Privacy Policy
This policy explains what personal data exactbench collects, how it's used, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable laws.
Last updated: 26 May 2026 · Version 1.0
Contents
1. Who we are
exactbench is operated by Niall Dunne, a sole trader based in Sweden, trading as exactbench. For GDPR purposes, Niall Dunne is the data controller for the personal data described in this policy.
Contact: niall@exactbench.com
2. What data we collect
2.1 If you visit exactbench.com
- Server logs — IP address, browser type, pages visited, timestamp. Used to operate the site and detect abuse.
- Email and consent — if you submit your email to download a guide, request a demo, or join a pilot, we store the email, the action you took, and whether you consented to marketing follow-up.
2.2 If you use the product app at /app
- Account data — your email and an API access key tied to it.
- Manuals you upload — the PDF file, the parsed text and figures, and the embeddings derived from them. Stored under your account.
- Questions and answers — the questions you ask, the answers returned, the citations, and any feedback (👍/👎, flags). Used to improve answer quality for your own account.
- Usage logs — which manual was queried, response time, model used.
2.3 If your company runs a pilot with us
- Contact details of the pilot lead and named users.
- Documents uploaded on behalf of the company (manuals, service bulletins, sample tickets).
- Per-user activity — same scope as 2.2, scoped to the pilot account.
3. Why we collect it (lawful basis under GDPR)
- Contract performance (Art. 6(1)(b)) — providing the product you signed up for: ingesting your manuals, answering your questions, sending pilot onboarding email.
- Legitimate interest (Art. 6(1)(f)) — server logs for security, abuse detection, basic product analytics. Balanced against your right to expect a working, safe service.
- Consent (Art. 6(1)(a)) — marketing emails, but only if you actively tick the box. You can withdraw consent at any time using the unsubscribe link.
- Legal obligation (Art. 6(1)(c)) — tax records, fraud prevention.
4. Who we share it with (subprocessors)
We use a small set of third-party services to deliver exactbench. The full list — what each one processes, where they're located, and links to their DPAs — is on our subprocessors page.
We do not sell personal data. We do not share it with advertisers. OpenAI is contractually prohibited from training on data we send via the API.
5. International transfers
Our subprocessors are based in the United States. Transfers from the EU/EEA to the US are covered by the EU-US Data Privacy Framework (where the vendor is certified) and the EU Standard Contractual Clauses referenced in each vendor's DPA. Enterprise pilots can request EU-only data residency.
6. How long we keep it
- Server logs: 30 days, then purged.
- Pilot data (manuals, embeddings, Q&A logs): for the duration of the pilot plus 30 days, then deleted. Earlier on request.
- Lead emails (marketing opt-in): until you unsubscribe or 24 months of inactivity, whichever is sooner.
- Lead emails (no marketing consent): stored only with the action that produced them (e.g., "downloaded SOP on date X"), purged after 12 months.
- Invoicing and tax records: 7 years (Swedish bookkeeping law).
7. Your rights under GDPR
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure ("right to be forgotten") — request deletion of your data.
- Restriction — ask us to stop processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for anything done on consent basis (e.g., marketing email).
- Lodge a complaint — with your local data protection authority (in Sweden: Integritetsskyddsmyndigheten (IMY)).
To exercise any of these, email niall@exactbench.com with the subject data request. We respond within 30 days.
8. Cookies and tracking
exactbench.com does not use third-party tracking cookies, analytics tags, or advertising pixels. We use a small number of strictly necessary browser storage items to make the product work:
ai-manuals.apiKey— your access key, stored in your browser's localStorage so you don't have to paste it on every visit.ai-manuals.emailGiven— a flag that remembers you've already provided your email, so we don't ask again in the same session.
These are stored locally on your device only and are not sent to any third party. Clearing your browser data removes them. Because we don't use non-essential cookies, no cookie consent banner is shown.
If we add analytics in future, we will update this policy and add a proper opt-in banner before any tracking starts.
9. AI-generated output
The exactbench product uses a large language model (OpenAI) combined with retrieval from your own uploaded manuals. Answers are generated by AI and cite the source page. AI output can still contain errors — always verify safety-critical procedures against the original manual and your organisation's standards. Don't use exactbench as the sole source of truth for life-safety decisions.
10. Security
- TLS encryption in transit for all traffic (HTTPS).
- Access keys hashed at rest.
- Database encryption at rest (managed by Render/PostgreSQL).
- Subprocessor selection limited to vendors with documented security practices and DPAs.
- Incident response: if we become aware of a personal data breach, we notify affected customers without undue delay (within 72 hours where GDPR requires it).
11. Changes to this policy
If we make material changes, we update the "Last updated" date and, for active pilot customers, email a summary of what changed.
12. Contact
Questions, requests, or complaints: niall@exactbench.com
Postal: Niall Dunne (sole trader, trading as exactbench), Sweden. Full postal address available on request to verified data-subject requesters.