Privacy Policy
Privacy Policy
Effective Date: September 16th, 2026
1. Introduction
Understand Tech Inc. ("Understand.tech", "we", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services (the "Site" or "Platform"), when you order or use an AI-in-a-Box appliance, and how we handle data retrieved through third-party integrations and AI features.
This Policy applies to:
Visitors to our website,
Registered users of the Platform (including free, Explorer, Business and Enterprise accounts),
Customers who order and operate AI-in-a-Box appliances, and
End users who interact with AI assistants, portals or workflows hosted on the Platform by our customers.
If you use the Platform on behalf of a company or organization, you confirm that you have authority to do so.
2. Who Is Responsible for Processing Your Personal Data?
Understand Tech Inc., a Delaware corporation, 100 Church St, Rm 800, New York, NY 10007-2621, United States, is the data controller for personal data processed in connection with the Platform and our website.
Where your contract is with our French entity, Understand Consulting Group EURL (Frontignan, France), that entity is the controller for your account, billing and support data, and Understand Tech Inc. acts on its behalf for Platform operations. Both entities apply this Policy.
For certain activities (e.g., R&D, infrastructure operations), our affiliates and service providers act as processors or sub-processors on our behalf. Where required by law, we enter into data processing agreements with these parties.
If you are a Business or Enterprise customer, additional data protection terms may apply under a separate Data Processing Agreement (DPA) or Enterprise Agreement.
3. What Personal Data Do We Collect?
We collect and process the following categories of data, depending on how you use the Platform:
3.1 Account Data
Email address
Name or display name
Profile picture (optional)
Account and notification preferences
Organization / company name (if provided)
Role or job title (if provided)
3.2 Authentication & Authorization Data
Credentials or tokens for third-party services you connect (e.g., OAuth tokens, API keys, access/refresh tokens)
SSO-related identifiers (where Single Sign-On is configured by your organization)
3.3 Billing, Order & Transaction Data (Paid Plans)
Billing contact details (name, email, company, billing address, VAT or tax ID)
Subscription plan, orders, quotes, purchase orders and billing history
Payment-related identifiers from our payment processor (Stripe): payment method type, card brand and last four digits, payment status. We do not store full card numbers; card data is entered on and processed by Stripe under its own privacy policy.
Wire transfer details as they appear on bank statements (payer name, bank reference)
3.4 AI-in-a-Box Order & Delivery Data
If you order an AI-in-a-Box appliance we also process:
Shipping and installation site address and the name, email and phone number of the delivery and on-site contacts
Appliance serial number and the link between the appliance and your account
Information required for export-control and sanctions screening: company legal name, country, ownership information and end-use statements where requested
Warranty and return records (failure reports, replacement shipments, return confirmations)
3.5 User Files & Documents
Data you choose to upload or link, including (as applicable):
Files uploaded directly to the Platform (e.g., PDFs, Office documents, spreadsheets, images, audio)
Data and documents from connected services:
Google Drive
OneDrive / SharePoint
GitHub
Azure DevOps
Jira
Confluence
AWS S3
Notion
Salesforce and other CRM systems
Public or private websites (if you use the web crawler)
Metadata about those files (e.g., filenames, sizes, paths, last modified dates)
3.6 AI Interaction Data
Prompts and questions you or your end users submit
AI-generated responses and artifacts (reports, decks, summaries)
Feedback and ratings on responses (optionally encrypted)
Workflow executions and node-level logs (e.g., which nodes ran, success/failure, timestamps)
3.7 Usage & Device Data
IP address
Browser type, language, and version
Device type and operating system
Page views and interactions (clicks, navigation, timestamps)
Session identifiers, login timestamps, and error logs
Aggregated usage metrics (e.g., number of Prompts, assistants, workflows, training data volume)
3.8 Support & Communication Data
Emails and tickets you send to support@understand.tech
Messages exchanged through our support or feedback channels
Information you provide during demos, onboarding, setup sessions, or account reviews
Content you choose to show us during a remote support session
4. AI-in-a-Box Appliances: Data Stays on Your Premises
AI-in-a-Box appliances run the Understand Tech platform entirely on hardware installed at your site. For these deployments:
Documents, prompts, AI responses, embeddings, logs and configuration are processed and stored on the appliance, inside your network. They are not transmitted to Understand Tech.
The appliance can operate fully offline. Updates are delivered as signed packages that you or our engineers install; installing an update does not send your content to us.
Optional telemetry (appliance health, software version, usage counters, without document or prompt content) can be enabled by your administrators and disabled at any time. It is off by default in air-gapped mode.
We access the appliance only during a support session you open, or when you ship a unit to us for replacement. Before returning an appliance you may wipe its storage using the procedure we provide; on receipt we erase all storage and, on request, issue a certificate of data destruction.
If your administrators enable access to public LLM APIs from the appliance, prompts sent to those providers are processed under the provider's terms; this is your configuration choice.
For AI-in-a-Box customers, Understand Tech therefore processes only the account, order, delivery, billing, screening and support data described in Sections 3.1 to 3.4 and 3.8. You are the controller of all personal data processed on the appliance.
5. Data Source Integrations
We support integrations with several third-party services. Data is only accessed after explicit user or admin authorization.
5.1 Services with Persistent Access
For the following services, once you connect them, we may maintain access (via tokens) to keep assistants and knowledge bases up to date until you revoke access or disconnect:
Google Drive
OneDrive / SharePoint
Salesforce (per-user OAuth, where enabled)
We use such access to:
Index and embed content you select
Refresh content periodically (depending on your configuration)
Synchronize records you configure (e.g., CRM opportunities) in both directions
5.2 Services with Limited / On-Demand Access
For the following services, we typically access data only during active actions (e.g., when you create or update an AI assistant or workflow, or run a specific node):
GitHub
Azure DevOps
Jira
Confluence
AWS S3
Notion
Other HTTP/REST or custom JSON API data sources you configure
We access only the repositories, spaces, buckets, projects, or paths you configure.
5.3 Revoking Access
You can revoke access at any time:
From within the Platform (disconnecting an integration), and/or
Via the third-party platform (e.g., Google Account settings, Microsoft consent dashboard, GitHub / Atlassian / Notion / Salesforce security settings).
Once revoked, we can no longer fetch new data from that service, though we may retain previously ingested content and embeddings as part of your AI assistants and knowledge bases, until you delete them.
6. Use of Google Workspace APIs
Our application uses the following Google Drive API scopes:
https://www.googleapis.com/auth/drive.readonlyhttps://www.googleapis.com/auth/drive.metadata.readonly
These scopes allow us to read and analyze files on your Google Drive for the sole purpose of creating AI assistants and workflows based on content you've authorized us to process.
We comply fully with the Google API Services User Data Policy, including the Limited Use requirements:
We do not use your Google Drive data to train or improve any AI or ML models.
We do not share or sell your Google Drive data.
We only process content to generate AI responses and knowledge bases for your own use and for the operation of assistants you configure.
You may revoke access at any time.
Access to your Google Drive is granted only after your explicit consent and remains active only while connected.
All content access is governed by strict internal security and access control mechanisms.
Disclosure: The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Website Crawling and User Responsibility
We offer functionality that lets you crawl websites and create AI assistants based on publicly available web content.
You are solely responsible for:
Ensuring that you have the right to crawl the website
Respecting the site's
robots.txt, terms of use, and intellectual property rightsEnsuring that you do not ingest content that you are not authorized to process or share
Understand.tech assumes no responsibility or liability for unauthorized web crawling or for any breaches of third-party terms caused by your use of this feature.
8. Use of AI/ML APIs and Models
We use AI/ML providers and models (SaaS and, where applicable, self-hosted or on-premise):
For SaaS LLMs (e.g., OpenAI, Anthropic, Google, Mistral, or the Understand Tech partner AI API), we use enterprise modes or configurations that disable data logging and training by the provider.
For self-hosted, private-cloud and AI-in-a-Box LLMs, your data does not leave the environment you control, except for the minimal telemetry or logs you configure.
This ensures:
Your prompts and documents are not used to train general-purpose foundation models.
Providers do not retain your content beyond what is needed to deliver the response (subject to their enterprise terms).
Optional encryption (including ephemeral key-based or public-key encryption) may be applied to chat logs and feedback stored in our databases.
Specific terms for Business and Enterprise customers may be detailed in your Order Form, Enterprise Agreement or DPA.
9. Why We Process Your Data (Purposes & Legal Bases)
We process your data for the following purposes:
9.1 Service Provision and Account Management
To create and manage your account
To authenticate you and provide secure access
To run AI assistants, workflows, and knowledge bases you configure
To integrate with third-party data sources you connect
To process orders, deliver and install appliances, and manage warranty replacements
9.2 Billing and Payments
To invoice you, collect payments by card or wire, manage renewals and handle overage billing
To detect and prevent payment fraud, together with our payment processor
9.3 Legal Compliance and Screening
To perform export-control and sanctions screening before accepting orders, especially for AI-in-a-Box appliances, as required by U.S. and EU law
To keep accounting, tax and customs records
9.4 Customer Support and Communication
To respond to support requests and technical issues
To notify you about important service updates, security alerts, renewals, or policy changes
To communicate about your subscription, orders and billing
9.5 Service Improvement and Analytics
To understand how the Platform is used (in aggregate and pseudonymized forms)
To improve performance, UX, and features
To detect abuse, anomalies, and security risks
9.6 Marketing (B2B)
To send you product updates, invitations to events, or relevant content (within B2B context) where allowed by law and your preferences.
You can opt out of marketing communications at any time by using the unsubscribe link or contacting us.
Legal Bases (for EEA/UK Users): Depending on the context, we process your data based on:
Contract performance (Art. 6(1)(b) GDPR): to provide the Platform, deliver appliances and related services.
Legitimate interests (Art. 6(1)(f) GDPR): e.g., for security, service improvement, limited B2B marketing, and fraud detection, where these do not override your rights.
Consent (Art. 6(1)(a) GDPR): where required, for certain cookies, marketing, or optional integrations.
Legal obligation (Art. 6(1)(c) GDPR): where we must retain or disclose data under applicable law, including export-control, sanctions, tax and accounting rules.
10. Cookies and Similar Technologies
We use cookies and similar technologies to:
Authenticate and keep you logged in
Maintain session state and security
Measure usage and performance (analytics)
Improve user experience
You can disable cookies via your browser settings, but this may limit certain functionalities (e.g., login, persistent sessions). Where required by law, we will present a cookie banner or preferences manager to obtain your consent for non-essential cookies.
11. Automated Processing and Profiling
We use automated processing to:
Generate responses from AI models based on your prompts and selected data
Execute workflows and apply rules you configure
Screen orders against sanctions and denied-party lists; any match is reviewed by a person before an order is declined
We do not perform automated decision-making that produces legal or similarly significant effects without human involvement. The Platform is a tool to assist humans; final decisions remain with you and your organization.
12. Data Sharing
We do not sell or trade your personal data.
We only share your personal data with:
12.1 Infrastructure and Subprocessors
Cloud hosting providers (e.g., AWS)
Storage, database, and search infrastructure
AI/ML providers (e.g., OpenAI, Anthropic, self-hosted LLMs), in configurations that disable training and logging
Payment processing (Stripe) and banking providers
Monitoring, logging, and analytics tools
Email and communication providers
These providers act as processors or sub-processors and are contractually bound to protect your data. A current list of subprocessors is available in our Trust Center (https://trust.understand.tech) or on request.
12.2 Logistics and Hardware Partners
For AI-in-a-Box, we share delivery contact details and site address with our hardware suppliers and carriers to ship, install and replace appliances, and with customs brokers where required for international shipments.
12.3 CRM and Support Tools
CRM platforms and support tools used to manage our relationship with you (e.g., for ticketing, onboarding, customer success).
12.4 Enterprise, Private-Cloud & On-Prem Customers
For dedicated hosted, private-cloud or AI-in-a-Box deployments, data sharing is further limited and detailed in your specific contract. In these cases, Platform content stays within the environment you control except for the telemetry you choose to send us (Section 4).
12.5 Legal Requirements and Corporate Transactions
We may disclose data:
To comply with applicable laws, legal processes, or enforceable government requests, including export-control and sanctions authorities
To enforce our agreements or protect the rights, property, or safety of Understand Tech, our customers, or others
In connection with a merger, acquisition, financing, or sale of all or part of our business (in which case we will take steps to ensure appropriate safeguards).
13. Data Security
We implement strong security measures designed to protect your data, including:
TLS 1.2+ (or higher) for all data in transit
Encryption at rest using industry-standard algorithms (e.g., AES-256 or equivalent)
Strict network segmentation and access controls; single-tenant isolation for dedicated environments
Role-based access control, confidentiality levels and least-privilege principles
Multi-factor authentication for internal administrative access
Audit logging of authentication, administrative changes, ingestion and access activity
Regular monitoring, logging, and security reviews
Signed software releases for appliance and on-premise updates
Encryption Architecture for Chats and Feedback (Selective Features): For certain plans and features, we use an encryption model where:
Asymmetric key pairs (public/private) are used to derive per-record or per-session symmetric keys.
We store only encrypted values and the non-sensitive metadata required to operate (such as an ephemeral public key).
Decryption keys are held by you or generated from secrets that we do not store in plaintext.
Details on the scope and status of our security certifications (such as SOC 2) are available in our Trust Center or Security Assurance Plan.
14. International Data Transfers
We may process and store data in the United States and other countries where we or our service providers operate. Dedicated hosted environments are provisioned in the region agreed in your Order (for example a United States or European Union region).
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, where data is transferred outside these regions, we rely on:
Adequacy decisions (where applicable, including the EU-U.S. Data Privacy Framework where our providers are certified); and/or
Standard Contractual Clauses (SCCs) or equivalent safeguards with our processors and sub-processors.
You can contact us for more information about these safeguards.
15. Data Retention
We retain personal data only for as long as necessary to:
Provide the Platform and services
Fulfill our contractual and legal obligations
Resolve disputes and enforce our agreements
Maintain appropriate business records (e.g., billing, audit logs)
Retention periods vary depending on the data type and context. Examples:
Account and billing data: retained while your subscription is active and for a reasonable period thereafter (e.g., 3 to 10 years) to meet legal, tax and accounting requirements.
Order, shipping, export-screening and customs records: retained for the period required by export-control and customs law (generally 5 years after shipment in the U.S. and EU).
Logs and analytics data: retained for limited periods to support security and service improvement.
Uploaded documents, assistants, workflows, and chat histories (SaaS): retained until you delete them or your account is closed; after termination they remain available for export for 30 days, then are deleted from production systems and, within the backup retention period (30 days), from backups, subject to legal requirements.
Data on AI-in-a-Box appliances: under your control; erased by us when an appliance is returned.
You can request deletion of your data at any time (see Section 16).
16. Your Rights
Depending on your location, you may have the following rights:
Access: to obtain a copy of your personal data.
Rectification: to correct inaccuracies or incomplete data.
Erasure: to request deletion of personal data, subject to legal and contractual constraints.
Restriction: to request that we limit certain processing.
Portability: to receive personal data in a structured, commonly used, machine-readable format where technically feasible.
Objection: to object to processing based on legitimate interests, including direct marketing.
Withdraw Consent: where processing is based on consent, you can withdraw it at any time.
To exercise these rights, contact us at support@understand.tech. We may need to verify your identity before responding.
If you are in the EEA/UK/Switzerland and believe that our processing of your personal data violates applicable law, you also have the right to lodge a complaint with your local data protection authority (in France, the CNIL).
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have equivalent rights to know, delete, correct and opt out of the sale or sharing of personal data. We do not sell personal data or share it for cross-context behavioral advertising. Requests may be made at the same address, and we do not discriminate against anyone for exercising their rights.
If you are an end user of a customer's assistant or portal, your data is controlled by that customer; please direct requests to them, and we will assist them as their processor.
17. Children's Privacy
Our Platform is not intended for users under the age of 16. We do not knowingly collect personal data from children under this age. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
18. CRM and Workflow Automation Integrations
Our Platform offers optional integrations with CRM systems (such as Salesforce, HubSpot and Zoho) and workflow automation tools (such as n8n).
If you choose to enable these integrations and provide valid API keys or OAuth authorization, our Platform may:
Collect and write information about your end users or contacts (such as name, email, or phone number) to your CRM system
Register and log assistant conversations, opportunities, activities or events in your CRM or automation workflow
These features are provided on your behalf and under your direction. You, as the account owner and host of the assistant, portal or chatbot, are solely responsible for:
Informing your end users of this data collection and logging
Ensuring your use of these integrations complies with applicable privacy laws
Managing and securing your CRM and workflow platform access and configurations
We do not retain or use your end users' CRM data for any purpose other than operating the features you explicitly configure.
19. Changes to This Policy
We may update this Policy from time to time. The date at the top reflects the latest version.
For material changes, we will provide appropriate notice (e.g., via email or in-app notice). Continued use of the Platform after the updated Policy takes effect constitutes your acceptance of the changes.
20. Contact
If you have any questions or requests regarding this Privacy Policy or our data practices, please contact:
Understand Tech Inc.
100 Church St, Rm 800
New York, NY 10007-2621, United States
support@understand.tech
www.understand.tech
For customers contracting with Understand Consulting Group EURL, the same address and email apply, and requests are handled by both entities jointly.
