Privacy

Pilot Privacy & Data Handling Notice

What Sefixa currently collects, processes, stores and deletes in the hosted private pilot.

Pilot notice. This page describes the current Sefixa private-pilot data flow. The final contracting legal entity and commercial legal documents must be completed before a public paid launch. Nothing on this page is a claim of regulatory certification.

What Sefixa processes

Why it is processed

Sefixa processes these data to authenticate users, isolate workspaces, store and parse customer documents, rank evidence against requirements, create reviewable response drafts, support human approval/export, provide security/audit controls, enforce service limits, troubleshoot incidents and honour data-export/deletion requests.

Customer content

Workspace content is treated as private application data and is scoped to the authenticated workspace. Sefixa does not use workspace content to train its own models.

Human review

Generated or deterministic drafts are working material, not verified compliance statements. Reviewers control what becomes an approved/exported answer.

AI processing

Sefixa can operate with deterministic evidence-backed drafting and can also use a configured external drafting provider. If external AI drafting is enabled, the content needed to draft a response may be sent to that configured provider. Provider/model execution metadata is designed to be visible to workspace owners without putting provider credentials into the audit trail. Provider-specific data-use/training commitments must be verified against the configured provider contract before confidential paid-pilot use; Sefixa does not extend its own “no training” statement into an unverified promise about third parties.

Hosting and subprocessors

SupabaseDatabase, authentication and private object storage for the hosted pilot.
VercelApplication hosting, serverless execution and delivery for the hosted pilot.
External AI providerConditional only when configured for drafting. The specific provider/model must be disclosed and contractually reviewed before confidential paid-pilot use.

These providers may process data outside the customer's country. Region and transfer terms must be reviewed as part of the final DPA/security package for each paid pilot.

Retention, export and deletion

Workspace owners can configure retention controls, export structured workspace data and delete projects/evidence. Whole-workspace deletion is currently support-led. The deletion procedure distinguishes application data, private object storage and authentication identity removal; Sefixa does not report a deletion complete until the requested scope is verified.

Security

Current controls include authenticated workspace isolation, database row-level policies as an additional boundary, private source storage, rotating HttpOnly sessions, persistent rate limiting, audit history, request identifiers and security response headers. These are internally tested controls, not independent certification.

Your requests

Send access, correction, export, deletion and privacy requests to hello@sefixa.com. Include the workspace ID and requested scope, but do not email document contents, passwords, authentication tokens or service credentials.

Open the Sefixa support/data-request guide →