Privacy Policy

1. Scope

This policy applies to all users of DefensibleHR.ai, including visitors who use our free compliance scan, registered account holders, our website, application, and API. It does not cover third-party services that may integrate with our platform, each of which maintains its own privacy policy.

"Customer" means an organization that accesses or uses the Services under the Terms of Service or an applicable Order Form. Capitalized terms not defined in this Privacy Policy have the meanings given in the Terms of Service or the Data Processing Addendum, as applicable.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

2.2 Free Scan Information

The free compliance scan runs before any email address is collected. When you run a scan, we collect:

If you verify an email address, this information is stored in our leads database and used to deliver your scan results, prevent abuse of the free scan feature, and contact you about DefensibleHR.ai services. If you never provide an email address, we retain no contact information: the extracted document text is automatically deleted within 24 hours, and we keep only the consent and scan record described above (without any email) for abuse prevention and legal-compliance purposes. We do not store the full scan results or the extracted document text in association with you — only the summary metadata listed above is linked to your contact information. The same document processing and AI disclosure practices described in Section 3 apply to free scans.

Scan result cache: To make repeat scans of an identical document deterministic and efficient, we retain a copy of the full scan results in a result cache keyed to a cryptographic hash of the document's redacted text — not to your name, email, or account. Cached results are automatically deleted after 90 days and cannot be used to look up who submitted a document.

Guides, sample reports, tools, and demo requests: If you provide contact details to unlock guide materials or the sample report, to have a checklist emailed to you, or to request a demo, we collect the details you enter (which may include your name, work email address, firm or company, role, and message), your IP address and browser information, and which material or request it was. We store this in our leads database to deliver what you asked for, to send a follow-up about your request, and to contact you about DefensibleHR.ai services as described in Section 3.4. When you unlock the sample report we also set a cookie so that you are not asked for your details again for 180 days.

2.3 Uploaded Documents

You may upload workplace documents including investigation reports, termination letters, performance improvement plans (PIPs), and HR memos. These documents may contain:

Important: You are responsible for ensuring you have proper authorization to upload any document containing employee or third-party personal data. By uploading a document, you represent that you have the legal authority to do so.

2.4 Scan Results

For registered users, we store Full Outputs — including the overall risk level, each flagged issue with its category label (required, recommended, or optional), jurisdiction, and cited authority, the passage of your document each finding rests on, and suggested remediation language — for the period stated in Section 4. For Free Compliance Scan users, Full Outputs are not stored in association with you after scan generation; we retain only the limited contact information and scan summary metadata identified in Section 2.2. In addition, the scan result cache described in Section 2.2 applies to all scans: a copy of the full results is retained for up to 90 days, keyed to a cryptographic hash of the document's redacted text rather than to your account, so that identical documents produce identical results on re-scan.

2.5 Usage Information

We automatically collect:

2.6 Cookies

We use essential cookies for authentication and session management, including httpOnly, secure cookies for authentication tokens. We may also use non-essential cookies or similar technologies for analytics or advertising-conversion measurement as described below and only where permitted by Applicable Privacy Laws.

We use the Google Ads tag (gtag.js), which sets third-party cookies to measure advertising conversions — for example, whether a visit or signup originated from one of our ads. These cookies are used for advertising measurement and are set by Google; Google's use of this data is described in Google's advertising technologies policy. You can opt out of personalized advertising at Google Ads Settings or aboutads.info, and you can block third-party cookies entirely in your browser without affecting your ability to use the Services. Advertising cookies are never used on your uploaded documents or scan results, which are not shared with advertising providers.

Bot protection. Our contact, free-scan, and demo-request forms use Cloudflare Turnstile to distinguish people from automated traffic. Turnstile is provided by Cloudflare, Inc., evaluates browser and network signals including your IP address, and may set a Cloudflare cookie; Cloudflare\'s use of this data is described in its privacy policy.

Other first-party storage. We set a cookie for 180 days when you unlock the sample report so you are not asked to enter your details again; your browser\'s session storage holds the random session identifier used for the conversion events described in Section 2.5; and local storage holds your display-theme preference. None of these contains your documents or scan results.

2.7 SMS Information

If you separately opt in to receive SMS messages, we collect your mobile telephone number, consent status, consent timestamp, and records of messages and opt-out requests. We use this information to send the message types disclosed at the time of opt-in and to administer your preferences. SMS consent is not a condition of purchase. You may revoke consent by using the account setting identified at enrollment or by replying STOP. We share SMS information only with service providers that deliver or support the messaging program and retain it only as reasonably necessary for the program, compliance, and legal claims.

2.8 Feedback on Findings

If you use the "This rule looks out of date" control on a finding, we record your user and organization identifiers, the finding concerned, and the note you write in our internal rule-review queue. We use this to review and, where appropriate, update our rule library. Feedback is visible to the personnel and reviewers who maintain the rule library, is not published, and is retained as part of the rule library\'s editorial record. Please do not include employee names or other personal information in a feedback note.

2.9 Account Activity Record

For each account we keep a record of actions taken by its users — for example sign-ins, uploads, scans, report exports, and settings changes — with the user, timestamp, IP address, and browser information. The record cannot be edited, is retained for 365 days, and can be viewed and exported by the account\'s administrators for supervision and security purposes.

3. How We Use Your Information

3.1 Document Processing

Uploaded documents are processed as follows:

Redaction Limitations. Although Company uses automated measures designed to identify and redact certain categories of personally identifiable information before AI processing, automated redaction is not infallible and may fail to identify, redact, or accurately redact all personal information or other sensitive information. Customer is solely responsible for reviewing Customer Data before upload and for determining whether it is appropriate to submit any personal information, sensitive personal information, or other regulated data to the Services. Customer should avoid submitting personal information, sensitive personal information, or other regulated data unless submission is necessary for Customer's intended use of the Services, Customer is authorized to disclose that information, and Customer accepts the risk that automated redaction may be incomplete.

3.2 AI Processing Disclosure

Document text is processed using Anthropic's Claude API. Key facts about this processing:

For details on Anthropic's data practices, see Anthropic's Privacy Policy.

Automated decision-making: All scan results are AI-generated without human review by DefensibleHR LLC. However, we do not use AI to make automated decisions that produce legal or similarly significant effects about any individual. The Services analyze documents for your organization's human reviewers; they do not evaluate, score, or make decisions about employees or job applicants, and scan results are delivered only to your organization.

3.3 Other Uses

We also use your information to:

We do not use Customer Data containing personal information or Full Outputs for marketing purposes, and we do not sell Customer Personal Data. Subject to the Terms of Service, applicable law, and any applicable Enterprise opt-out, we may use De-Identified Data to operate, secure, test, validate, and improve the Services, including our rule library and prompts. We do not use your documents, extracted text, or scan results to train any artificial-intelligence or machine-learning model. We do not attempt to reidentify individuals or Customers from De-Identified Data. "De-Identified Data" means information that has been de-identified or anonymized, as applicable, in accordance with Applicable Privacy Laws and is not reasonably capable of being linked to, or used to infer information about, Customer or an identified or identifiable individual.

3.4 Lead Communications

We use the contact details you provide for a Free Compliance Scan, the sample report, an emailed checklist, a template, or a demo request to deliver what you asked for and to send related transactional messages. Where the page says so, we may send one personal follow-up about your request. We may also send marketing communications about DefensibleHR.ai services only where permitted by Applicable Privacy Laws. Every marketing email includes a one-click unsubscribe mechanism. You may also opt out by replying "unsubscribe" or contacting [email protected]. We honor opt-out requests within ten (10) business days. Opting out does not affect transactional, security, billing, or legally required communications.

4. Document Handling & Data Retention

Given the sensitive nature of workplace investigation documents, we apply the following retention practices:

Legal hold. If a dispute, claim, or legal proceeding is pending or reasonably anticipated, we suspend the deletion timelines above for the affected records until the matter is resolved, as permitted or required by law. This preserves records we may need to establish, exercise, or defend legal claims.

You may request deletion of your documents and scan history at any time by contacting us at [email protected]. Deletion requests are honored subject to the legal-hold and integrity-record exceptions described above.

5. How We Share Information

We do not sell, rent, or trade your personal information or document data. We share information only in the following limited circumstances:

5.1 Service Providers

Each provider processes data under contractual obligations to protect confidentiality and security. Company uses authorized AI/API providers to process Extracted Text. Company configures and contracts with those providers to process Customer Personal Data only as necessary to provide the Services, subject to the provider's applicable service terms and Company's DPA obligations.

5.2 Legal Requirements

We may disclose information if required by law, subpoena, or court order. Where legally permitted, we will notify you before disclosure and limit the scope of information shared.

5.3 Business Transfers

In the event of a merger, acquisition, or asset sale, your information may be transferred to the successor entity, subject to the same privacy protections described here. We will notify you of any such transfer.

5.4 With Your Consent

We may share information when you explicitly direct us to do so.

6. Security

We maintain administrative, technical, and physical safeguards designed to protect Customer Personal Data against unauthorized access, use, alteration, disclosure, loss, or destruction, including encryption in transit and at rest and access controls appropriate to the Services. Subject to the scope of our then-current systems and the DPA:

In the event of a confirmed Security Breach involving Customer Personal Data, we will notify the affected Customer without undue delay and, where reasonably practicable, no later than seventy-two (72) hours after confirmation, as further described in the DPA. Customer remains responsible for determining and carrying out any required notifications to individuals or regulators, except to the extent applicable law requires otherwise.

While we work to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

To exercise privacy rights, contact [email protected]. We may verify your identity and authority before responding. We will respond within the period required by Applicable Privacy Laws, subject to any permitted extension. Where required by law, an authorized agent may submit a request on a consumer's behalf, subject to verification of the agent's authority. If we deny a request, users in jurisdictions that provide an appeal right may appeal by contacting [email protected] with the subject line "Privacy Appeal."

7.1 Customer Personal Data Requests

For personal information that Company controls directly, including account, billing, website, support, and marketing information, individuals may submit requests using the methods in this Section 7. For Customer Personal Data that Company processes on behalf of a Customer, including employee or applicant information contained in uploaded documents, the applicable Customer is ordinarily responsible for responding to rights requests. Company will, as required by Applicable Privacy Laws and the DPA, promptly forward the request to the Customer or assist the Customer in responding. Company may respond directly only where Company is legally required or authorized to do so.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

We do not sell personal information. We use the Google Ads conversion tag described in Section 2.6 to measure whether visits and signups originated from our advertising. We do not use it to build remarketing or other advertising audiences, and your uploaded documents and scan results are never shared with advertising providers. To opt out of advertising cookies, use the links in Section 2.6 or block third-party cookies in your browser.

To submit a request, email [email protected].

For Customer Personal Data processed on behalf of an employer or other business customer, DefensibleHR acts as a Service Provider or Contractor, as applicable, under the CCPA/CPRA. Company's contractual restrictions regarding such Customer Personal Data, including restrictions on selling, sharing, retaining, using, disclosing, and combining personal information, are set forth in the DPA.

We do not sell Customer Personal Data. We do not share uploaded documents, Extracted Text, Full Outputs, or account contents for cross-context behavioral advertising. Our use of advertising conversion technology is limited to website and advertising-measurement information as described in Section 2.6.

9. Employer and Employee Data

Our customers are employers, HR professionals, and legal teams. Documents uploaded to our platform typically contain information about employees who are not direct users of our Services.

The Data Processing Addendum, incorporated automatically through the Terms of Service when Company processes Customer Personal Data on Customer's behalf, governs processing instructions, security measures, subprocessors, assistance, incident notification, retention, and deletion.

10. Health and Medical Information

Workplace investigation documents may incidentally contain references to medical conditions, disabilities, or health-related information. While DefensibleHR.ai is not a HIPAA-covered entity or business associate:

11. Children's Privacy

The Services are intended only for business users who are at least eighteen (18) years old, as provided in the Terms, and are not directed to children or other minors. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will delete it promptly.

12. Geographic Scope

Our Services are hosted in and offered exclusively within the United States, and are intended solely for businesses located in the United States. We do not target, market, or make the Services available to individuals or entities in the European Economic Area, the United Kingdom, or Switzerland, and we do not offer Standard Contractual Clauses or other cross-border transfer mechanisms. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with applicable local law; any information you submit will be transferred to and processed in the United States.

13. Changes to This Policy

We may update this Privacy Policy as our practices or legal requirements change. We will notify you of material changes by email or through a prominent notice on our website at least 10 days before the changes take effect. Your continued use of the Services after changes become effective constitutes acceptance of the updated policy. Where Applicable Privacy Laws require additional notice, consent, or another lawful basis before a material change in processing takes effect, we will take those steps before implementing that change.

14. Contact Us

For questions about this Privacy Policy, to exercise your data rights, or to report a privacy concern: