Privacy Policy

Last updated: August 22, 2026

This policy covers the personal information of prospective or existing Alessia users and administrative contacts for customer organizations (“you”). In summary, we collect and use personal information to set up and manage your account and provide the Services. We never sell personal information, and we do not share it except as needed to operate the Services or as described below.

At a glance

Is our data mixed with other customers’?No. Each customer runs in a dedicated single-tenant environment with separate storage, search index, and credentials.
Where does data live?United States by default. Each customer runs on a dedicated Azure environment in East US (eastus). Other US regions can be requested at provisioning.
Is it encrypted?Yes. AES-256 at rest and TLS 1.2 or higher in transit, from upload through answer generation.
Do you train AI on our data?No. Not our models, not OpenAI’s, not any third party’s. No fine-tuning, shared embeddings, or cross-customer learning.
Which AI providers see content?OpenAI, via its commercial API, under terms that prohibit training on submitted data. Only retrieved passages for a given query are sent — never your full corpus.
What happens if we leave?Full export in usable formats, then deletion of documents, extracted text, embeddings, indexes, metadata, and logs within 30 days. A certificate of deletion is available on request.
Security contactsecurity@backbayautomation.com

1. What personal information do we collect?

Information you provide

Personal information you may provide through the Services or otherwise includes:

The Alessia platform is designed for business use. It is not intended to hold personal data beyond routine business contact details for your users, HR records, payment card data, protected health information, or similar categories described in our customer agreements.

Automatic data collection

On our marketing website, we may automatically collect device and online activity data, such as IP address, browser type, pages viewed, and referral source. See Section 8 for cookies and analytics.

2. How do we use personal information?

We use personal information to:

We do not use your query text to improve the product for other customers. We may use aggregate, anonymized operational metrics — such as query counts, error rates, and latency — to operate and improve the platform.

3. How do we share personal information?

We may share personal information with:

We do not sell personal information. We do not share customer documentation with other customers or unrelated third parties for their own marketing.

4. Customer documentation and platform data

When your organization uses Alessia, you may upload technical documentation — catalogs, manuals, cut sheets, application notes, and similar materials — so your team can query them in natural language. You retain ownership of this content. We process it only to provide the Services to your organization.

Key commitments for customer documentation:

For full security and data-handling detail, see our Privacy Policy.

5. AI processing

Alessia uses retrieval-augmented generation to answer questions from your documentation. When a user asks a question:

Only the passages retrieved for a given question — typically a few thousand words — are transmitted to the model provider, along with the question itself. Your corpus as a whole is never uploaded to OpenAI.

We do not train on your data. We do not fine-tune, adapt, or otherwise improve any model using your documents, queries, or answers. We do not build shared embeddings or indexes across customers. Under OpenAI’s API terms, data submitted through the API is not used to train OpenAI models.

Image-based documents may be sent to Mistral OCR for text extraction during ingestion. Mistral is listed as a subprocessor in our Privacy Policy.

6. Your choices

Depending on where you live, you may have additional rights to access, correct, restrict, or object to certain processing. Contact us to make a request.

7. Retention and deletion

During your engagement. Source documents are retained for as long as you keep them in the platform. Query and audit logs are retained for 12 months, then deleted automatically unless your agreement specifies otherwise.

On termination. When your engagement ends:

On request, we provide written confirmation of deletion identifying what was deleted and when.

8. Cookies and analytics

Our marketing website may use cookies and similar technologies for basic functionality and analytics. We use Google Analytics to understand general traffic patterns (for example, pages viewed and referral sources). Google Analytics collects information such as IP address and browser type. Learn more at Google’s Privacy Policy, or opt out via the Google Analytics Opt-out Browser Add-on.

9. Third-party services

The Services may contain links to third-party websites or integrate with services operated by third parties. We do not control those services and encourage you to read their privacy policies.

Our authoritative subprocessor list — including Microsoft Azure, Qdrant Cloud, OpenAI, Clerk, Vercel, Mistral OCR, and Google Analytics — is described in our Privacy Policy. We provide 15 days’ written notice before adding a subprocessor that can access customer content.

10. Security

We use technical and organizational safeguards to protect personal information and customer documentation, including AES-256 encryption at rest, TLS 1.2 or higher in transit, single-tenant isolation, least-privilege access for Back Bay personnel, and logging of administrative access to customer environments.

No method of transmission or storage is completely secure. In the event of a data security incident involving your personal information, we will notify you without undue delay as required by applicable law. For security questions, contact security@backbayautomation.com.

Back Bay Automation is not SOC 2 certified today. We will not claim otherwise. We support customer security review directly and make engineering available for technical questions.

11. International processing

We are headquartered in the United States. Customer data is stored and processed in United States Azure regions by default. If you access the Services from outside the United States, your information may be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.

Where personal data is processed on behalf of a business customer, we act as processor and the customer acts as controller. A Data Processing Addendum is available as part of our contracting package.

12. Children

The Services are intended for business users and are not directed to anyone under 16. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. Material changes may also be communicated by email or in-product notice where appropriate. Continued use of the Services after changes become effective constitutes acceptance of the updated policy.

14. Contact us

Privacy and security questions may be sent to security@backbayautomation.com, or through our demo request form.

For subprocessor information and security questions, contact security@backbayautomation.com or see our Privacy Policy.