Iseer Logo

Privacy Policy of Iseer & Co.

This Privacy Policy (hereinafter "Policy") delineates the principles, protocols, and legal framework governing the processing of Personal Data by Iseer & Co. and its affiliates (collectively, "the Company," "Iseer," "We," "Us," "Our"). This document constitutes a binding legal agreement between the Company and all natural persons who access, use, or otherwise interact with Our websites, applications, and proprietary Synthetic Intelligence Systems (collectively, the "Services"). Iseer & Co. is unequivocally committed to upholding the highest standards of data protection and privacy. Our operations are founded upon the legal and ethical principles of Privacy by Design and by Default, which are integral to the entire lifecycle of our technological development, from initial conception to global deployment. This Policy is engineered to provide comprehensive transparency regarding our data processing activities and to ensure our compliance with a complex and evolving global regulatory landscape. It serves as a cornerstone of our commitment to responsible innovation and to fostering a relationship of trust with our users ("Data Subjects," "Consumers," "You," "Your").

Your Privacy Matters

We are committed to protecting your privacy and ensuring transparency in how we collect, use, and protect your information.

Last Updated: October 07, 2025

Article I: Definitional Framework

For the purposes of this Policy, the following terms shall have the meanings ascribed to them below. These definitions are constructed to ensure legal precision and harmonize concepts across multiple international legal frameworks.

1.1. Anonymisation

The irreversible alteration of Personal Data in such a manner that the Data Subject is not or is no longer identifiable by any means reasonably likely to be used, either by the Controller or by any other person. Data that has undergone such a process is not considered Personal Data and falls outside the scope of this Policy.

1.2. Consent

Any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.

1.3. Controller / Business

The natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this Policy, Iseer & Co. is the Controller and/or Business with respect to the Personal Data processed through its Services.

1.4. Data Subject / Consumer

An identified or identifiable natural person to whom Personal Data relates. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier.

1.5. Input

Any data, text, images, files, code, prompts, or other information, content, or material provided by a User to the Synthetic Intelligence System.

1.6. Interaction Data

A comprehensive category of data encompassing all Inputs provided by a User, all Outputs generated by the Synthetic Intelligence System in response thereto, and all associated metadata, including but not limited to, timestamps, session identifiers, user feedback ratings, and feature usage metrics. The creation of this specific definition is a deliberate legal measure to provide absolute clarity regarding the data that may be subject to Processing for the purposes of model training and improvement, thereby mitigating the risk of ambiguity that has been the subject of regulatory scrutiny in the technology sector.

1.7. Output

Any text, images, code, predictions, classifications, or other content, information, or material generated and returned by the Synthetic Intelligence System in response to an Input.

1.8. Personal Data / Personal Information

Any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Data Subject or, where applicable, their household. This definition is intentionally broad to encompass the expansive interpretations under both the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended. It includes, but is not limited to:

  • Direct identifiers such as name, postal address, email address, and account name.
  • Indirect and online identifiers such as an Internet Protocol (IP) address, cookie identifiers, unique personal identifiers, device identifiers, and location data.
  • Commercial information, including records of products or services purchased, obtained, or considered.
  • Subjective information, such as opinions, evaluations, or assessments relating to a natural person.
  • Inferences drawn from any of the information identified above to create a profile about a Data Subject reflecting their preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

1.9. Personal Data Breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.

1.10. Processing

Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. The term is to be interpreted in its broadest sense and includes, but is not limited to, collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

1.11. Processor / Service Provider

A natural or legal person which Processes Personal Data on behalf of the Controller.

1.12. Profiling

Any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

1.13. Pseudonymisation

The Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person. It is critical to note that Personal Data which has undergone Pseudonymisation is still considered Personal Data and remains within the scope of this Policy.

1.14. Special Categories of Personal Data / Sensitive Personal Information

A specific subset of Personal Data which, due to its nature, is afforded a higher level of protection under applicable law. This category includes, but is not limited to, Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; data concerning health; data concerning a natural person's sex life or sexual orientation; government-issued identifiers (such as Social Security, driver's license, or passport numbers); precise geolocation data; and the contents of a user's mail, email, and text messages where the Company is not the intended recipient.

1.15. Synthetic Intelligence System (or "AI System")

A machine-based system developed in computer software, physical hardware, or other context that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the Input it receives how to generate Outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This definition is constructed in alignment with prevailing international legal and technical definitions to ensure regulatory clarity.

1.16. Training Data

Any data used for the purpose of establishing, implementing, maintaining, testing, validating, or continually improving the underlying machine learning models, algorithms, and cognitive architectures of the Synthetic Intelligence System. This may be further classified as (i) Pre-training Data, comprising vast, generalized datasets obtained from publicly available sources and licensed third-party corpora, and (ii) Fine-tuning and Improvement Data, which may, subject to the conditions stipulated in Article VI of this Policy, include certain Interaction Data.

Article II: Scope and Applicability

2.1. Applicability to Individuals

This Policy applies to all natural persons, irrespective of their geographic location, who access or use the Services, visit our websites, or otherwise interact with the Company in a manner that involves the Processing of their Personal Data.

2.2. Territorial Scope

The Company operates on a global basis, and this Policy is designed to be globally applicable, providing a high, harmonized standard of data protection. The Processing of Personal Data by the Company is subject to this Policy regardless of the Data Subject's country of residence. Specific rights and legal provisions applicable to residents of certain jurisdictions are detailed in Article XII. The cross-border nature of our data Processing activities necessitates a robust framework for international compliance.

Article III: Core Principles of Data Processing

The Company's data Processing architecture is predicated upon a steadfast adherence to the fundamental principles of data protection as enshrined in the GDPR and mirrored in preeminent data protection laws worldwide. These principles form the non-negotiable foundation of all our data handling operations.

3.1. Lawfulness, Fairness, and Transparency

All Processing of Personal Data shall be conducted lawfully, fairly, and in a transparent manner in relation to the Data Subject. We shall provide clear, accessible, and comprehensive information about our Processing activities.

3.2. Purpose Limitation

Personal Data shall be collected for specified, explicit, and legitimate purposes and not further Processed in a manner that is incompatible with those purposes. Any secondary use of data will only occur where legally permissible, such as for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to appropriate safeguards.

3.3. Data Minimization

The Personal Data we collect and Process shall be adequate, relevant, and strictly limited to what is necessary in relation to the purposes for which they are Processed. The development of sophisticated AI Systems necessitates the use of large and diverse datasets to ensure model accuracy, safety, and the mitigation of bias. This operational requirement presents a direct tension with the principle of Data Minimization. The Company reconciles this tension by implementing a multi-faceted strategy: (a) utilizing Anonymised or Pseudonymised data for model training and development wherever technically and operationally feasible; (b) architecting our data collection mechanisms to limit the ingestion of direct personal identifiers not essential for the provision of the Services; (c) applying strict data retention schedules to raw data post-processing to ensure it is not held indefinitely; and (d) continuously researching and deploying privacy-enhancing technologies that reduce the data footprint required for model efficacy. This demonstrates a sophisticated and proactive approach to balancing technological necessity with fundamental data protection principles.

3.4. Accuracy

We shall take every reasonable step to ensure that Personal Data are accurate and, where necessary, kept up to date. Mechanisms will be provided for Data Subjects to rectify inaccurate data concerning them.

3.5. Storage Limitation

Personal Data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the Personal Data are Processed. Retention periods are determined based on legal, regulatory, and legitimate business requirements, as detailed in Article X.

3.6. Integrity and Confidentiality (Security)

Personal Data shall be Processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures.

3.7. Accountability

As the Data Controller, the Company is responsible for, and must be able to demonstrate compliance with, the principles enumerated in this Article. This is achieved through comprehensive documentation, regular audits, Data Protection Impact Assessments (DPIAs), and the governance structure outlined in this Policy.

Article IV: Lawful Bases for Data Processing

The Processing of Personal Data by the Company is conducted only where a valid lawful basis exists under applicable data protection law. We have identified and hereby articulate the specific legal grounds for our distinct Processing activities.

4.1. Performance of a Contract (GDPR Article 6(1)(b))

A significant portion of our Processing is necessary for the performance of the contract to which the Data Subject is party, namely our Terms of Service. This includes, but is not limited to:

  • Creating, authenticating, and maintaining user accounts.
  • Processing payments and managing subscriptions for paid Services.
  • Receiving and processing Inputs to generate and deliver Outputs as the core function of the Services.
  • Providing customer support and responding to user inquiries.

4.2. Legitimate Interests (GDPR Article 6(1)(f))

We Process certain Personal Data based on our legitimate interests, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the Data Subject. These activities include:

  • Ensuring the security of our Services, networks, and information systems, including fraud detection, prevention of illegal activity, and mitigation of cybersecurity threats.
  • Analyzing usage patterns to improve the user experience, functionality, and performance of our existing Services.
  • Conducting business analytics and planning.
  • Sending administrative communications regarding the Services, such as updates to our terms or policies.

Note: For each activity based on legitimate interests, we have conducted and documented a Legitimate Interest Assessment (LIA) to balance our interests against those of the Data Subject.

4.3. Consent (GDPR Article 6(1)(a))

We rely on the Data Subject's explicit and informed Consent for certain Processing activities, including:

  • The processing of Special Categories of Personal Data or Sensitive Personal Information that may be incidentally included in Inputs, where no other legal basis applies.
  • The placement of non-essential cookies and similar tracking technologies on a User's device.
  • Sending direct marketing communications via electronic means.
  • As detailed in Section 4.5, for the use of Interaction Data for the purpose of model training and improvement.

Note: Consent, once given, may be withdrawn by the Data Subject at any time without affecting the lawfulness of Processing based on Consent before its withdrawal. The mechanisms for withdrawal shall be as clear and accessible as the mechanisms for granting Consent.

4.4. Legal Obligation (GDPR Article 6(1)(c))

We may Process Personal Data where it is necessary for compliance with a legal obligation to which the Company is subject, such as responding to a lawful subpoena, court order, or request from a regulatory or law enforcement authority.

4.5. Lawful Basis for Model Training and Improvement

The use of Personal Data, specifically Interaction Data, for the purpose of training, fine-tuning, and improving our Synthetic Intelligence Systems represents a high-risk processing activity requiring a distinct and transparent lawful basis. The Company has adopted a bifurcated approach based on user choice and control, reflecting best practices in the AI industry. The primary lawful basis for this activity is the explicit, granular, and opt-in Consent of the Data Subject. By default, Interaction Data is not used for model improvement. Users are provided with a clear and unambiguous choice, typically via their account settings, to permit this specific use of their data. Where a User provides such Consent, they may withdraw it at any time, and such withdrawal will apply prospectively. In certain limited jurisdictions and for specific, narrowly defined improvement purposes (e.g., safety model enhancement), the Company may, in the alternative, rely on its Legitimate Interest, supported by a comprehensive LIA and subject to the Data Subject's absolute right to object.

Article V: Categories of Personal Data Processed

To ensure full transparency, this Article provides a systematic and granular inventory of the categories of Personal Data that the Company Processes, categorized by their source and nature.

5.1. Data Provided Directly by the Data Subject

This category comprises information that Users actively and voluntarily provide when interacting with our Services.

Account Information

When you register for an account, we collect identifiers and professional information, including your name, email address, contact details, account credentials (e.g., password), and, for paid services, payment card information and transaction history.

User-Generated Content (Inputs)

We collect any and all data you provide as Input to our AI System. This may include text, code, questions, documents, images, audio, or other files you upload or submit. The content of these Inputs is determined solely by you.

Communications and Feedback

We collect Personal Data when you communicate with our customer support teams, participate in surveys or research studies, provide feedback on the Services, or otherwise contact us.

5.2. Data Collected Automatically

This category comprises information collected through automated technical means as a consequence of your interaction with our Services.

Usage Data and Technical Information

We collect information about your interactions with the Services, such as the features you use, the actions you take, session duration, and performance metrics. We also collect technical log data, which includes your Internet Protocol (IP) address, browser type and settings, device information (such as operating system and device identifiers), and the dates and times of your requests.

Location Information

We may infer your general geographic location (e.g., country, city) from your IP address. This is used for purposes such as security monitoring (e.g., detecting anomalous login attempts) and optimizing service delivery. We do not collect precise geolocation data without your explicit, prior Consent.

Cookies and Similar Technologies

We use cookies and other tracking technologies to operate and administer our Services, gather usage data, and support our marketing efforts. A detailed explanation of these technologies and your choices regarding them is provided in our separate Cookie Policy.

5.3. Data Obtained from Third-Party Sources

For the purpose of pre-training our foundational AI models, we may Process vast datasets obtained from third-party sources. This data consists primarily of information that is publicly available on the internet or licensed from data providers. We take contractual and technical steps to ensure that such data is sourced lawfully and ethically.

5.4. Inferred, Derived, and Generated Data

This category comprises data that is not directly collected from you but is generated by our systems through the Processing of other data.

Outputs

We Process the Outputs generated by the AI System in response to your Inputs in order to deliver the Service to you. These Outputs are owned by you, subject to our Terms of Service.

Inferences and Profiles

Our AI Systems may, in the course of their operation, draw inferences from the data they Process. In compliance with laws such as the CCPA/CPRA, we hereby disclose that we may generate profiles reflecting a User's preferences, characteristics, behavior, or aptitudes. Such profiling is an inherent function of the AI System's operation and is used to provide and personalize the Services. Where such profiling has a legal or similarly significant effect, you have specific rights as detailed in Article XI.

5.5. Processing of Special Categories of Personal Data and Sensitive Personal Information

The Company does not intentionally collect or solicit Special Categories of Personal Data or Sensitive Personal Information. However, our AI Systems may Process such data if it is contained within the Inputs you provide. In such instances, the Processing is incidental to the provision of the Service. Where applicable law requires a specific legal basis for such Processing (e.g., explicit consent under GDPR), your provision of such data within an Input, coupled with your continued use of the Service, may be interpreted as such consent where no other basis applies. We implement heightened security measures for any such data we identify and advise you not to submit sensitive information you do not wish for us to Process.

Article VI: The Synthetic Intelligence Data Lifecycle and Purposes of Use

This Article provides a detailed and transparent exposition of how Personal Data is utilized within the Company's operational and technological framework, with a particular focus on the lifecycle of data within our Synthetic Intelligence Systems.

6.1. Legitimate Purposes for Processing

The Company Processes Personal Data for the following specified, explicit, and legitimate purposes:

  • Service Provision and Maintenance: To operate, maintain, secure, and provide the core functionalities of our Services.
  • Service Improvement and Development: To understand how our Services are used, to enhance their performance, accuracy, and safety, and to research and develop new features, models, and services.
  • Security and Fraud Prevention: To protect the security and integrity of our systems, prevent misuse, and enforce our Terms of Service and other policies.
  • Legal and Regulatory Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
  • Communication: To communicate with you regarding your account, service updates, security alerts, and support matters.

6.2. Elucidation of the AI Data Lifecycle

To demystify the complex processes underlying our AI Systems, we outline the key stages of the data lifecycle, which are essential for building and maintaining state-of-the-art models.

Data Collection and Pre-processing

The foundational stage involves the acquisition of vast and diverse datasets from public and licensed sources. This data undergoes rigorous pre-processing, including cleaning, normalization, tokenization, and de-duplication, to create a high-quality corpus for training.

Pre-training

Our large-scale, foundational models are pre-trained on this extensive corpus. This unsupervised learning phase allows the model to learn general patterns, grammar, reasoning abilities, and world knowledge.

Fine-tuning and Adaptation

Pre-trained models are then fine-tuned on smaller, more specialized datasets to enhance their performance on specific tasks or in particular domains (e.g., code generation, legal analysis). This may also include Reinforcement Learning with Human Feedback (RLHF) to align model behavior with human preferences and safety guidelines.

Inference

This is the operational stage where the trained model receives a User's Input and generates an Output. This process is computationally intensive and is optimized for speed and efficiency.

Monitoring and Maintenance

Deployed models are continuously monitored for performance degradation, data drift, and the emergence of biases. Regular maintenance and retraining are necessary to ensure the model remains accurate, reliable, and safe over time.

6.3. Policy on Use of Interaction Data for Model Training and Improvement

The use of User data for model improvement is a critical and sensitive aspect of AI development. Our policy is designed to prioritize user control and transparency.

Default Position and User Control

By default, the Interaction Data generated from your use of our consumer Services is not used to train our AI models. You are provided with a clear and easily accessible control mechanism within your account settings to provide your explicit, opt-in Consent to allow us to use your Interaction Data for the purpose of model improvement. This privacy-protective default aligns with emerging best practices among leading AI providers.

Scope of Consent

If you choose to opt-in, your Consent applies prospectively to new Interaction Data generated after the setting is enabled. It allows us to use this data for fine-tuning, validation, and the general improvement of our AI Systems' performance, safety, and capabilities.

Human Review

To enhance model safety and quality, some Interaction Data may be reviewed by authorized human personnel. In such cases, we implement technical measures to protect your privacy, such as disassociating the data from your account and removing direct personal identifiers before review. You are advised not to enter confidential or sensitive information into the Services that you would not want a human reviewer to see.

Data Retention for Training

Interaction Data designated for model improvement pursuant to your Consent may be retained for a longer period than other data, as specified in Article X, to facilitate longitudinal analysis and model development cycles.

Distinction for Enterprise Services

It is essential to distinguish our consumer Services from our enterprise offerings. Enterprise clients are governed by a separate Master Services Agreement and a Data Processing Addendum (DPA). Under these commercial terms, client data, including all Inputs and Outputs, is contractually and technically segregated and is never used to train our general-purpose AI models. This bifurcation of data handling policies reflects the heightened privacy, confidentiality, and intellectual property assurances required by our enterprise clients.

Article VII: Disclosure and Sharing of Personal Data

The Company does not sell Personal Data in the traditional sense of the word. We will only disclose or share Personal Data with third parties under the following limited and legally permissible circumstances:

7.1. Processors / Service Providers

We engage trusted third-party vendors and service providers to perform functions and provide services on our behalf. These may include cloud hosting providers, payment processors, content delivery networks, and customer support service providers. These entities act as our Processors and are contractually bound by Data Processing Agreements to Process Personal Data only upon our instructions and to implement robust security and confidentiality measures.

7.2. Legal and Regulatory Compliance

We may disclose Personal Data if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to:

  • Comply with any applicable law, regulation, legal process, or enforceable governmental request.
  • Enforce our applicable Terms of Service, including investigation of potential violations.
  • Detect, prevent, or otherwise address fraud, security, or technical issues.
  • Protect against harm to the rights, property, or safety of the Company, our users, or the public as required or permitted by law.

7.3. Business Transfers

In the event that the Company is involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your Personal Data may be sold or transferred as part of that transaction. We will provide notice to you before your Personal Data is transferred and becomes subject to a different privacy policy.

7.4. Corporate Affiliates

We may share Personal Data with our corporate affiliates (i.e., entities under common ownership or control) for purposes consistent with this Policy, such as for centralized administration and operational efficiency.

7.5. With Your Consent

We may share Personal Data with third parties for other purposes when we have your explicit Consent to do so.

Article VIII: International Transfers of Personal Data

As a global entity, the Company may transfer Personal Data to, and Process it in, countries other than the country in which you reside. Such cross-border transfers are conducted in strict compliance with applicable data protection laws.

8.1. Mechanisms for Lawful Transfer

We ensure that any transfer of Personal Data from jurisdictions with comprehensive data protection laws (such as the EEA, UK, and Switzerland) to a third country is underpinned by a lawful transfer mechanism. These mechanisms include:

8.2. Transfer Impact Assessments (TIAs)

In accordance with the requirements stemming from the Court of Justice of the European Union's "Schrems II" judgment, for every transfer of Personal Data from the EEA or UK based on SCCs, we conduct and document a rigorous Transfer Impact Assessment (TIA) prior to the transfer. The decision to adhere to the stringent EDPB methodology for all transfers, including those originating from the UK, is a strategic compliance choice. This approach avoids the operational complexity of maintaining dual standards (i.e., the EDPB's TIA vs. the UK ICO's Transfer Risk Assessment) and adopts the highest, most defensible legal standard globally, thereby providing greater assurance to all our users and regulators. Our TIA process involves a case-by-case assessment of:

8.3. Supplementary Measures

Where a TIA reveals that the laws and practices of the third country may impinge on the effectiveness of the SCCs, we will identify and implement effective supplementary measures to ensure that the transferred Personal Data benefits from a level of protection that is essentially equivalent to that guaranteed within the originating jurisdiction. Such measures may be:

Article IX: Data Security and Governance

The Company has implemented a comprehensive, multi-layered security program designed to protect the confidentiality, integrity, and availability of the Personal Data we Process. Our approach is risk-based and continuously evolving to address emerging threats.

9.1. Information Security Management System (ISMS)

We have established and maintain a formal Information Security Management System (ISMS) that provides a systematic approach to managing sensitive company information, including Personal Data. Our ISMS is aligned with the framework and controls specified in the ISO/IEC 27001 international standard, ensuring a holistic and process-oriented approach to information security.

9.2. Third-Party Audits and Certifications

To provide independent assurance of our security and privacy posture, we undergo regular third-party audits against globally recognized standards. We maintain a SOC 2 Type II attestation report, which evaluates the operational effectiveness of our controls over time against the Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, as defined by the American Institute of Certified Public Accountants (AICPA). These certifications serve as external validation of our commitment to robust data governance.

9.3. Technical and Organizational Measures (TOMs)

Our security program includes, but is not limited to, the following TOMs:

Article X: Data Retention and Erasure Policy

In accordance with the principle of storage limitation, the Company retains Personal Data only for the period necessary to fulfill the purposes for which it was collected, to meet our legitimate business needs, and to comply with our legal and regulatory obligations.

10.1. Retention Principles

Our data retention schedules are designed to ensure that Personal Data is not kept in an identifiable form for longer than is necessary. We apply these principles consistently across all categories of Personal Data we Process.

10.2. Criteria for Determining Retention Periods

The specific retention period for any given category of Personal Data is determined by a careful evaluation of several factors, including:

10.3. Specific Retention Periods

While specific periods may vary, our general retention framework is as follows:

10.4. Deletion and Anonymisation Procedures

Upon the expiration of the applicable retention period, Personal Data is securely and permanently deleted from our production systems. In some cases, we may choose to Anonymise the data for statistical or research purposes, in which case it is no longer considered Personal Data.

Article XI: Data Subject and Consumer Rights

The Company recognizes and is committed to facilitating the exercise of the rights granted to individuals under applicable data protection laws. We have established procedures to respond to verifiable requests from Data Subjects and Consumers in a timely and compliant manner.

11.1. The Right of Access

You have the right to obtain from us confirmation as to whether or not Personal Data concerning you is being Processed, and, where that is the case, to access the Personal Data and receive supplementary information about the Processing.

11.2. The Right to Rectification

You have the right to obtain the rectification of inaccurate Personal Data concerning you without undue delay.

11.3. The Right to Erasure ('Right to be Forgotten')

You have the right to obtain the erasure of Personal Data concerning you without undue delay where certain grounds apply, such as when the data is no longer necessary for the purposes for which it was collected or when you withdraw Consent.

11.4. The Right to Restrict Processing

You have the right to obtain a restriction of Processing where certain conditions apply, such as when the accuracy of the Personal Data is contested.

11.5. The Right to Data Portability

Where Processing is based on Consent or a contract and is carried out by automated means, you have the right to receive the Personal Data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller.

11.6. The Right to Object

You have the right to object, on grounds relating to your particular situation, at any time to the Processing of Personal Data concerning you which is based on our legitimate interests. We shall no longer Process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override your interests, rights, and freedoms. You have an absolute right to object to Processing for direct marketing purposes.

11.7. Rights Related to Automated Decision-Making and Profiling

You have the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal or similarly significant effects concerning you. Our Services may involve automated Processing and Profiling to generate Outputs; however, we stipulate in our Terms of Service that these Outputs should not be used as the sole basis for making important decisions about individuals without appropriate human review. We are committed to providing meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing.

Article XII: Jurisdiction-Specific Provisions

While this Policy is designed to provide a globally consistent standard of protection, we recognize that certain jurisdictions have specific legal requirements. This Article provides addenda that supplement and, where applicable, modify the general provisions of this Policy for residents of those jurisdictions.

12.1. Addendum for European Economic Area (EEA), Switzerland, and the United Kingdom

Legal Basis

The lawful bases for Processing your Personal Data are as described in Article IV of this Policy, in accordance with Article 6 of the GDPR.

Data Protection Officer

The contact details for our designated Data Protection Officer are provided in Article XIV.

EU/UK Representative

Pursuant to Article 27 of the GDPR, our designated representative in the European Union and the United Kingdom is.

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the Processing of Personal Data relating to you infringes the GDPR. Contact details for the European Data Protection Supervisor and national supervisory authorities are provided in Annex A.

12.2. Addendum for California and other U.S. States

Virginia residents have the right to: (1) Confirm whether we are processing your personal data and to access such data; (2) Correct inaccuracies; (3) Delete personal data; (4) Obtain a copy of your personal data in a portable format (data portability); and (5) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.

Colorado residents have the right to: (1) Access; (2) Correct; (3) Delete; (4) Data Portability; and (5) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling.

Connecticut residents have the right to: (1) Access; (2) Correct; (3) Delete; (4) Obtain a copy of personal data; and (5) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling.

Utah residents have the right to: (1) Access personal data; (2) Delete personal data they have provided to us; (3) Obtain a copy of the personal data they have provided to us (data portability); and (4) Opt out of the processing of personal data for purposes of targeted advertising or the sale of personal data.

12.3. Addendum for Canada

For residents of Canada, our Processing of Personal Information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA). We adhere to PIPEDA's ten Fair Information Principles: (1) Accountability; (2) Identifying Purposes; (3) Consent; (4) Limiting Collection; (5) Limiting Use, Disclosure, and Retention; (6) Accuracy; (7) Safeguards; (8) Openness; (9) Individual Access; and (10) Challenging Compliance.

12.4. Addendum for Brazil

For residents of Brazil, our Processing of Personal Data is governed by the Lei Geral de Proteção de Dados (LGPD). You have rights under the LGPD including the right to: (1) Confirmation of the existence of the processing; (2) Access to the data; (3) Correction of incomplete, inaccurate or outdated data; (4) Anonymization, blocking or deletion of unnecessary or excessive data; (5) Portability of the data to another service or product provider; and (6) Information about public and private entities with which the controller has shared data.

12.5. Addendum for Australia

For residents of Australia, our handling of Personal Information is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We are committed to complying with the APPs, which govern the open and transparent management of personal information, collection, use and disclosure, data quality and security, and the rights of individuals to access and correct their personal information.

RightGDPR (EEA/UK)CCPA/CPRA (California)VCDPA (Virginia)CPA (Colorado)PIPEDA (Canada)LGPD (Brazil)Privacy Act (Australia)
Right to Access / KnowYesYes (Specific categories & pieces)YesYesYesYesYes
Right to Rectification / CorrectionYesYesYesYesYes (Accuracy)YesYes (Correction)
Right to Erasure / DeletionYes (Conditional)Yes (Conditional)Yes (Conditional)Yes (Conditional)Partial (Withdrawal of Consent)YesYes (Destruction when no longer needed)
Right to Data PortabilityYesYesYesYesNoYesNo
Right to Object to ProcessingYes (for legitimate interests, direct marketing)N/A (See Opt-Out)N/A (See Opt-Out)N/A (See Opt-Out)Yes (Withdrawal of Consent)YesYes (Object to Direct Marketing)
Right to Opt-Out of Sale / SharingN/AYes (Broadly defined)Yes ("Sale")Yes ("Sale")N/ANoNo
Right to Opt-Out of Targeted AdvertisingYes (via Right to Object)Yes (via Opt-Out of Sharing)YesYesNoNoYes
Right to Limit Use of Sensitive InfoYes (Requires explicit consent)YesYes (Requires opt-in consent)Yes (Requires opt-in consent)Yes (Requires consent)Yes (Requires specific consent)Yes (Requires consent)

Article XIII: Personal Data Breach Notification Protocol

The Company maintains a robust incident response plan to address any Personal Data Breach in a timely and effective manner, in full compliance with our legal obligations.

Article XIV: Governance, Amendments, and Contact Information

14.1. Data Protection Officer (DPO)

The Company has appointed a Data Protection Officer who is responsible for overseeing our compliance with this Policy and applicable data protection laws. Our DPO can be contacted for any inquiries, requests, or complaints related to your Personal Data.

14.2. Amendments to this Policy

We reserve the right to amend this Privacy Policy at any time to reflect changes in our practices, the Services, or applicable law. We will provide notice of any material changes by posting the updated Policy on our website and updating the "Last Updated" date. For significant changes, we may also provide more prominent notice, such as by sending an email notification. Your continued use of the Services after the effective date of the revised Policy constitutes your acceptance of the terms.

14.3. How to Contact Us

For general questions about this Privacy Policy or our privacy practices, please contact us at:

Contact Information for Supervisory Authorities

In the spirit of transparency and empowerment, this Annex provides contact information for key data protection and privacy supervisory authorities. This list is provided to facilitate your right to lodge a complaint directly with a competent authority should you have concerns about our processing of your Personal Data. This is not an exhaustive list, and you may have the right to contact an authority in your specific jurisdiction.

European Union

European Data Protection Supervisor (EDPS)
Rue Wiertz 60, B-1047 Brussels, Belgium
+32 2 283 19 00

United Kingdom

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK
0303 123 1113

California, USA

California Privacy Protection Agency (CPPA)
400 R Street, Suite 350, Sacramento, CA 95811, USA
916-572-2900

Virginia, USA

Office of the Attorney General of Virginia, Consumer Protection Section
900 East Main Street, Richmond, VA 23219, USA
1-800-552-9963 (in VA) or 804-786-2042

Colorado, USA

Colorado Attorney General, Consumer Protection Unit

Connecticut, USA

Office of the Attorney General, State of Connecticut
165 Capitol Avenue, Hartford, CT 06106, USA
860-808-5420

Utah, USA

Utah Division of Consumer Protection
PO Box 146704, Salt Lake City, UT 84114-6704, USA
801-530-6601

Canada

Office of the Privacy Commissioner of Canada (OPC)
30 Victoria Street, Gatineau, QC K1A 1H3, Canada
1-800-282-1376

Brazil

Autoridade Nacional de Proteção de Dados (ANPD)
Setor Comercial Norte - SCN, Quadra 6, Conjunto "A", Edifício Venâncio 3000, Bloco "A", 9º andar, CEP 70.716-900 - Brasília – DF, Brazil
+55 (61) 2017-3338

Australia

Office of the Australian Information Commissioner (OAIC)
GPO Box 5288, Sydney NSW 2001, Australia
1300 363 992

France

Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715 – 75334 Paris, Cedex 07, France
+33 1 53 73 22 22

Germany

The Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Straße 153, 53117 Bonn, Germany
+49 228 997799 0

Frequently Asked Questions

What personal data does Iseer collect?
How does Iseer use my data for AI training?
Can I delete my data from Iseer's systems?
How does Iseer protect my data?
Does Iseer share my data with third parties?
How can I exercise my privacy rights?
What happens if there's a data breach?
How often does Iseer update this privacy policy?
Ask Arete