Privacy Policy
Last updated: August 22, 2026
This Privacy Policy describes how Back Bay Automation (“Back Bay,” “we,” “us,” or “our”) handles personal information we collect through our website, the Alessia AI document intelligence platform (collectively, the “Services”), our social media channels, or directly from you by other means.
This policy covers the personal information of prospective or existing Alessia users and administrative contacts for customer organizations (“you”). In summary, we collect and use personal information to set up and manage your account and provide the Services. We never sell personal information, and we do not share it except as needed to operate the Services or as described below.
At a glance
| Is our data mixed with other customers’? | No. Each customer runs in a dedicated single-tenant environment with separate storage, search index, and credentials. |
|---|---|
| Where does data live? | United States by default. Each customer runs on a dedicated Azure environment in East US (eastus). Other US regions can be requested at provisioning. |
| Is it encrypted? | Yes. AES-256 at rest and TLS 1.2 or higher in transit, from upload through answer generation. |
| Do you train AI on our data? | No. Not our models, not OpenAI’s, not any third party’s. No fine-tuning, shared embeddings, or cross-customer learning. |
| Which AI providers see content? | OpenAI, via its commercial API, under terms that prohibit training on submitted data. Only retrieved passages for a given query are sent — never your full corpus. |
| What happens if we leave? | Full export in usable formats, then deletion of documents, extracted text, embeddings, indexes, metadata, and logs within 30 days. A certificate of deletion is available on request. |
| Security contact | security@backbayautomation.com |
1. What personal information do we collect?
Information you provide
Personal information you may provide through the Services or otherwise includes:
- Contact data, such as your name, work email address, company name, job title, and phone number.
- Communications data based on our exchanges with you, including demo requests, support messages, and security inquiries.
- Profile and account data, such as your username, organization membership, and authentication details managed through our identity provider.
- Usage data, such as queries you submit, documents retrieved, timestamps, and feedback you provide in the application.
- Other data not specifically listed here, which we use as described in this policy or as disclosed at the time of collection.
The Alessia platform is designed for business use. It is not intended to hold personal data beyond routine business contact details for your users, HR records, payment card data, protected health information, or similar categories described in our customer agreements.
Automatic data collection
On our marketing website, we may automatically collect device and online activity data, such as IP address, browser type, pages viewed, and referral source. See Section 8 for cookies and analytics.
2. How do we use personal information?
We use personal information to:
- Provide, operate, secure, and improve the Services
- Authenticate users and enforce organization-based access controls
- Communicate with you about the Services, including support, security alerts, and administrative messages
- Respond to inquiries and schedule onboarding or demos
- Comply with legal obligations and protect our rights and safety
- Analyze website usage in aggregate on our marketing site
We do not use your query text to improve the product for other customers. We may use aggregate, anonymized operational metrics — such as query counts, error rates, and latency — to operate and improve the platform.
3. How do we share personal information?
We may share personal information with:
- Service providers that help us host, operate, or support the Services, under confidentiality obligations. Our current subprocessors are listed in our Privacy Policy.
- AI providers to the extent necessary to generate answers from retrieved document passages, as described in Section 5.
- Professional advisors, such as lawyers or auditors, where reasonably necessary.
- Authorities when required by law or to protect rights and safety.
- Business transferees in connection with a merger, acquisition, or similar transaction, with notice where required by law.
We do not sell personal information. We do not share customer documentation with other customers or unrelated third parties for their own marketing.
4. Customer documentation and platform data
When your organization uses Alessia, you may upload technical documentation — catalogs, manuals, cut sheets, application notes, and similar materials — so your team can query them in natural language. You retain ownership of this content. We process it only to provide the Services to your organization.
Key commitments for customer documentation:
- Single-tenant isolation. Each manufacturing customer is deployed into a dedicated environment. Your documents, vector index, metadata, and query logs are not co-located with any other customer’s data.
- No cross-customer access. A defect in application logic cannot expose your content to another customer, because another customer’s environment has no path to your storage.
- Role-based access. You control which users in your organization can access the platform. Collections and documents can be restricted so that, for example, price books or pre-release specifications are visible only to designated groups. Permissions are enforced at retrieval time.
- Query logs are your data. Records of what your team asked and when are held in your environment, subject to the same isolation and deletion commitments as your documents. Query and audit logs are retained for 12 months unless adjusted in your agreement.
- Sensitive content. Price books, pre-release product data, engineering drawings, and customer RFQs uploaded by your team are treated as restricted content. Export-controlled technical data is not in scope for a standard engagement without a separate written agreement.
For full security and data-handling detail, see our Privacy Policy.
5. AI processing
Alessia uses retrieval-augmented generation to answer questions from your documentation. When a user asks a question:
- The question is matched against your dedicated search index only.
- The highest-scoring passages are retrieved and filtered against that user’s permissions.
- Those passages and the question are sent over TLS to the OpenAI API, which generates an answer with citations to source documents.
Only the passages retrieved for a given question — typically a few thousand words — are transmitted to the model provider, along with the question itself. Your corpus as a whole is never uploaded to OpenAI.
We do not train on your data. We do not fine-tune, adapt, or otherwise improve any model using your documents, queries, or answers. We do not build shared embeddings or indexes across customers. Under OpenAI’s API terms, data submitted through the API is not used to train OpenAI models.
Image-based documents may be sent to Mistral OCR for text extraction during ingestion. Mistral is listed as a subprocessor in our Privacy Policy.
6. Your choices
- Access or update your information. Organization administrators can manage users through the platform. Contact us if you need help accessing or updating account information.
- Opt out of marketing. You may opt out of non-essential marketing emails using unsubscribe instructions in those messages, if provided. Service-related communications may still be sent.
- Deletion requests. You may request deletion of personal information subject to applicable law and contractual limits. Customer documentation deletion on termination is described in Section 7.
Depending on where you live, you may have additional rights to access, correct, restrict, or object to certain processing. Contact us to make a request.
7. Retention and deletion
During your engagement. Source documents are retained for as long as you keep them in the platform. Query and audit logs are retained for 12 months, then deleted automatically unless your agreement specifies otherwise.
On termination. When your engagement ends:
- You receive an export of your source documents in their original formats, plus extracted content and metadata in a machine-readable form.
- You have 30 days from termination to retrieve your export.
- At the close of the export window, we delete source files, extracted text, chunks, embeddings, indexes, metadata, caches, and query logs from your dedicated environment. Backups expire on their normal rotation within 90 days.
On request, we provide written confirmation of deletion identifying what was deleted and when.
8. Cookies and analytics
Our marketing website may use cookies and similar technologies for basic functionality and analytics. We use Google Analytics to understand general traffic patterns (for example, pages viewed and referral sources). Google Analytics collects information such as IP address and browser type. Learn more at Google’s Privacy Policy, or opt out via the Google Analytics Opt-out Browser Add-on.
9. Third-party services
The Services may contain links to third-party websites or integrate with services operated by third parties. We do not control those services and encourage you to read their privacy policies.
Our authoritative subprocessor list — including Microsoft Azure, Qdrant Cloud, OpenAI, Clerk, Vercel, Mistral OCR, and Google Analytics — is described in our Privacy Policy. We provide 15 days’ written notice before adding a subprocessor that can access customer content.
10. Security
We use technical and organizational safeguards to protect personal information and customer documentation, including AES-256 encryption at rest, TLS 1.2 or higher in transit, single-tenant isolation, least-privilege access for Back Bay personnel, and logging of administrative access to customer environments.
No method of transmission or storage is completely secure. In the event of a data security incident involving your personal information, we will notify you without undue delay as required by applicable law. For security questions, contact security@backbayautomation.com.
Back Bay Automation is not SOC 2 certified today. We will not claim otherwise. We support customer security review directly and make engineering available for technical questions.
11. International processing
We are headquartered in the United States. Customer data is stored and processed in United States Azure regions by default. If you access the Services from outside the United States, your information may be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Where personal data is processed on behalf of a business customer, we act as processor and the customer acts as controller. A Data Processing Addendum is available as part of our contracting package.
12. Children
The Services are intended for business users and are not directed to anyone under 16. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. Material changes may also be communicated by email or in-product notice where appropriate. Continued use of the Services after changes become effective constitutes acceptance of the updated policy.
14. Contact us
Privacy and security questions may be sent to security@backbayautomation.com, or through our demo request form.
For subprocessor information and security questions, contact security@backbayautomation.com or see our Privacy Policy.