Statute OS

Privacy Policy

Effective date: July 11, 2026

1. Who we are

Statute OS is operated by TOM projet inc., a company registered in the Province of Quebec, Canada. We provide an AI governance platform that helps organizations assess their AI systems against regulatory frameworks including the EU AI Act, GDPR, NIST AI RMF, and ISO 42001. For the purposes of the EU General Data Protection Regulation (GDPR) and Quebec's Act respecting the protection of personal information in the private sector (Law 25), we are the controller of the personal data described in this policy. You can reach us at privacy@statuteos.com.

2. The zero-copy principle: what we deliberately do not collect

Statute OS is built on a zero-copy architecture. When you connect a data platform (Databricks, Snowflake, AWS, GCP, Azure), our scanners read only metadata and audit configuration — table names, permission settings, encryption flags, audit log settings. We never read, copy, ingest, or store the contents of your tables, your training data, your model weights, or your customers' personal data. Your data stays in your environment; we only ever see how it is governed, not what it is.

3. What personal data we collect

We collect the following categories of personal data:

  • Account data — your name, work email address, password (hashed by our authentication provider), and organization name and industry, collected when you sign up.
  • Billing data — subscription tier and payment status. Card details are processed and stored by Stripe; they never touch our servers.
  • Evidence documents — files you choose to upload as compliance evidence (e.g. policies, model cards). These may contain personal data you control; you remain the controller of that content and we process it as your processor.
  • Platform connection credentials — API tokens you provide to connect your platforms, encrypted at rest with AES-256-GCM. Used solely to run metadata scans you initiate.
  • Usage and audit data — actions taken in the platform (assessment created, report downloaded), recorded in a tamper-evident audit log, plus IP addresses for rate limiting and security.
  • Support communications — messages you send us.

4. Why we process it (legal bases)

  • Performance of contract (Art. 6(1)(b) GDPR) — providing the platform: running scans, generating gap analyses, reports, and badges.
  • Legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse (rate limiting), and maintaining the integrity of the audit log.
  • Legal obligation (Art. 6(1)(c)) — tax and accounting records related to billing.
  • Consent (Art. 6(1)(a)) — optional product communications. We do not send marketing email without consent, and you can withdraw it at any time.

5. AI processing disclosure

Statute OS uses large language models to summarize evidence documents you upload (Anthropic Claude) and to map your questionnaire answers and scan findings to regulatory requirements (xAI Grok). This processing happens only on content you submit for assessment, under our instructions, and is not used by us or our providers to train models.

Our gap analyses and compliance scores are decision-support outputs reviewed and acted on by you. We do not make automated decisions about you that produce legal or similarly significant effects within the meaning of Art. 22 GDPR.

6. Who we share data with (subprocessors)

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storageEU/US (configurable region)
VercelApplication hosting and deliveryEU/US
StripePayment processing (we never store card details)US/EU
AnthropicAI summarization of evidence documents you uploadUS
xAIAI gap analysis of your questionnaire answers and scan metadataUS
OpenAIText embeddings for regulatory document search (regulatory texts only, not your data)US
UpstashRate limiting (IP addresses only)EU/US

We never sell personal data. We share data with these providers only as needed to run the service, under data processing agreements.

7. International transfers

Where personal data is transferred outside the European Economic Area (for example to US-based subprocessors), we rely on the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions such as the EU–US Data Privacy Framework.

8. Retention

  • Account data — kept while your account is active; deleted within 30 days of account deletion.
  • Evidence documents and assessments — kept while your organization's workspace exists; deleted on workspace deletion.
  • Audit logs — retained for the life of the workspace to preserve tamper-evidence; they record actions, not document contents.
  • Billing records — retained as required by tax law (typically 7–10 years).
  • Rate-limiting IP data — automatically expires within 1 hour.

9. Your rights

Under the GDPR (and similar laws such as Quebec Law 25, PIPEDA, CCPA, and LGPD), you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Have your data erased (Art. 17)
  • Restrict or object to processing (Arts. 18, 21)
  • Receive your data in a portable format (Art. 20)
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with your supervisory authority

To exercise any of these rights, email privacy@statuteos.com. We respond within 30 days.

10. Security

We protect your data with encryption in transit (TLS, HSTS) and at rest, AES-256-GCM encryption for platform credentials, row-level security isolating each organization's data, HMAC-chained tamper-evident audit logging, and role-based access controls. No method of transmission or storage is 100% secure, but security is the core of what we sell and we treat it accordingly.

11. Cookies

We use only essential cookies: the authentication session cookie that keeps you signed in and a preference cookie for your active organization. We do not use advertising or cross-site tracking cookies, so there is no cookie banner to click.

12. Children

Statute OS is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

If we make material changes, we will notify account holders by email and update the effective date above. Continued use after the effective date constitutes acceptance.

14. Contact

TOM projet inc., Province of Quebec, Canada. Email: privacy@statuteos.com. If you are in the EU, you may contact your local data protection authority; in Quebec, the Commission d'accès à l'information (CAI).

See also our Terms of Service.