AdvEngine
Sign In
AdvEngine
PrivacyPolicy

How we collect, use, and protect your data

Last updated: 4 August 2026

1. Introduction

1.1 Scope and Applicability

This Privacy Policy ("Policy") describes how AdvEngine Inc. ("AdvEngine," "Company," "we," "us," or "our") collects, uses, shares, and protects Personal Information through our public-facing website at https://advengine.com (the "Website"), our software platform, available at app.advengine.com and other domains we operate (the "Service"), and our related sales, marketing, account-management, and support activities.

This Policy applies to Personal Information we gather when you access or use our Website or the Service. The Service is offered for business and professional use. For clients under a Master Service Agreement, the processing of "Client Data" and Output within the Service is governed by the Master Service Agreement (MSA), Data Processing Addendum (DPA), and other commercial agreements executed with those clients; the MSA and DPA shall control in the event of any conflict with this Policy.

For Trial users, invited evaluators, and other clients who have not executed an MSA, including paying clients under an Order Form, Client Data and Output are handled as described in Section 4 of this Policy, in our Terms and Conditions, and in any applicable Order Form.

By accessing our Website, you acknowledge that you have read and understood this Policy. Your use of the Website and the Service is also subject to our Terms and Conditions.

1.2 Key Definitions

Personal Information: Information that identifies, relates to, or could reasonably be linked, directly or indirectly, to a particular individual or household. Personal Information does not include Anonymized Data or Aggregated Data. This Policy governs Personal Information we collect from Website visitors, Service users, business contacts, and other individuals with whom we interact. For Personal Information used for Website, account, billing, security, marketing, and support purposes, we act as a controller or equivalent responsible organization. When we process Personal Information contained in Client Data or Output on behalf of a client, we generally act as a processor or service provider, and the client determines the purposes of that processing. Requests concerning Personal Information contained in Client Data or Output should ordinarily be directed to the relevant client, and we will assist the client as required by applicable law and the applicable agreement.

Client Data: Financial information, research materials, investment data, and other content that our clients and their authorized users provide to our Service for processing.

Output: Content generated by the Service in response to Client Data or user instructions. As described in our Terms and Conditions, clients own their Output.

Anonymized Data: Data processed to irreversibly prevent identification of any individual.

Aggregated Data: Information combined from multiple users and analyzed as a whole, such that no individual can be identified.

Usage Data: Telemetry, product usage, diagnostic, and similar technical data that we collect or generate in connection with use of the Service, such as feature-usage statistics, performance and reliability metrics, error and crash reports, and configuration data (for example, account identifiers and settings). Usage Data may also include aggregated, de-identified statistics about how the Service is used, such as the general types of tasks performed and the general subject matter of requests. These statistics do not identify any particular client. Apart from these statistics, Usage Data does not contain Client Data or Output, such as your prompts, documents, or generated results. Where Usage Data contains Personal Information, we handle it in accordance with this Policy.

2. Information We Collect

2.1 Information You Provide Directly

Contact and Professional Information: When you request a demo, contact us, subscribe to updates, or register for an account, we collect your name, email address, phone number, company name, job title, and any information you choose to provide.

Account Information: For Service access, we collect information to create and manage your account, including name, email, credentials, and preferences.

Communication Records: We maintain records of support requests, feedback, and inquiries, including message content and metadata.

Payment Information: We use third-party payment processors for transactions. We do not store complete credit card numbers; payment data is handled directly by processors under their privacy policies.

2.2 Information Collected Automatically

Log Data: We automatically collect IP address, browser type, operating system, device characteristics, referring URLs, pages visited, and visit timestamps. This data maintains Website security and supports internal analytics.

Cookies and Tracking Technologies: We use cookies and similar technologies to operate our Website and understand usage patterns. The categories of cookies we use are:

  • Essential Cookies: Required for basic functionality (cannot be disabled).
  • Performance Cookies: Analyze usage and improve functionality (aggregated/anonymous).
  • Functional Cookies: Remember your preferences for enhanced features.

We do not currently use advertising or cross-site tracking cookies. If we introduce them in the future, we will update this Policy and, where required by law, obtain your consent first. You can manage or disable cookies through your browser settings; disabling essential cookies may affect Website functionality. Where required by law, we will present a consent mechanism for non-essential cookies.

Location Information: We derive general geographic location from IP addresses for security (detecting unusual activity) and experience customization. We do not collect precise geolocation without explicit consent.

2.3 Information from Third Parties

Employers: If you access the Service through an employer-provided account, we may receive your information from them.

Business Partners: We may receive information from marketing and advertising partners about your engagement with our content.

Financial and other Data Providers: Our Service integrates with third-party financial and other data providers. Data flows through our platform for processing as described in Section 4.

3. How We Use Personal Information

We process Personal Information only when we have a valid legal basis under applicable law.

To Provide and Maintain the Service: To fulfill contractual obligations, manage accounts, provide access, process transactions, and deliver support.

Lawful Basis (GDPR): Performance of a Contract

To Improve and Personalize: We analyze usage patterns to understand behavior, troubleshoot issues, and enhance user experience.

Lawful Basis (GDPR): Legitimate Interest

Security and Fraud Prevention: To verify identity, prevent fraud and unauthorized access, investigate illegal activities, and enforce our policies.

Lawful Basis (GDPR): Legitimate Interest; Legal Obligation

Service Communications: We send essential technical notices, security alerts, and administrative messages. These are part of the Service and cannot be opted out of.

Lawful Basis (GDPR): Performance of a Contract; Legitimate Interest

Marketing: With your consent or where permitted, we send promotional communications. You may opt out at any time.

Lawful Basis (GDPR): Consent; Legitimate Interest (with opt-out)

Legal Compliance: To comply with laws, regulations, court orders, and lawful government requests.

Lawful Basis (GDPR): Legal Obligation

4. Client Data and AI Processing for Financial Services

This section outlines our core commitments regarding financial information, investment data, and research materials processed through our Service. For clients under an executed MSA, these commitments are contractually enforced through the MSA, DPA, and other executed agreements. For all other clients, including paying clients under an Order Form, they are enforced through our Terms and Conditions and any applicable Order Form.

4.1 The Nature of Client Data in Financial Services

Client Data includes, but is not limited to, financial documents, investment analysis, portfolio data, market data, and queries, prompts, and other inputs you provide to the Service. Except for Feedback as described below, information you provide to the Service remains Client Data for purposes of our processing, no-training, retention, and deletion commitments even if it is publicly available, although public information does not become confidential merely because it is uploaded. You retain all ownership rights to your Client Data.

For clarity, the protections in this Section cover your Client Data as you provide it to the Service and the Output generated for you; they do not extend to information that we lawfully obtain from other sources (such as public filings, licensed data providers, or our own research) or independently develop, even if it is the same as or similar to information contained in your Client Data or Output. This does not create any right for us to use your Client Data or Output itself.

To the extent anything you submit constitutes feedback, comments, suggestions, bug reports, or ideas regarding the Service, it is treated as Feedback under our Terms and Conditions rather than as Client Data. Content that is by its nature Client Data, such as your files, financial or business information, or other content you process through the Service, is not Feedback and remains Client Data.

4.2 No Training on Client Data or Output

Notwithstanding any other provision in this Policy, we do not use Client Data or Output to train, retrain, fine-tune, or otherwise improve our AI models or any third-party AI models. If you request a client-specific customization (for example, a model or template adapted to your workflows), it will be developed only as expressly agreed with you.

Client Data and Output are processed exclusively to provide the Service to you. In the course of operating the Service, we may generate the aggregated Usage Data statistics described in Section 1.2; these do not identify any particular client. Client Data and Output are not:

  • Used to improve our general AI models.
  • Shared with other clients without your permission.
  • Used for research or product development; for those purposes we rely on aggregated Usage Data as described in Section 4.5.
  • Provided to AI model providers for their training purposes.

Our authorized sub-processors may process Client Data and Output solely to deliver and support the Service, including to generate Usage Data, and are bound by confidentiality obligations; AI model providers in particular are engaged under terms that do not permit the use of Client Data or Output to train or improve their models.

4.3 Financial Services Data Security Architecture

Data Flow and Processing: Data is transmitted to our infrastructure using current, industry-standard versions of TLS encryption, processed by our systems, including AI agents, and stored encrypted at rest (AES-256 or stronger).

Access Controls: We implement strict role-based access controls and a Zero Trust security model. Our technical staff may access Client Data or Output only when necessary for technical support at your request, to troubleshoot critical issues, or to comply with legal obligations, under logged and audited conditions.

Special Deployment Options: We offer tailored deployment solutions, including private cloud deployments, under separate agreements for clients with heightened privacy and security requirements.

4.4 Third-Party AI Service Providers

We use third-party AI foundation models as a component of our Service. The specific providers are identified in our sub-processor list, available to clients upon request. These providers process Client Data and Output solely to deliver the Service to us, under agreements that prohibit the use of Client Data or Output to train or improve their models.

Default configuration: We configure every provider to minimize data retention to the fullest extent their standard terms allow, and we do not enable optional data-sharing, logging, or model-improvement features. Some providers nonetheless retain inputs and outputs for a limited period, typically to monitor for abuse or to satisfy their own legal obligations. Retention periods vary by provider and by model.

Zero data retention: Where a provider and model support it, we can enable a zero-data-retention configuration for your account on request. Not every model can operate this way: some providers do not offer the option, and some are subject to legal or regulatory requirements that mandate a minimum retention period. Enabling zero data retention may also limit which models are available to you and may affect Service performance and cost, as provider terms for these configurations differ from standard terms. To discuss scope and applicable terms, contact us at legal@advengine.com.

4.5 Usage Data

We collect and use Usage Data (as defined in Section 1.2) to operate, secure, support, and improve our Service. Apart from the aggregated statistics described in Section 1.2, Usage Data does not contain Client Data or Output. Where Usage Data contains Personal Information, such as account identifiers, we handle it in accordance with this Policy. We do not disclose Usage Data to third parties except as described in Section 5 or where it is aggregated and de-identified so that it does not identify you or your users and does not reveal Client Data or Output.

4.6 Material Non-Public Information (MNPI)

You may not provide Material Non-Public Information to the Service unless expressly permitted under an executed MSA or other written agreement with us. As stated in our Terms and Conditions, you are responsible for classifying the information you submit, and you represent and warrant that you have all necessary rights and consents for any information you provide.

4.7 Data Retention

For Trial and Other Non-Paying Users: Client Data and Output are deleted from our active systems 90 days after the end of the Trial (or other relevant period), or earlier if you request deletion. Copies of such data may persist in backup systems that are segregated from active systems and maintained under strict privacy and security requirements; backup copies expire under our standard backup schedule within 90 days after deletion from active systems. Client Data and Output may be retained beyond these periods only where required by law or regulation, or where reasonably necessary to investigate security incidents or enforce our agreements. If your account is terminated, the post-termination export and deletion timelines set out in our Terms and Conditions apply instead. You may request deletion of your data at any time by contacting legal@advengine.com; we honor such requests promptly to the extent technically possible and permitted by applicable law.

For Paying Clients: For clients under an executed MSA, retention is governed by the MSA. For paying clients without an MSA, retention is governed by our Terms and Conditions and any applicable Order Form. Upon termination of your agreement, Client Data and Output are deleted in accordance with the applicable agreement.

5. How We Share Information

We do not sell Personal Information, Client Data, or Output to third parties, and we do not share Personal Information for cross-context behavioral advertising (as those terms are defined under applicable U.S. state privacy laws). We share information only in these limited circumstances:

Service Providers and Sub-processors: We engage third-party vendors for functions including cloud hosting, payment processing, analytics, and email delivery. These providers are contractually obligated to protect information and, in general, may use it only to provide services to us. Certain providers, such as payment processors, also process information as independent controllers under their own privacy policies, for example for fraud prevention. A list of our material sub-processors is available to clients upon request.

AI Service Providers: As described in Section 4.4, we use AI foundation model providers under strict contractual protections that prohibit model training.

Business Transfers: In a merger, acquisition, bankruptcy, or asset sale, your information may be transferred. We will use reasonable efforts to ensure the acquiring entity honors this Policy.

Legal Requirements: We disclose information when required by law, regulation, or valid legal process.

With Your Consent: We share information with third parties when you explicitly direct us to do so.

6. Data Security

We maintain a security program with administrative, technical, and physical safeguards appropriate to the nature of the data we process, designed to protect Personal Information, Client Data, and Output.

Technical Measures:

  • Encryption: Data is encrypted in transit using current, industry-standard versions of TLS and at rest (e.g., AES-256 or stronger).
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and least-privilege access principles.
  • Vulnerability Management: Regular security scanning, penetration testing, and risk assessments.
  • Monitoring: Continuous monitoring for suspicious activity and security incidents.

Organizational Measures:

  • Mandatory security awareness training for all employees.
  • Background checks for personnel with access to sensitive systems.
  • Strict confidentiality obligations and non-disclosure agreements.
  • Incident response procedures, including notifying affected clients without undue delay after we confirm a security incident affecting their data.

Disclaimer: While we implement robust security measures, no system is perfectly secure.

7. Data Retention

We retain Personal Information only as long as necessary for the purposes described in this Policy and to comply with legal obligations. When we no longer need Personal Information, we securely delete or anonymize it.

When we delete Personal Information, residual copies may persist for a limited time in segregated backup systems and are removed in the ordinary course of our backup cycles.

8. Your Privacy Rights

8.1 General Rights

Access and Correction: You may request access to or correction of your Personal Information.

Deletion: You may request deletion of your Personal Information, subject to exceptions under applicable law (for example, where retention is required by law or needed to complete a transaction, provide the Service, maintain security, or establish or defend legal claims).

Communication Preferences: Opt out of promotional emails via the "unsubscribe" link.

8.2 Region-Specific Rights (EEA/UK, U.S. states incl. California, Canada, etc.)

Depending on where you live, local laws may grant additional rights. To exercise your rights, contact us at legal@advengine.com. We will respond in accordance with applicable law. We will not discriminate against you for exercising your privacy rights. To the extent the GDPR, UK GDPR, or similar laws apply to you, you may also have the right to object to or restrict certain processing, to receive a copy of your Personal Information in a portable format, to withdraw consent at any time (without affecting prior processing), and to lodge a complaint with your local data protection supervisory authority.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States and Canada. For transfers of Personal Information from the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we implement appropriate safeguards, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and recognized Swiss contractual safeguards or adaptations, together with transfer-risk assessments and supplementary measures where appropriate. Information about the applicable safeguards is available upon request.

10. Children's Privacy

Our Service is not directed to individuals under the age of 18 or the applicable age of majority in their jurisdiction, whichever is higher ("Minors"), and our Terms and Conditions require users to meet this age requirement. We do not knowingly permit Minors to create or use Service accounts or knowingly collect their Personal Information through the Service. If we learn that a Minor has provided Personal Information through the Service, we will take reasonable steps to delete it. If you believe a Minor has provided us Personal Information, contact us at legal@advengine.com.

11. Third-Party Links

Our Website may link to third-party websites. We are not responsible for their privacy practices.

12. Changes to This Policy

We may update this Policy to reflect changing legal, technical, or business developments. When we update the Policy, we will post the revised version on this page and update the "Last Updated" date. If the changes are material, we will provide additional notice, such as by email or a prominent notice on the Website, before the changes take effect.

13. Contact Us

For questions about this Privacy Policy or to exercise your privacy rights, please contact:

AdvEngine Inc.
Privacy Officer
Email: legal@advengine.com
Mailing address: available upon request