Overview
Augmas (“we”, “us”, “our”) operates the Enterprise AI Platform at augmas.ai. This Privacy Policy explains how we collect, use, store, and share your information when you use our platform, including the web application, API, Slack bot, Microsoft Teams bot, and related services (the “Service”).
By using the Service, you agree to this policy. If you do not agree, please do not use the Service.
Information We Collect
Information you provide
- Account details — name, work email, and password (or SSO credentials).
- Organisation details — company name, billing address, and subscription plan.
- Payment information — processed by our payment provider; we do not store full card details.
- Support communications — messages sent to our support team or contact forms.
- Configuration — connector settings, agent instructions, and workspace preferences.
Information collected automatically
- Usage data — features used, queries submitted (metadata only), session duration, interaction patterns.
- Log data — IP address, browser type, operating system, pages visited, and timestamps.
- Device information — hardware model, OS version, and unique device identifiers.
- Analytics — anonymised, aggregated metrics to understand platform performance.
Information from connected sources
When you connect third-party tools (Jira, Slack, Google Drive, GitHub, HubSpot, and others), Augmas retrieves and indexes content to power your workspace AI. This content is:
- Stored in an isolated, per-tenant vector index — never mixed with other customers’ data.
- Subject to your own tool’s permission model — Augmas only retrieves what your account is authorised to access.
- Used exclusively to generate answers within your workspace — not for any other purpose.
How We Use Your Data
| Purpose | Legal Basis (GDPR) | Description |
| Providing the Service | Contract performance | Processing queries, generating AI responses, syncing connected sources, and delivering core functionality. |
| Account management | Contract performance | Creating and managing your workspace, processing payments, and sending service-critical communications. |
| Security & fraud prevention | Legitimate interest | Detecting, investigating, and preventing fraudulent, abusive, or harmful activity. |
| Platform improvement | Legitimate interest | Analysing anonymised usage patterns to improve reliability, performance, and features. |
| Legal compliance | Legal obligation | Complying with applicable laws, regulations, and lawful requests from authorities. |
| Marketing (optional) | Consent | Product updates and newsletters — only if you have opted in. Withdraw consent at any time. |
Your Data in Augmas
Multi-tenant isolation
Every workspace operates in hard isolation. Every database query and every vector search is tenant-scoped — there is no code path that could return data from one customer’s workspace to another. Connector credentials are stored with AES-256-GCM encryption at rest.
Vector indexing
Content from your connected tools is chunked, embedded using a semantic embedding model, and stored in your dedicated vector index. This enables the AI to retrieve relevant content when your users ask questions.
LLM processing
When a user submits a query, retrieved content is sent to your configured LLM (Claude, GPT-4, Gemini, or Groq) along with the query to generate a response. If you use a third-party LLM provider, their data processing terms also apply to that transmission.
Per-user OAuth
When users connect their own Google or Microsoft accounts for MCP agent actions, Augmas acts using that individual user’s OAuth token — not a shared service account. Tokens are stored encrypted and refreshed automatically. Users can revoke access at any time.
Access controls
Every retrieval simultaneously applies tenant isolation, per-user ACL, document-set scope, source-type, and time filters. A user can only receive answers based on content they are authorised to access in the underlying source system.
Sharing & Disclosure
We do not sell your personal information. We do not share your connected source content with any third party except as described below.
Service providers
We engage trusted service providers under strict data processing agreements — including infrastructure providers, LLM API providers (when you use a third-party model), payment processors, and analytics services. Each is bound by confidentiality and data protection obligations.
LLM providers
If your workspace uses a third-party LLM (OpenAI, Anthropic, Google), retrieved content is transmitted to that provider’s API. We recommend reviewing the applicable provider’s API data usage policy. By default, most major providers do not use API inputs to train their models.
Business transfers
If Augmas is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
Legal requirements
We may disclose your information where required by law, court order, or governmental authority, or to protect the rights, property, or safety of Augmas, our users, or the public.
Data Retention
We retain your data for as long as your workspace is active and as necessary to provide the Service.
| Data type | Retention period |
| Account data | Lifetime of account + 30 days after deletion. |
| Indexed content | Until you disconnect a source, delete documents, or delete your workspace. |
| Chat history | Per your workspace retention settings (default: indefinite; configurable by admins). |
| Audit logs | 12 months by default for enterprise workspaces. |
| Billing records | 7 years as required by applicable financial regulations. |
When you delete your workspace, we delete all associated data within 30 days, except where retention is required by law.
Security
We implement industry-standard technical and organisational measures to protect your information, including:
• AES-256-GCM encryption of all connector credentials and sensitive configuration at rest.
• TLS 1.2+ encryption for all data in transit.
• Hard multi-tenant isolation — every query is scoped at the database and vector store level.
• Role-based access control (Super Admin, Admin, Member, Limited, Service Account) with SSO/SAML.
• SCIM 2.0 for automated user provisioning and deprovisioning.
• Full audit logging of all administrative and data access events.
• Regular security reviews and penetration testing.
No method of electronic storage is 100% secure. In the event of a breach affecting your personal information, we will notify you in accordance with applicable law.
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
| Right | What it means |
| Access | Request a copy of the personal information we hold about you. |
| Correction | Request that we correct inaccurate or incomplete information. |
| Deletion | Request that we delete your personal information, subject to legal exceptions. |
| Portability | Request a machine-readable copy of your data to transfer to another service. |
| Objection | Object to processing based on legitimate interest, including direct marketing. |
| Restriction | Request that we restrict processing in certain circumstances. |
| Withdraw consent | Withdraw consent at any time where processing is based on consent. |
To exercise any of these rights, contact us at info@augmas.com. We will respond within 30 days. If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection authority.
Cookies
| Category | Can be disabled? | Purpose |
| Essential | No — required to function | Authentication session, CSRF protection, core platform functionality. |
| Functional | Yes | Remembering your preferences (theme, language, sidebar state). |
| Analytics | Yes — opt out via browser settings | Anonymised, aggregated metrics to understand platform usage and improve features. |
You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the Service.
International Transfers
Augmas is operated from the United Arab Emirates. If you access the Service from outside the UAE — including from the EEA or UK — your information may be transferred to and processed in countries with different data protection laws.
Where we transfer personal data from the EEA or UK to countries without adequate protection, we use Standard Contractual Clauses approved by the European Commission. Enterprise customers with specific data residency requirements are encouraged to contact us at info@augmas.com to discuss available options.
Children
Augmas is designed for enterprise and business use. It is not directed at children under 16. We do not knowingly collect personal information from children. If you believe we have done so, please contact us at info@augmas.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
• Update the “Last updated” date at the top of this policy.
• Notify workspace administrators by email at least 14 days before changes take effect.
• Display a prominent notice inside the Augmas platform.
Your continued use of the Service after the effective date constitutes acceptance of the changes. If you do not agree, please discontinue use and contact us to close your account.
Contact Us
Augmas Privacy Team
Email: info@augmas.com
General: info@augmas.com
Website: www.augmas.ai
We aim to respond to all privacy enquiries within 5 business days and complete data subject requests within 30 days.