Last update: 12.12.2025

Privacy Policy

We take your privacy very seriously. Please read this Privacy Policy carefully as it contains important information on who we are and our information practices, meaning how and why we collect, use, disclose, share, store, and retain your personal information. It also explains your rights in relation to your personal information and how to contact us or supervisory authorities in the event you have a complaint or request.

We act as a controller of your personal data when you sign up for the Service, visit our Website, or interact with us through other channels. We use this data for a variety of purposes, including to provide the Service to you, contact you about relevant content, and improve and promote our products and services. 

We act as a processor when Customer as they are defined in [TERMS OF SERVICE] uses the Service. To learn more about how we process your information, you can request a copy of our data processing agreement.

We collect, use, and are responsible for certain personal information about you. When we offer services to individuals in the European Economic Area (EEA), we are subject to the EU General Data Protection Regulation (EU GDPR), which applies across the entire European Union. For California consumers, we are subject to the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA). We are responsible as a “controller” of that personal information for the purposes of the GDPR. We are responsible for your personal information as a “business” under the CCPA/CPRA.

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22(1) and (4) of the GDPR. Where we use automated tools - such as fraud detection, security monitoring, or analytics - to support and enhance our Service, these tools operate to assist our personnel and do not replace human review or decision-making. If, in the future, we engage in automated decision-making that has legal or similarly significant effects, we will provide you with clear notice, explain the logic involved, describe the significance and potential consequences of such processing, and obtain your consent where required by applicable law.

All capitalized terms in this Privacy Policy and not defined shall have the meaning given them in the Terms of Service. 

Table of contents

Section 1. Key Terms.

We are committed to protecting your privacy. Here are the key terms that we will use in this Privacy Policy.

References to the Company
“We,” “us,” and “our” refer to Ogment, Inc.

Contact Person
Man Wai Li, Data Protection Officer

Contact Email
legal@ogment.ai

Personal Information
Any information relating to an identified or identifiable individual.

Sensitive Personal Information
Personal information that reveals a consumer’s Social Security number, driver’s license number, passport number, account numbers, or account credentials.

Section 2. Personal Information We Collect About You.

We may collect and use the following personal information, including sensitive personal information, that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household:

Categories of Personal Information and Specific Types Collected

Identifiers
Examples include a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
Specific types collected include: real name, alias, unique personal identifier, email address, and account name.

Account and Financial Information
Includes account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account.
Specific types collected include: account log-in information.

Characteristics of Protected Classifications Under California or Federal Law
Not collected.
Ogment does not collect information revealing race, color, national origin, religion, sex, gender identity, sexual orientation, disability, medical conditions, marital status, veteran status, or any other protected classification.

Internet or Other Electronic Network Activity Information
Includes browsing history, search history, and information regarding a consumer’s interaction with an internet website, application, or advertisement.
Specific types of information collected include:

  • Device and browser metadata (such as IP address, browser type and version, and operating system).
  • Usage analytics related to the Ogment platform (such as pages visited, actions taken within the dashboard, timestamps, and navigation flows).
  • Log data from MCP server deployments interacted with through Ogment (such as request metadata and tool invocation metadata), excluding underlying Customer Data unless the customer explicitly configures logging.
  • Error logs and system performance metrics.

Contents of a Consumer’s Mail, Email, and Text Messages
Not collected.
Ogment does not access, collect, or store the contents of a consumer’s mail, email, SMS messages, or other communications unless the communication is directly sent to Ogment (for example, support emails sent to support@ogment.ai or messages submitted through Ogment support channels).
In such cases, Ogment processes the communication solely for support or operational purposes.

If you do not provide the personal information required to provide the Service to you, it may delay or prevent us from providing the Service to you.

Section 3. How Your Personal Information Is Collected.

We collect personal information from the following categories of sources:

  1. You, directly in person, by telephone, text, or email, and via our Website.
  2. Third parties with your consent (e.g., your bank).
  3. Data analytics providers.
  4. Operating systems and platforms.
  5. Publicly accessible sources (e.g., property records).
  6. Cookies on our Website.
  7. Our IT and security systems, including:
    - Door entry systems and reception logs.
    - Automated monitoring of our Websites and other technical systems, such as our computer networks and connections, CCTV and access control systems, communications systems, email, and instant messaging systems. 

Section 4. Account Creation Information.

When you create an account with us, we collect certain personal information directly from you, including your name, email address, telephone number, username, password, and any other information you choose to provide during the account registration process.

We may also collect information necessary to verify your identity or comply with applicable legal or regulatory obligations, including authentication information, account credentials, or verification documents where required. Providing this information is necessary for us to create, maintain, and secure your account. If you choose not to provide this information, we may be unable to create or maintain your account or provide the Service to you.

Section 5. How and Why We Use Your Personal Information.

Under data protection laws, we can only use your personal information if we have a proper reason for doing so, for example:

  1. To comply with our legal and regulatory obligations.
  2. For the performance of our contract with you or to take steps at your request before entering into a contract.
  3. For our legitimate interests or those of a third party.
  4. Where you have given consent.

A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests.

The table below explains what we use (process) your personal information for and our reasons for doing so:

What We Use Your Personal Information For and Our Reasons

Providing the Service
We use your personal information to provide the Service to you.
This processing is necessary for the performance of our contract with you, or to take steps at your request before entering into a contract.

Fraud Prevention and Detection
We use personal information to prevent and detect fraud against any Authorized User, Admin, or Customer.
This processing is based on our legitimate interests, or those of a third party, in minimizing fraud that could be damaging to both you and us.

Customer Due Diligence and Compliance Checks
We process personal information to conduct checks to identify our customers and verify their identity, including screening for financial and other sanctions or embargoes.
Additional processing may be required to comply with professional, legal, and regulatory obligations that apply to our business, such as health and safety regulations or rules issued by professional regulators.
These activities are carried out to comply with our legal and regulatory obligations.

Regulatory Audits, Inquiries, and Investigations
We use personal information to gather and provide information required by, or relating to, audits, inquiries, or investigations conducted by regulatory bodies.
This processing is necessary to comply with our legal and regulatory obligations.

Protection of Confidential and Commercially Sensitive Information
We process personal information to ensure the confidentiality of commercially sensitive information.
This processing is based on our legitimate interests, or those of a third party, in protecting trade secrets and other commercially valuable information, as well as to comply with our legal and regulatory obligations.

System Security and Access Control
We use personal information to prevent unauthorized access to, and modification of, our systems.
This processing is carried out based on our legitimate interests, or those of a third party, in preventing and detecting criminal activity that could be damaging to both you and us, and to comply with our legal and regulatory obligations.

Marketing and Business Promotion
We use personal information to market our services to:

  • Existing and former customers.
  • Third parties who have previously expressed an interest in our services.
  • Third parties with whom we have had no previous dealings.

This processing is based on our legitimate interests, or those of a third party, in promoting our business to existing and former customers.

External Audits and Quality Assurance
We process personal information for external audits and quality checks, such as ISO certifications, Investors in People accreditation, and audits of our accounts.
This processing is based on our legitimate interests, or those of a third party, in maintaining our accreditations and demonstrating that we operate to high standards, as well as to comply with our legal and regulatory obligations.

For EEA Data Subjects: The above table does not apply to special category personal information, which we will only process with your explicit consent.

Section 6. EEA Data Subjects: Promotional Communications.

We may use your personal information to send you updates (by email, text message, telephone, or post) about our Service, including exclusive offers, promotions, or new services.

We have a legitimate interest in processing your personal information for promotional purposes (see Section 5). This means we do not usually need your consent to send you promotional communications. However, where consent is needed, we will ask for this consent separately and clearly

You have the right to opt-out of receiving promotional communications at any time by:

  1. Contact us at support@ogment.ai.
  2. Using the “unsubscribe” link in emails or “STOP” number in texts. 

We may ask you to confirm or update your marketing preferences if you instruct us to provide further the Service in the future, or if there are changes in the law, regulation, or the structure of our business.

Section 7. Who We Share Your Personal Information With.

We routinely share personal information with:

  1. Our affiliates.
  2. Service providers we use to help deliver our Service to you.
  3. Other third parties we use to help us run our business, such as marketing agencies or website hosts.
  4. Third parties approved by you, including social media sites you choose to link your account to or third-party payment providers.
  5. Credit reporting agencies.
  6. Our insurers and brokers.
  7. Our banks.

We only allow our Service providers to handle your personal information if we are satisfied that they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure that they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, e.g., in relation to ISO accreditation and the audit of our accounts.

We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

We may also need to share some personal information with other parties, such as potential buyers of some or all of our business or during a re-structuring. We will typically anonymize information, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.

Section 8. Categories of Personal Information We Disclosed for a Business Purpose.

In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:

  1. Identifiers (e.g., a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver's license number, passport number, or other similar identifiers).
  2. Information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, their name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.
  3. Characteristics of protected classifications under California or federal law.
  4. Commercial information (e.g., records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies).
  5. Internet or other electronic network activity information (e.g., browsing history, search history, and information regarding a consumer's interaction with an internet website, application, or advertisement).
  6. Geolocation data.
  7. Audio, electronic, visual, thermal, olfactory, or similar information.
  8. Professional or employment-related information.
  9. Education information, defined as information that is not publicly available personally identifiable information as defined in the FERPA.
  10. Inferences drawn from any of the information identified above to create a profile about a consumer reflecting the consumer's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
  11. Sensitive personal information.

Section 9. How Long Your Personal Information Will Be Kept.

We will keep your personal information while you have an account with us or while we are providing services to you. Thereafter, we will keep your personal information for as long as is necessary:

  1. To respond to any questions, complaints, or claims made by you or on your behalf.
  2. To show that we treated you fairly.
  3. To keep records required by law.

We will not retain your personal information for longer than necessary for the purposes set out in this policy, or three (30) days after the termination of the Service. When it is no longer necessary to retain your personal information, we will delete it.

You have the right to request from us: (a) access to your personal data, (b) rectification of any inaccurate or incomplete personal data, (c) erasure of your personal data, (d) restriction of the processing of your personal data, (e) to object to the processing of your personal data, and (f) the right to data portability at any time during your use of the Service. We reserve the right to terminate the Service if we are unable to deliver it due to the lack of personal data needed from you.

Section 10. California Consumers: Your Rights Under the CCPA/CPRA.

Under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA),  you have the right  to request the following disclosure free of charge:

Disclosure of Personal Information We Collect About You

You have the right to know and request disclosure of the following information:

  • The categories of personal information we have collected about you, including sensitive personal information.
  • The categories of sources from which your personal information is collected.
  • The categories of third parties to whom we disclose personal information, if any.
  • The specific pieces of personal information we have collected about you.

Please note that we are not required to do the following:

  • Retain personal information that was collected for a single, one-time transaction if that information is not retained in the ordinary course of business.
  • Reidentify or otherwise link data that is not maintained in a manner that would be considered personal information in the ordinary course of business.
  • Provide personal information to you more than twice within a twelve (12) month period.

Disclosure of Personal Information Shared or Disclosed for a Business Purpose

If we share or disclose personal information to a third party for a business purpose, you have the right to know:

  • The categories of personal information that were shared and the categories of third parties with whom the information was shared.
  • The categories of personal information that were disclosed for a business purpose and the categories of persons to whom the information was disclosed.

You have the right to opt out of the sharing of your personal information for the purpose of targeted behavioral advertising. If you exercise your right to opt out of the sale or sharing of your personal information, we will refrain from selling or sharing your personal information unless you later provide express authorization to do so.

To opt out of the sharing of your personal information, please contact us at support@ogment.ai.

Right to Limit Use of Sensitive Personal Information

You have the right to limit the use and disclosure of your sensitive personal information to uses that are necessary to:

  • Perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services.
  • Help ensure security and integrity, to the extent such use is reasonably necessary and proportionate.
  • Enable short-term, transient use, including non-personalized advertising shown as part of your current interaction with the business, provided that your personal information is not disclosed to a third party or used to build a profile or alter your experience outside the current interaction.
  • Perform services on behalf of the business, including maintaining or servicing accounts, providing customer support, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, analytics, storage, or similar services.
  • Verify or maintain the quality or safety of a service or device owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance such services or devices.
  • Comply with additional uses as authorized by applicable regulations.

You also have the right to know whether your sensitive personal information is used or disclosed to a service provider or contractor for additional, specified purposes.

To limit the use of your sensitive personal information, please contact us at support@ogment.ai.

Right to Deletion

Subject to certain exceptions, upon receipt of a verifiable request from you, we will:

  • Delete your personal information from our records.
  • Direct third parties to whom we have sold or shared your personal information to delete that information, unless doing so proves impossible or involves disproportionate effort.

We may not delete your personal information if it is reasonably necessary to:

  • Complete a transaction, fulfill a written warranty or product recall, provide a good or service requested by you, or perform a contract with you.
  • Help ensure security and integrity where use of the information is reasonably necessary and proportionate.
  • Debug systems to identify and repair errors that impair intended functionality.
  • Exercise free speech, protect the free speech rights of others, or exercise rights provided by law.
  • Comply with the California Electronic Communications Privacy Act.
  • Conduct public or peer-reviewed scientific, historical, or statistical research in the public interest where deletion would seriously impair the research and where informed consent has been obtained.
  • Enable internal uses that are reasonably aligned with your expectations based on your relationship with us.
  • Comply with a legal obligation.
  • Otherwise use the information internally in a lawful manner compatible with the context in which it was provided.

Right of Correction

If we maintain inaccurate personal information about you, you have the right to request correction. Upon receipt of a verifiable request, we will use commercially reasonable efforts to correct the inaccurate personal information.

Protection Against Retaliation

You have the right not to be retaliated against for exercising any of your rights under the CCPA or CPRA. This means we will not:

  • Deny goods or services to you.
  • Charge different prices or rates, including through discounts, benefits, or penalties.
  • Provide a different level or quality of goods or services.
  • Suggest that you will receive a different price, rate, or level or quality of service.

We may, however, charge different prices or provide different levels or quality of services if the difference is reasonably related to the value your personal information provides to our business. We may also offer loyalty programs, rewards, premium features, discounts, or similar programs consistent with these rights, including programs that involve compensation related to the collection, sale, or retention of personal information.

Section 11. EEA Data Subjects: Your Rights Under the EU GDPR.

Your Data Protection Rights

Right to Be Informed
You have the right to be informed about the collection and use of your personal information.

Right to Access
You have the right to request and receive a copy of the personal information we hold about you.

Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal information.

Right to Be Forgotten
You have the right to request deletion of your personal information in certain circumstances.

Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability
You have the right to receive the personal information you have provided to us in a structured, commonly used, and machine-readable format and, where applicable, to have that information transmitted to a third party.

Right to Object
You have the right to object at any time to the processing of your personal information for direct marketing purposes, including profiling.
You also have the right to object in certain other situations to our continued processing of your personal information, such as processing carried out for our legitimate interests.

Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.

For further information on each of those rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioner's Office (ICO) on individual rights under the EU General Data Protection Regulation.

Section 12. How to Exercise Your Rights.

If you would like to exercise any of your rights as described in this Privacy Policy, you can email us at support@ogment.ai

  1. Please note that you may only make a CCPA/CPRA-related data access or data portability disclosure request twice within a 12-month period.
  2. If you choose to contact us directly via our Website, you will need to provide us with:
    - Enough information to identify you (e.g., your full name, address, and customer or matter reference number).
    - Proof of your identity and address (e.g., a copy of your driving license or passport and a recent utility or credit card bill) –and–
    - A description of what right you want to exercise and the information to which your request relates.
  3. We are not obligated to make a data access or data portability disclosure if we cannot verify that the person making the request is the person about whom we collected information or is someone authorized to act on such person's behalf.
  4. Any personal information we collect from you to verify your identity in connection with your request will be used solely for the purposes of verification.

13. EEA Data Subjects: Where Your Personal Information is Held.

Information may be held at our offices, third-party agencies, service providers, representatives, and agents as described above (see Section 7).

Some of these third parties may be based outside the EEA. For more information, including on how we safeguard your personal information when this occurs, see Section 15.

Section 14. Transferring Your Personal Information.

We do not transfer personal data between EEA and US regions. Customer data remains in the customer's chosen territory.

Section 15. Keeping Your Personal Information Secure.

We have appropriate security measures in place to prevent personal information from being accidentally lost, used, or accessed in an unauthorized way. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

Section 16. EEA Data Subjects: How to File a GDPR Complaint.

We hope that we can resolve any query or concern you raise about our use of your information.

The GDPR also gives you the right to lodge a complaint with a supervisory authority in the European Union (or EEA) state where you work, normally live, or where any alleged infringement of data protection laws occurred.

Section 17. Changes to This Privacy Policy.

This Privacy Policy was published on 14th August 2024  and last updated on 11th December 2025.

We may change this Privacy Policy from time to time–when we do, we will inform you via our Website or email.

Section 18. How to Contact Us.

Please contact us by email on legal@ogment.ai, if you have any questions about this Privacy Policy or the information we hold about you.

Section 19. Do You Need Extra Help?

If you would like this notice in another format (for example: audio, large print, braille), please contact us at support@ogment.ai