Privacy Policy
Privacy Policy for Example Draft
- Effective date
- 2026-09-23
01Introduction
This Privacy Policy explains how Example Software Ltd (fictional) processes personal information in connection with Example Draft at https://example.org. It takes effect on 2026-09-23. It is based on the service practices described by its operator and should be read together with notices shown when information is collected.
02Who operates this service
Example Software Ltd (fictional) is the business responsible for this policy and is established in the United Kingdom, with a postal address at 3 Example Road, Example Town.
03Scope
This policy applies to the software-as-a-service platform offered under the Example Draft name. It does not govern independent third-party services that publish their own privacy terms.
05Sources of information
Information comes from users directly and automatic collection from the devices used to access the service. Information received from another source is handled for the purposes described in this policy and subject to applicable restrictions.
06How we use information
Information is used for providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. It may also be used to prevent misuse, establish or defend legal claims, meet legal obligations, and enforce service terms where those activities are relevant and permitted.
07Messages and email
The service sends transactional service messages using Postmark. Contact details are used for delivery, service administration, and the purposes described when the details are collected.
Transactional messages are sent only as needed to provide, secure, or administer the service. The operator does not measure message opens or link interactions.
08EU legal bases for processing
For processing governed by the EU GDPR, the relied-on legal bases are performance of a contract or steps requested before a contract, compliance with a legal obligation, and legitimate interests. The operator's purpose-to-basis mapping is: providing the workspace and AI features: contract; billing records: legal obligation; security and product analytics: legitimate interests. Legitimate interests include securing the service and understanding aggregate product usage, balanced against affected rights and expectations. Consent can be withdrawn for future processing at any time without affecting processing that was lawful before withdrawal.
09UK legal bases for processing
For processing governed by the UK GDPR, the relied-on legal bases are performance of a contract or steps requested before a contract, compliance with a legal obligation, and legitimate interests. The operator's purpose-to-basis mapping is: providing the workspace and AI features: contract; billing records: legal obligation; security and product analytics: legitimate interests. Legitimate interests include securing the service and understanding aggregate product usage, balanced against affected rights and expectations. Consent can be withdrawn for future processing at any time without affecting processing that was lawful before withdrawal.
10Cookies and tracking technologies
The service uses essential browser storage or cookies only where needed for security, sessions, saved choices, load balancing, or requested functionality. These technologies are not used for cross-service advertising.
11Analytics
The service uses privacy-focused analytics with Plausible to understand service operation, usage, errors, and improvements. Analytics data may include technical, device, interaction, approximate-location, and identifier information according to the selected configuration and provider controls.
12Payments
Payments are processed using Stripe for recurring subscriptions. The operator does not directly store full payment-card information; the payment provider handles card details under its own privacy terms.
13Artificial intelligence processing
Example Draft uses artificial intelligence for workspace drafting and summarization. To provide these features, the service sends the following information to Anthropic: the prompts and documents a user submits to the AI features.
People who use these features interact with an AI system, and responses or other content produced by these features are generated by AI. AI-generated content can be inaccurate or incomplete and should be checked before it is relied on.
Prompts, submitted content, or outputs of the AI features are stored. The operator describes how long the service and the AI providers keep them as follows: prompts and outputs stay in the workspace until the user deletes them.
The operator states that information submitted to the AI features is not used to train AI models, by the operator or by the AI providers under the terms that apply to the service. The operator states that people at the operator and the AI providers do not review prompts, submitted content, or outputs.
The operator states that the service asks for the user's permission before personal data is shared with a third-party AI provider.
The operator states that AI is not used to make decisions that produce legal or similarly significant effects on people.
Choices about the AI features: available by turning off AI features in workspace settings. Questions and privacy requests about information processed by the AI features can be sent to privacy@example.org.
14Sharing and disclosures
Information may be disclosed to service providers and authorities or professional advisers for the purposes described in this policy, subject to contracts and legal limits where required. It may also be disclosed to authorities, courts, advisers, or transaction counterparties when reasonably necessary for law, safety, claims, or a business reorganization. Selected service providers include AWS, Stripe, Anthropic, and Sentry.
The operator states that it does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable United States privacy laws. Ordinary disclosures to service providers, legal recipients, and user-directed recipients are not treated as a sale when statutory conditions are met.
15International transfers
Information may be processed outside the United Kingdom. The stated location and safeguard approach is: standard contractual clauses and the UK International Data Transfer Addendum. For EU information, the transfer mechanism is: standard contractual clauses and the UK International Data Transfer Addendum. Users may request information about the mechanism used. For UK information, the transfer mechanism is: standard contractual clauses and the UK International Data Transfer Addendum. Users may request information about the mechanism used.
16Data retention
The retention model is: records are kept while the account or relationship remains active and for a justified period afterward. Records may be kept longer when reasonably necessary for security, disputes, tax, accounting, fraud prevention, legal obligations, or enforcement. Deletion or de-identification follows the stated model and applicable law.
17Security
The operator uses encryption, access restrictions, and backups and monitoring, selected according to the nature and risk of the information. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.
18Children's privacy
The service is intended for adults only. If the operator learns that information was collected from a child contrary to the stated audience or applicable law, it will take reasonable steps to delete it and may ask for age or authority verification.
19Your choices and privacy rights
Depending on location and processing, users may ask to access, correct, delete, restrict, or receive information; withdraw consent; unsubscribe; object; or opt out of sale, sharing, or targeted advertising. Requests are supported through the account settings or by email to privacy@example.org. The operator may verify identity and authority, apply legal exceptions, and explain a denial and available appeal where required.
20European Economic Area privacy rights
The EU GDPR has applied since May 25, 2018. Where it applies, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the competent supervisory authority. Rights depend on the processing, lawful basis, and statutory exceptions. Requests may be made through the account settings or at privacy@example.org.
21United Kingdom privacy rights
Where the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, apply, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the UK Information Commissioner's Office. Rights depend on the processing, lawful basis, and statutory exceptions. Requests and data-protection complaints may be made through the account settings or at privacy@example.org. The operator will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate without undue delay, keep the complainant informed, and communicate the outcome.
22United States privacy disclosures
United States privacy duties vary by state, sector, data type, and business activity. This policy describes selected factual practices and adds state-specific rights only where the operator identified those laws as applicable. It does not claim that one nationwide GDPR-equivalent framework governs every user or processing activity.
23Other United States state privacy rights
Several United States states have comprehensive consumer privacy laws, such as the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Texas Data Privacy and Security Act. Whether one of these laws, or a similar law of another state, applies depends on the consumer's state of residence, the operator's activities, the law's thresholds, and its exemptions. This section summarizes rights and practices under those laws and does not expand or waive any statutory right.
Where such a law applies, residents may, subject to its definitions and exceptions, confirm whether their personal data is processed and access it, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. Requests can be submitted through the account settings or by email to privacy@example.org. The operator may need to verify the identity of the person making a request.
For these laws, the categories of personal data processed are identity and contact information; account information, submitted content, and communications; technical, usage, and device information; and payment, location, sensitive, or other information, and the purposes of processing are providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. The operator describes the personal data it shares with third parties, and the categories of those third parties, as follows: account, workspace, and billing information is shared with hosting, AI, payment, and error-monitoring providers that process it for the service; no personal data is sold.
The operator states that it does not process sensitive data as these laws define it, such as precise geolocation, health, genetic or biometric data, or data revealing racial or ethnic origin or religious beliefs.
If the operator declines to act on a request made under a state privacy law, the consumer may appeal that decision. Appeals can be submitted as follows: email the privacy contact with the subject line Privacy appeal. The operator responds to an appeal in writing within the period set by the applicable state law and explains the action taken or not taken.
If an appeal is denied, the consumer may submit a complaint to the Attorney General of the consumer's state of residence. Where the applicable law requires it, the appeal decision identifies an online mechanism, if available, or another method for contacting the Attorney General.
24Account and data deletion
Users can request account and associated-data deletion through email to privacy@example.org or the account settings. Some records may remain for security, legal, tax, payment, dispute, fraud-prevention, or backup-cycle needs and will remain restricted to those purposes.
25Third-party links and services
The service integrates or links to AWS, Stripe, Anthropic, and Sentry. Those providers may act independently and publish separate privacy terms. The operator is not responsible for an independent service's practices, and users should review its notice before supplying information.
26Changes to this policy
This policy may be updated to reflect service, legal, or operational changes. The current version will be posted at https://example.org with a revised effective date. Additional notice or consent will be provided only when required by applicable law.