LEGAL_REVIEW_CONFIRMED=true is set only after that review.
Privacy Policy
Effective date: [DATE]
This policy describes how [YOUR LEGAL ENTITY NAME] ("we", "us") handles information when providing Oz FreightOps and the Oz Core platform, including freight-operations workflows.
Roles and scope
Depending on the processing context, we may act as a controller for account, security, support, and billing information and may process customer-supplied freight information on behalf of an organization using the Service. The final reviewed policy and customer agreements govern those roles.
What we collect
Account data: email, password (stored as a one-way hash), organization name, and role.
API keys: we store a hash and display prefix; the full key is shown at creation and should be treated as a credential.
Generic API usage metadata: endpoint, model, token counts, latency, status, timestamp, and bounded operational metadata. Normal usage-event records do not store prompt or model-response bodies.
Freight operations content: inbound sender/subject/full parsed message body, message identifiers, extracted business facts, confidence, review notes, suggested actions, quotes, shipments, shipment updates, and related audit history.
Original freight email attachments: original inbound files are stored within the organization boundary. Supported files may be temporarily parsed for bounded analysis. We persist the original attachment and bounded analysis metadata such as status, detected document type, page count, and error code; temporary extracted text is not stored in those attachment-analysis metadata fields.
Uploaded files / retrieval content: general upload and retrieval features can store the file and extracted/chunked retrieval content where the feature requires persistence.
Audit and security data: actor, organization, timestamp, resource identifiers, IP address where applicable, and bounded metadata. Extracted attachment text is intentionally excluded from freight audit metadata.
Billing data: where live billing is enabled, Paddle processes payment details. We store the customer/subscription identifiers and state needed to associate an organization with billing.
Cookies: one HttpOnly console session cookie. The current product does not use advertising or behavioral-tracking cookies.
How we use it
- Authenticate users and enforce organization boundaries, roles, quotas, and API-key scopes.
- Provide freight intake, extraction, document handling, operator workflows, model routing, and billing/support functions.
- Maintain security, tenant isolation, auditability, reliability, recovery, and incident/failure investigation.
We do not sell customer data. The current Service does not use customer freight messages, attachments, prompts, or model outputs to train our models.
AI assistance and human review
AI output can be incomplete or incorrect. The current freight workflow keeps consequential actions such as pricing, booking commitments, cancellations, carrier selection, shipment-update application, and customer-facing sends behind explicit human review or action.
Providers and recipients
- Hetzner hosts documented production infrastructure in Helsinki, Finland, including application/database storage and the self-hosted freight model runtime.
- Groq may process requests deliberately routed to configured hosted Groq models; the dedicated initial freight model is designed to use self-hosted Ollama.
- Paddle processes payment/subscription data when live paid billing is enabled.
- Customer-selected email/integration providers process data necessary for configured integrations, such as email routing or a customer TMS connector.
We do not share customer data with unrelated parties except as needed to provide configured services, with authorization where applicable, or where legally required.
International storage and transfers
Production infrastructure is documented in Finland, and optional providers may process information in other countries. Final legal/privacy review must confirm the notices, safeguards, contracts, registrations, or authorizations required for storage or transfer outside Rwanda and for the customer jurisdictions actually served.
Data retention
[RETENTION SCHEDULE REQUIRED BEFORE LAUNCH] — configure a real retention period before commercial publication.
Your privacy rights
Subject to applicable law and our role in the processing, you may have rights to request information about processing; access or a copy of personal data; correction; restriction; erasure; objection; portability; information about international transfers; and protections relating to solely automated decisions. Contact [PRIVACY CONTACT EMAIL]. Where applicable, you may also complain to the competent data-protection supervisory authority.
Security
Passwords are hashed; API keys are hashed and revocable. The application includes TLS for production traffic, organization scoping, role checks, audit logs, restricted freight-ingestion keys, attachment access controls, request-size limits, CSRF/same-origin protection for console mutations, bounded operational logs, backup/restore tooling, and human-approval gates. No security measure can guarantee absolute security.
Children's privacy
The Service is a business product and is not directed at children.
Changes
Material changes will be communicated through the Service, by email, or another reasonable method where required. The effective date above identifies the published version.
Contact
[PRIVACY CONTACT EMAIL]