Privacy Policy
Effective Date: May 22, 2026
Visum AI, Inc. (“Visum AI,” “we,” “our,” or “us”) respects your privacy and is committed to protecting personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit https://visum.ai (the “Website”) or use our application at https://docgen.visum.ai (the “Platform”), collectively the “Services.”
This Policy applies to visitors, customers, prospective customers, and authorized users of our Services.
1. Company Information
Visum AI, Inc.
A Delaware corporation
Mountain View, California, United States
Contact: the contact form on our website
2. Information We Collect
We collect information in the following categories.
A. Information You Provide Directly
Contact information. Name, work email address, company name, job title, and phone number (if provided). Collected when you request a demo, contact us, subscribe to updates, or enter into a pilot or commercial agreement.
Account information (Platform users). Login credentials, user role and permissions, and organization affiliation.
Customer Content. If you use our Platform, you or your organization may upload engineering drawings (such as single-line diagrams), equipment lists, operational standards, SOP, MOP, EOP documents, and other documentation related to critical facility operations. We process Customer Content solely to provide the Services.
B. Information We Collect Indirectly
We may receive personal data about you from sources other than yourself, including business partners, public business directories, sales-intelligence providers, conference attendee lists, customer-provided user provisioning, and publicly available professional sources such as LinkedIn. The categories of indirectly collected data are the same as those listed under Section 2.A.
C. Automatically Collected Information
When you access the Website or Platform, we may automatically collect IP address, browser type and version, device information, referring URLs, pages visited, and date and time of access. This data is used for security, analytics, and service improvement.
D. Cookies and Tracking Technologies
We use cookies and similar technologies to enable core website functionality, improve performance and usability, analyze traffic patterns, and support marketing and outreach. Where required by law, including for visitors in the European Economic Area, the United Kingdom, and other jurisdictions with prior-consent cookie regimes, non-essential cookies fire only after you grant consent through our cookie banner. You may withdraw or change your consent at any time through the cookie settings link in our website footer.
3. How We Use Information
We use collected information to provide and operate the Services, generate AI-assisted operational procedures, communicate with customers and prospects, improve product performance and reliability, monitor system usage and security, comply with legal obligations, and enforce contractual rights.
We do not use Customer Content to train our AI models or any third party’s AI models. We may use anonymized, aggregated, or de-identified data and metadata derived from operation of the Services for lawful business purposes, including operating, improving, and developing our Services and for benchmarking and analytics, provided that such data does not identify any customer or individual.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (as amended by the California Privacy Rights Act).
4. Legal Basis for Processing (EEA, UK, Switzerland)
Where applicable data protection laws including the General Data Protection Regulation require a lawful basis, we rely on the following bases for the corresponding purposes.
- Performance of a contract. Providing the Platform to authorized users under a customer agreement, processing Customer Content to deliver outputs, billing, and customer support.
- Legitimate business interests. Operating, securing, and improving the Services, preventing fraud and abuse, communicating with prospects and customers about products and services they have shown interest in, and exercising legal claims and defenses. We have assessed that our legitimate interests are not overridden by your rights and freedoms.
- Consent. Marketing communications where consent is required, non-essential cookies, and any optional processing identified at the point of collection. You may withdraw consent at any time.
- Compliance with a legal obligation. Tax, accounting, records retention, law enforcement requests, and responding to data subject requests.
We do not engage in solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 of the GDPR.
5. How We Share Information
We do not sell or rent personal information. We share information only as described below.
Service providers. Trusted third-party providers who help us operate our business, including cloud infrastructure providers, email and communication platforms, analytics providers, and security and monitoring services. These providers are contractually obligated to protect personal data and process it only on our instructions. Enterprise customers may request our then-current list of service providers that process Customer Content; we provide it under confidentiality.
Legal and compliance requirements. We may disclose information if required by law, subpoena, court order, or to protect our legal rights, customer safety, or system security.
Business transfers. If Visum AI undergoes a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to the recipient honoring this Policy.
6. Data Security
We implement commercially reasonable administrative, physical, and technical safeguards designed to protect personal data, including cloud infrastructure hosted with established commercial providers, secure access controls and authentication, role-based access permissions, encryption in transit (HTTPS or TLS), and restricted internal access to Customer Content. No system can guarantee absolute security; however, we take security seriously and continuously improve our controls. In the event of a personal data breach affecting your information, we will notify affected parties and relevant supervisory authorities in accordance with applicable law and contractual commitments.
7. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected and as required by law or contract. Indicative retention periods are as follows.
- Account and authentication data. For the duration of the customer relationship and up to twenty-four months thereafter to enable reactivation and respond to disputes.
- Marketing and prospect contact data. Until you unsubscribe or for up to twenty-four months of inactivity, whichever is earlier.
- Customer Content. Retained according to the applicable customer agreement and statement of work, including any required deletion or return commitments. Aggregated and de-identified data may be retained indefinitely.
- Operational and security logs. Up to thirteen months unless a longer period is required for a security incident investigation or legal hold.
- Financial and tax records. As required by applicable law, typically up to seven years.
8. International Data Transfers
Visum AI is headquartered in the United States. If you access our Services from outside the United States, your information may be transferred to and processed in the United States or other jurisdictions where our service providers operate. For personal data transferred from the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses together with, for transfers from the United Kingdom, the UK International Data Transfer Addendum. For transfers from Switzerland, we apply equivalent safeguards recognized by the Swiss Federal Data Protection and Information Commissioner. We supplement these mechanisms with additional safeguards where required by law. A copy of the relevant transfer mechanism is available on request through the contact form on our website.
9. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data.
- Right to access your personal data and obtain a copy.
- Right to correct inaccurate or incomplete personal data.
- Right to delete personal data, subject to legal and contractual exceptions.
- Right to restrict or object to certain processing, including direct marketing.
- Right to data portability for data provided to us and processed by automated means.
- Right to withdraw consent where processing is based on consent.
- Right to lodge a complaint with your local supervisory authority (for EEA, UK, or Swiss residents).
To exercise these rights, use the contact form on our website. We will verify your identity using information already on file and respond in accordance with applicable law. Where a request is submitted on your behalf by an authorized agent, we may require additional verification.
California Residents
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides the following additional rights.
- Right to know. Request the categories and specific pieces of personal information we have collected about you, the sources of that information, the business or commercial purposes for collection, and the categories of third parties with whom we share it.
- Right to delete. Request deletion of personal information we have collected from you, subject to exceptions under the law.
- Right to correct. Request correction of inaccurate personal information.
- Right to opt out of sale or sharing. Direct us not to sell or share your personal information. We do not currently sell personal information and do not share personal information for cross-context behavioral advertising, but we honor opt-out signals including the Global Privacy Control where technically supported.
- Right to limit use of sensitive personal information. Where we use sensitive personal information beyond purposes permitted by law, direct us to limit such use. Our current uses fall within the permitted purposes.
- Right to non-discrimination. We will not deny services, charge different prices, or provide a different level of service because you exercised any of these rights.
To submit a request, use the contact form on our website. Authorized agents may submit requests on your behalf with a signed permission, your verification of identity, and the agent’s confirmation of identity and authorization.
10. Enterprise Customers
For customers using the Platform under a commercial agreement, Visum AI acts as a service provider or processor with respect to Customer Content, and as a controller or business with respect to account administration, support records, billing, and website analytics. Customer data ownership remains with the customer. Data handling, confidentiality, security obligations, breach notice, and international transfer terms are governed by the executed master services agreement, statement of work, and data processing addendum (if any). In the event of any conflict between this Policy and an executed customer agreement, the customer agreement controls.
11. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites.
12. Minors
Our Services are intended for business use and are not directed to minors. We do not knowingly collect personal information from minors. If you believe we have collected personal information from a minor, please contact us so we can delete it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the Effective Date above, post the revised Policy on our Website, and where required by law or by an executed customer agreement provide advance notice through email or in-product notification. Material changes for existing customers will not modify executed customer agreements except in accordance with their own amendment provisions.
14. Contact Information
If you have questions about this Privacy Policy or our data practices, please contact:
Visum AI, Inc.
Contact: the contact form on our website
Website: https://visum.ai