TRUST & LEGAL · PRIVACY & DATA

Your governance data should be yours to understand and control.

EdenTouch AI Governance Delivery OS is designed to help consultants and organisations manage AI governance records with clear workspace separation, transparent storage options, and honest boundaries around how the platform handles information.

What information may pass through the platform.

The following types of information may be entered into or generated within the platform during normal use.

Account and login information
Consultant profile details
Client workspace names and metadata
AI system inventory records
Risk assessment records and scores
Vendor evaluation records
Governance decisions and notes
Action records and ownership assignments
Evidence files uploaded to the platform or connected storage
Generated reports
Microsoft connection metadata where integrations are enabled

Each client workspace is separate.

Consultants who manage more than one client do so through separate client workspaces. Each workspace holds its own AI systems, evidence, reports, actions, and governance records. Records from one client workspace should not appear in another.

Workspace separation is a core design requirement of the platform — not an optional feature.

Storage options that keep control with you.

Where enabled, the platform supports three Microsoft storage integrations. These are optional connections — not requirements. Each one moves a layer of control closer to the consultant or client.

Microsoft Sign-In

Users may sign in using their Microsoft 365 account. When this is enabled, login credentials are managed by Microsoft — not stored on the platform.

OneDrive Report Export

Generated reports may be exported directly to a consultant's personal OneDrive. When connected, the platform does not retain the exported report — it lives in the consultant's own Microsoft storage.

SharePoint Evidence Storage

Evidence documents may be uploaded to a client's connected Microsoft SharePoint rather than to platform storage. When connected, the document lives in the client's own Microsoft environment. The platform holds a reference only.

These integrations support storage visibility and client-controlled document workflows. They do not guarantee legal compliance, regulatory certification, or data residency obligations. Organisations with specific data residency requirements should confirm suitability with their legal or IT teams.

What users are responsible for.

Using the platform responsibly means making informed decisions about what is entered into it. These responsibilities sit with the user — not the platform.

  • Only upload information you are authorised to process.
  • Consider whether personal or sensitive data needs to be included in each record.
  • Confirm your own client-specific privacy and data obligations before uploading.
  • Use appropriate access controls and workspace permissions.
  • Consult qualified legal or data protection professionals when your situation requires it.

Cookies & Tracking Technologies

Cookies, analytics & session recordings.

EdenTouch uses three categories of storage and tracking technologies. The table below explains each one.

Essential

Always On

Required for login, security, session continuity, billing, and core platform operation. These cannot be disabled. They are necessary for the platform to function.

Analytics & Product Improvement

Optional

Used to understand page usage, onboarding friction, errors, and feature engagement. No client governance data is used for advertising or sold.

Session Recordings (Pilot)

Optional — Off by Default

Used only during controlled pilot phases to improve onboarding, identify usability errors, and understand where users get stuck. Not active until you explicitly opt in.

Session recordings — what they are and how we use them.

Session recordings capture anonymised interactions with the EdenTouch platform — such as clicks, scrolls, and navigation paths — to help us identify friction points and improve the product experience.

Session recordings are used for product improvement only. They are not used for:

  • Client assessment or profiling
  • Governance scoring or risk decisions
  • Legal or compliance reporting
  • Consultant performance evaluation
  • Inclusion in board-ready reports or evidence packs

What is masked or excluded.

We take steps to mask or exclude sensitive data from recordings where technically possible, including:

  • Passwords and authentication fields
  • Payment and billing screens
  • API keys and secrets
  • Personal data fields
  • Evidence and document upload content
  • Free-text prompts or notes that may contain client-sensitive information

Your consent and your choices.

Session recordings will not activate unless you have actively opted in. You can manage your preferences at any time via the Privacy Preferences panel.

Essential Only / Reject Optional — Keeps session recordings off.

Accept All — Enables optional analytics and session recordings.

Manage Preferences — Allows you to control each category separately.

Your consent is recorded with a timestamp and session reference. You may withdraw or change your consent at any time from Privacy Preferences. Continued use of the platform is not treated as consent to optional technologies. Pre-ticked boxes are not used.

Retention

Session recording data is retained only for the duration of the active pilot phase and reviewed at regular intervals. Data is not retained beyond what is necessary for product improvement purposes.

Legal basis (UK)

Under PECR and UK GDPR, non-essential cookies and similar technologies require informed, freely given consent before use. EdenTouch does not activate session recordings without that consent.

Questions about your data?

For any privacy or data-related questions about the platform, please use the contact page. We will respond as clearly as we can.

Contact EdenTouch →

This page provides a plain-English overview of privacy and data handling. It is not a legal privacy notice and does not replace qualified legal or data protection advice. A formal Privacy Notice covering all applicable obligations should be reviewed and published before public platform launch.

OAuth & Identity Data

How Google and Microsoft Login Handle Your Data

EdenTouch AI Governance Delivery OS uses Microsoft and Google as authentication providers. This section explains exactly what data each provider shares with us, what we do with it, and what we never access.

What We Receive From Microsoft

When you sign in with Microsoft, we receive:

  • Your name
  • Your email address
  • A unique identifier from Microsoft (we use this to recognise you on return visits)

We do NOT receive:

  • Access to your Outlook emails
  • Access to your OneDrive personal files (unless you explicitly connect OneDrive for report exports — see below)
  • Access to your SharePoint sites (unless you explicitly connect SharePoint for evidence storage — see below)
  • Your Microsoft password (we never see or store it)
  • Access to your Microsoft Teams, Calendar, or Contacts

Microsoft authentication is handled entirely by Microsoft. We never see your password. We receive only the identity information Microsoft chooses to share.

What We Receive From Google

When you sign in with Google, we receive:

  • Your name
  • Your email address
  • A unique identifier from Google (we use this to recognise you on return visits)

We do NOT receive:

  • Access to your Gmail
  • Access to your Google Drive files
  • Access to your Google Calendar or Contacts
  • Your Google password (we never see or store it)
  • Access to any other Google service

Google authentication is handled entirely by Google. We never see your password. We receive only the identity information Google chooses to share.

OneDrive Report Export — What Happens When You Connect

If you choose to connect OneDrive for report exports, we request access to:

  • Create and save files in a specific folder path: EdenTouch Governance OS/Client/Reports/
  • Write report files to that folder only

We do NOT request:

  • Access to read, modify, or delete any existing files in your OneDrive
  • Access to any other folder in your OneDrive
  • Access to your personal files, photos, or documents
  • Access to your Outlook, Calendar, or Contacts

You can disconnect OneDrive at any time from your workspace settings. Disconnection immediately revokes our access.

SharePoint Evidence Storage — What Happens When You Connect

If you choose to connect SharePoint for client evidence storage, we request access to:

  • Upload evidence files to a specific SharePoint document library you designate
  • List files within that designated library (so you can see what's stored)

We do NOT request:

  • Access to any other SharePoint site or library
  • Access to read, modify, or delete existing SharePoint content
  • Access to your organisation's Teams, email, or calendar
  • Administrator or site owner permissions

You can disconnect SharePoint at any time from your workspace settings. Disconnection immediately revokes our access.

Data Minimisation Principle

We follow a strict data minimisation approach to OAuth:

  • We request only the scopes (permissions) required for the specific feature you are using
  • We never request broader access than needed
  • Each integration (login, OneDrive, SharePoint) requires separate, explicit consent
  • You can revoke any integration at any time without affecting your account access
  • Revoking an integration does not delete your EdenTouch account or your governance data

If you revoke Microsoft or Google login access, you can continue using email and password login. Your governance data remains intact.

Your Rights and Controls

You have the right to:

  • Know what data Microsoft and Google share with us (listed above)
  • Disconnect any integration at any time from your workspace settings
  • Request deletion of your identity data from our systems
  • Continue using the platform with email and password if you revoke OAuth access
  • See which integrations are active in your Data Sovereignty Panel

We do not sell, share, or transfer your OAuth data to any third party.

EdenTouch AI Governance Delivery OS is designed around a simple principle: you control your data. Microsoft and Google are used to verify your identity and, only when you choose, to store files in your own systems. We never see your passwords, never access more than we need, and never hold your data hostage.