Legal

Privacy Policy

VisiStrat is a B2B strategy management platform. Companies use it to store confidential business strategy information, so we keep this policy specific about what we collect, why we hold it, and what you control.

Last updated: 1 August 2026

1. Who we are

VisiStrat is operated by [Your Legal Entity Name], [Registered address, City, Postcode, Country]. For most business customers, your company is the data controller for the strategy content in your workspace and [Your Legal Entity Name] acts as the processor. We are the controller for account and billing records we hold about you directly.

2. Data we collect

We collect three categories of data.

Account information

  • Name, work email address and password (stored only as a salted hash — we never see it).
  • Company or workspace name, your role within that workspace, and invitations you send or accept.
  • Onboarding answers such as industry, approximate revenue band and team size.
  • Authentication events: sign-in, sign-out, failed sign-in attempts, password changes and member role changes, with timestamp, IP address and browser user agent.

Company strategy data

  • Vision, mission, ideal customer profile, competitive advantage and other strategy sections.
  • Markets, products, customers, market assessments (TAM/SAM/SOM, effort, technical fit) and 90-day plans.
  • Priorities, effort and cost estimates, risks, opportunities and quarterly or weekly planning entries.
  • AI Advisor conversations, generated insight reports and the prompts you submit.

Technical and usage data

  • Request logs and error diagnostics needed to keep the service running and secure.
  • Counts of AI feature usage per workspace, used to apply fair-use limits and prevent abuse.

We do not sell your data, and we do not use your company strategy data for advertising or to train third-party foundation models.

3. Why we use it

  • To provide the service: authenticate you, show your workspace and save your changes.
  • To operate AI features you trigger — your strategy content is sent to our AI provider only to produce the response you asked for.
  • To keep the platform secure: audit logging, abuse and rate-limit enforcement, and incident investigation.
  • To support you when you contact us, and to send essential service notices.
  • To meet legal, accounting and tax obligations.

Our legal bases are performance of a contract, our legitimate interest in securing and improving the service, and legal obligation. Where consent is required (for example non-essential cookies or marketing email), we ask for it and you can withdraw it.

4. Who we share it with

We share data only with the sub-processors that make the product work:

  • Cloud hosting and application delivery — running the app and its APIs.
  • Managed database and authentication provider — storing your workspace data and credentials securely.
  • AI model provider — processing the specific prompts and context you send to the AI Advisor or Insights features.
  • Email delivery — authentication emails such as sign-up confirmations and password resets, sent by our authentication provider.
  • [Payment processor] — billing details, if and when paid plans are enabled.

Each sub-processor is bound by a data processing agreement. We may also disclose data if legally required, or as part of a merger or acquisition — in which case we will notify you. A current sub-processor list is available from [privacy@yourdomain.com].

5. Security practices

Confidential strategy data is the whole point of the product, so isolation is enforced in the database itself, not just in the interface:

  • Every business record belongs to a company (tenant), and row-level security policies restrict every read and write to companies you are a member of.
  • Team administration — inviting, removing and changing the role of members — is limited to workspace owners and admins.
  • All traffic is encrypted in transit with TLS; data is encrypted at rest by our hosting provider.
  • Passwords are hashed, checked against known-breached password lists, and email addresses are confirmed at sign-up.
  • Privileged service credentials exist only on the server and are never exposed to the browser.
  • Security-relevant events are written to a tamper-resistant audit log that clients cannot forge.
  • AI endpoints have per-account daily quotas to limit abuse.
  • Backups are handled by our managed hosting provider under its own backup schedule, and workspace owners can export their data at any time.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to [security@yourdomain.com] rather than disclosing it publicly.

6. Retention

  • Workspace content is kept while your account is active.
  • AI Advisor history can be purged at any time from Settings.
  • When a workspace is deleted, its records are removed and cascade-deleted from the live database; residual copies in encrypted backups age out with the backup cycle.
  • Audit and billing records are kept for [12 months] and [7 years] respectively to meet security and accounting obligations.

7. Your rights

Depending on where you live (including the UK and EEA under UK GDPR/GDPR), you may request:

  • Access to the personal data we hold about you — download it directly in Settings → Your data → Download my personal data (JSON).
  • Correction of inaccurate data — most fields are editable directly in Settings.
  • Deletion of your account and workspace, available in Settings → Your data → Delete account.
  • A portable export of your workspace in machine-readable JSON, available in Settings → Your data → Export workspace data.
  • Restriction of or objection to certain processing, and withdrawal of consent.
  • To lodge a complaint with your data protection authority (in the UK, the ICO).

For complex requests, deletion beyond the self-service scope, or questions, email [privacy@yourdomain.com]. We will respond within one month. If your company administers the workspace, we may direct your request to them as the controller.

8. International transfers and children

Our providers may process data outside your country. Where that happens we rely on appropriate safeguards such as standard contractual clauses. VisiStrat is a business tool and is not directed at anyone under 16.

9. Changes and contact

We will post material changes here and notify workspace owners by email. Questions about this policy: [privacy@yourdomain.com]. Data protection contact: [dpo@yourdomain.com]. General enquiries: [hello@yourdomain.com].

This page is maintained by [Your Legal Entity Name] and describes how VisiStrat is operated today. It is not an independent audit or certification. Replace the placeholders in square brackets with your own details before launch, and have the wording reviewed by a qualified lawyer for your jurisdiction.

© 2026 VisiStratPrivacy PolicyTerms of ServiceCookie Policy