Scope and controller
This notice covers the public Aiscovery website, waitlist and launch-partner application. It does not yet cover a future authenticated product or customer audit workspace.
The operator shown above is the current product identity. The final legal entity name, registered address and any representative or data-protection contact must be inserted during legal review where applicable.
Information the current site collects
The public site collects information only when a visitor submits a form or when infrastructure processes an ordinary web request.
- Waitlist: work email, locale, source page and submission timestamp.
- Partner application: email, company, website, role, use case, journey, test environment, optional timeline and optional security context.
- Request metadata: hosting and security systems may process IP address, user agent, timestamps and request diagnostics.
- Optional production observability: anonymized page views, route, referrer, device/browser categories, country, Core Web Vitals and allowlisted conversion-event categories. Form values and query parameters are excluded.
- Locale preference: NEXT_LOCALE may be stored to preserve the selected language.
Purposes and legal basis
Waitlist data is intended to provide requested Aiscovery access and product updates. Partner-application data is intended to assess fit, scope a potential pilot, communicate about the request and protect the application process from abuse.
The final lawful basis for each purpose, including any distinction between requested service communication and optional marketing, must be approved for the jurisdictions in scope. No automated eligibility decision is implemented in the current code.
Service providers and transfers
The site is intended for Vercel hosting and can use Vercel Web Analytics and Speed Insights after production approval. Form submissions are sent server-side to configured waitlist and partner-application webhook providers. Those providers are not named in this draft because the production integrations have not been confirmed.
Before approval, the team must document each processor, hosting region, international transfer, contract and applicable safeguard. The current site does not sell personal data or submit payment information.
Retention and security
Data should be retained only while needed for the stated purpose, legal obligations, security and dispute handling, then deleted or anonymized. A specific retention schedule must be approved before this notice becomes public.
The application validates form payloads, uses server-side webhook boundaries, supports idempotency keys and keeps integration tokens out of browser code. No system can be guaranteed completely secure.
Choices and privacy rights
Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection or portability, and may be able to withdraw consent or complain to a supervisory authority.
Requests can be sent to the privacy contact shown above. The mailbox, identity-verification process, response workflow and relevant supervisory authority must be confirmed before legal approval.