Legal · PrivacyLast updated August 2026

What we do with your data.

The data the platform handles, why it handles it, who it goes to, and how to get it back — stated plainly, with the periods and the safeguards written down.

Hosted in the EU. Never used to train models. No trackers.We are the controller for our own account holders and website visitors, and a processor for everything inside a customer's workspace. The live sub-processor list, the data processing agreement and our security documentation are published on our own trust center at trust.oathly.ai.

01Scope and our role

This policy explains what personal data oathly.ai handles, why, and what you can do about it. It covers the oathly.ai website, the oathly.ai platform, and the public trust centers hosted on it.

Our role depends on whose data it is. For our own account holders, website visitors and prospects, oathly.ai decides how data is used — we are the controller. For the content and visitor data inside a customer's workspace and trust center, the customer decides how it is used and we act on their documented instructions as a processor, under the data processing agreement published at trust.oathly.ai. If you are a trust-center visitor asking about your data, the company operating that trust center is your first point of contact; we will support them in answering you.

The controller for the processing described here is Oathly ApS, a private limited company (anpartsselskab) registered in Denmark under CVR number 46654897 (VAT DK46654897), with its registered office at A.P. Møllers Allé 43B, 2791 Dragør, Denmark. Contact us at privacy@oathly.ai.

02Data we handle

Account and workspace data

Name, email address, job title, time zone and working hours, workspace role and team membership, invitation and sign-in activity, and a record of the actions a member takes that change what is published or who can see it — approvals, releases, access decisions and integration activity.

Customer content

Everything a customer uploads or authors: policies, files, certifications, knowledge-base articles, questionnaire questions and answers, and trust-center page content. This may contain personal data if the customer puts it there.

Trust-center visitor data

Email address, and any name, company or registration details a visitor supplies; access requests and the grants issued for them; acceptance of NDAs or policies where a customer requires it; conversation messages; and activity events such as page views and document downloads, which the operating customer sees in its analytics.

Integration data

Where a customer connects a third-party system, we retrieve what that connection's scopes allow — for example CRM contacts and deals, or documents from a connected file store — and may write trust-center activity back to it.

Billing data

Company name, billing address, VAT identification number, plan and subscription history, and the invoices raised. Card details are entered directly with our payment processor and are never stored on our systems — we hold only a token, the card's last four digits and its expiry.

Technical and contact data

Log and device data such as IP address, browser and request metadata; cookies described below; and anything you send through our contact or demo-request forms.

03How we use it, and on what legal basis

  • To provide the Service — hosting trust centers, authenticating people, applying the access rules a customer configures, generating AI-assisted answers from approved content, and producing the analytics a customer sees about its own trust centers and questionnaires. Basis: performance of our contract with the customer; for data inside a workspace, the customer's instructions as controller.
  • To send transactional messages — invitations, access decisions, request and reminder notifications, service notices. Basis: performance of the contract.
  • To keep the Service secure and reliable — preventing abuse, rate limiting, debugging, auditing privileged actions, and maintaining backups. Basis: our legitimate interest in a secure service, and our legal obligation to protect personal data.
  • To take payment and keep our books — invoicing, tax records, and collections. Basis: performance of the contract, and legal obligations under Danish accounting and tax law.
  • To support customers and answer enquiries you send us, including demo requests. Basis: our legitimate interest in responding to people who contact us, or steps taken at your request before entering a contract.
  • To send occasional product or marketing email to business contacts. Basis: consent where the law requires it, otherwise our legitimate interest — and every such message has a one-click unsubscribe.

We do not sell personal data, we do not share it with advertising networks, and we do not use trust-center visitor data for our own marketing.

We do not train AI models on your data. Customer content, questionnaire answers and visitor data are never used to train, fine-tune or evaluate a machine-learning model — ours or a provider's — and we only use model providers whose terms prohibit training on the data sent to them.

04Who we share it with

  • The customer operating a trust center. A visitor's identity, requests and activity are visible to the company whose trust center they use — that is the point of the product.
  • Infrastructure and service providers that host the platform, store files, deliver email and run background processing on our behalf, all within the European Union.
  • Stripe, our payment processor, for subscriptions, invoices and tax calculation.
  • AI model providers selected by the customer's configuration — by default Mistral AI, in France. Customers that must keep inference in-house can point the platform at a self-hosted model instead.
  • Third-party systems a customer connects, within the scopes granted at connection time.
  • Authorities, where we are legally required to disclose — and, where we are permitted to, we will tell the affected customer.
  • A successor, if we are ever party to a merger, acquisition or sale of assets, subject to this policy and with notice to affected customers.

Every sub-processor we use, what it does for us and where it processes data, is listed and kept current on our own trust center at trust.oathly.ai — along with the data processing agreement and our security documentation. Customers are notified of new sub-processors as set out in that agreement, and may object.

05Cookies and similar technologies

We use cookies that are necessary to run the Service: a session cookie that keeps you signed in, and a signed cookie that links a conversation started anonymously on a trust center to your account when you later sign in. Preference storage in your browser remembers choices such as light or dark mode.

We set no advertising cookies and no third-party analytics trackers — not on the website, not in the platform, not on the trust centers we host. Because our cookies are strictly necessary to deliver a service you asked for, no consent banner is required for them.

Blocking necessary cookies will break sign-in and gated access. Where a customer embeds its own third-party scripts into its trust center, those are the customer's responsibility and are governed by that customer's own cookie policy.

06Retention

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires. In practice:

DataHow long we keep it
Account and workspace dataWhile the workspace is active. Erased immediately if the owner deletes the workspace; otherwise deleted from live systems within 60 days of termination.
Customer contentWhile the workspace is active. If the owner deletes the workspace, erased immediately and permanently. If we terminate the agreement, read-only for 30 days so the customer can export, then deleted within 60 days.
Trust-center visitor records — requests, grants, acceptances, conversations, activity eventsControlled by the customer operating the trust center, which can delete them at any time; otherwise deleted with the workspace.
Publishing, approval and access-decision historyFor the life of the workspace — a record of who approved or released what is only worth keeping if it is complete.
AI assistant audit recordsThe full detail of what a query retrieved is cleared after 90 days; the summary record is deleted after 12 months. Workspaces on plans with extended audit retention keep both longer — up to 12 and 24 months respectively — and never shorter.
Integration and webhook delivery history30 days.
Internal product signals (usage events we act on)90 days after processing, or 7 days if never processed.
Unclaimed magic-link records (a link requested but never opened)Deleted automatically once the link has expired.
Encrypted backupsRolled off within 35 days, so deleted data leaves backups within 35 days of deletion.
Operational, security and request logs90 days.
Billing records and invoicesFive years from the end of the financial year, as Danish bookkeeping law requires.
Contact and demo-request enquiries24 months from our last exchange with you, unless you ask us to delete them sooner.

Where we must keep something for a legal reason after you have asked for deletion, we restrict it to that purpose and delete it when the obligation ends.

07Your rights

Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy in a portable format, to restrict or object to certain processing — including any processing based on our legitimate interests — and to withdraw consent at any time without affecting what was done before.

Account holders can update or delete much of their own data directly in the platform. For anything else, email privacy@oathly.ai. We answer within one month, and will tell you if we need longer because a request is complex. We do not charge for this, and we will ask for enough information to be sure who you are.

If your data sits inside a customer's workspace, that customer is the controller: we will pass the request to them without undue delay and support them in answering it.

If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority, in our case Datatilsynet, the Danish Data Protection Agency (datatilsynet.dk), or to the authority where you live or work.

08Automated decisions

We do not make decisions with legal or similarly significant effects about you by automated means. AI-drafted answers are proposals for a person to review, not decisions. Where a customer's access rules automatically approve or decline a request to see a document, that rule belongs to the customer operating the trust center — ask them for a human review, and we will support them in providing it.

09Security

The platform is multi-tenant with per-account isolation, role-based access controls for workspace members, and rule-based access controls for trust-center visitors. Traffic is served over encrypted transport, data is encrypted at rest, credentials and integration tokens are stored encrypted. Access to production is limited to the people who need it. Publishing, approval and access decisions are recorded so a customer can show who released what, and when. Our current technical and organisational measures are documented on trust.oathly.ai.

If a breach affects your personal data, we notify the supervisory authority within 72 hours where the law requires it, and affected customers without undue delay — with what they need to meet their own obligations.

To report a vulnerability, email security@oathly.ai. No security programme is perfect — we would rather hear about a problem than not, and we will not pursue anyone who reports one in good faith.

10International transfers

The platform is hosted in the European Union, and we choose sub-processors that process personal data inside the EU or EEA wherever we can.

Where a sub-processor processes personal data outside the EEA, we rely on the European Commission's Standard Contractual Clauses, together with any additional safeguards the transfer needs, and on an adequacy decision where one covers the destination. Which sub-processors those are, and where each one processes, is stated in the list on trust.oathly.ai. You can ask us for a copy of the safeguards in place at privacy@oathly.ai.

11Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, tell us at privacy@oathly.ai and we will delete it.

12Changes to this policy

We update this policy as the Service changes. The "last updated" date at the top of this page always reflects the current version, and we notify workspace owners of material changes at least 30 days before they take effect.

Questions, requests or complaints: privacy@oathly.ai, or by post to Oathly ApS, A.P. Møllers Allé 43B, 2791 Dragør, Denmark.

Questions about this document?Email legal@oathly.ai or use the contact page — every message is logged with an owner and a reply deadline.