TRUST & LEGAL · PRIVACY & DATA
EdenTouch AI Governance Delivery OS is designed to help consultants and organisations manage AI governance records with clear workspace separation, transparent storage options, and honest boundaries around how the platform handles information.
The following types of information may be entered into or generated within the platform during normal use.
Consultants who manage more than one client do so through separate client workspaces. Each workspace holds its own AI systems, evidence, reports, actions, and governance records. Records from one client workspace should not appear in another.
Workspace separation is a core design requirement of the platform — not an optional feature.
Where enabled, the platform supports three Microsoft storage integrations. These are optional connections — not requirements. Each one moves a layer of control closer to the consultant or client.
Users may sign in using their Microsoft 365 account. When this is enabled, login credentials are managed by Microsoft — not stored on the platform.
Generated reports may be exported directly to a consultant's personal OneDrive. When connected, the platform does not retain the exported report — it lives in the consultant's own Microsoft storage.
Evidence documents may be uploaded to a client's connected Microsoft SharePoint rather than to platform storage. When connected, the document lives in the client's own Microsoft environment. The platform holds a reference only.
These integrations support storage visibility and client-controlled document workflows. They do not guarantee legal compliance, regulatory certification, or data residency obligations. Organisations with specific data residency requirements should confirm suitability with their legal or IT teams.
Using the platform responsibly means making informed decisions about what is entered into it. These responsibilities sit with the user — not the platform.
Cookies & Tracking Technologies
EdenTouch uses three categories of storage and tracking technologies. The table below explains each one.
Required for login, security, session continuity, billing, and core platform operation. These cannot be disabled. They are necessary for the platform to function.
Used to understand page usage, onboarding friction, errors, and feature engagement. No client governance data is used for advertising or sold.
Used only during controlled pilot phases to improve onboarding, identify usability errors, and understand where users get stuck. Not active until you explicitly opt in.
Session recordings capture anonymised interactions with the EdenTouch platform — such as clicks, scrolls, and navigation paths — to help us identify friction points and improve the product experience.
Session recordings are used for product improvement only. They are not used for:
We take steps to mask or exclude sensitive data from recordings where technically possible, including:
Session recordings will not activate unless you have actively opted in. You can manage your preferences at any time via the Privacy Preferences panel.
Essential Only / Reject Optional — Keeps session recordings off.
Accept All — Enables optional analytics and session recordings.
Manage Preferences — Allows you to control each category separately.
Your consent is recorded with a timestamp and session reference. You may withdraw or change your consent at any time from Privacy Preferences. Continued use of the platform is not treated as consent to optional technologies. Pre-ticked boxes are not used.
Session recording data is retained only for the duration of the active pilot phase and reviewed at regular intervals. Data is not retained beyond what is necessary for product improvement purposes.
Under PECR and UK GDPR, non-essential cookies and similar technologies require informed, freely given consent before use. EdenTouch does not activate session recordings without that consent.
For any privacy or data-related questions about the platform, please use the contact page. We will respond as clearly as we can.
Contact EdenTouch →This page provides a plain-English overview of privacy and data handling. It is not a legal privacy notice and does not replace qualified legal or data protection advice. A formal Privacy Notice covering all applicable obligations should be reviewed and published before public platform launch.
OAuth & Identity Data
EdenTouch AI Governance Delivery OS uses Microsoft and Google as authentication providers. This section explains exactly what data each provider shares with us, what we do with it, and what we never access.
When you sign in with Microsoft, we receive:
We do NOT receive:
Microsoft authentication is handled entirely by Microsoft. We never see your password. We receive only the identity information Microsoft chooses to share.
When you sign in with Google, we receive:
We do NOT receive:
Google authentication is handled entirely by Google. We never see your password. We receive only the identity information Google chooses to share.
If you choose to connect OneDrive for report exports, we request access to:
We do NOT request:
You can disconnect OneDrive at any time from your workspace settings. Disconnection immediately revokes our access.
If you choose to connect SharePoint for client evidence storage, we request access to:
We do NOT request:
You can disconnect SharePoint at any time from your workspace settings. Disconnection immediately revokes our access.
We follow a strict data minimisation approach to OAuth:
If you revoke Microsoft or Google login access, you can continue using email and password login. Your governance data remains intact.
You have the right to:
We do not sell, share, or transfer your OAuth data to any third party.
EdenTouch AI Governance Delivery OS is designed around a simple principle: you control your data. Microsoft and Google are used to verify your identity and, only when you choose, to store files in your own systems. We never see your passwords, never access more than we need, and never hold your data hostage.
Privacy Preferences
We use essential cookies to run EdenTouch. With your permission, we may also use analytics and session recordings to improve onboarding, fix errors, and understand where users get stuck. Session recordings are for product improvement only and are not used in governance reports or client assessments. Privacy & Data Policy