Your data, and exactly what we do with it.
Written to be read, not survived. If anything here is unclear, write to us and a person will answer.
Hedge · consulthedge.ai · version 7 · effective 8 August 2026
Who is responsible: Hedge Labs for Project Management L.L.C., trading as Hedge AI ("Hedge", "we"), operating the Hedge AI platform at consulthedge.ai and serving customers worldwide. Contact us at support@consulthedge.ai; our registered company details are available on request.
One standard, everywhere. We apply the same privacy standard to every customer in every country, rather than a weaker one where the local law happens to allow it. Where your country gives you a right this policy does not mention, you still have it.
At a glance
| Question | Answer |
|---|---|
| What do you collect? | Account details (name, email, mobile number), the work you put in, what the platform produced, billing records, and ordinary technical logs. |
| Do you sell my data? | No. No advertising networks, no data brokers. |
| Do you train AI on my data? | Not on your work, unless you say yes — a separate switch, off by default, revocable any time. We do use anonymous records of how the platform ran, and material stripped of anything identifying you or anyone else. |
| Where does it live? | The service and database run on Google Cloud in the europe-west1 region (Belgium). Files you upload are held in Google Cloud Storage. |
| Can other companies see my work? | No. Companies are separated at the point data is read or written. |
| How do I exercise my rights? | Email support@consulthedge.ai — access, correction, deletion, export, objection, withdrawal of consent. |
1 · What this policy covers, and our two roles
This policy covers personal data handled when you visit consulthedge.ai, create an account, and use the Hedge AI platform. It applies wherever you are.
We act in two distinct roles:
- For your account data (name, email, mobile number, billing and usage records) we are the controller — we decide how and why it is processed, as described here.
- For the content you put into the platform (documents, files, mail, repositories and other material, which routinely contains personal data about other people — your clients, employees or counterparties) we are a processor: we process it only on your instructions, to provide the Service. You are responsible for having the right to put that material in. Company customers can request our Data Processing Addendum, which governs this in contractual detail.
2 · What we collect
- Account details — your name, email address and mobile number: to create and secure your account and reach you about the Service.
- Your content — the tasks you ask for, the files and documents you upload, the systems you connect, and your knowledge base.
- What the platform produced — your finished files, and the record of each task: what was asked, what was used, what was produced, and what it cost.
- Billing data — your plan, credit purchases and consumption. Card payments are handled by payment service providers; we receive confirmation and billing records, not full card numbers.
- Technical data — the ordinary logs a service keeps to stay secure and available: IP address, device and browser information, timestamps, and security events.
- Communications — what you send to support, so we can help you.
About your mobile number: we collect it for account security and service contact. Verification codes are sent by email today; WhatsApp may be added as a channel later. We do not send SMS, and we do not use your number for marketing.
3 · Why we use it, and on what legal basis
| Purpose | What it means | Legal basis |
|---|---|---|
| Providing the Service | Producing your work, storing it, delivering it where you told us to | Performance of our contract with you |
| Security and abuse prevention | Keeping the platform and customers safe, investigating incidents | Legitimate interest / legal obligation |
| Billing | Recording what was produced and what it cost; invoicing | Performance of contract / legal obligation |
| Service communications | Verification codes, receipts, notices about your account | Performance of contract |
| Improving the platform | Using records of how the Service ran — effort levels, scores, retries, timings, costs, failure patterns — to find what to fix | Legitimate interest |
| Training our models on your actual work | Using your files, tasks and finished documents as they are | Your consent only — see Section 4 |
| Training on de-identified material | Using material from which everything identifying you, your business and any person has been irreversibly removed | Once material is irreversibly de-identified it is no longer personal data, and data-protection law no longer applies to it |
| Complying with law | Responding to lawful orders; tax and accounting records | Legal obligation |
Where the law that applies to you recognises different grounds, or requires your consent for something listed above, we rely on the ground that law provides. We do not use your personal data for advertising, and we do not profile you for marketing.
4 · AI and your data
- The AI systems that produce your work read your content to do the task you asked for — that is the Service working, not a secondary use.
- We do not use your content in identifiable form to train shared models unless you turn on the "improve the service" consent. It is a separate question on its own screen, presented off by default, never bundled with the Terms, and the same switch stays in your account so you can turn it off at any time. Turning it off stops the use going forward.
- We may offer you credits for turning it on. If we do, it stays your free choice: the platform and every plan work exactly the same if you say no, and if you turn it off later we do not take the credits back or charge you for credits you already spent.
- Two things we use without asking, because neither one is about you. First, the record of how the Service ran — which effort level, what it scored, how many retries, how long, what it cost. Second, material from which everything identifying you, your business and any person has been irreversibly stripped. Once that stripping is genuine and cannot be undone, the material is no longer about anybody, and we use it to improve and train the systems that produce work. Until the stripping is genuine, it is still your content and the paragraph above governs it.
- Material that fails our quality bar is never used to teach anything — a bad input cannot quietly become a lesson.
- Third-party model providers process data only on our instructions to perform your tasks; we do not permit them to use your content to train their models.
Our public AI Policy describes how AI systems are selected, controlled and held accountable.
5 · Where your data lives
The Service and its database run on Google Cloud, in the europe-west1 region (Belgium). Files you upload are held in Google Cloud Storage, reachable only through the application and only by people you have given access to.
Because we serve customers globally and our team works from more than one country, data may be accessed from outside the region where it is stored — for example by our staff supporting the Service, or when you or your team sign in from another country. Access is limited to people who need it, controlled by role, and recorded. Where the law requires safeguards or authorisations for international transfers, we apply those described in Section 14.
6 · Who can see your data inside the platform
- One company cannot see another's work. Separation is enforced at the point data is read or written — not only at sign-in.
- Access follows the role you assign a person, and that check happens on our servers, never in the browser.
- Administrators are confined to their own company. Permissions over money are separated from permissions over administration.
- Connecting a source never widens who can see a file — the sharing rules of the system you connected are enforced as they are, and the connection's credentials are scoped to you, encrypted at rest, and only ever assembled on the server.
- Refused access attempts are recorded.
7 · Who we share it with
We do not sell your information. We do not share it with advertising networks or data brokers.
We share personal data only with:
- Service providers (sub-processors) — a limited set of providers we use to run the Service, in these categories: cloud infrastructure and storage; AI model providers; authentication; payment processing; and communications delivery. They act on our documented instructions, under contracts restricting them to providing their service to us.
- Professional advisers and authorities — where the law requires it or to establish or defend legal claims, disclosing the minimum necessary and, where lawful, telling you first.
- A buyer of the business — if Hedge is reorganised or sold, under this policy's protections, with notice to you.
The specific composition of our AI engine is confidential.
8 · Security
- Data is encrypted in transit and at rest.
- Every action carries who asked and who executed it, in an append-only record that nobody — including us — can alter or selectively delete.
- Actions that cannot be quietly undone — spending money, publishing publicly, changing the rules an AI specialist works under — always stop for a human approval.
- Code execution runs in an isolated sandbox created for one piece of work and destroyed afterwards, holding no platform credentials and no route to our database, keys or storage.
- Cross-customer isolation is covered by an automated test suite that runs against the platform.
If a breach of security affects your personal data, we will inform you and the competent authority without undue delay and within the deadlines the law applying to you sets, and tell you what happened, what it affects and what we are doing about it.
9 · How long we keep it
- Your content stays for as long as your account does — the archive is part of what you pay for. You can delete items, or your account, at any time.
- The task and audit record (who asked for what, who executed it, what it cost) is kept as a permanent, append-only log — it is what makes "who did this?" answerable, for you and for us.
- Billing records are kept as long as tax and accounting law requires.
- Unverified accounts may be removed after 90 days.
When you delete: the content of your work is deleted from the live systems. What is retained is the minimal event record — that a task ran, when, by whom, and its cost — with the content itself removed. Backups roll off on their cycle.
What deletion does not reach: records of how the Service ran, and material that has already been irreversibly de-identified, are not deleted — because they can no longer be traced to you or to anyone else, there is nothing in them left to delete. Where anything de-identified could still be traced back to you, it counts as your content and deletion does reach it.
10 · Your rights
Wherever you are, you can at any time:
- Access — ask for a copy of the personal data we hold about you.
- Correct — tell us what is wrong; we fix it.
- Delete — ask, and your data is removed as Section 9 describes — not merely hidden from you.
- Export — take your work and your data with you, in the formats you put them in.
- Object or restrict — object to processing based on legitimate interest, or ask us to restrict processing while a dispute is resolved.
- Withdraw consent — the "improve the service" switch is yours to turn off at any time; withdrawal does not affect processing that already lawfully happened.
- Complain — to us first, we hope. You always have the right to complain to the data protection authority in your own country, and to any supervisory authority with jurisdiction over us.
We do not make automated decisions that produce legal or similarly significant effects about you: consequential actions on this platform require a human decision by design.
Write to support@consulthedge.ai. A person — not an automated system — handles rights requests. We may need to verify your identity before acting. We respond without undue delay, and always within the deadline the law applying to you sets.
11 · Cookies and similar technologies
We use cookies that are necessary for the Service to work: keeping you signed in, keeping the platform secure, and remembering your settings. We do not use advertising or cross-site tracking cookies, so no consent banner is needed to visit the site. If we ever introduce optional analytics cookies, we will ask you first, with the choice unticked by default.
12 · Children
The Service is for professional use by adults. It is not directed at children, and you must be 18 or older to hold an account. We do not knowingly collect children's data; if you believe a child has given us personal data, contact us and we will delete it.
13 · Connected services
When you connect a third-party system (mail, storage, boards, repositories), we access it only with the permissions you granted, for the purpose you connected it. Revoking the connection stops that access. The third party's own privacy policy governs their side.
14 · International transfers
We run a single global service, so personal data moves between countries: it is stored in the EU (Section 5), accessed by our team from the countries in which we operate, and processed by service providers in several countries. Where the law that applies to you requires safeguards or authorisations for those movements, we put them in place — contractual protections with our providers, and any permit or approval that law provides for. We will honour any stricter residency commitment made in a written agreement with your company.
15 · Changes to this policy
If we change this policy in a way that materially affects you, we will notify account holders before the change takes effect. The date at the top is always the version you are reading.
16 · Contact
Hedge Labs for Project Management L.L.C., trading as Hedge AI
support@consulthedge.ai
Registered company details and address are available on request.