Data and Privacy
Privacy Policy
This is a working draft prepared for legal review. It has not been reviewed or approved by a lawyer, it still contains unfilled placeholders written in double square brackets, and it does not create any binding obligation on Neoteric or on you. It is published so the structure can be read and corrected before the final policy is issued.
This explains what information we collect about you, what Autom does with the business information you put into it, and the choices you have. Today the only information this website collects is what you type into the Contact Sales form.
Who we are
Neoteric is the company behind Autom. The organisation responsible for the information described in this policy is [[LEGAL_ENTITY_NAME]], registered at [[REGISTERED_ADDRESS]] under company number [[COMPANY_REGISTRATION_NUMBER]].
Where this policy says we, us, or our, it means that organisation. Where it says Autom, it means the desktop application and the services that support it.
What this policy covers
This policy covers two different things, and it is worth keeping them apart.
The first is information we collect about you when you visit this website, for example when you send us an enquiry through the Contact Sales form. We decide how that information is used.
The second is the business information a customer puts into the Autom application: the description of the company, its departments, the tasks given to AI teammates, and the material those teammates work with. We handle that information on the customer's instructions, under the agreement between us and that customer. Section eleven of this policy and [[DPA_REFERENCE]] set out how.
This policy does not cover other companies' websites or software that we link to or that a customer connects to Autom.
Information we collect through this website
The Contact Sales form is the only place on this website where we ask you for information. It collects your full name, your work email address, your company name, your company size, your industry, your country or region, your primary use case, and the message you write.
The form also carries one hidden field that is not shown to you and that you are not asked to fill in. It exists to catch automated form-fillers. Its value is never forwarded to anyone and is not part of what a destination receives.
Enquiries submitted through this form are delivered to [[CONTACT_FORM_DESTINATION]] and are not stored by this website, which has no database. If no destination is configured, the form tells you plainly that your message was not sent rather than accepting it and discarding it.
There is one exception to that, and it is stated here rather than left for you to discover. A submission that fills the hidden field described above is treated as automated: it is discarded, nothing is forwarded, and the form answers as though it had been sent. If a browser or extension fills that field on your behalf, your enquiry will not reach us and you will not be told. If you send an enquiry and hear nothing, that is a reason to try another route once one is published.
Our hosting provider records ordinary server logs when a page is served, which may include your IP address, the page requested, the time of the request, and your browser's user agent string. Details of what is logged and for how long depend on the hosting arrangement described at [[HOSTING_LOCATIONS]].
We do not run analytics, advertising, or tracking scripts on this website, and we do not build profiles of visitors. See the Cookie Policy for the current position on cookies.
Information Autom processes inside the product
Autom works by asking a customer to describe their business in ordinary language. That description, the departments built from it, the AI teammates configured inside those departments, the tasks those teammates are given, the approval decisions people make, and any material a customer supplies as part of the work are together referred to here as customer content.
Customer content is chosen entirely by the customer. It can include information about identifiable people, such as employees, colleagues, clients, or suppliers, if the customer chooses to put it there. Customers should only put in what they have a lawful basis to share.
Autom also records operational information needed to run the product, such as account and workspace membership, which teammate performed which task, and whether a person approved, declined, or asked for another attempt. This makes the approval trail visible to managers in the customer's workspace.
How we use information
We use enquiry information to reply to you, to understand what you are asking for, and to discuss whether Autom fits your organisation.
We use server logs to keep the website available, to diagnose faults, and to detect abuse.
We use customer content to provide the product: to build the operating model, to let AI teammates carry out the tasks they are given, to apply the approval settings the customer has chosen, and to support the customer when they ask for help.
We use aggregated or de-identified operational information to find defects and improve the product's reliability and performance. Whether customer content itself is used to improve our own systems is set out at [[PRODUCT_IMPROVEMENT_USE]].
We do not sell personal information, and we do not use it for advertising.
Legal bases for processing
Where [[APPLICABLE_DATA_PROTECTION_LAW]] requires a legal basis, we rely on the following.
Contract: to provide Autom to a customer and to administer that customer's subscription.
Legitimate interests: to respond to a sales enquiry you have sent us, to keep our website and product secure, and to improve product reliability. We balance those interests against your rights and stop where yours prevail.
Legal obligation: to keep records we are required to keep and to answer lawful requests from authorities.
Consent: where we ask for it, such as for optional cookies once any are introduced, or for marketing messages. You can withdraw consent at any time without affecting anything done before you withdrew it.
Where we act on a customer's instructions in relation to customer content, the customer is responsible for establishing the legal basis for that processing.
AI processing and third-party language models
This section matters more than any other, so read it carefully.
Autom offers a choice of language models. To carry out a task, business content a customer has described to Autom, together with the instructions given to an AI teammate, is sent to the language model the customer has selected. Those models are operated by third parties, not by us.
The providers that may receive that content are listed at [[MODEL_PROVIDERS]]. The terms on which they handle it, including whether content is retained by them and for how long, are governed by their own agreements, summarised at [[MODEL_PROVIDER_TERMS]].
Whether content sent to a model provider may be used to train that provider's models is set out at [[MODEL_TRAINING_POSITION]]. Customers should treat this as a material decision when choosing a model.
Model output is generated text. It can be wrong, incomplete, or out of date, and it should be reviewed before it is relied on. Human approval in Autom is optional and configurable: if a customer switches it off for a task, work executes without a person checking it first. That choice belongs to the customer.
We do not use Autom to make automated decisions producing legal or similarly significant effects about you. If a customer configures AI teammates to do so within their own organisation, that customer is responsible for the safeguards required by [[APPLICABLE_DATA_PROTECTION_LAW]].
Sharing and sub-processors
We share information with service providers who help us run the website and the product, such as hosting, infrastructure, email delivery, payment processing, and the language model providers described above. The current list is published at [[SUBPROCESSOR_LIST]].
Each provider is engaged under a written contract that limits what they may do with the information and requires appropriate security.
We may also disclose information where we are legally required to, to establish or defend legal claims, or to protect the rights and safety of people or of our systems.
If our business or its assets are transferred to another organisation, information may transfer with it. We will tell affected customers before that happens.
International transfers
Our infrastructure and our providers are located at [[HOSTING_LOCATIONS]], so information may be processed in a country other than yours.
Where information leaves a jurisdiction that restricts transfers, we rely on the mechanism set out at [[TRANSFER_MECHANISM]]. You can ask us for a copy of the relevant safeguards using the contact details below.
How long we keep information
We keep sales enquiries for [[ENQUIRY_RETENTION_PERIOD]].
We keep customer content for as long as the customer's account is active, and after the account ends for [[CUSTOMER_CONTENT_RETENTION_PERIOD]], so that the customer has a chance to export it. The export window itself is [[POST_TERMINATION_EXPORT_WINDOW]].
Backups follow their own cycle and are overwritten after [[BACKUP_RETENTION_PERIOD]], so deleted information can persist in a backup for a short period before it is removed.
We keep records we are legally required to keep for as long as the law requires.
Security
We use technical and organisational measures to protect information, described at [[SECURITY_MEASURES_SUMMARY]].
No system is completely secure, and we do not claim that ours is. We will tell affected customers and, where required, the relevant authority about a personal data breach within [[NOTIFICATION_WINDOW]].
Autom is a desktop application, so part of the security picture is on the customer's side: keeping devices patched, controlling who can sign in, and deciding which people belong in the shared company workspace.
If you believe you have found a security problem, please tell us at [[SECURITY_CONTACT_EMAIL]] before disclosing it publicly.
Your rights
Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have it corrected, to have it deleted, to receive it in a portable format, to object to or restrict how we use it, and to withdraw any consent you gave.
To exercise a right, write to [[PRIVACY_CONTACT_EMAIL]]. We will respond within [[RIGHTS_RESPONSE_PERIOD]]. We may need to verify who you are before we act.
If your information is held inside a customer's Autom workspace, that customer decides what happens to it. Send your request to them; if you send it to us, we will pass it on and support them in answering it.
You can also complain to a data protection authority. The authority for our establishment is [[SUPERVISORY_AUTHORITY]], and you can complain to the authority where you live instead. Our representative for the purposes of [[APPLICABLE_DATA_PROTECTION_LAW]], where one is required, is [[EU_UK_REPRESENTATIVE]].
Children
Autom is a business product and is not directed at children. We do not knowingly collect personal information from anyone under [[MINIMUM_AGE]].
If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We will update this policy as the product changes, and Autom is still pre-release, so changes are likely.
The effective date and last updated date are shown at the top of this page. If a change materially affects how we use personal information, we will give notice before it takes effect, by email to account holders or by a notice on this site.
How to contact us
Privacy questions, requests, and complaints go to [[PRIVACY_CONTACT_EMAIL]]. Post can be sent to [[LEGAL_ENTITY_NAME]] at [[REGISTERED_ADDRESS]].
Contact
Privacy enquiries: [[PRIVACY_CONTACT_EMAIL]] — [[LEGAL_ENTITY_NAME]], [[REGISTERED_ADDRESS]].
