Privacy Notice
Entity: {{LEGAL_ENTITY}} · Product: CommitLayer · Draft updated 2026-09
1. Who we are
{{LEGAL_ENTITY}} operates CommitLayer. This notice explains what personal data we process, why, and the choices you have.
2. Data we process
- Account data: name, work email, role, authentication identifiers from the identity provider.
- Connected system data: records read from systems the Customer connects (for example helpdesk ticket events, CSAT scores, refund records). These may contain personal data of the Customer's end users. We process this data as a processor on the Customer's instructions.
- Vendor claim data: usage exports and invoices uploaded by the Customer.
- Usage and diagnostics: page views and errors, collected only if analytics or error reporting is enabled in the deployment.
3. Purposes
To provide the Service, produce statements and evidence, secure the Service, and communicate with Customers. We do not use Customer data to train models.
4. Transcript assist
If a Customer enables transcript assist, redacted excerpts of sampled conversations are sent to a language-model provider listed on the subprocessors page. This is off by default and cost-capped.
5. Sharing
We share personal data only with subprocessors necessary to run the Service, with counterparties a Customer explicitly grants read-only access to, and where required by law.
6. Retention
Retention is configurable per Customer. Audit logs are retained for the period required by the Customer's agreement.
7. Your rights
Depending on your location you may have rights to access, correct, delete or restrict processing of your personal data. Requests from Customer end users are routed to the Customer as controller.
8. Security
See the Trust Center for current controls.
9. Contact
Use the contact page. A dedicated privacy contact will be added after counsel review.