1. Scope
This policy applies to our public marketing pages, authentication flows, and the Service generally. If you interact only with unauthenticated marketing content, we collect minimal technical data typical of any website (see below). If your organization provisions the Service, your administrator controls many workspace policies; we process customer data as a processor where applicable.
2. Information we collect
2.1 You or your organization provide
- Account identifiers (such as name, email, organizational role) when you sign in or are invited.
- Billing and contract details if you purchase paid offerings.
- Support communications and attachments you voluntarily send us.
- Content you store in the Service (documents, notes, models, configurations) — treated as customer data subject to access controls.
2.2 Automatic collection
- Device and network data: IP address, approximate location derived from IP, user agent, timestamps.
- Diagnostic and security logs: events needed to secure accounts, debug outages, and detect abuse.
- Cookies or similar technologies for sessions, preferences, and fraud prevention (see §7).
2.3 Third-party sources
Identity providers (e.g. federated sign-in) may send basic profile attributes. Data vendors linked by your workspace are governed by their terms and your choices.
3. How we use information
- Provide, maintain, secure, and improve the Service.
- Authenticate users, enforce access control, and prevent fraud or abuse.
- Communicate about the Service, security, or legal requirements.
- Analyze aggregate or de-identified usage to improve reliability and product design.
- Comply with law, regulation, lawful process, or enforceable government requests.
- Protect rights, safety, and property of users, us, or third parties.
4. Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, we rely on contract (to deliver the Service), legitimate interests (security, product improvement balanced against your rights), consent where required (e.g. certain cookies or marketing), and legal obligation where applicable.
6. Retention
We retain information as long as needed to provide the Service, meet legal, tax, or audit obligations, resolve disputes, and enforce agreements. Retention schedules may differ by category (e.g. transactional logs vs. archived workspaces). Customer administrators may request deletion flows consistent with backup and legal holds.
8. Security
We implement administrative, technical, and organizational measures designed to protect information (encryption in transit, access controls, logging, vulnerability management). No method of transmission or storage is perfectly secure; notify us promptly of suspected incidents .
9. Your privacy rights
Depending on jurisdiction, you may have rights to access, correct, delete, port, or restrict certain processing, and to object or withdraw consent where processing is consent-based. You may lodge a complaint with a supervisory authority. To exercise rights, contact your workspace administrator or use in-product controls where available. We may verify requests to prevent fraud.
If you are a California resident, you may have additional rights under the CCPA/CPRA (know, delete, correct, limit use of sensitive data, opt out of “selling/sharing” — we do not sell covered personal information for monetary consideration). We do not use or disclose sensitive personal information for inferring characteristics beyond permitted service operation.
10. Children
The Service is not directed to children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal information from children.
11. International transfers
We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
12. Changes to this policy
We will post updates here and adjust the “last updated” date. Material changes may require additional notice where required by law.
13. Contact
Data controller for the Service: NorthLine Terminal. Privacy inquiries: through your account administrator.
Enterprise customers may require a Data Processing Agreement (DPA); use your procurement or security channel for executed documents.