1.Status of this document
This is not a privacy policy. It is the outline one will be written from. Statements marked as observed describe how the product works today and still need counsel's confirmation. Everything else is a TODO.
2.Who we are
[Legal entity, address and privacy contact: to be confirmed by counsel].
For attorney review
TODO: counsel to determine whether LuxeCraft acts as a processor or service provider for client content, a controller for account data, or both.
3.Information the product handles
Observed in the product, to be confirmed by counsel
Account information for each person in a workspace: name, work email address, access level, and whether they have a sign-in.
Observed in the product, to be confirmed by counsel
The content a company puts into its workspace: procedures, roles, training, resources, company profile, branding and settings.
Observed in the product, to be confirmed by counsel
Records of activity, kept as history: who drafted, published, reviewed or changed what and when, who was added or removed and by whom, learning completions, and LuxeCraft support access.
For attorney review
TODO: confirm the complete list, including server and provider logs, before publication.
4.How information is used
Observed in the product, to be confirmed by counsel
To sign people in, to show each workspace's content to its own members according to their access level, and to keep the history described above.
For attorney review
TODO: counsel to confirm purposes and, where required, the legal basis for each.
5.Service providers
Observed in the product, to be confirmed by counsel
Sign-in, invitations and password recovery are provided by Supabase. Invitation and recovery emails are sent through that service.
Observed in the product, to be confirmed by counsel
Workspace content is stored in a Postgres database.
Observed in the product, to be confirmed by counsel
The product does not send workspace content to an AI model provider. Reading a pasted procedure happens inside the product's own code.
[Hosting provider, database location and region: to be confirmed].
For attorney review
TODO: list every subprocessor with its role and location, and keep this list in step with the product.
7.Who can see your information
Observed in the product, to be confirmed by counsel
Members of a workspace see that workspace's content according to their access level. Members of other workspaces cannot see it. This separation is enforced in the database.
Observed in the product, to be confirmed by counsel
LuxeCraft support people can reach a workspace only through access granted to them by name, which that workspace's admins can see and end.
8.Retention and deletion
Observed in the product, to be confirmed by counsel
Several history records are append-only by design, so they are not edited or removed in normal operation.
For attorney review
TODO: counsel to set retention periods and a deletion process, and to reconcile append-only history with deletion requests.
9.Security
For attorney review
TODO: describe security measures only once they are confirmed. Do not describe the product as secure, compliant or certified without evidence counsel has reviewed.
10.Your choices and rights
For attorney review
TODO: counsel to determine which privacy laws apply and the rights, request process and response times that follow.
11.International transfers
For attorney review
TODO: to be determined once hosting locations are confirmed.
12.Children
For attorney review
TODO: counsel to confirm the statement. The product is built for businesses and their staff.
13.Changes to this policy
For attorney review
TODO: notice method and timing.
14.Contact
[Privacy contact: to be confirmed].