Legal & Data Protection
How Dormot Technologies Ltd (“Achi”, “we”, “us”) collects, processes, isolates, and protects personal data and customer content across the Achi platform and its enterprise services.
01 — Role & Architecture
When operating the Achi platform for enterprise workflow automation:
02 — Information We Collect
Name, corporate email address, business role, password hashes, and authentication tokens required to manage platform access and role-based permissions.
Form fields, uploaded evidence (PDFs, images, identity documents), reviewer comments, approval notes, and review checklists created within stage workspaces.
IP addresses, user-agent details, session timestamps, feature-usage counts, and system logs collected to ensure security, enforce audit trails, and operate the platform.
03 — Data Ownership, Un-Siloing & API Access
Achi is built around data un-siloing. Customers retain full ownership of their records and submitted content, and Achi provides built-in mechanisms to exercise it:
GET /api/v1/submissions).submission.created, approval.granted, workflow.completed.04 — Security & Multi-Tenant Isolation
org_id, so cross-tenant access is blocked at the database layer, not just in application code.05 — Retention, Deletion & Compliance
Customers can configure retention for completed workflows. On account termination or an explicit deletion request, Achi purges the associated tenant data and uploaded attachments from active production systems within 30 days. Individuals seeking to exercise data-subject rights (access, correction, erasure) over data they submitted through a customer form should contact that customer (the Data Controller) directly.
Dormot Technologies Ltd · Achi Privacy Policy
AI Governance Policy →