Privacy

Pilot Privacy & Data Handling Notice

What Sefixa currently collects, processes, stores and deletes in the hosted private pilot.

Pilot notice. This page describes the current Sefixa private-pilot data flow. The final contracting legal entity and commercial legal documents must be completed before a public paid launch. Nothing on this page is a claim of regulatory certification.

What Sefixa processes

  • Account and workspace data: email address, workspace membership and role, authentication/session state and account lifecycle events.
  • Workspace content: questionnaires/RFPs, approved evidence, extracted requirements, draft and approved answers, and source-linked evidence references.
  • Operational metadata: audit events, retention settings, usage/plan counters, rate-limit state, request identifiers and service diagnostics.

Why it is processed

Sefixa processes these data to authenticate users, isolate workspaces, store and parse customer documents, rank evidence against requirements, create reviewable response drafts, support human approval/export, provide security/audit controls, enforce service limits, troubleshoot incidents and honour data-export/deletion requests.

Customer content and AI

Sefixa does not use workspace content to train its own models. Sefixa can operate with deterministic evidence-backed drafting and can also use a configured external drafting provider. If external AI drafting is enabled, content needed to draft a response may be sent to that configured provider. Provider-specific data-use/training commitments must be verified against the configured provider contract before confidential paid-pilot use; Sefixa does not extend its own “no training” statement into an unverified promise about third parties.

Hosting and subprocessors

SupabaseDatabase, authentication and private object storage for the hosted pilot.
VercelApplication hosting, serverless execution and delivery for the hosted pilot.
External AI providerConditional only when configured for drafting. The specific provider/model must be disclosed and contractually reviewed before confidential paid-pilot use.

These providers may process data outside the customer's country. Region and transfer terms must be reviewed as part of the final DPA/security package for each paid pilot.

Retention, export and deletion

Workspace owners can configure retention controls, export structured workspace data and delete projects/evidence. Whole-workspace deletion is currently support-led. The deletion procedure distinguishes application data, private object storage and authentication identity removal; Sefixa does not report a deletion complete until the requested scope is verified.

Your requests

Send access, correction, export, deletion and privacy requests to hello@sefixa.com. Include the workspace ID and requested scope, but do not email document contents, passwords, authentication tokens or service credentials.