Privacy posture

Tenant-scoped privacy boundaries for invite-only contract operations.

ControlLayer V1 handles operational contract records through invite-only access, manual provisioning, private tenant workspaces, and human-reviewed workflows. Public pages do not create tenants, collect payment credentials, or provide legal advice.

Privacy stance

Manual activation before tenant data is introduced.

A tenant workspace is created by an implementation owner, not through self-service tenant creation. Provider-backed features operate only when configured, approved, and available for that tenant.

Access

Invite-only

Users enter through issued invitations and tenant membership checks rather than public account creation.

Provisioning

Manual

Tenant activation, module rollout, and provider readiness are reviewed before operational data is used.

Billing

Fixed subscription

Commercial records and plan limits use fixed subscription controls; V1 does not post metered overage charges or collect payment credentials on public routes.

Data we expect

Operational contract data stays tenant scoped.

ControlLayer is designed for post-signature contract operations: contract registers, supplier records, site coverage, renewal dates, notice windows, compliance evidence, tasks, reports, and audit activity.

Customer documents and extracted operational metadata should belong to the tenant workspace that supplied them. Public routes are read-only orientation surfaces and do not accept contract uploads or create tenant records.

Private workspace records

Contract files, evidence records, OCR text, AI extraction candidates, and source spans belong behind authenticated tenant boundaries.

Metadata-only commercial posture

Billing meters may track counts and entity references, but source files, prompts, signed URLs, and payment credentials do not belong in billing records.

No self-service tenant creation

Public pages can explain access and pricing, but tenant setup is manually provisioned by an implementation owner.

Use and review

Human review remains part of the privacy boundary.

AI, document extraction, imports, notifications, file handling, and exports are available only after the relevant setup and review checks are complete.

ControlLayer surfaces operational summaries, records, queues, and source-backed evidence for review. It does not provide legal advice or silently turn AI output into authoritative legal conclusions.

Provider-backed features only when configured

Files, document extraction, AI, email, notifications, exports, and billing connections are enabled only after approved setup and review.

Signed and scoped access

Document access should use tenant-aware permissions, private storage, signed access, audit events, and expiration controls where applicable.

No silent external sends

Email, supplier outreach, exports, and connected-system updates require explicit review before anything is sent or changed.

Retention and control

Tenant owners control rollout, exports, and retention decisions.

Retention, export, support, and removal requests should follow the tenant's commercial and operational arrangement. ControlLayer public copy does not replace those tenant-specific instructions.

Operational support can help with product use, imports, evidence organization, and access issues. Support does not provide legal advice about contract meaning, enforceability, or obligations.

Configurable retention posture

Retention rules should be configured per tenant and supported by audit-ready operational records.

Export boundaries

Exports should preserve tenant scope, source boundaries, permissions, and review expectations.

Billing and support

Billing questions, plan changes, and commercial records stay aligned to fixed subscription controls with finance and support owner review.

Privacy commitments

What this privacy page commits to

Public orientation only

01

Invite-only access

Users should reach tenant workspaces through issued invitations, authenticated sessions, and tenant membership checks.

02

Manual provisioning

Workspace setup, module access, connected services, and billing arrangements are reviewed before use.

03

No legal advice

Operational summaries and extracted records support review, but they are not legal advice or a substitute for professional review.

Provider boundary

Public privacy copy does not imply external action.

Describing an optional capability does not mean it is enabled for every workspace.

Activation rule

Provider-backed features operate only when configured, approved, and release-ready.

If a provider is unavailable, disabled, or not approved for the tenant, production behavior should block or stay manual rather than substitute blocked data or hidden automation.

Configure

An implementation owner confirms tenant setup, modules, access, billing posture, and provider readiness.

Review

Operators review extracted records, evidence, recipients, exports, and source context before critical decisions.

Operate

The workspace operates through tenant-aware API, storage, audit, and permission boundaries.

This privacy page is a V1 product posture summary for ControlLayer public routes. Tenant-specific notices, commercial terms, data processing terms, and support instructions may add further controls.