Privacy Policy

Last updated: August 10, 2026

This Privacy Policy describes how AZ2, Inc. ("AZ2", "we", "us") collects, uses, and shares personal data when you visit az2.ai, interact with us, or use the AZ2 platform. Where AZ2 processes personal data contained in documents and data our customers submit to the platform, we act as a processor on the customer’s behalf; that processing is governed by our Data Processing Agreement, and the customer’s own privacy notices apply.

1. Information We Collect

Information you provide: name, work email, firm, role, and message contents when you request a demo, join a waitlist, subscribe to updates, or contact us; account and profile details when your organization provisions you as a platform user; and support communications. Information collected automatically: log data (IP address, browser type, pages viewed, referrer, timestamps) and, only if you enable analytics cookies, aggregated page-usage statistics. We do not purchase personal data from data brokers and we do not collect precise geolocation.

2. How We Use Information

We use personal data to: respond to inquiries and demo requests; provide, secure, and support the platform; authenticate users and enforce role-based permissions; send administrative notices; send product and marketing communications you have opted into (with unsubscribe in every message); analyze site usage to improve content (where analytics are enabled); comply with legal obligations; and establish, exercise, or defend legal claims.

3. What We Do Not Do

We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not use customer platform data to train foundation models. We do not run third-party advertising trackers on az2.ai.

4. Legal Bases

Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (providing the platform to your organization and responding to your requests); legitimate interests (securing the Services, understanding site usage, business development toward professional contacts, enforcing our rights) balanced against your interests and rights; consent (marketing emails where required, analytics cookies), which you may withdraw at any time; and legal obligation (tax, accounting, and regulatory requirements).

5. Cookies

az2.ai uses essential cookies required for the site to function (session, security, and preference cookies) and, optionally, analytics cookies that produce aggregate usage statistics. Analytics cookies are off by default and set only if you enable them. Your browser settings can also block or delete cookies; blocking essential cookies may break parts of the site.

6. How We Share Information

We share personal data only with: service providers bound by contract to process it on our instructions (cloud hosting, CRM, email delivery, support tooling); professional advisers (lawyers, accountants, auditors) under confidentiality; authorities or other parties where required by law, to protect rights and safety, or to enforce our agreements; and a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy. A current list of platform subprocessors is available on request.

7. International Transfers

AZ2 is based in the United States. Where we transfer personal data from the EEA, UK, or Switzerland to the U.S. or other countries without an adequacy decision, we rely on Standard Contractual Clauses and the UK Addendum, plus supplementary measures where appropriate.

8. Retention

We keep personal data only as long as needed for the purposes above: website inquiries and marketing contacts, up to 24 months after last meaningful contact; platform account data, for the customer’s subscription term plus 90 days; security and access logs, 12 months; records we must keep by law (for example billing), for the legally required period. When retention ends, data is deleted or irreversibly de-identified.

9. Security

We protect personal data with the same program that protects the platform: encryption in transit and at rest, access controls and SSO, logging and monitoring, vendor security review, and independent audits (SOC 2 Type II). No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and regulators as required by law.

10. Your Rights

Depending on your location, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to processing, and to withdraw consent. To exercise a right, email privacy@az2.ai; we verify requests and respond within the legally required period (30 days under GDPR, 45 days under CCPA, extendable where permitted). You will not be discriminated against for exercising rights. EEA/UK residents may lodge complaints with their supervisory authority; California residents may contact the California Privacy Protection Agency.

11. California Notice

For California residents, the categories of personal information we collect are identifiers, professional information, internet activity, and inferences drawn from them, collected for the business purposes in Section 2. We have not sold or shared personal information as defined by the CCPA in the preceding 12 months. Authorized agents may submit requests on your behalf with proof of authorization.

12. Children

The Services are for business users and are not directed to children under 16. We do not knowingly collect personal data from children; if you believe a child has provided personal data to us, contact privacy@az2.ai and we will delete it.

13. Changes to This Policy

We will post updates to this policy on this page and revise the date above. For material changes, we will provide additional notice, by email to platform customers or a prominent notice on the site, before the change takes effect.

14. Contact

AZ2, Inc., privacy@az2.ai. If you are in the EEA or UK, you may also contact our EU/UK representative, details available on request.

Placeholder draft, have counsel review before publishing.