Last updated: 2026-04-19
Privacy Policy
Concord AI ("we", "us") provides contract automation and e-signature software for service businesses. This policy explains what personal information we collect, why, and the rights you have. It applies to concord.ai and all Concord AI-hosted workspaces.
1. Information we collect
- Account data: name, work email, hashed password, organization, role.
- Workspace content: contract templates, agreement drafts, client records, signature images, executed PDFs.
- Signing evidence: typed signer name, drawn signature, IP address, user-agent, timestamps, consent flags. Captured server-side and stored as immutable audit events (ESIGN/UETA).
- Usage telemetry: pages viewed, features used, error logs. Aggregated and pseudonymized.
- We do NOT collect: SSN, payment card data, government IDs, biometrics, precise geolocation.
2. Lawful basis (GDPR)
We process personal data under: (a) contract — to provide the service to workspace owners; (b) legitimate interests — securing the platform and preventing abuse; (c) legal obligation — recordkeeping for ESIGN/UETA, IRS, HIPAA, and state insurance/financial rules; (d) consent — for optional marketing communications (you can withdraw at any time).
3. How we use information
- Operate the e-signature, audit, and approval workflows you initiate.
- Generate executed PDFs with embedded audit certificates.
- Send transactional emails (invites, signed copies, reminders) and security notices.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and respond to lawful requests.
We do not sell or rent personal information. We do not use customer workspace content to train AI models.
4. Sub-processors
A current list of sub-processors (cloud hosting, email delivery, error monitoring) is published at /trust and updated at least 30 days before any addition.
5. Data residency
Default region: US (us-east-1). EU residency available on request (eu-west-1). Data does not cross regions without explicit customer authorization.
6. Retention
- Active agreements: retained for the life of the workspace.
- Completed agreements: 7 years by default to satisfy IRS, HIPAA, and most state insurance/financial recordkeeping rules. Configurable per workspace.
- Deleted records: soft-deleted for 30 days, then permanently purged.
7. Your rights
Subject to applicable law (GDPR, CCPA/CPRA, others), you may request access, portability, correction, deletion, restriction, or objection. Email privacy@concordapp.ai from the address on file. We respond within statutory timeframes (typically 30 days). Identity verification is required before any data is released.
8. Security
TLS 1.2+ in transit, AES-256 at rest, multi-tenant isolation via PostgreSQL Row-Level Security, immutable audit logs, HaveIBeenPwned password screening, and least-privilege role-based access. Full controls matrix at /trust.
9. Children
Concord AI is not directed to children under 16 and we do not knowingly collect their data.
10. Changes
We will notify workspace owners by email at least 30 days before any material change. The "Last updated" date at the top reflects the current version.
11. Contact
- Privacy / DSR: privacy@concordapp.ai
- Security: security@concordapp.ai
- Compliance: compliance@concordapp.ai
This document is informational and does not constitute legal advice.