Data Usage Policy
Effective date: August 4, 2026 · Last updated: August 8, 2026
1. Why this document exists
GOVERNBOX.ai asks organizations to describe their AI tools, risks, technology, and data practices in order to generate governance documentation. That is sensitive business information, and increasingly it includes information about your own staff. You are owed a plain-language explanation of exactly what happens to it — separate from the more general legal language in our Privacy Policy.
2. What you put into the Service
The Service has five modules. Four are licensed individually or as a bundle; the fifth, Privacy, is included with the Pro and Agency plans and adds no data categories of its own beyond the documents and framework mappings described under AI Governance and Data Management. Depending on which modules you license, your organization may enter:
AI Governance
- Organization profile details (sector, size, risk appetite, data sensitivity level, mission statement, selected compliance frameworks, logo, and a business contact)
- An inventory of AI tools and use cases in production or under evaluation
- Risk register entries and risk-treatment plans
- Impact assessment questionnaire responses
- AI project and AI agent registrations
- Incident reports
- Training plan records
- AI and technology cost records
- Answers to the free Readiness Scorecards
- The organizational context you provide when generating a document through a wizard
Enterprise Risk Management
- Organization-wide risks across six categories, with likelihood and impact scoring
- Key risk indicators, their thresholds, current readings, and review dates
IT Inventory & Management
- Devices and hardware assets, including assignee, location, warranty and end-of-life dates
- Software subscriptions, including vendor, owner, seat counts, cost, and renewal dates
- Systems, including hosting, administrator, backup posture, single sign-on and multi-factor status, and data classification
- Access records — who has access to which systems, at what level, and whether they have been offboarded
Data Management
- An inventory of data categories you hold, their classification, steward, and lawful basis
- Data flows, including where data goes, who processes it, and whether it crosses borders
- Retention schedules and disposal methods
- Individual privacy requests (DSARs), including the requester’s name and email, the request type, and your notes and resolution
3. Information about people. Read this before you upload a roster
Some features are specifically designed to hold information about individuals, most of whom will never use the Service:
- Attestation rosters. To ask staff to read and sign off on a policy, you upload their names, business email addresses, and departments by typing them or importing a spreadsheet. They receive an individual link by email. They do not get accounts and never sign in.
- Attestation signatures. When someone signs, we record the name they type and the moment they did it. This record is permanent by design. It cannot be edited, re-signed, or removed, because its entire purpose is to be evidence you can show an auditor or a board.
- Training completion against that same roster.
- IT access records, naming individuals and what they can reach.
- Privacy request records, naming the person who made the request.
- Named owners throughout — a use case owner, a risk owner, a data steward, a task assignee, the person who approved a policy.
- External reviewers. If you share a document by link, anyone with that link can comment and leave their name and email.
Your organization is responsible for this information. You decide whose details go in, and you should be satisfied you have a lawful basis and, where appropriate, have told those people. We process it on your instructions. If one of your staff asks us directly to remove their details, we will refer them to you, because it is your record, not ours.
4. How your data is used to generate documents
When you generate a document, the Service does the following, in order:
- Your organization’s profile and the specific inputs you provide are converted into a search query.
- That query is matched against GOVERNBOX.ai’s proprietary regulation library.
- The matched controls, along with your organizational context, are sent to a third-party AI model (currently Anthropic’s Claude).
- The resulting document sections are saved to your organization’s isolated records, each tagged with the identified controls and stamped with the exact library version, model, and prompt version used.
- You are prompted to review the document before approving, finalizing, or exporting it.
5. What we do not do with your data
- We do not use your content to train or fine-tune any AI model — not any model of our own. Your submissions are used only to produce the specific output you requested.
- We do not let one organization’s data reach another organization. Every tenant table is isolated by organization identifier, enforced both in our application code and as a database-level access policy, through a database account that has no ability to override it. It fails closed: if the isolation context is missing, the query returns zero rows rather than another tenant’s rows.
- We do not sell your governance content or your customer data.
- We do not log your governance content to our error-monitoring tooling. Monitoring captures technical error details without the substance of what you submitted.
- Gradient Descent staff do not casually browse customer data. A small number of authorized staff have cross-tenant administrative access strictly for support and platform maintenance, and every such action is written to your organization’s own audit log, which you can review.
6. Where your data goes
At a high level, governance content you submit flows like this:
Your browser → our application servers → our tenant-isolated database and, only for the specific action of generating or searching a document, outward to our AI provider, with the result written back into your isolated database record.
Separately, and not mixed with your governance content:
- Authentication details go to our identity provider.
- Billing details go to our billing provider, which settles payment through its own downstream payment processor. We never see or store card numbers.
- Product usage events go to our analytics provider. When you are signed in, those events are associated with your name and email address.
- Technical error signals, scrubbed of your content, go to our error-monitoring provider.
- Transactional email — including attestation invitations to the roster you upload — goes to our email delivery provider.
- Business contact details from your organization profile go to our customer relationship management system so we can support the account.
All of our infrastructure is located in the United States. We do not currently offer regional data residency.
7. Our public website is measured for advertising
Our marketing pages and the free Readiness Scorecards load third-party advertising and analytics tags, including Google Tag Manager, a Google Ads conversion tag, and product analytics. We record the marketing campaign and advertising click identifiers that brought a visitor to us, and when an account is created we report that conversion, including the account holder’s email address, to our advertising provider so we can measure which campaigns work.
Our marketing pages also carry a visitor-identification tag, from Apollo.io. Plainly: it takes the IP address of a visitor to our public website and matches it against a third-party business dataset to work out which organization — and sometimes which person — is browsing, so our sales team can follow up. It runs on our public pages only. It is switched off inside the signed-in Service, and switched off on attestation links, shared documents, and Trust Pages, so nobody your organization sends to one of those pages is identified by us. Visitors who use the opt-out on our website are not identified at all. Full detail is in Privacy Policy §3.8 and §6.9.
This is separate from your governance content, which is never used for advertising and is never sent to an advertising provider.
8. Your control over your data
- Export. Organization Owners can export their organization’s data as a structured file at any time through the Admin Console.
- Deletion. Deleting a record removes it from the application. Closing an organization account ends access and marks the organization inactive. Neither immediately erases the underlying rows from our database, and we do not currently run an automated purge on a schedule. If you want your data permanently erased, contact us and we will do it manually — see Section 12.
- Two deliberate exceptions. Your audit log and your attestation signature records are permanent and are not deleted when related records are. Both exist to be evidence, and evidence that can be quietly removed is not evidence. If this conflicts with an obligation you have, talk to us before you rely on those features.
- Backups. After deletion from active systems, residual copies remain in encrypted backups for our hosting provider’s retention cycle.
- Audit trail. Every create, edit, export, approval, and role change is recorded in an append-only log that you, not just we, can view.
- Framework and module selection. You choose which compliance frameworks apply and which modules you license; those choices determine what is retrieved and generated for you going forward.
9. Analytics, separate from your governance content
We track product usage events — which features get used, whether a document was generated and successfully exported — to understand adoption and improve the product. This is operational telemetry about how the product is used, not the substantive content of what you entered, and it is never used to generate your documents.
When you are signed in, these events are linked to your user account, name, and email address, not held as anonymous aggregates. That is how we can tell whether a given customer is getting value from a feature.
10. A note on sensitive personal data
Please avoid entering sensitive personal data about identifiable individuals (health records, government identifiers, financial account numbers, biometric data) into free-text fields, unless you have a specific written agreement with us covering that category of data. The frameworks the Service can reference — including HIPAA, GDPR, and CCPA — describe governance obligations your organization may have; supporting those frameworks in generated language is not the same as our infrastructure carrying a corresponding certification. If this applies to you, contact us before submitting that data.
11. Not legal or compliance advice
Documents generated by the Service are drafting aids grounded in a control library, not a substitute for legal review. Every document requires human review before your organization relies on, approves, or publishes it. Coverage and gap analysis is advisory information for your reviewer, not a determination that you are or are not compliant. Gradient Descent LLC is not a law firm, and using the Service does not create an attorney-client relationship.
12. Questions
If you have questions about how your data is used, before or after you sign up, use our Contact page or email info@gradientdescent.biz with the subject line “Data Usage Question.” We are glad to walk through this in more detail, including for procurement or security-review purposes, and can provide a named list of our service providers on request.