Skip to main content

Privacy notice

Your technology record should work for you, not become someone else's data product.

This notice explains what DemarcLabs collects, where information comes from, why it is used, who receives it, how long it is kept, and the choices available to people and customer organizations.

Last updated August 31, 2026Version privacy-notice-2026-08-31.2
Authorized Production data: submit only records your organization is authorized to use and only data categories permitted by the applicable Order Form and Data Processing Addendum. Credentials, payment-card data, regulated data, export-controlled information, and other restricted categories require express written approval.

Information DemarcLabs handles

DemarcLabs collects the information required to create a private workspace, organize authorized technology evidence, protect the service, and preserve accountable decisions.

Account information
Name, work email, authentication records, organization membership, role, and workspace preferences.
Technology records
Authorized contracts, invoices, inventory, locations, ownership, usage context, and the private source documents a workspace chooses to provide.
Review and decision history
Relay suggestions, corrections, approvals, record changes, support-access decisions, and the actor and time associated with governed actions.
Security and service records
Request identifiers, file-scan receipts, provider usage, rate-limit events, and minimized diagnostics needed to protect and operate DemarcLabs.
Commercial information
Plan, subscription, billing contact, and payment status when billing services are enabled. Source documents are not sent to the billing provider.

How information is used

Bound to the service the customer selected.

DemarcLabs uses information to authenticate users, maintain the authorized workspace, extract proposed facts, support human review, compare approved records, produce governance insights, prevent abuse, and provide customer-approved assistance.

No advertising data sale

DemarcLabs does not sell workspace records or use them to create advertising audiences.

No automatic authority

Relay can propose and explain. A person approves important facts before DemarcLabs uses them for comparisons or decisions.

No partner sales feed

Customer records do not become leads for agents, distributors, carriers, or other customers without explicit authorization.

No shared-model training

DemarcLabs does not use Live customer source documents to train a model shared across customers.

Sources

Where information comes from

  • Directly from users who create accounts, upload records, enter data, approve findings, or submit requests.
  • From workspace administrators who invite users, assign roles, configure access, or authorize support.
  • Automatically from service use, such as authentication events, request identifiers, security signals, and minimized operational diagnostics.
  • From configured service providers when they return authentication, malware-screening, extraction, hosting, billing, or delivery status.

Purposes

Why DemarcLabs uses it

  • Provide accounts, private workspaces, storage, review workflows, exports, and customer-requested support.
  • Propose evidence-linked facts and findings, preserve corrections, and reconcile approved records.
  • Authenticate users, enforce permissions, scan files, limit abuse, investigate incidents, and protect tenants.
  • Administer plans, respond to privacy requests, comply with law, resolve disputes, and enforce agreements.
  • Measure aggregate service reliability and improve customer-specific workflows without training a shared model on customer source documents.

Providers and sharing

Service providers receive only the information needed for hosting, authentication, private storage, malware screening, or optional extraction. Customer-controlled sharing remains separate.

Review the provider register

Retention and deletion

Workspace records remain while an account is active and are deleted through the governed workspace-deletion process. Security, billing, acceptance, and request evidence may be kept for the period reasonably needed for security, disputes, legal obligations, and enforcement. Provider backups age out under provider schedules. Customer-specific periods are stated in the applicable Order Form, retention schedule, or Data Processing Addendum.

Cookies and tracking

DemarcLabs uses necessary authentication and workspace-preference cookies. DemarcLabs does not use advertising cookies or sell browsing activity. Optional analytics remain disabled unless separately configured and disclosed.

Customer and DemarcLabs roles

For workspace content, the customer generally determines purpose and means and DemarcLabs processes on its instructions. DemarcLabs independently controls limited account, security, legal, and service-administration processing. The signed agreement controls if it states a different lawful allocation.

International processing

DemarcLabs operates the service from the United States. Providers may process information in the United States and other locations where they operate. Customer-specific residency and transfer commitments are documented in the applicable agreement and Data Processing Addendum.

Children

DemarcLabs is a business service and is not directed to children under 18. Do not create an account or submit information about a child. Report suspected child information through the private support process for prompt review.

Access, correction, export, deletion, and objection.

Depending on location and applicable law, a person may have rights to know, access, correct, delete, obtain a copy, restrict or object to processing, or appeal a request decision. DemarcLabs does not sell personal information or share it for cross-context behavioral advertising. DemarcLabs will not discriminate for exercising a privacy right.

Signed-in users should use Settings so identity and workspace authority can be verified without emailing source documents. Authorized agents may submit a request where law permits, subject to verification.

Open Data and privacy settings

Questions and prospective-user requests

Customer users should use the private support channel defined in their agreement. Prospective users may use the request form and write “privacy” in the notes. Do not attach documents, credentials, or sensitive content.

Submit a privacy inquiry

Customer-specific data categories, retention, transfers, incident terms, and privacy responsibilities are documented in the applicable Order Form and Data Processing Addendum.