Privacy Policy
Muniment
1. Who we are and what this policy covers
Muniment (“Muniment”, “we”, “us”) captures the definition of your conversational assistants from your bot platform on every publish, stores it as a dated, hash-chained record set in a bucket you own, and returns evidence packs showing exactly what was live at a timestamp you name. We do not run your assistant, we do not read your conversations, and we do not put anything back into your platform.
Registered at Muniment Records, Inc., 10 Dorrance Street, Suite 700, Providence, RI 02903, United States.
This policy explains how we handle personal data in two distinct capacities, which are governed by different rules:
| Whose data | Our role | Governed by | |
|---|---|---|---|
| Part A | Website visitors, prospects, people who contact us | Controller — we decide why and how | This policy |
| Part B | Assistant definitions exported from your bot platform, and the answer strings you paste into the resolver | Processor — we act only on the customer’s documented instructions | This policy and the Data Processing Agreement signed with that customer |
Where the Data Processing Agreement (“DPA”) and this policy conflict in respect of Part B, the DPA governs.
Part A — When we are the controller
This part covers personal data we collect for our own purposes: running our website, responding to access requests, and communicating with prospective and existing customers.
A.1 What we collect
Information you give us. When you submit the access request form we collect your first name, last name, work email address and company name, together with the fact that you agreed to be contacted. If you email us or talk to us during evaluation or onboarding, we hold the content of that correspondence and any business contact details in it.
Information collected automatically. Our web server records the IP address the request came from, the user agent string, the pages requested, referring URL and timestamp. These logs exist to keep the site available and secure.
We do not knowingly collect special categories of personal data under Article 9 GDPR in this part, and the form should not be used to send us any.
A.2 Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Responding to an access request and evaluating fit | Form submissions, correspondence | Art. 6(1)(b) — steps at your request prior to a contract |
| Administering a customer relationship, billing, support | Contact details, correspondence | Art. 6(1)(b) — performance of a contract |
| Site availability, security, abuse prevention | Server logs | Art. 6(1)(f) — legitimate interest in operating a secure service |
| Direct outreach to business contacts about the service | Work email, company | Art. 6(1)(f) — legitimate interest in B2B marketing, subject to your right to object at any time |
| Meeting tax, accounting and legal obligations | Billing and contract records | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interest, we have assessed that interest against your rights and are able to provide the assessment on request.
A.3 How long we keep it
- Access requests that do not become customers: 12 months from last contact, then deleted.
- Customer contact and contract records: for the term of the agreement plus 6 years, to meet limitation periods and accounting obligations.
- Server logs: 30 days.
- Records of an objection or opt-out: retained indefinitely, so that we can honour it.
A.4 Your rights
If you are in the EEA or UK you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. You may exercise any of these by writing to [email protected]. We answer within one month.
You also have the right to complain to a supervisory authority. If you are in the EEA you may complain to the authority in your country of residence or workplace; our EU representative is identified in section 5.
Part B — When we are the processor
Two kinds of material reach us and they carry very different risk. An assistant definition is your configuration: dialog tasks, nodes, prompt strings, entities, knowledge answers, channel settings and the identity of whoever published them. It is commercially sensitive and it is not, as a rule, about any member or customer. An answer string is different: you paste it in because you are trying to find out which node produced it, and it came out of a real conversation, so it can carry member or customer detail you did not intend to send. This part describes how we treat each.
B.1 What we process, and why it is personal data
Account data, meaning your work email, company, billing contact and the names of people you authorize to pull evidence packs, we hold as a controller. Assistant definitions, the derived record set, resolver queries, reviewer decisions and evidence packs we process as your processor, on your instruction, for as long as your archive exists.
- The assistant definition — Everything the platform's export API returns for an assistant: dialog tasks, nodes, prompt and response strings, entities, knowledge answers, channel and integration settings, version numbers, publish timestamps and the publisher's identity. If your team left a real member name in a test utterance, it is in the export and it is in the archive.
- Publish event metadata — Which assistant published, when, by whom, and the version identifier the platform assigned, polled from the platform's own event feed. This is what triggers a capture.
- Resolver queries — The timestamp you name and the answer string you paste. We store the query so the evidence pack can be reproduced and audited later, which means an answer string carrying member detail is retained with the matter it belongs to until you delete it.
- Reviewer decisions — Which unresolved query or low-margin lineage join a named person on your side confirmed or corrected, stored as a pair with the node version it points at, the person and the timestamp.
We do not connect to your CCaaS, your CRM or your recording estate, and we hold no transcripts, no call audio and no member records. The only conversation text we ever see is a string you paste into the resolver yourself.
Because we hold no PHI by design and take no feed from a system that produces it, we do not offer or sign a Business Associate Agreement. If your compliance office requires one from every vendor regardless of scope, say so before you connect, because we will not sign one for a scope we do not have.
Redact before you paste. The resolver works on the wording of the answer, not on the member, so removing names, member ids and amounts from a pasted string does not degrade the result.
An evidence pack is a document, and a document can be forwarded. Treat one containing a pasted answer string the way your matter-management rules treat any other exhibit.
B.2 What we do with it
Your archive lives in your bucket. Parquet and JSON record sets, raw exports and signed manifests are written to an S3 bucket you own, in your account, under Object Lock in compliance mode for a retention period you set at connection and default to seven years. We hold the index, the embeddings and the manifest hash chain, in S3 in us-east-2; the evidence itself sits where your cloud team controls it.
Nobody deletes a version quietly, including us. Object Lock in compliance mode means neither your administrators nor ours can remove a captured version inside its retention period. Removing one requires a signed instruction from two named people on your side, is executed only on the objects that instruction identifies, and leaves a tombstone row naming the instruction, the two people and the date.
Resolver queries and their packs. Stored against the matter reference you supply, so that the same question asked twice returns the same answer with the same hashes. Deleting a matter deletes its queries, its pasted strings and its packs together. The captured versions they pointed at are unaffected, because those are the record.
The reviewer corpus stays in your account. Confirmed and corrected pairs fine-tune lineage and resolution on Azure Machine Learning in East US 2, for the account that produced them only, and are not pooled with any other customer's. A pair carries the node version and the node text a reviewer matched, never the pasted answer string. What does carry across accounts is the platform grammar, meaning which export field is a node label and which is a prompt string, which is a claim about the platform's schema and contains no string of yours.
B.3 Models, inference and training
Where inference runs. Resolver inference, the cross-encoder that carries node lineage across versions, and every model touching a pasted answer string run on EC2 GPU instances we operate on AWS in us-east-2 (Ohio). No pasted answer string, transcript excerpt or evidence pack is ever sent to a hosted model API, Azure OpenAI included, because customers in regulated industries cannot pass member conversation text to one. For that text Amazon and Microsoft are infrastructure, not model vendors. Bulk embedding during onboarding backfill handles assistant configuration text only and runs on Azure OpenAI in East US 2 under zero data retention. The hosted third-party embedding endpoint it replaces, under contractual zero-retention and no-training terms and listed in our subprocessor register, is retired by March 2027. All of it runs in the United States.
Training. We do not train on your assistant definitions, your resolver queries or your pasted answer strings, and neither Azure OpenAI nor the endpoint it replaces retains or trains on the configuration text we embed. The exception is exact and narrow: reviewer confirmations and corrections create labeled pairs, being (matched node text, node version) and (node version N, node version N+1), which fine-tune lineage and resolution on Azure Machine Learning in East US 2 for the account that produced them and for no other account. The pairs are the labels, not the documents. No pair carries the pasted answer string, and no pair is pooled across customers. What is shared across customers is the platform grammar, meaning which export field on a given bot platform is a node label, a prompt string or an entity, which describes the platform's schema and contains no configuration, string or query of yours.
Human review. The model proposes and a person decides. A resolver match below 0.90 confidence returns unresolved and the evidence pack states in those words that no node in the version live at that timestamp matches the supplied text above threshold; it never returns a best guess dressed as an answer. Unresolved queries and low-margin lineage joins go to a review queue where a named person on your side confirms or corrects the link, and that decision is written back as an audited row carrying the person and the timestamp. No automated decision made here produces a legal or similarly significant effect on any individual: the subject of every classification is a node in a configuration file you published, and the human who uses the output is your own lawyer or compliance officer.
B.4 Where the data sits
All processing stays in the United States, on Amazon Web Services and Microsoft Azure, and we run no global edge cache. Neither provider acts as a model vendor for anything you paste.
AWS, us-east-2 (Ohio): capture, parsing, indexing and evidence-pack generation; the index, embeddings and hash chain in S3; and the resolver, the cross-encoder and every model touching a pasted answer string on EC2 GPU instances we operate.
Microsoft Azure, East US 2: Azure OpenAI embeddings for bulk onboarding backfill, on assistant configuration text only and under zero data retention, and Azure Machine Learning for per-account fine-tuning of lineage and resolution on reviewer pairs. No pasted answer string reaches Azure.
The hosted third-party embedding endpoint that Azure OpenAI replaces stays named in our subprocessor register, under zero-retention and no-training terms and on configuration text only, until it is retired by March 2027.
Your archive bucket is yours: you choose its region, and if you place it outside us-east-2 the objects live there while our index and processing stay in us-east-2.
Model evaluation uses assistant definitions we author ourselves against test platform tenants, never a customer's.
B.5 Retention, deletion, and the limits of deletion
Captured assistant versions, raw exports and manifests: for the Object Lock retention period you set on your own bucket, seven years by default. We cannot shorten it and neither can you, which is the point of it.
Resolver queries, pasted answer strings and generated evidence packs: until you delete the matter they belong to, or the account closes.
The reviewer corpus: for the life of the account, deleted with it.
Our index, embeddings and hash chain: removed within 30 days of account closure. Your bucket is untouched by closure and stays readable without us.
Account and billing records: seven years after closure, as US corporate and tax record rules require.
API and console access logs, without payloads: 90 days.
B.6 Requests from individuals whose data we process
A pasted answer string may carry detail about one of your members or customers, and evidence packs may name the employees who published a version. If one of them asks you what is held, it is in your archive and your account, and exportable by you. If they ask us, we route them to you as the controller of the decision to send that string. For data we hold about you as a customer, write to [email protected] and we will answer within 30 days.
Common provisions
5. International transfers
Muniment is incorporated in the United States and serves customers established in the EEA. Personal data transferred outside the EEA is protected by the European Commission’s Standard Contractual Clauses, together with a transfer impact assessment and the supplementary technical measures described in our security documentation. A copy of the clauses is available on request.
EU representative (Article 27 GDPR)
6. Security
We maintain measures appropriate to the risk, including encryption in transit and at rest, credentials scoped to the minimum necessary, access control on the principle of least privilege, isolation of each customer’s data, and audit logging of access to production systems.
We notify affected customers of a personal data breach without undue delay and, in any event, within 36 hours of becoming aware of it, with the information they need to meet their own notification duties.
7. Children
The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
8. Changes to this policy
We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect, and the version number and date at the top of this page are updated in every case.
9. Contact
Privacy enquiries and general: [email protected]
Postal: Muniment, Muniment Records, Inc., 10 Dorrance Street, Suite 700, Providence, RI 02903, United States