Legal
Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how Bravent Systems ("we", "us") collects, uses, discloses, and protects personal information when you visit govengine.ai or use the GovEngine platform (the "Service"). By using the Service you agree to the practices described here.
1. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email address, organisation, role, access status | You, or your identity provider at sign-in |
| Content data | Agent definitions, prompts, run inputs and outputs, artifacts, evaluation results | You, and agents you run |
| Connector data | OAuth tokens and the third-party data an agent reads or writes on your instruction (e.g. Google Drive, Slack, SharePoint, email) | The third-party service you connect |
| Usage and log data | IP address, browser type, pages viewed, timestamps, audit records of approvals and egress events | Automatically, as you use the Service |
We do not knowingly collect special-category personal data, and the Service is not directed to children under 16.
2. How we use information
- To provide, operate, and maintain the Service, including running the agents you approve.
- To authenticate you and enforce access approval and permission controls.
- To keep the audit trail that is the core purpose of the Service — records of who approved what, when, and which egress points were acknowledged.
- To monitor security, prevent abuse, debug faults, and enforce usage and spend limits.
- To communicate with you about the Service, including security and change notices.
- To comply with legal obligations and to establish or defend legal claims.
Where we rely on legitimate interests (security, service improvement, and communications), we balance those interests against your rights. Where consent is required — for example to connect a third-party account — we ask for it and you may withdraw it at any time.
3. AI model processing
The Service sends prompts and the content you provide to third-party large language model providers in order to generate agent output. We do not authorise those providers to use your content to train their models. Egress from an agent to any external destination is enumerated and requires human acknowledgement before that agent version is approved to run.
4. Sharing and disclosure
We do not sell personal information. We share it only with:
- Sub-processors who host, secure, or operate parts of the Service (cloud infrastructure, model providers, email delivery), under contracts that limit their use of the data to providing that service to us.
- Third-party services you connect, and only to the extent your agents are approved to read from or write to them.
- Authorities or counterparties where required by law, or to protect our rights, safety, or property.
- An acquirer, in the event of a merger, acquisition, or sale of assets — subject to this Policy.
5. Retention
We keep account data for as long as your account is active. Content data, run history, and audit records are retained for as long as needed to provide the Service and to satisfy the audit and compliance purpose for which they were created, then deleted or anonymised. Backups are rotated on a fixed schedule. On request we will delete your account data, subject to records we are required to keep by law.
6. Security
Traffic is encrypted in transit with TLS. Access to production data is limited to personnel who need it. Deployments are gated and database migrations are forward-only and tracked. Credentials for connected accounts are stored encrypted. No system is perfectly secure, and we cannot guarantee absolute security.
7. International transfers
We and our sub-processors may process personal information in countries other than your own. Where such a transfer is from the EEA, the UK, or Switzerland, we rely on an adequacy decision or on Standard Contractual Clauses.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; and to withdraw consent. California residents may request disclosure of the categories of personal information collected and disclosed, and may opt out of any "sale" or "sharing" (we do neither). To exercise a right, contact us at the address below. You also have the right to complain to your local data protection authority.
If you use the Service through an organisation, that organisation is the controller of the content data and you should direct your request to them; we will assist them as their processor.
9. Cookies
We use strictly necessary cookies only: a session cookie to keep you signed in and a CSRF token cookie to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies. Blocking these cookies will prevent you from signing in.
10. Changes to this Policy
We may update this Policy. We will change the "last updated" date above and, if the change is material, notify you by email or in the Service before it takes effect.
11. Contact
Bravent Systems — ak@braventsystems.com