processors or sub-processors and are contractually bound to protect your data. A current list of subprocessors is available in our Trust Center (https://trust.understand.tech) or on request.

    12.2 Logistics and Hardware Partners

    For AI-in-a-Box, we share delivery contact details and site address with our hardware suppliers and carriers to ship, install and replace appliances, and with customs brokers where required for international shipments.

    12.3 CRM and Support Tools

    • CRM platforms and support tools used to manage our relationship with you (e.g., for ticketing, onboarding, customer success).

    12.4 Enterprise, Private-Cloud & On-Prem Customers

    For dedicated hosted, private-cloud or AI-in-a-Box deployments, data sharing is further limited and detailed in your specific contract. In these cases, Platform content stays within the environment you control except for the telemetry you choose to send us (Section 4).

    12.5 Legal Requirements and Corporate Transactions

    We may disclose data:

    • To comply with applicable laws, legal processes, or enforceable government requests, including export-control and sanctions authorities

    • To enforce our agreements or protect the rights, property, or safety of Understand Tech, our customers, or others

    • In connection with a merger, acquisition, financing, or sale of all or part of our business (in which case we will take steps to ensure appropriate safeguards).

    13. Data Security

    We implement strong security measures designed to protect your data, including:

    • TLS 1.2+ (or higher) for all data in transit

    • Encryption at rest using industry-standard algorithms (e.g., AES-256 or equivalent)

    • Strict network segmentation and access controls; single-tenant isolation for dedicated environments

    • Role-based access control, confidentiality levels and least-privilege principles

    • Multi-factor authentication for internal administrative access

    • Audit logging of authentication, administrative changes, ingestion and access activity

    • Regular monitoring, logging, and security reviews

    • Signed software releases for appliance and on-premise updates

    Encryption Architecture for Chats and Feedback (Selective Features): For certain plans and features, we use an encryption model where:

    • Asymmetric key pairs (public/private) are used to derive per-record or per-session symmetric keys.

    • We store only encrypted values and the non-sensitive metadata required to operate (such as an ephemeral public key).

    • Decryption keys are held by you or generated from secrets that we do not store in plaintext.

    Details on the scope and status of our security certifications (such as SOC 2) are available in our Trust Center or Security Assurance Plan.

    14. International Data Transfers

    We may process and store data in the United States and other countries where we or our service providers operate. Dedicated hosted environments are provisioned in the region agreed in your Order (for example a United States or European Union region).

    For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, where data is transferred outside these regions, we rely on:

    • Adequacy decisions (where applicable, including the EU-U.S. Data Privacy Framework where our providers are certified); and/or

    • Standard Contractual Clauses (SCCs) or equivalent safeguards with our processors and sub-processors.

    You can contact us for more information about these safeguards.

    15. Data Retention

    We retain personal data only for as long as necessary to:

    • Provide the Platform and services

    • Fulfill our contractual and legal obligations

    • Resolve disputes and enforce our agreements

    • Maintain appropriate business records (e.g., billing, audit logs)

    Retention periods vary depending on the data type and context. Examples:

    • Account and billing data: retained while your subscription is active and for a reasonable period thereafter (e.g., 3 to 10 years) to meet legal, tax and accounting requirements.

    • Order, shipping, export-screening and customs records: retained for the period required by export-control and customs law (generally 5 years after shipment in the U.S. and EU).

    • Logs and analytics data: retained for limited periods to support security and service improvement.

    • Uploaded documents, assistants, workflows, and chat histories (SaaS): retained until you delete them or your account is closed; after termination they remain available for export for 30 days, then are deleted from production systems and, within the backup retention period (30 days), from backups, subject to legal requirements.

    • Data on AI-in-a-Box appliances: under your control; erased by us when an appliance is returned.

    You can request deletion of your data at any time (see Section 16).

    16. Your Rights

    Depending on your location, you may have the following rights:

    • Access: to obtain a copy of your personal data.

    • Rectification: to correct inaccuracies or incomplete data.

    • Erasure: to request deletion of personal data, subject to legal and contractual constraints.

    • Restriction: to request that we limit certain processing.

    • Portability: to receive personal data in a structured, commonly used, machine-readable format where technically feasible.

    • Objection: to object to processing based on legitimate interests, including direct marketing.

    • Withdraw Consent: where processing is based on consent, you can withdraw it at any time.

    To exercise these rights, contact us at support@understand.tech. We may need to verify your identity before responding.

    If you are in the EEA/UK/Switzerland and believe that our processing of your personal data violates applicable law, you also have the right to lodge a complaint with your local data protection authority (in France, the CNIL).

    If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have equivalent rights to know, delete, correct and opt out of the sale or sharing of personal data. We do not sell personal data or share it for cross-context behavioral advertising. Requests may be made at the same address, and we do not discriminate against anyone for exercising their rights.

    If you are an end user of a customer's assistant or portal, your data is controlled by that customer; please direct requests to them, and we will assist them as their processor.

    17. Children's Privacy

    Our Platform is not intended for users under the age of 16. We do not knowingly collect personal data from children under this age. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.

    18. CRM and Workflow Automation Integrations

    Our Platform offers optional integrations with CRM systems (such as Salesforce, HubSpot and Zoho) and workflow automation tools (such as n8n).

    If you choose to enable these integrations and provide valid API keys or OAuth authorization, our Platform may:

    • Collect and write information about your end users or contacts (such as name, email, or phone number) to your CRM system

    • Register and log assistant conversations, opportunities, activities or events in your CRM or automation workflow

    These features are provided on your behalf and under your direction. You, as the account owner and host of the assistant, portal or chatbot, are solely responsible for:

    • Informing your end users of this data collection and logging

    • Ensuring your use of these integrations complies with applicable privacy laws

    • Managing and securing your CRM and workflow platform access and configurations

    We do not retain or use your end users' CRM data for any purpose other than operating the features you explicitly configure.

    19. Changes to This Policy

    We may update this Policy from time to time. The date at the top reflects the latest version.

    For material changes, we will provide appropriate notice (e.g., via email or in-app notice). Continued use of the Platform after the updated Policy takes effect constitutes your acceptance of the changes.

    20. Contact

    If you have any questions or requests regarding this Privacy Policy or our data practices, please contact:

    Understand Tech Inc.
    100 Church St, Rm 800
    New York, NY 10007-2621, United States
    support@understand.tech
    www.understand.tech

    For customers contracting with Understand Consulting Group EURL, the same address and email apply, and requests are handled by both entities jointly.

    Chat with AI Assistant