Legal
Privacy Policy
This policy explains what personal data Osseus collects, how and why we use it, who we share it with, and the choices and rights you have. It covers the Osseus platform, the Osseus marketplace, and this website.
1.Who is responsible
The company trading as Osseus (“Osseus”, “we”, “us”) is responsible for the personal data described here. For most content inside a business workspace, your organisation is the controller of that data and Osseus acts as its processor; for account, billing, marketplace and website data, Osseus is the controller. Contact us at hello@osseus.ai.
2.Data we collect
- Account & identity. Name, email, organisation, and the identifiers from our sign-in provider when you authenticate. We do not store your password — authentication is handled by our identity provider.
- Profile. Display name, role, avatar, and (for the Marketplace) your storefront name, location and description.
- Workspace content. The engineering records you upload or connect — for example documents, drawings, models, bills of materials, issues, messages and the metadata from tools you link — and material derived from them to power search and review. This can contain personal data such as the names of authors, reviewers and commenters.
- Connected-tool data. When you connect a third-party tool, we access only the data within the scope you authorise, to provide the features you asked for.
- Marketplace data. Listings, orders, rentals, deposits, on-platform messages, reviews, and wanted requests.
- Payment data. Processed by Stripe. We receive confirmation and limited details (such as status and the last digits/brand of a card) but we do not store full card numbers.
- Usage & device data. Log data, IP address, timestamps, and diagnostic and audit records needed to run and secure the Services.
- Communications. Messages you send us, including support requests and waitlist submissions.
3.How we use it
- To provide, operate and secure the Services and your workspace.
- To power review, change-impact and assistant features over your connected records.
- To process Marketplace orders, rentals, deposits, messages and reviews.
- To take payment, manage subscriptions and prevent fraud.
- To provide support and respond to you.
- To maintain audit and security records, including a record of when data leaves the system through an approved integration.
- To send service messages, and — where permitted — occasional product updates you can opt out of.
- To comply with legal obligations and enforce our terms.
4.AI features & your content
We do not sell your data, and we do not allow your confidential workspace content to be used to train third-party foundation models. Simulations and tests run locally on infrastructure you control. Osseus can be deployed on-premises or in your private cloud, keeping designs, requirements and test data within your controlled environment. Where external AI APIs are used, we use Zero Data Retention configurations so submitted data is not stored by the provider or used for model training.
AI features are delivered with the help of third-party model providers acting as our subprocessors under confidentiality and data-protection terms. Outputs are assistive and cited to their sources so you can verify them.
5.Legal bases
Where the UK GDPR or EU GDPR applies, we rely on:
- Contract — to provide the Services you or your organisation signed up for, including payments and marketplace transactions.
- Legitimate interests — to secure, maintain and improve the Services, prevent fraud and abuse, and communicate about the product, balanced against your rights.
- Consent — where we ask for it, such as certain marketing; you can withdraw it at any time.
- Legal obligation — to meet tax, accounting and other legal requirements.
7.Marketplace & other users
On the Marketplace, some information is necessarily shared with the people you transact with. A published listing and its photos, your storefront profile, and reviews are visible to other users; when you place or receive an order, the counterparty sees the details needed to fulfil it and the messages you exchange. Public visitors browsing the Marketplace see only summary listing cards and their photos — not seller identity, contact details, orders or messages — until they sign in.
8.International transfers
We and our subprocessors may process data in countries other than yours. Where we transfer personal data across borders, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
10.Retention & deletion
We keep personal data for as long as needed to provide the Services and for legitimate or legal purposes such as accounting, dispute resolution and security. The Services are built as an append-only record: rather than hard-deleting, we typically retract data so it stops being visible and stops being used, which preserves the integrity of history like orders and reviews. When you close a workspace or ask us to delete data, we will delete or de-identify it within a reasonable period, except where we must keep it (for example a transaction record or an invoice).
11.Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to withdraw consent. To exercise them, email hello@osseus.ai. If your data sits inside a business workspace, we may direct your request to that organisation as the controller, or act on its instructions.
If you are in the UK or EEA and believe we have mishandled your data, you can complain to your supervisory authority — in the UK, the Information Commissioner’s Office (ICO) — though we would welcome the chance to resolve it first.
12.Security
We enforce confidentiality by architecture, not by trusting a model to behave. Each workspace’s data is isolated at the database level, an agent is only connected to the systems and records its owner is already permitted to access, and data leaving the system through an integration passes an audited gate. We use encryption in transit and at rest and restrict access to personal data. No system is perfectly secure, but you can read more on our security page.
13.Children
The Services are for businesses and professionals and are not directed to children. We do not knowingly collect personal data from anyone under 18.
14.Changes
We may update this policy. If a change is material we will give reasonable notice. The “last updated” date above shows when it last changed.
15.Contact
Questions or requests about your privacy? Email hello@osseus.ai.