§ 01Who We Are
§ 02Information We Collect
We collect the following categories of personal information:
| Category | What it includes | Source |
|---|---|---|
| Account information | Name, email address, password (hashed), organisation, role, jurisdiction. | You |
| Billing information | Billing address, VAT/GST number, payment method (handled by our payment processor — we do not store full card numbers). | You · Payment processor |
| Usage data | Queries you submit, documents you upload, Work Product generated, session timestamps, feature usage, and quota consumption. | You · Service |
| Technical data | IP address, browser type, device type, operating system, referring URL, time-zone, and language preference. | Your device |
| Communications | Emails, support tickets, and feedback you send to us. | You |
| Cookies and analytics | See § 10 for full detail. | Your browser |
Queries you submit and documents you upload may contain sensitive personal information about you or third parties (including special category data under GDPR Article 9, such as health information or information about criminal convictions, if relevant to your matter). You are responsible for ensuring that you have the legal right to submit such information to the Service. We process this content only to generate your Work Product, in accordance with this Policy.
§ 03How We Use Your Information
- To provide the Service — process queries, generate analysis, retrieve and surface citations, deliver Work Product, and maintain your account.
- To bill you — process subscription fees, send invoices, and enforce usage caps.
- To support you — respond to your enquiries, resolve issues, and provide service announcements.
- To improve the Service — analyse aggregate usage to debug, measure performance, and identify reliability issues. We do not use Your Content to train foundation models without your explicit, opt-in consent.
- To secure the Service — detect, prevent, and respond to fraud, abuse, security incidents, and unauthorised access.
- To comply with the law — meet our legal, regulatory, tax, and accounting obligations, and respond to valid legal process.
§ 04Legal Bases for Processing
- Contract — to provide the Service you have subscribed to (Article 6(1)(b)).
- Legitimate interests — to operate, secure, and improve the Service, balanced against your rights (Article 6(1)(f)).
- Legal obligation — to comply with applicable law (Article 6(1)(c)).
- Consent — for non-essential cookies, marketing communications, and any optional model training participation (Article 6(1)(a)). You may withdraw consent at any time.
§ 05Sharing Your Information
- Service providers (sub-processors) — cloud hosting, AI inference, payment processing, email delivery, analytics, error monitoring, and customer support tooling. Each is bound by a written data processing agreement and processes data only on our instructions.
- AI inference providers — your queries and uploaded documents are transmitted to our AI inference providers solely to generate Work Product. We require providers to operate under zero-retention or short-retention configurations and not to use Your Content for model training.
- Professional advisers — lawyers, accountants, and auditors, where necessary and bound by confidentiality.
- Legal and regulatory authorities — where required by valid legal process or to protect our or others' rights, property, or safety.
- Successors — in connection with a merger, acquisition, or sale of assets, subject to confidentiality protections and notice to you.
§ 06International Transfers
- Standard Contractual Clauses approved by the European Commission and/or the UK Information Commissioner's Office;
- adequacy decisions, where applicable;
- the ASEAN Model Contractual Clauses for cross-border data flows in Southeast Asia; and
- contractual confidentiality and security commitments from our sub-processors.
§ 07Data Retention
- Account information — for the duration of your subscription, plus 12 months after termination.
- Queries and Work Product — up to 12 months by default. You can delete individual chats or your full history at any time from your account settings.
- Billing records — 7 years, as required by tax and accounting law.
- Support communications — 3 years from the date of resolution.
- Security logs — 12 months.
§ 08Security
- encryption in transit (TLS 1.2+) and at rest (AES-256);
- role-based access control with the principle of least privilege;
- multi-factor authentication for staff access to production systems;
- regular security audits, penetration tests, and vulnerability scanning;
- incident response procedures with notification timelines aligned to GDPR Article 33; and
- employee confidentiality obligations and security awareness training.
§ 09Your Rights
- Access — request a copy of the personal information we hold about you.
- Rectification — request correction of inaccurate or incomplete information.
- Erasure ("right to be forgotten") — request deletion of your information, subject to legal exceptions.
- Restriction — request that we limit processing in certain circumstances.
- Portability — receive your information in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with your local data protection authority.
§ 10Cookies and Tracking
- Strictly necessary — required to deliver the Service (authentication, security, load balancing). These are always active.
- Functional — remember your preferences (language, jurisdiction, theme).
- Analytics — help us understand how the Service is used (page views, feature engagement, error rates). We use privacy-preserving analytics that do not build cross-site profiles.
§ 11Children's Privacy
§ 12Changes to This Policy
§ 13Contact and Complaints
For privacy questions or to exercise your rights, contact our Data Protection contact:
Data Protection — CommonBench
privacy@commonbench.ai
If you are based in the UK or EEA and are dissatisfied with our response, you have the right to lodge a complaint with your national supervisory authority (in the UK, the Information Commissioner's Office).
© 2026 CommonBench. All rights reserved.