Privacy Policy of Iseer & Co.
This Privacy Policy (hereinafter "Policy") delineates the principles, protocols, and legal framework governing the processing of Personal Data by Iseer & Co. and its affiliates (collectively, "the Company," "Iseer," "We," "Us," "Our"). This document constitutes a binding legal agreement between the Company and all natural persons who access, use, or otherwise interact with Our websites, applications, and proprietary Synthetic Intelligence Systems (collectively, the "Services"). Iseer & Co. is unequivocally committed to upholding the highest standards of data protection and privacy. Our operations are founded upon the legal and ethical principles of Privacy by Design and by Default, which are integral to the entire lifecycle of our technological development, from initial conception to global deployment. This Policy is engineered to provide comprehensive transparency regarding our data processing activities and to ensure our compliance with a complex and evolving global regulatory landscape. It serves as a cornerstone of our commitment to responsible innovation and to fostering a relationship of trust with our users ("Data Subjects," "Consumers," "You," "Your").
Your Privacy Matters
We are committed to protecting your privacy and ensuring transparency in how we collect, use, and protect your information.
Last Updated: October 07, 2025
Article I: Definitional Framework
For the purposes of this Policy, the following terms shall have the meanings ascribed to them below. These definitions are constructed to ensure legal precision and harmonize concepts across multiple international legal frameworks.
1.1. Anonymisation
The irreversible alteration of Personal Data in such a manner that the Data Subject is not or is no longer identifiable by any means reasonably likely to be used, either by the Controller or by any other person. Data that has undergone such a process is not considered Personal Data and falls outside the scope of this Policy.
1.2. Consent
Any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.
1.3. Controller / Business
The natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this Policy, Iseer & Co. is the Controller and/or Business with respect to the Personal Data processed through its Services.
1.4. Data Subject / Consumer
An identified or identifiable natural person to whom Personal Data relates. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier.
1.5. Input
Any data, text, images, files, code, prompts, or other information, content, or material provided by a User to the Synthetic Intelligence System.
1.6. Interaction Data
A comprehensive category of data encompassing all Inputs provided by a User, all Outputs generated by the Synthetic Intelligence System in response thereto, and all associated metadata, including but not limited to, timestamps, session identifiers, user feedback ratings, and feature usage metrics. The creation of this specific definition is a deliberate legal measure to provide absolute clarity regarding the data that may be subject to Processing for the purposes of model training and improvement, thereby mitigating the risk of ambiguity that has been the subject of regulatory scrutiny in the technology sector.
1.7. Output
Any text, images, code, predictions, classifications, or other content, information, or material generated and returned by the Synthetic Intelligence System in response to an Input.
1.8. Personal Data / Personal Information
Any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Data Subject or, where applicable, their household. This definition is intentionally broad to encompass the expansive interpretations under both the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended. It includes, but is not limited to:
- Direct identifiers such as name, postal address, email address, and account name.
- Indirect and online identifiers such as an Internet Protocol (IP) address, cookie identifiers, unique personal identifiers, device identifiers, and location data.
- Commercial information, including records of products or services purchased, obtained, or considered.
- Subjective information, such as opinions, evaluations, or assessments relating to a natural person.
- Inferences drawn from any of the information identified above to create a profile about a Data Subject reflecting their preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
1.9. Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.
1.10. Processing
Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. The term is to be interpreted in its broadest sense and includes, but is not limited to, collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.11. Processor / Service Provider
A natural or legal person which Processes Personal Data on behalf of the Controller.
1.12. Profiling
Any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
1.13. Pseudonymisation
The Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person. It is critical to note that Personal Data which has undergone Pseudonymisation is still considered Personal Data and remains within the scope of this Policy.
1.14. Special Categories of Personal Data / Sensitive Personal Information
A specific subset of Personal Data which, due to its nature, is afforded a higher level of protection under applicable law. This category includes, but is not limited to, Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; data concerning health; data concerning a natural person's sex life or sexual orientation; government-issued identifiers (such as Social Security, driver's license, or passport numbers); precise geolocation data; and the contents of a user's mail, email, and text messages where the Company is not the intended recipient.
1.15. Synthetic Intelligence System (or "AI System")
A machine-based system developed in computer software, physical hardware, or other context that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the Input it receives how to generate Outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This definition is constructed in alignment with prevailing international legal and technical definitions to ensure regulatory clarity.
1.16. Training Data
Any data used for the purpose of establishing, implementing, maintaining, testing, validating, or continually improving the underlying machine learning models, algorithms, and cognitive architectures of the Synthetic Intelligence System. This may be further classified as (i) Pre-training Data, comprising vast, generalized datasets obtained from publicly available sources and licensed third-party corpora, and (ii) Fine-tuning and Improvement Data, which may, subject to the conditions stipulated in Article VI of this Policy, include certain Interaction Data.
Article II: Scope and Applicability
2.1. Applicability to Individuals
This Policy applies to all natural persons, irrespective of their geographic location, who access or use the Services, visit our websites, or otherwise interact with the Company in a manner that involves the Processing of their Personal Data.
2.2. Territorial Scope
The Company operates on a global basis, and this Policy is designed to be globally applicable, providing a high, harmonized standard of data protection. The Processing of Personal Data by the Company is subject to this Policy regardless of the Data Subject's country of residence. Specific rights and legal provisions applicable to residents of certain jurisdictions are detailed in Article XII. The cross-border nature of our data Processing activities necessitates a robust framework for international compliance.
Article III: Core Principles of Data Processing
The Company's data Processing architecture is predicated upon a steadfast adherence to the fundamental principles of data protection as enshrined in the GDPR and mirrored in preeminent data protection laws worldwide. These principles form the non-negotiable foundation of all our data handling operations.
3.1. Lawfulness, Fairness, and Transparency
All Processing of Personal Data shall be conducted lawfully, fairly, and in a transparent manner in relation to the Data Subject. We shall provide clear, accessible, and comprehensive information about our Processing activities.
3.2. Purpose Limitation
Personal Data shall be collected for specified, explicit, and legitimate purposes and not further Processed in a manner that is incompatible with those purposes. Any secondary use of data will only occur where legally permissible, such as for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to appropriate safeguards.
3.3. Data Minimization
The Personal Data we collect and Process shall be adequate, relevant, and strictly limited to what is necessary in relation to the purposes for which they are Processed. The development of sophisticated AI Systems necessitates the use of large and diverse datasets to ensure model accuracy, safety, and the mitigation of bias. This operational requirement presents a direct tension with the principle of Data Minimization. The Company reconciles this tension by implementing a multi-faceted strategy: (a) utilizing Anonymised or Pseudonymised data for model training and development wherever technically and operationally feasible; (b) architecting our data collection mechanisms to limit the ingestion of direct personal identifiers not essential for the provision of the Services; (c) applying strict data retention schedules to raw data post-processing to ensure it is not held indefinitely; and (d) continuously researching and deploying privacy-enhancing technologies that reduce the data footprint required for model efficacy. This demonstrates a sophisticated and proactive approach to balancing technological necessity with fundamental data protection principles.
3.4. Accuracy
We shall take every reasonable step to ensure that Personal Data are accurate and, where necessary, kept up to date. Mechanisms will be provided for Data Subjects to rectify inaccurate data concerning them.
3.5. Storage Limitation
Personal Data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the Personal Data are Processed. Retention periods are determined based on legal, regulatory, and legitimate business requirements, as detailed in Article X.
3.6. Integrity and Confidentiality (Security)
Personal Data shall be Processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures.
3.7. Accountability
As the Data Controller, the Company is responsible for, and must be able to demonstrate compliance with, the principles enumerated in this Article. This is achieved through comprehensive documentation, regular audits, Data Protection Impact Assessments (DPIAs), and the governance structure outlined in this Policy.
Article IV: Lawful Bases for Data Processing
The Processing of Personal Data by the Company is conducted only where a valid lawful basis exists under applicable data protection law. We have identified and hereby articulate the specific legal grounds for our distinct Processing activities.
4.1. Performance of a Contract (GDPR Article 6(1)(b))
A significant portion of our Processing is necessary for the performance of the contract to which the Data Subject is party, namely our Terms of Service. This includes, but is not limited to:
- Creating, authenticating, and maintaining user accounts.
- Processing payments and managing subscriptions for paid Services.
- Receiving and processing Inputs to generate and deliver Outputs as the core function of the Services.
- Providing customer support and responding to user inquiries.
4.2. Legitimate Interests (GDPR Article 6(1)(f))
We Process certain Personal Data based on our legitimate interests, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the Data Subject. These activities include:
- Ensuring the security of our Services, networks, and information systems, including fraud detection, prevention of illegal activity, and mitigation of cybersecurity threats.
- Analyzing usage patterns to improve the user experience, functionality, and performance of our existing Services.
- Conducting business analytics and planning.
- Sending administrative communications regarding the Services, such as updates to our terms or policies.
Note: For each activity based on legitimate interests, we have conducted and documented a Legitimate Interest Assessment (LIA) to balance our interests against those of the Data Subject.
4.3. Consent (GDPR Article 6(1)(a))
We rely on the Data Subject's explicit and informed Consent for certain Processing activities, including:
- The processing of Special Categories of Personal Data or Sensitive Personal Information that may be incidentally included in Inputs, where no other legal basis applies.
- The placement of non-essential cookies and similar tracking technologies on a User's device.
- Sending direct marketing communications via electronic means.
- As detailed in Section 4.5, for the use of Interaction Data for the purpose of model training and improvement.
Note: Consent, once given, may be withdrawn by the Data Subject at any time without affecting the lawfulness of Processing based on Consent before its withdrawal. The mechanisms for withdrawal shall be as clear and accessible as the mechanisms for granting Consent.
4.4. Legal Obligation (GDPR Article 6(1)(c))
We may Process Personal Data where it is necessary for compliance with a legal obligation to which the Company is subject, such as responding to a lawful subpoena, court order, or request from a regulatory or law enforcement authority.
4.5. Lawful Basis for Model Training and Improvement
The use of Personal Data, specifically Interaction Data, for the purpose of training, fine-tuning, and improving our Synthetic Intelligence Systems represents a high-risk processing activity requiring a distinct and transparent lawful basis. The Company has adopted a bifurcated approach based on user choice and control, reflecting best practices in the AI industry. The primary lawful basis for this activity is the explicit, granular, and opt-in Consent of the Data Subject. By default, Interaction Data is not used for model improvement. Users are provided with a clear and unambiguous choice, typically via their account settings, to permit this specific use of their data. Where a User provides such Consent, they may withdraw it at any time, and such withdrawal will apply prospectively. In certain limited jurisdictions and for specific, narrowly defined improvement purposes (e.g., safety model enhancement), the Company may, in the alternative, rely on its Legitimate Interest, supported by a comprehensive LIA and subject to the Data Subject's absolute right to object.
Article V: Categories of Personal Data Processed
To ensure full transparency, this Article provides a systematic and granular inventory of the categories of Personal Data that the Company Processes, categorized by their source and nature.
5.1. Data Provided Directly by the Data Subject
This category comprises information that Users actively and voluntarily provide when interacting with our Services.
Account Information
When you register for an account, we collect identifiers and professional information, including your name, email address, contact details, account credentials (e.g., password), and, for paid services, payment card information and transaction history.
User-Generated Content (Inputs)
We collect any and all data you provide as Input to our AI System. This may include text, code, questions, documents, images, audio, or other files you upload or submit. The content of these Inputs is determined solely by you.
Communications and Feedback
We collect Personal Data when you communicate with our customer support teams, participate in surveys or research studies, provide feedback on the Services, or otherwise contact us.
5.2. Data Collected Automatically
This category comprises information collected through automated technical means as a consequence of your interaction with our Services.
Usage Data and Technical Information
We collect information about your interactions with the Services, such as the features you use, the actions you take, session duration, and performance metrics. We also collect technical log data, which includes your Internet Protocol (IP) address, browser type and settings, device information (such as operating system and device identifiers), and the dates and times of your requests.
Location Information
We may infer your general geographic location (e.g., country, city) from your IP address. This is used for purposes such as security monitoring (e.g., detecting anomalous login attempts) and optimizing service delivery. We do not collect precise geolocation data without your explicit, prior Consent.
Cookies and Similar Technologies
We use cookies and other tracking technologies to operate and administer our Services, gather usage data, and support our marketing efforts. A detailed explanation of these technologies and your choices regarding them is provided in our separate Cookie Policy.
5.3. Data Obtained from Third-Party Sources
For the purpose of pre-training our foundational AI models, we may Process vast datasets obtained from third-party sources. This data consists primarily of information that is publicly available on the internet or licensed from data providers. We take contractual and technical steps to ensure that such data is sourced lawfully and ethically.
5.4. Inferred, Derived, and Generated Data
This category comprises data that is not directly collected from you but is generated by our systems through the Processing of other data.
Outputs
We Process the Outputs generated by the AI System in response to your Inputs in order to deliver the Service to you. These Outputs are owned by you, subject to our Terms of Service.
Inferences and Profiles
Our AI Systems may, in the course of their operation, draw inferences from the data they Process. In compliance with laws such as the CCPA/CPRA, we hereby disclose that we may generate profiles reflecting a User's preferences, characteristics, behavior, or aptitudes. Such profiling is an inherent function of the AI System's operation and is used to provide and personalize the Services. Where such profiling has a legal or similarly significant effect, you have specific rights as detailed in Article XI.
5.5. Processing of Special Categories of Personal Data and Sensitive Personal Information
The Company does not intentionally collect or solicit Special Categories of Personal Data or Sensitive Personal Information. However, our AI Systems may Process such data if it is contained within the Inputs you provide. In such instances, the Processing is incidental to the provision of the Service. Where applicable law requires a specific legal basis for such Processing (e.g., explicit consent under GDPR), your provision of such data within an Input, coupled with your continued use of the Service, may be interpreted as such consent where no other basis applies. We implement heightened security measures for any such data we identify and advise you not to submit sensitive information you do not wish for us to Process.
Article VI: The Synthetic Intelligence Data Lifecycle and Purposes of Use
This Article provides a detailed and transparent exposition of how Personal Data is utilized within the Company's operational and technological framework, with a particular focus on the lifecycle of data within our Synthetic Intelligence Systems.
6.1. Legitimate Purposes for Processing
The Company Processes Personal Data for the following specified, explicit, and legitimate purposes:
- Service Provision and Maintenance: To operate, maintain, secure, and provide the core functionalities of our Services.
- Service Improvement and Development: To understand how our Services are used, to enhance their performance, accuracy, and safety, and to research and develop new features, models, and services.
- Security and Fraud Prevention: To protect the security and integrity of our systems, prevent misuse, and enforce our Terms of Service and other policies.
- Legal and Regulatory Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Communication: To communicate with you regarding your account, service updates, security alerts, and support matters.
6.2. Elucidation of the AI Data Lifecycle
To demystify the complex processes underlying our AI Systems, we outline the key stages of the data lifecycle, which are essential for building and maintaining state-of-the-art models.
Data Collection and Pre-processing
The foundational stage involves the acquisition of vast and diverse datasets from public and licensed sources. This data undergoes rigorous pre-processing, including cleaning, normalization, tokenization, and de-duplication, to create a high-quality corpus for training.
Pre-training
Our large-scale, foundational models are pre-trained on this extensive corpus. This unsupervised learning phase allows the model to learn general patterns, grammar, reasoning abilities, and world knowledge.
Fine-tuning and Adaptation
Pre-trained models are then fine-tuned on smaller, more specialized datasets to enhance their performance on specific tasks or in particular domains (e.g., code generation, legal analysis). This may also include Reinforcement Learning with Human Feedback (RLHF) to align model behavior with human preferences and safety guidelines.
Inference
This is the operational stage where the trained model receives a User's Input and generates an Output. This process is computationally intensive and is optimized for speed and efficiency.
Monitoring and Maintenance
Deployed models are continuously monitored for performance degradation, data drift, and the emergence of biases. Regular maintenance and retraining are necessary to ensure the model remains accurate, reliable, and safe over time.
6.3. Policy on Use of Interaction Data for Model Training and Improvement
The use of User data for model improvement is a critical and sensitive aspect of AI development. Our policy is designed to prioritize user control and transparency.
Default Position and User Control
By default, the Interaction Data generated from your use of our consumer Services is not used to train our AI models. You are provided with a clear and easily accessible control mechanism within your account settings to provide your explicit, opt-in Consent to allow us to use your Interaction Data for the purpose of model improvement. This privacy-protective default aligns with emerging best practices among leading AI providers.
Scope of Consent
If you choose to opt-in, your Consent applies prospectively to new Interaction Data generated after the setting is enabled. It allows us to use this data for fine-tuning, validation, and the general improvement of our AI Systems' performance, safety, and capabilities.
Human Review
To enhance model safety and quality, some Interaction Data may be reviewed by authorized human personnel. In such cases, we implement technical measures to protect your privacy, such as disassociating the data from your account and removing direct personal identifiers before review. You are advised not to enter confidential or sensitive information into the Services that you would not want a human reviewer to see.
Data Retention for Training
Interaction Data designated for model improvement pursuant to your Consent may be retained for a longer period than other data, as specified in Article X, to facilitate longitudinal analysis and model development cycles.
Distinction for Enterprise Services
It is essential to distinguish our consumer Services from our enterprise offerings. Enterprise clients are governed by a separate Master Services Agreement and a Data Processing Addendum (DPA). Under these commercial terms, client data, including all Inputs and Outputs, is contractually and technically segregated and is never used to train our general-purpose AI models. This bifurcation of data handling policies reflects the heightened privacy, confidentiality, and intellectual property assurances required by our enterprise clients.
Article VII: Disclosure and Sharing of Personal Data
The Company does not sell Personal Data in the traditional sense of the word. We will only disclose or share Personal Data with third parties under the following limited and legally permissible circumstances:
7.1. Processors / Service Providers
We engage trusted third-party vendors and service providers to perform functions and provide services on our behalf. These may include cloud hosting providers, payment processors, content delivery networks, and customer support service providers. These entities act as our Processors and are contractually bound by Data Processing Agreements to Process Personal Data only upon our instructions and to implement robust security and confidentiality measures.
7.2. Legal and Regulatory Compliance
We may disclose Personal Data if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to:
- Comply with any applicable law, regulation, legal process, or enforceable governmental request.
- Enforce our applicable Terms of Service, including investigation of potential violations.
- Detect, prevent, or otherwise address fraud, security, or technical issues.
- Protect against harm to the rights, property, or safety of the Company, our users, or the public as required or permitted by law.
7.3. Business Transfers
In the event that the Company is involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your Personal Data may be sold or transferred as part of that transaction. We will provide notice to you before your Personal Data is transferred and becomes subject to a different privacy policy.
7.4. Corporate Affiliates
We may share Personal Data with our corporate affiliates (i.e., entities under common ownership or control) for purposes consistent with this Policy, such as for centralized administration and operational efficiency.
7.5. With Your Consent
We may share Personal Data with third parties for other purposes when we have your explicit Consent to do so.
Article VIII: International Transfers of Personal Data
As a global entity, the Company may transfer Personal Data to, and Process it in, countries other than the country in which you reside. Such cross-border transfers are conducted in strict compliance with applicable data protection laws.
8.1. Mechanisms for Lawful Transfer
We ensure that any transfer of Personal Data from jurisdictions with comprehensive data protection laws (such as the EEA, UK, and Switzerland) to a third country is underpinned by a lawful transfer mechanism. These mechanisms include:
8.2. Transfer Impact Assessments (TIAs)
In accordance with the requirements stemming from the Court of Justice of the European Union's "Schrems II" judgment, for every transfer of Personal Data from the EEA or UK based on SCCs, we conduct and document a rigorous Transfer Impact Assessment (TIA) prior to the transfer. The decision to adhere to the stringent EDPB methodology for all transfers, including those originating from the UK, is a strategic compliance choice. This approach avoids the operational complexity of maintaining dual standards (i.e., the EDPB's TIA vs. the UK ICO's Transfer Risk Assessment) and adopts the highest, most defensible legal standard globally, thereby providing greater assurance to all our users and regulators. Our TIA process involves a case-by-case assessment of:
8.3. Supplementary Measures
Where a TIA reveals that the laws and practices of the third country may impinge on the effectiveness of the SCCs, we will identify and implement effective supplementary measures to ensure that the transferred Personal Data benefits from a level of protection that is essentially equivalent to that guaranteed within the originating jurisdiction. Such measures may be:
Article IX: Data Security and Governance
The Company has implemented a comprehensive, multi-layered security program designed to protect the confidentiality, integrity, and availability of the Personal Data we Process. Our approach is risk-based and continuously evolving to address emerging threats.
9.1. Information Security Management System (ISMS)
We have established and maintain a formal Information Security Management System (ISMS) that provides a systematic approach to managing sensitive company information, including Personal Data. Our ISMS is aligned with the framework and controls specified in the ISO/IEC 27001 international standard, ensuring a holistic and process-oriented approach to information security.
9.2. Third-Party Audits and Certifications
To provide independent assurance of our security and privacy posture, we undergo regular third-party audits against globally recognized standards. We maintain a SOC 2 Type II attestation report, which evaluates the operational effectiveness of our controls over time against the Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, as defined by the American Institute of Certified Public Accountants (AICPA). These certifications serve as external validation of our commitment to robust data governance.
9.3. Technical and Organizational Measures (TOMs)
Our security program includes, but is not limited to, the following TOMs:
Article X: Data Retention and Erasure Policy
In accordance with the principle of storage limitation, the Company retains Personal Data only for the period necessary to fulfill the purposes for which it was collected, to meet our legitimate business needs, and to comply with our legal and regulatory obligations.
10.1. Retention Principles
Our data retention schedules are designed to ensure that Personal Data is not kept in an identifiable form for longer than is necessary. We apply these principles consistently across all categories of Personal Data we Process.
10.2. Criteria for Determining Retention Periods
The specific retention period for any given category of Personal Data is determined by a careful evaluation of several factors, including:
10.3. Specific Retention Periods
While specific periods may vary, our general retention framework is as follows:
10.4. Deletion and Anonymisation Procedures
Upon the expiration of the applicable retention period, Personal Data is securely and permanently deleted from our production systems. In some cases, we may choose to Anonymise the data for statistical or research purposes, in which case it is no longer considered Personal Data.
Article XI: Data Subject and Consumer Rights
The Company recognizes and is committed to facilitating the exercise of the rights granted to individuals under applicable data protection laws. We have established procedures to respond to verifiable requests from Data Subjects and Consumers in a timely and compliant manner.
11.1. The Right of Access
You have the right to obtain from us confirmation as to whether or not Personal Data concerning you is being Processed, and, where that is the case, to access the Personal Data and receive supplementary information about the Processing.
11.2. The Right to Rectification
You have the right to obtain the rectification of inaccurate Personal Data concerning you without undue delay.
11.3. The Right to Erasure ('Right to be Forgotten')
You have the right to obtain the erasure of Personal Data concerning you without undue delay where certain grounds apply, such as when the data is no longer necessary for the purposes for which it was collected or when you withdraw Consent.
11.4. The Right to Restrict Processing
You have the right to obtain a restriction of Processing where certain conditions apply, such as when the accuracy of the Personal Data is contested.
11.5. The Right to Data Portability
Where Processing is based on Consent or a contract and is carried out by automated means, you have the right to receive the Personal Data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller.
11.6. The Right to Object
You have the right to object, on grounds relating to your particular situation, at any time to the Processing of Personal Data concerning you which is based on our legitimate interests. We shall no longer Process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override your interests, rights, and freedoms. You have an absolute right to object to Processing for direct marketing purposes.
11.7. Rights Related to Automated Decision-Making and Profiling
You have the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal or similarly significant effects concerning you. Our Services may involve automated Processing and Profiling to generate Outputs; however, we stipulate in our Terms of Service that these Outputs should not be used as the sole basis for making important decisions about individuals without appropriate human review. We are committed to providing meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing.
Article XII: Jurisdiction-Specific Provisions
While this Policy is designed to provide a globally consistent standard of protection, we recognize that certain jurisdictions have specific legal requirements. This Article provides addenda that supplement and, where applicable, modify the general provisions of this Policy for residents of those jurisdictions.
12.1. Addendum for European Economic Area (EEA), Switzerland, and the United Kingdom
Legal Basis
The lawful bases for Processing your Personal Data are as described in Article IV of this Policy, in accordance with Article 6 of the GDPR.
Data Protection Officer
The contact details for our designated Data Protection Officer are provided in Article XIV.
EU/UK Representative
Pursuant to Article 27 of the GDPR, our designated representative in the European Union and the United Kingdom is.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the Processing of Personal Data relating to you infringes the GDPR. Contact details for the European Data Protection Supervisor and national supervisory authorities are provided in Annex A.
12.2. Addendum for California and other U.S. States
Virginia residents have the right to: (1) Confirm whether we are processing your personal data and to access such data; (2) Correct inaccuracies; (3) Delete personal data; (4) Obtain a copy of your personal data in a portable format (data portability); and (5) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
Colorado residents have the right to: (1) Access; (2) Correct; (3) Delete; (4) Data Portability; and (5) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling.
Connecticut residents have the right to: (1) Access; (2) Correct; (3) Delete; (4) Obtain a copy of personal data; and (5) Opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling.
Utah residents have the right to: (1) Access personal data; (2) Delete personal data they have provided to us; (3) Obtain a copy of the personal data they have provided to us (data portability); and (4) Opt out of the processing of personal data for purposes of targeted advertising or the sale of personal data.
12.3. Addendum for Canada
For residents of Canada, our Processing of Personal Information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA). We adhere to PIPEDA's ten Fair Information Principles: (1) Accountability; (2) Identifying Purposes; (3) Consent; (4) Limiting Collection; (5) Limiting Use, Disclosure, and Retention; (6) Accuracy; (7) Safeguards; (8) Openness; (9) Individual Access; and (10) Challenging Compliance.
12.4. Addendum for Brazil
For residents of Brazil, our Processing of Personal Data is governed by the Lei Geral de Proteção de Dados (LGPD). You have rights under the LGPD including the right to: (1) Confirmation of the existence of the processing; (2) Access to the data; (3) Correction of incomplete, inaccurate or outdated data; (4) Anonymization, blocking or deletion of unnecessary or excessive data; (5) Portability of the data to another service or product provider; and (6) Information about public and private entities with which the controller has shared data.
12.5. Addendum for Australia
For residents of Australia, our handling of Personal Information is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We are committed to complying with the APPs, which govern the open and transparent management of personal information, collection, use and disclosure, data quality and security, and the rights of individuals to access and correct their personal information.
| Right | GDPR (EEA/UK) | CCPA/CPRA (California) | VCDPA (Virginia) | CPA (Colorado) | PIPEDA (Canada) | LGPD (Brazil) | Privacy Act (Australia) |
|---|---|---|---|---|---|---|---|
| Right to Access / Know | Yes | Yes (Specific categories & pieces) | Yes | Yes | Yes | Yes | Yes |
| Right to Rectification / Correction | Yes | Yes | Yes | Yes | Yes (Accuracy) | Yes | Yes (Correction) |
| Right to Erasure / Deletion | Yes (Conditional) | Yes (Conditional) | Yes (Conditional) | Yes (Conditional) | Partial (Withdrawal of Consent) | Yes | Yes (Destruction when no longer needed) |
| Right to Data Portability | Yes | Yes | Yes | Yes | No | Yes | No |
| Right to Object to Processing | Yes (for legitimate interests, direct marketing) | N/A (See Opt-Out) | N/A (See Opt-Out) | N/A (See Opt-Out) | Yes (Withdrawal of Consent) | Yes | Yes (Object to Direct Marketing) |
| Right to Opt-Out of Sale / Sharing | N/A | Yes (Broadly defined) | Yes ("Sale") | Yes ("Sale") | N/A | No | No |
| Right to Opt-Out of Targeted Advertising | Yes (via Right to Object) | Yes (via Opt-Out of Sharing) | Yes | Yes | No | No | Yes |
| Right to Limit Use of Sensitive Info | Yes (Requires explicit consent) | Yes | Yes (Requires opt-in consent) | Yes (Requires opt-in consent) | Yes (Requires consent) | Yes (Requires specific consent) | Yes (Requires consent) |
Article XIII: Personal Data Breach Notification Protocol
The Company maintains a robust incident response plan to address any Personal Data Breach in a timely and effective manner, in full compliance with our legal obligations.
Article XIV: Governance, Amendments, and Contact Information
14.1. Data Protection Officer (DPO)
The Company has appointed a Data Protection Officer who is responsible for overseeing our compliance with this Policy and applicable data protection laws. Our DPO can be contacted for any inquiries, requests, or complaints related to your Personal Data.
14.2. Amendments to this Policy
We reserve the right to amend this Privacy Policy at any time to reflect changes in our practices, the Services, or applicable law. We will provide notice of any material changes by posting the updated Policy on our website and updating the "Last Updated" date. For significant changes, we may also provide more prominent notice, such as by sending an email notification. Your continued use of the Services after the effective date of the revised Policy constitutes your acceptance of the terms.
14.3. How to Contact Us
For general questions about this Privacy Policy or our privacy practices, please contact us at:
Contact Information for Supervisory Authorities
In the spirit of transparency and empowerment, this Annex provides contact information for key data protection and privacy supervisory authorities. This list is provided to facilitate your right to lodge a complaint directly with a competent authority should you have concerns about our processing of your Personal Data. This is not an exhaustive list, and you may have the right to contact an authority in your specific jurisdiction.
European Union
European Data Protection Supervisor (EDPS)
United Kingdom
Information Commissioner's Office (ICO)
California, USA
California Privacy Protection Agency (CPPA)
Virginia, USA
Office of the Attorney General of Virginia, Consumer Protection Section
Connecticut, USA
Office of the Attorney General, State of Connecticut
Utah, USA
Utah Division of Consumer Protection
Canada
Office of the Privacy Commissioner of Canada (OPC)
Brazil
Autoridade Nacional de Proteção de Dados (ANPD)
Australia
Office of the Australian Information Commissioner (OAIC)
France
Commission Nationale de l'Informatique et des Libertés (CNIL)
Germany
The Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Frequently Asked Questions
Iseer collects data necessary to provide our AI services, including account information, usage data, and content you provide to our systems. We also collect technical data like IP addresses and device information for security and service improvement purposes.
We may use anonymized and aggregated data to improve our AI models. Personal data is only used for training with explicit consent, and we implement strict data protection measures including differential privacy and data minimization techniques.
Yes, you have the right to request deletion of your personal data. You can do this through your account settings or by contacting our Data Protection Officer at dpo@iseer.co. We will process your request within 30 days.
We implement enterprise-grade security measures including end-to-end encryption, regular security audits, access controls, and secure data centers. Our systems are designed with privacy by design principles and comply with international security standards.
We only share data with third parties when necessary for service provision, with your explicit consent, or as required by law. We never sell your personal data and maintain strict data processing agreements with any third-party service providers.
You can access, correct, delete, or port your data through your account dashboard. For additional requests or questions about your privacy rights, contact our Data Protection Officer. We respond to all requests within the legally required timeframes.
In the unlikely event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by law. We maintain incident response procedures and continuously monitor our systems to prevent and quickly respond to any security incidents.
We review and update our privacy policy regularly to reflect changes in our services, legal requirements, and best practices. We will notify you of any material changes via email or through our services at least 30 days before they take effect.