Privacy Policy
Last Updated: December 2025
1. Introduction
AMIDS USA ("Company", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use AMIDS Scribe ("Service").
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, name, organization name, and password when you create an account
- Questionnaire Responses: Information you provide when completing compliance questionnaires to generate documents
- Payment Information: Payment card details processed through Stripe (we do not store full card numbers)
- Communications: Information in emails, support requests, or other communications with us
2.2 Information Collected Automatically
- Usage Data: Features used, documents generated, pages visited, and actions taken
- Device Information: Browser type, operating system, device type, and screen resolution
- Log Data: IP address, access times, and referring URLs
- Cookies: Session and preference cookies for authentication and functionality
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Generate compliance documents based on your inputs
- Process payments and manage subscriptions
- Send transactional emails (receipts, document notifications)
- Respond to your requests and provide customer support
- Monitor and analyze usage patterns to improve user experience
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
4. AI Processing and Data Handling
How Your Data is Used with AI
AMIDS Scribe uses AI models (provided by Anthropic) to generate compliance documentation. Here's how your data is handled:
- Questionnaire Processing: Your responses are sent to AI systems to generate customized documents
- No Training: Your data is NOT used to train AI models
- Data Minimization: We only send information necessary for document generation
- Secure Transmission: All data is encrypted in transit using TLS
- Temporary Processing: AI providers do not retain your data after processing
5. Data Sharing and Disclosure
We may share your information with:
5.1 Service Providers
- Supabase: Database and authentication services
- Anthropic: AI processing for document generation
- Stripe: Payment processing
- Vercel: Hosting and infrastructure
5.2 Legal Requirements
We may disclose information if required by law or to:
- Comply with legal process or government requests
- Protect our rights, privacy, safety, or property
- Enforce our Terms of Service
- Investigate potential violations
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
6. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Secure authentication with password hashing
- Row Level Security (RLS) for database access control
- Regular security audits and monitoring
- Limited employee access to personal data
However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Data Retention
- Account Data: Retained while your account is active, deleted within 30 days of account closure
- Generated Documents: Retained for 1 year from generation date, then automatically deleted
- Questionnaire Responses: Retained while account is active for regeneration purposes
- Payment Records: Retained for 7 years for legal and tax compliance
- Usage Logs: Retained for 90 days for security and analytics
8. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate data
- Deletion: Request deletion of your data
- Portability: Receive your data in a portable format
- Opt-out: Opt out of marketing communications
- Restrict Processing: Limit how we use your data
To exercise these rights, contact us at privacy@amidsusa.com.
9. Cookies and Tracking
9.1 Cookies We Use
- Essential Cookies: Required for authentication and core functionality
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how users interact with the Service
9.2 Managing Cookies
You can control cookies through your browser settings. Disabling essential cookies may affect functionality.
10. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification.
13. Contact Us
For questions about this Privacy Policy or our data practices, contact us at:
AMIDS USA
Privacy Inquiries: privacy@amidsusa.com
General Support: support@amidsusa.com
Website: https://amidsusa.com