Privacy Policy
Effective September 3, 2026
This policy explains what the Newton3 GRC Assessor collects, how it is used, where it is stored and how long it is kept. The application is built for de-identified AI governance records, so it is designed to hold as little personal information as possible.
1. What we collect
- Account data: name, work email, firm, role and sign in timestamps.
- Firm governance content: use case descriptions, assessment findings, risk entries, memos, action items and approval records.
- Uploaded documents: vendor terms, policies and other artifacts the firm chooses to attach.
- Operational records: model run logs with model name, prompt version and token counts, usage limit events, prompt safety events and an append only audit log of workflow actions.
2. What we ask the firm not to enter
The application is not a case management system. The firm should not enter client names, matter names, court identifiers or contact details. Every use case runs through an identifier screen and submission is blocked while identifiers are found.
3. How we use it
- To run the assessment workflow the firm asked for.
- To draft intake fields, findings, risks and memo narrative with a pinned commercial model.
- To keep an audit trail of who changed a status, issued an assessment or adopted one.
- To enforce usage limits and to detect attempts to manipulate the assessment model.
- To support the firm and to keep the service secure and available.
We do not sell firm data. We do not use firm content for advertising. Firm content is not used to train any model.
4. Model processing
Text the firm submits for drafting is sent to a commercial model provider under a business agreement that forbids training on that text. Firm text is sanitized and placed inside a data fence before it reaches the model, so text inside a document cannot act as an instruction. Each run is logged so the firm can see on the usage page what was processed and when.
5. Storage and security
- Firm records are stored in a managed Postgres database with row level security, so a firm can only read its own rows.
- Uploaded documents and rendered memos are stored in private buckets and reached only through short lived signed links.
- Each stored document carries a SHA-256 hash so a change can be detected.
- Access is by role. Newton3 staff can issue an assessment but the firm decides whether to adopt it.
- Data is encrypted in transit and at rest.
6. Sharing
We share data only with the service providers needed to run the application: the hosting and database provider, the model provider described above, and email delivery for account messages. We disclose data if the law requires it and will tell the firm unless we are prohibited from doing so.
7. Retention
Governance records, memos and audit entries are kept for the life of the firm account because they are the firm's evidence of its assessment work. Model run logs, usage limit events and prompt safety events are kept for twenty four months. After termination the firm has thirty days to export, then the workspace and its documents are deleted. Audit entries are append only and cannot be edited from inside the application.
8. Rights and requests
A firm administrator can correct or remove account data in the settings area. A user may ask for a copy of the account data we hold about them, ask us to correct it, or ask us to delete it where we are not required to keep it. Send requests to support@newton3ai.com and we will respond within thirty days.
9. Children and consumers
The application is a business tool for law firms. It is not offered to anyone under sixteen and it is not intended to hold consumer records.
10. Changes and contact
Material changes to this policy will be posted here with a new effective date. Contact support@newton3ai.com or +1-813-461-4197 with any privacy question. See also the Terms of Service.
