Legal

Privacy Policy

How VISION handles account information, the business context you provide, and the outputs generated from it.

Last updated: 22 August 2026. This policy describes current practices for the VISION platform. Company entity details, data protection contact and any regional representatives are being finalised and will be published here before general availability.

1. Who we are

VISION is an AI business strategy operating system. When you create a workspace, we act as the controller for your account data and as processor for the business content you upload or enter into your workspace.

2. Data we collect

  • Account data: email address, authentication credentials handled by our identity provider, and profile details you enter.
  • Workspace content: business DNA, objectives, constraints, decisions, tasks, evidence, uploaded documents and URLs you ask VISION to ingest.
  • AI interaction data: prompts, model outputs, validation results and generation metadata used for traceability and auditing.
  • Technical data: log entries, device and browser information, IP address and security events.
  • Cookie data: only as described in the Cookie Policy and subject to your consent choices.

3. Why we process it

  • To provide the service: running your workspace, generating recommendations and preserving the decision-to-learning chain.
  • To secure the service: authentication, tenant isolation, abuse prevention and audit logging.
  • To improve the service: aggregated diagnostics and reliability measurement.
  • To communicate: service notices and, where you consent, product updates.

Legal bases under GDPR: performance of a contract, legitimate interests (security and service improvement), consent (non-essential cookies and marketing), and legal obligation where applicable.

4. AI processing

Workspace content may be sent to third-party AI model providers to generate analysis and recommendations. We do not sell your content and we do not use your workspace content to train third-party foundation models. Model outputs are stored with the inputs and prompt versions used, so any recommendation can be traced back to what supported it. AI output is decision support, not professional advice.

5. Sharing and sub-processors

We share data only with infrastructure and service providers acting on our instructions: cloud hosting and database, authentication, AI model providers, analytics (only with consent) and email delivery. A published sub-processor list will accompany our data processing agreement.

6. International transfers

Data may be processed outside your country, including in the United States and the European Union. Where required, transfers rely on Standard Contractual Clauses or an equivalent transfer mechanism, together with technical safeguards such as encryption in transit and at rest.

7. Retention

  • Workspace content is retained while your account is active.
  • Deleting a business removes its records, including its audit trail, under a cascading delete.
  • Account deletion removes account data within 30 days, except where retention is required by law.
  • Security and system logs are kept for a limited period for abuse investigation.

8. Your rights

Depending on where you live you may have the right to access, correct, delete, port or restrict processing of your personal data, to object to processing, and to withdraw consent at any time.

  • EU/UK (GDPR): the rights above plus the right to complain to your supervisory authority.
  • California (CCPA/CPRA): right to know, delete, correct and opt out of sale or sharing. We do not sell personal information.
  • MENA (including Saudi PDPL and UAE PDPL): access, correction, deletion and withdrawal of consent.
  • South-East Asia (including Singapore PDPA and Indonesia PDP Law): access, correction, withdrawal of consent and complaint handling.

To exercise a right, contact us using the address published in the contact section of this site. We respond within the period required by applicable law.

9. Security

Access to workspace data is restricted per tenant at the database level, sensitive history is append-only, privileged operations run server-side, and outbound content fetching is filtered to prevent internal network access. No system is perfectly secure; we notify affected users of qualifying breaches as required by law.

10. Children

VISION is a business tool and is not directed to anyone under 16.

11. Changes

We will post any material change to this policy on this page and update the date above. Continued use after the effective date constitutes acceptance.