Privacy policy
This policy explains how the issuers.ai service processes personal data, who receives it, how long it is kept and how you can use your rights.
Who is responsible
The controller of personal data processed through the website issuers.ai and the issuers.ai application is the administrator of the issuers.ai service ("we", "us"). You can reach us about anything in this policy at [email protected].
Our two roles
We process personal data in two different roles, and it helps to know which applies.
- As controller, for data about visitors to our website, people who request a sample brief, account holders and billing contacts. This policy describes that processing in full.
- As processor, for data our customers put into their workspaces, such as investor contacts, meeting notes, data room documents, insider lists and messages. We process that data on the customer's instructions under our terms and, where agreed, a data processing agreement. The customer is the controller and its own privacy notice applies. See the section on investors and contacts below.
Data we process
Website visitors and sample briefs
When you visit the website, our servers receive technical data such as IP address, browser type, the pages requested and the time of the request. When you request a sample brief, we process the ticker or company name and the options you choose, and we use the IP address to apply the limit of one sample brief per day. We measure visits with analytics that do not use cookies and do not build a profile of you.
Accounts
When you create an account, we process your email address, a password stored only in hashed form, your name if you give it, the confirmation code we send you, the workspace you belong to and your role in it, and records of sign in such as date, time and IP address.
Billing
When a workspace subscribes, we process the billing contact, billing address and tax identifier if the customer provides them, the plan, the billing period, invoices and payment status. Card details are entered directly with our payment operator and we never see or store full card numbers.
Use of the application
We record usage needed to run the plan limits (for example the number of AI actions and briefs in the billing period) and an audit trail of actions in the workspace, as described on our security page.
Support
When you write to [email protected] or use help inside the app, we process your message, your email address and anything you choose to include, such as screenshots.
Purposes and legal bases
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases.
- Providing the Service and the account, including sign in, the workspace, plan limits and support: performance of a contract (Article 6(1)(b)).
- Billing, invoicing and tax records: compliance with legal obligations (Article 6(1)(c)) and performance of a contract.
- Security, fraud prevention and abuse limits, including the sample brief limit and logs: our legitimate interest in keeping the Service safe and available (Article 6(1)(f)).
- Cookie free analytics of aggregated website usage: our legitimate interest in understanding how the website is used.
- Service emails such as confirmation codes, invoices, security notices and changes to the Service: performance of a contract.
- Product news by email to account holders, only where the law allows it or you agreed. You can unsubscribe at any time from the link in each email.
- Establishing or defending legal claims: our legitimate interest.
We do not sell personal data and we do not use it for advertising profiles. We do not use customer workspace content to train AI models.
Who receives data
We share personal data only with service providers who process it on our behalf and under contract, and only as far as needed for the purpose. By category, they are:
- a hosting provider that runs our servers, databases, backups and file storage, in the EU or in the US depending on the workspace setting where offered;
- a payment operator that processes subscriptions, card payments, invoices and fraud checks;
- an email delivery provider that sends service emails such as confirmation codes and invoices;
- an AI model provider that processes the content of a request to return an answer, without using it to train its models;
- licensed market data providers, which receive identifiers of the companies you look up but no personal data about you;
- professional advisers such as accountants and lawyers, under a duty of confidentiality.
We may also disclose data where the law requires it, for example to a court or a public authority with a valid legal request, or to protect the rights and safety of users and the Service.
International transfers
Some providers may process data outside the European Economic Area or the United Kingdom. Where that happens, we use safeguards recognised by law, such as an adequacy decision or the European Commission standard contractual clauses, with additional measures where needed. Enterprise workspaces can choose EU or US data residency for workspace content. You can ask us for information about the safeguards at [email protected].
How long we keep data
- Server logs: up to 90 days, longer only when needed to investigate a security incident.
- Sample brief requests: the per IP limit record for up to 30 days.
- Account data: for as long as the account exists, then deleted or anonymised within 90 days, except what we must keep by law.
- Billing and invoice records: for the period required by tax and accounting law, usually 5 to 10 years depending on the country.
- Workspace content and audit trail: for the retention set by the plan (12 months on Growth, 7 years on Public and Enterprise) and the customer's own settings, and deleted after the workspace is closed as described in the terms.
- Support messages: up to 3 years after the conversation ends.
- Backups: overwritten on a rolling schedule, so deleted data leaves backups within a limited time.
Cookies
We use only cookies that are strictly necessary for the website and application to work:
- a session cookie that keeps you signed in and remembers your choices during a visit;
- a security token cookie that protects forms against cross site request forgery.
We do not use advertising cookies, tracking pixels or cookies for analytics. Because we only use strictly necessary cookies, we do not show a cookie banner. You can delete cookies in your browser at any time, but you will then need to sign in again.
Security
We protect personal data with encryption in transit and at rest, role based access, an audit trail, regular backups and limits on who in our team can access production systems. No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will inform you and the relevant authority as the law requires.
Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete data, where we have no legal reason to keep it;
- restrict processing in certain cases;
- object to processing based on legitimate interest, and to direct marketing at any time;
- receive data you gave us in a portable format;
- withdraw consent where processing is based on consent, without affecting earlier processing;
- lodge a complaint with your data protection authority.
Residents of US states with privacy laws, such as California, have similar rights to know, correct and delete personal data and to not be discriminated against for using them. We do not sell or share personal data for cross context behavioural advertising.
To use a right, write to [email protected] from the email address the request is about. We answer within one month, and may ask for information to confirm your identity.
Investors and contacts in customer workspaces
Our customers use the Service to manage their relationships with investors, analysts and other contacts. If you are such a contact, the issuer that holds your details is the controller and decides why and how your data is used. Its privacy notice applies.
Investor and fund data that the Service builds from public filings, such as Form 13F holdings, comes from public sources and shows the source. If you write to us about data in a customer workspace, we pass your request to the customer and help it respond.
Children
The Service is for businesses and is not directed to children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We update this policy when our processing changes. The date at the top shows the latest version. If a change is material, we tell account holders by email before it takes effect.
Contact
Write to the administrator of the issuers.ai service at [email protected] with any question about privacy or this policy.