Legal draft
Privacy Policy
This page is a working policy outline and should be reviewed by an attorney before launch. The production version should reflect the actual Firebase, Stripe, email, scheduling, analytics, and AI providers used by the business.
Information collected
The site and portal may collect contact details, business details, project notes, uploaded files, AI opportunity notes, billing references, support requests, consent records, and usage records needed to provide services.
How information is used
Information is used to communicate with clients, deliver AI Systems Audits, build and support software systems, maintain billing records, improve service quality, document consent, and protect the portal.
Payments
Payment cards should be handled by Stripe or a similar payment provider. This app should store payment references and status, not raw card numbers.
Security
Client data should be scoped by organization, protected by authentication and authorization rules, stored privately, and accessed only as needed to provide services.