Privacy Policy
1. Who We Are and What This Covers
Backsplice is operated by Backsplice LLC ("we", "us"). This policy explains how we handle information about the people who use the service and visit our website. The records an organization puts into Backsplice belong to that organization; we process them on its behalf under our Data Processing Agreement ("DPA"), and this policy describes how the service treats them. [Counsel: controller and processor characterization for each category below.]
2. Information We Collect
- Account information: your name, email address and password (stored only as a one-way hash), your second-factor enrollments, and, when your organization uses single sign-on or SCIM, the identifiers your identity provider sends
- Organization content: what your organization enters, including AI systems, models and vendors, assessments and answers, reviews and approval decisions, model and system cards, governance registers, policies, comments and uploaded evidence files
- Usage and security data: IP address, browser user agent, sign-in events, and a security audit log of activity in your organization
- Billing information: your billing contact and subscription status. Card details are entered on our payment processor's hosted pages; we do not receive card numbers
- Messages you send us: what you write in our contact and demo-request forms or by email
3. How We Use Information
- To provide, secure and support the service
- To send service email: sign-in and security messages, invitations, notifications your organization turns on, billing receipts, and the demo and deletion reminders described below
- To answer your questions and requests
- To detect and prevent abuse and unauthorized access
- To meet legal obligations and enforce our agreements
We do not sell personal information, and we do not use organization content to advertise to anyone. [Counsel: state-law "sale" and "sharing" statements, and the legal bases for each use.]
4. Watney and the Model Provider
Watney, the service's AI assistant, is off until an organization admin opts in, and it is not part of the demo. Once it is on, each task sends the model provider only what that task needs: records you typed, documentation you pasted in, and the contents of uploaded evidence files (or its earlier summaries of them) when Watney reviews or drafts an answer or summarizes evidence. Anything typed into a record can contain personal information, whatever the field is for.
The model provider and the models are named on Watney's system card, which is the place to check how that provider handles what it receives. Separately, Backsplice staff can use an assistant of their own to answer questions about the platform; when it is switched on, its questions and answers can include account names and email addresses from any organization, and it reaches the same provider whatever an organization's own setting is. It is off today. [Counsel: how to describe the staff assistant before it is switched on.]
5. Sharing and Sub-processors
We share information only with the service providers we use to run Backsplice, in these categories:
- Hosting: the servers and storage the service runs on
- Email delivery: sending service email
- Payments: Stripe, for checkout, subscriptions and invoices
- AI model provider: the provider named on Watney's system card, for organizations that have turned Watney on, and for the staff assistant described in section 4
[Counsel: confirm sub-processor list.]
Your organization's admins can also send data to places they choose, such as a webhook, a SIEM, or an auditor or guest link. We disclose information when the law requires it, or to protect the rights, property or safety of Backsplice, our customers or others. [Counsel: scope of legal-process disclosures and notice to the customer.]
6. Retention and Deletion
We keep an organization's content while the organization exists. It is permanently deleted in these cases, with every number below read from the settings the service enforces:
- A demo that ends without a plan: the demo lasts 30 days. The organization is then locked, and it is permanently deleted 90 days after the lock unless a plan is chosen first.
- A paid subscription that ends: the organization is locked when the subscription is canceled or its payment finally fails, and is permanently deleted 90 days after the lock unless a plan is chosen first.
- A closure an admin requests: the organization is permanently deleted 30 days after the request, unless an admin cancels it before then.
Your organization's admins are emailed when the organization is locked and 14 days before a deletion that follows a lock; a demo's admins are also reminded before the demo ends (see the Terms of Service, section 4). Until deletion, an organization admin can download a copy of the organization's data from its settings page, or, while it is locked, from the lock page.
What deletion removes: the organization, the records in it, its uploaded evidence files and the export files generated for it, its members' memberships, and its API keys, integration tokens and webhooks.
What is kept after deletion:
- The security audit log. Audit log entries are not deleted with the organization; they stay, still labeled with the organization's identifier, so the record of what happened survives. The service's retention job currently keeps each entry for six years from when it was written. [Counsel: retention period and legal basis.]
- User accounts. A person's account that belongs to no other organization is deactivated, not deleted, so their name and email address remain on the deactivated account. [Counsel: whether deactivated accounts should be deleted or anonymized, and when.]
- Billing records. The log of billing events from our payment processor is kept, and Stripe keeps its own records under its own terms. [Counsel: billing record retention period and legal basis.]
Copies of deleted data remain in our database and file backups until those backups expire. [Counsel: the backup retention period to state, and whether it should be shortened.]
You can ask us to delete personal information about you sooner; see section 8.
7. Security
The measures we can state today:
- HTTPS everywhere, with HTTP Strict Transport Security
- Session cookies that are secure, HttpOnly and SameSite=Strict
- Multi-factor authentication with authenticator apps (TOTP) or passkeys, SAML single sign-on, and SCIM provisioning
- A per-organization IP allowlist, and role-based access (admin, contributor, auditor)
- A hash-chained audit log: a later change to a recorded entry is detectable unless it is made by someone holding the application's signing key and database access, so the log is tamper-evident, not immutable
- TOTP secrets, and the payment-processor API keys we store, encrypted with AES-256-GCM (card numbers go to Stripe, never to us)
- A Data Processing Agreement an organization admin accepts for the organization before any governance records can be created or changed; organization setup (profile, members, sign-in and integration settings) can be done first
No system is perfectly secure. If you find a security issue, we welcome a report at [email protected].
8. Your Rights
Depending on where you live, you may have the right to access, correct, delete or receive a portable copy of personal information about you, and to object to or restrict some processing. Where the information is part of an organization's content, that organization decides on the request, and we help it respond. To make a request, contact [email protected]. [Counsel: response time, identity verification, and the jurisdictions to name.]
9. Cookies and Browser Storage
We use a session cookie to keep you signed in, and your browser's local storage for preferences such as the color theme. We do not use advertising, retargeting or third-party tracking cookies, or third-party analytics. You can block cookies in your browser, but you will not be able to sign in.
10. Children
Backsplice is a business service for people acting in a professional capacity. It is not directed at anyone under 18, and we do not knowingly collect their information. If you believe we have, contact [email protected] and we will delete it.
11. International Transfers
The service is operated from the United States, and information is processed there. [Counsel: hosting location, and the transfer mechanism for users outside the United States.]
12. Changes to This Policy
We may update this policy. The version and date at the top of this page change when we do. [Counsel: how and how far in advance users are told about a material change.]
13. Contact
For privacy questions and requests, contact:
Backsplice LLC
[email protected]
© 2026 Backsplice LLC. All rights reserved. · Privacy Policy · Terms of Service · DPA