Customer content
Workspace content is treated as private application data and is scoped to the authenticated workspace. Sefixa does not use workspace content to train its own models.
What Sefixa currently collects, processes, stores and deletes in the hosted private pilot.
Sefixa processes these data to authenticate users, isolate workspaces, store and parse customer documents, rank evidence against requirements, create reviewable response drafts, support human approval/export, provide security/audit controls, enforce service limits, troubleshoot incidents and honour data-export/deletion requests.
Workspace content is treated as private application data and is scoped to the authenticated workspace. Sefixa does not use workspace content to train its own models.
Generated or deterministic drafts are working material, not verified compliance statements. Reviewers control what becomes an approved/exported answer.
Sefixa can operate with deterministic evidence-backed drafting and can also use a configured external drafting provider. If external AI drafting is enabled, the content needed to draft a response may be sent to that configured provider. Provider/model execution metadata is designed to be visible to workspace owners without putting provider credentials into the audit trail. Provider-specific data-use/training commitments must be verified against the configured provider contract before confidential paid-pilot use; Sefixa does not extend its own “no training” statement into an unverified promise about third parties.
| Supabase | Database, authentication and private object storage for the hosted pilot. |
|---|---|
| Vercel | Application hosting, serverless execution and delivery for the hosted pilot. |
| External AI provider | Conditional only when configured for drafting. The specific provider/model must be disclosed and contractually reviewed before confidential paid-pilot use. |
These providers may process data outside the customer's country. Region and transfer terms must be reviewed as part of the final DPA/security package for each paid pilot.
Workspace owners can configure retention controls, export structured workspace data and delete projects/evidence. Whole-workspace deletion is currently support-led. The deletion procedure distinguishes application data, private object storage and authentication identity removal; Sefixa does not report a deletion complete until the requested scope is verified.
Current controls include authenticated workspace isolation, database row-level policies as an additional boundary, private source storage, rotating HttpOnly sessions, persistent rate limiting, audit history, request identifiers and security response headers. These are internally tested controls, not independent certification.
Send access, correction, export, deletion and privacy requests to hello@sefixa.com. Include the workspace ID and requested scope, but do not email document contents, passwords, authentication tokens or service credentials.