Updated 14 Sep 2026
Where your data is, who sees it, and how you leave.
The work you do in PolicySpeak is among the most sensitive material your organization produces. This page says what happens to it, and only what we can stand behind.
At a glance
| Question | Answer |
|---|---|
| Where your workspace is stored | In the EU, in a managed database in Ireland |
| Where the application runs | On servers in the EU |
| Encryption | At rest (AES-256) and in transit (TLS), by our database provider |
| Other organizations | Kept out of your workspace by the database itself |
| Inside your organization | Administrators and members; administrators set each role |
| Training on your material | We train or fine-tune no model on it. Model providers appear on the sub-processor list |
| When a feature drafts or summarizes | The text goes to our model sub-processors at that moment, some outside the EU |
| Who did what | An activity log your organization can read |
| Getting it out | Word, PDF and spreadsheet (CSV) |
| GDPR role | Processor for your content; controller for this website and Who Filed What |
| Certification | Not certified against an external security standard today |
Ask us for our data processing terms. The sub-processor list is available to customers under NDA.
Data
Where it lives
Your account data and what your team creates sit in a managed database in Ireland, inside the EEA. When a feature drafts or summarizes, the text it works on is processed by our model sub-processors at that moment.
Access
Who sees it
People in your organization see your organization's workspace, and administrators decide each colleague's role. PolicySpeak staff open customer content only to provide or fix the service, or when the law requires it.
Activity log
Who did what
Your workspace keeps a record of who did what. Your organization reads it, not only its administrators, because a record nobody can see protects no one.
Exports
Getting it out
Briefings, files, stakeholder records and documents export as Word, PDF and spreadsheet (CSV) files. Take them whenever you like, not only at the end.
Exit
When you leave
Export what you want to keep, then ask us to delete your organization's data by writing to security@policyspeak.com.
Incidents
If something goes wrong
If we discover an incident affecting your data, we tell you without undue delay, with the facts as we know them, and follow up as we learn more.
Documents
Five documents
- Privacy Policy · how we handle personal data under GDPRRead
- Acceptable Use Policy · the rules for using the serviceRead
- AI Policy · how the drafting and summarizing features are built and runRead
- Data processing terms · for customersAsk us
- Sub-processor list · for customers, under NDAOn request
Request access
Running a security review? Ask us for our data processing terms and the sub-processor list here, or write to security@policyspeak.com.
Hosted in the EU · Security →
By submitting, you agree to our privacy policy.