Legal & Data Protection

Privacy Policy

How Dormot Technologies Ltd (“Achi”, “we”, “us”) collects, processes, isolates, and protects personal data and customer content across the Achi platform and its enterprise services.

01 — Role & Architecture

Data Controller vs. Data Processor

When operating the Achi platform for enterprise workflow automation:

  • Customer as Data Controller. Our enterprise customers are the Data Controllers for all submission data, uploaded documents, form fields, and operational workflows they process on Achi.
  • Achi as Data Processor. Achi acts as a Data Processor, executing workflow logic, storing record instances, and rendering reviewer workspaces in accordance with documented customer instructions and contract terms.

02 — Information We Collect

Categories of Processed Data

1. Account & Identity Information

Name, corporate email address, business role, password hashes, and authentication tokens required to manage platform access and role-based permissions.

2. Operational Workflow & Submission Content

Form fields, uploaded evidence (PDFs, images, identity documents), reviewer comments, approval notes, and review checklists created within stage workspaces.

3. Technical & Telemetry Data

IP addresses, user-agent details, session timestamps, feature-usage counts, and system logs collected to ensure security, enforce audit trails, and operate the platform.

03 — Data Ownership, Un-Siloing & API Access

Your Data Ownership Rights

Achi is built around data un-siloing. Customers retain full ownership of their records and submitted content, and Achi provides built-in mechanisms to exercise it:

  • Tenant REST API. Programmatically retrieve your form submissions, their full payload and audit trail using tenant-scoped API keys (GET /api/v1/submissions).
  • Real-time webhooks. Signed JSON payloads are dispatched to your endpoints on workflow lifecycle events — submission.created, approval.granted, workflow.completed.
  • Portability & export. Export structured data as JSON or CSV at any time (e.g. per-workflow export) for ingestion into your own data lake.

04 — Security & Multi-Tenant Isolation

Technical Safeguards

  • Encryption. Data in transit is encrypted with TLS; data at rest (databases, storage, backups) is encrypted with AES-256 by our infrastructure provider.
  • Row-Level Security (RLS). Database-level RLS policies isolate every tenant’s data by org_id, so cross-tenant access is blocked at the database layer, not just in application code.
  • Immutable audit trails. Every material state change — approvals, rejections, change requests, and invites — is written to an append-only activity log.

05 — Retention, Deletion & Compliance

Data Retention & GDPR / UK GDPR Rights

Customers can configure retention for completed workflows. On account termination or an explicit deletion request, Achi purges the associated tenant data and uploaded attachments from active production systems within 30 days. Individuals seeking to exercise data-subject rights (access, correction, erasure) over data they submitted through a customer form should contact that customer (the Data Controller) directly.

Dormot Technologies Ltd · Achi Privacy Policy

AI Governance Policy →