We take your privacy very seriously. Please read this Privacy Policy carefully as it contains important information on who we are and our information practices, meaning how and why we collect, use, disclose, share, store, and retain your personal information. It also explains your rights in relation to your personal information and how to contact us or supervisory authorities in the event you have a complaint or request.
We act as a controller of your personal data when you sign up for the Service, visit our Website, or interact with us through other channels. We use this data for a variety of purposes, including to provide the Service to you, contact you about relevant content, and improve and promote our products and services.
We act as a processor when Customer as they are defined in [TERMS OF SERVICE] uses the Service. To learn more about how we process your information, you can request a copy of our data processing agreement.
We collect, use, and are responsible for certain personal information about you. When we offer services to individuals in the European Economic Area (EEA), we are subject to the EU General Data Protection Regulation (EU GDPR), which applies across the entire European Union. For California consumers, we are subject to the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA). We are responsible as a “controller” of that personal information for the purposes of the GDPR. We are responsible for your personal information as a “business” under the CCPA/CPRA.
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22(1) and (4) of the GDPR. Where we use automated tools - such as fraud detection, security monitoring, or analytics - to support and enhance our Service, these tools operate to assist our personnel and do not replace human review or decision-making. If, in the future, we engage in automated decision-making that has legal or similarly significant effects, we will provide you with clear notice, explain the logic involved, describe the significance and potential consequences of such processing, and obtain your consent where required by applicable law.
All capitalized terms in this Privacy Policy and not defined shall have the meaning given them in the Terms of Service.
We are committed to protecting your privacy. Here are the key terms that we will use in this Privacy Policy.
References to the Company
“We,” “us,” and “our” refer to Ogment, Inc.
Contact Person
Man Wai Li, Data Protection Officer
Contact Email
legal@ogment.ai
Personal Information
Any information relating to an identified or identifiable individual.
Sensitive Personal Information
Personal information that reveals a consumer’s Social Security number, driver’s license number, passport number, account numbers, or account credentials.
We may collect and use the following personal information, including sensitive personal information, that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household:
Categories of Personal Information and Specific Types Collected
Identifiers
Examples include a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
Specific types collected include: real name, alias, unique personal identifier, email address, and account name.
Account and Financial Information
Includes account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account.
Specific types collected include: account log-in information.
Characteristics of Protected Classifications Under California or Federal Law
Not collected.
Ogment does not collect information revealing race, color, national origin, religion, sex, gender identity, sexual orientation, disability, medical conditions, marital status, veteran status, or any other protected classification.
Internet or Other Electronic Network Activity Information
Includes browsing history, search history, and information regarding a consumer’s interaction with an internet website, application, or advertisement.
Specific types of information collected include:
Contents of a Consumer’s Mail, Email, and Text Messages
Not collected.
Ogment does not access, collect, or store the contents of a consumer’s mail, email, SMS messages, or other communications unless the communication is directly sent to Ogment (for example, support emails sent to support@ogment.ai or messages submitted through Ogment support channels).
In such cases, Ogment processes the communication solely for support or operational purposes.
If you do not provide the personal information required to provide the Service to you, it may delay or prevent us from providing the Service to you.
We collect personal information from the following categories of sources:
When you create an account with us, we collect certain personal information directly from you, including your name, email address, telephone number, username, password, and any other information you choose to provide during the account registration process.
We may also collect information necessary to verify your identity or comply with applicable legal or regulatory obligations, including authentication information, account credentials, or verification documents where required. Providing this information is necessary for us to create, maintain, and secure your account. If you choose not to provide this information, we may be unable to create or maintain your account or provide the Service to you.
Under data protection laws, we can only use your personal information if we have a proper reason for doing so, for example:
A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests.
The table below explains what we use (process) your personal information for and our reasons for doing so:
What We Use Your Personal Information For and Our Reasons
Providing the Service
We use your personal information to provide the Service to you.
This processing is necessary for the performance of our contract with you, or to take steps at your request before entering into a contract.
Fraud Prevention and Detection
We use personal information to prevent and detect fraud against any Authorized User, Admin, or Customer.
This processing is based on our legitimate interests, or those of a third party, in minimizing fraud that could be damaging to both you and us.
Customer Due Diligence and Compliance Checks
We process personal information to conduct checks to identify our customers and verify their identity, including screening for financial and other sanctions or embargoes.
Additional processing may be required to comply with professional, legal, and regulatory obligations that apply to our business, such as health and safety regulations or rules issued by professional regulators.
These activities are carried out to comply with our legal and regulatory obligations.
Regulatory Audits, Inquiries, and Investigations
We use personal information to gather and provide information required by, or relating to, audits, inquiries, or investigations conducted by regulatory bodies.
This processing is necessary to comply with our legal and regulatory obligations.
Protection of Confidential and Commercially Sensitive Information
We process personal information to ensure the confidentiality of commercially sensitive information.
This processing is based on our legitimate interests, or those of a third party, in protecting trade secrets and other commercially valuable information, as well as to comply with our legal and regulatory obligations.
System Security and Access Control
We use personal information to prevent unauthorized access to, and modification of, our systems.
This processing is carried out based on our legitimate interests, or those of a third party, in preventing and detecting criminal activity that could be damaging to both you and us, and to comply with our legal and regulatory obligations.
Marketing and Business Promotion
We use personal information to market our services to:
This processing is based on our legitimate interests, or those of a third party, in promoting our business to existing and former customers.
External Audits and Quality Assurance
We process personal information for external audits and quality checks, such as ISO certifications, Investors in People accreditation, and audits of our accounts.
This processing is based on our legitimate interests, or those of a third party, in maintaining our accreditations and demonstrating that we operate to high standards, as well as to comply with our legal and regulatory obligations.
For EEA Data Subjects: The above table does not apply to special category personal information, which we will only process with your explicit consent.
We may use your personal information to send you updates (by email, text message, telephone, or post) about our Service, including exclusive offers, promotions, or new services.
We have a legitimate interest in processing your personal information for promotional purposes (see Section 5). This means we do not usually need your consent to send you promotional communications. However, where consent is needed, we will ask for this consent separately and clearly
You have the right to opt-out of receiving promotional communications at any time by:
We may ask you to confirm or update your marketing preferences if you instruct us to provide further the Service in the future, or if there are changes in the law, regulation, or the structure of our business.
We routinely share personal information with:
We only allow our Service providers to handle your personal information if we are satisfied that they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure that they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, e.g., in relation to ISO accreditation and the audit of our accounts.
We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.
We may also need to share some personal information with other parties, such as potential buyers of some or all of our business or during a re-structuring. We will typically anonymize information, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.
In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:
We will keep your personal information while you have an account with us or while we are providing services to you. Thereafter, we will keep your personal information for as long as is necessary:
We will not retain your personal information for longer than necessary for the purposes set out in this policy, or three (30) days after the termination of the Service. When it is no longer necessary to retain your personal information, we will delete it.
You have the right to request from us: (a) access to your personal data, (b) rectification of any inaccurate or incomplete personal data, (c) erasure of your personal data, (d) restriction of the processing of your personal data, (e) to object to the processing of your personal data, and (f) the right to data portability at any time during your use of the Service. We reserve the right to terminate the Service if we are unable to deliver it due to the lack of personal data needed from you.
Under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), you have the right to request the following disclosure free of charge:
Disclosure of Personal Information We Collect About You
You have the right to know and request disclosure of the following information:
Please note that we are not required to do the following:
Disclosure of Personal Information Shared or Disclosed for a Business Purpose
If we share or disclose personal information to a third party for a business purpose, you have the right to know:
You have the right to opt out of the sharing of your personal information for the purpose of targeted behavioral advertising. If you exercise your right to opt out of the sale or sharing of your personal information, we will refrain from selling or sharing your personal information unless you later provide express authorization to do so.
To opt out of the sharing of your personal information, please contact us at support@ogment.ai.
Right to Limit Use of Sensitive Personal Information
You have the right to limit the use and disclosure of your sensitive personal information to uses that are necessary to:
You also have the right to know whether your sensitive personal information is used or disclosed to a service provider or contractor for additional, specified purposes.
To limit the use of your sensitive personal information, please contact us at support@ogment.ai.
Right to Deletion
Subject to certain exceptions, upon receipt of a verifiable request from you, we will:
We may not delete your personal information if it is reasonably necessary to:
Right of Correction
If we maintain inaccurate personal information about you, you have the right to request correction. Upon receipt of a verifiable request, we will use commercially reasonable efforts to correct the inaccurate personal information.
Protection Against Retaliation
You have the right not to be retaliated against for exercising any of your rights under the CCPA or CPRA. This means we will not:
We may, however, charge different prices or provide different levels or quality of services if the difference is reasonably related to the value your personal information provides to our business. We may also offer loyalty programs, rewards, premium features, discounts, or similar programs consistent with these rights, including programs that involve compensation related to the collection, sale, or retention of personal information.
Your Data Protection Rights
Right to Be Informed
You have the right to be informed about the collection and use of your personal information.
Right to Access
You have the right to request and receive a copy of the personal information we hold about you.
Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal information.
Right to Be Forgotten
You have the right to request deletion of your personal information in certain circumstances.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive the personal information you have provided to us in a structured, commonly used, and machine-readable format and, where applicable, to have that information transmitted to a third party.
Right to Object
You have the right to object at any time to the processing of your personal information for direct marketing purposes, including profiling.
You also have the right to object in certain other situations to our continued processing of your personal information, such as processing carried out for our legitimate interests.
Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.
For further information on each of those rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioner's Office (ICO) on individual rights under the EU General Data Protection Regulation.
If you would like to exercise any of your rights as described in this Privacy Policy, you can email us at support@ogment.ai.
Information may be held at our offices, third-party agencies, service providers, representatives, and agents as described above (see Section 7).
Some of these third parties may be based outside the EEA. For more information, including on how we safeguard your personal information when this occurs, see Section 15.
We do not transfer personal data between EEA and US regions. Customer data remains in the customer's chosen territory.
We have appropriate security measures in place to prevent personal information from being accidentally lost, used, or accessed in an unauthorized way. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
We hope that we can resolve any query or concern you raise about our use of your information.
The GDPR also gives you the right to lodge a complaint with a supervisory authority in the European Union (or EEA) state where you work, normally live, or where any alleged infringement of data protection laws occurred.
This Privacy Policy was published on 14th August 2024 and last updated on 11th December 2025.
We may change this Privacy Policy from time to time–when we do, we will inform you via our Website or email.
Please contact us by email on legal@ogment.ai, if you have any questions about this Privacy Policy or the information we hold about you.
If you would like this notice in another format (for example: audio, large print, braille), please contact us at support@ogment.ai.