1. Scope
This policy covers personal data handled by State Affairs, Inc. through the State Affairs website and workspace application. It does not cover the legislative and regulatory records themselves: bills, administrative rules, statutes, votes and the details of public officials acting in their official capacity are public records, not personal data we have collected about you.
2. Data we collect
Data you give us
- Account details — name, work email, job title, phone number, and the organisation you belong to.
- Workspace content — issues you define, portfolios and positions, field notes, alert settings, saved reports, and the questions you ask the AI.
- Enquiries — what you send us in a demo request or support ticket.
- Billing details — plan, seat count and billing period. Card details are handled by our payment processor; we do not store full card numbers.
Data collected automatically
- Log data — IP address, browser and device type, pages requested, and timestamps.
- Session data — a session cookie that keeps you signed in.
- Audit records — a log of significant actions taken in an account (sign-in, permission changes, exports), kept for security and to give account administrators an activity trail.
3. How we use it
- To provide the Service: authenticating you, storing your workspace, running searches and answering questions.
- To operate alerts and scheduled reports you configure.
- To take payment and administer your plan.
- To provide support and respond to enquiries.
- To keep the Service secure — detecting abuse, investigating incidents, enforcing our Terms and usage limits.
- To understand and improve how the Service is used, in aggregate.
- To send service messages. Marketing email is only sent where you have opted in or where we are otherwise permitted, and every marketing message has an unsubscribe link.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
4. Legal bases (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process personal data on these bases: performance of a contract (providing the Service you signed up for); legitimate interests (securing the Service, preventing abuse, improving the product), balanced against your rights; consent (optional cookies and marketing email, which you can withdraw at any time); and legal obligation (tax, accounting and lawful requests).
5. When we share data
We share personal data only in these circumstances:
- Within your organisation. Workspace content is shared with other members of your organisation's account according to the visibility you choose. Account administrators can see membership and activity.
- Service providers acting on our instructions — cloud hosting and storage, the AI model provider that generates answers, email delivery, payment processing and error monitoring. They may process personal data only to provide their service to us.
- Legal reasons — where we must comply with law or valid legal process, or to protect our rights, users or the public. Where we are permitted to, we will tell you first.
- Business transfer — if we are involved in a merger, acquisition or sale of assets, data may transfer, subject to this policy.
6. AI processing
When you ask a question, the question and the passages retrieved from our document index are sent to our AI model provider to generate an answer. We do not send the private contents of your workspace — your notes, portfolios or team data — unless they form part of a question you have chosen to ask.
We do not permit our providers to use your questions to train their models, and we log the question, the answer and its citations to your account so that you can review them and so we can measure answer quality.
7. How long we keep it
- Account and workspace data — for as long as the account is open, and for up to 90 days after closure so it can be restored if closure was a mistake.
- Billing records — for as long as tax and accounting law requires, typically seven years.
- Audit and security logs — up to 24 months.
- Web server logs — up to 90 days.
We may keep data longer where we must for a legal claim or obligation.
8. Security
Traffic is encrypted with TLS. Passwords are stored only as salted hashes, never in a recoverable form. Access to production systems is limited to staff who need it, and significant account actions are logged. No system is perfectly secure, but if a breach affects your personal data we will notify you and any regulator as required by law.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy in a portable format;
- correct data that is inaccurate or incomplete;
- delete your data, subject to what we must keep by law;
- object to or restrict certain processing;
- withdraw consent where processing relies on it; and
- complain to your data protection authority.
Much of this is self-service: you can view and edit your profile, and export or delete your workspace content, from your account settings. For anything else, write to privacy@example.com. We will acknowledge within 10 days and respond substantively within the period the applicable law requires (usually 30 to 45 days). We will not treat you differently for exercising a right.
10. California and other U.S. state rights
If you are a California resident, the CCPA/CPRA gives you the right to know the categories and specific pieces of personal data collected, the sources, and the purposes; to delete it; to correct it; and to opt out of sale or sharing. We do not sell or share personal data as those terms are defined, so there is no opt-out to exercise. You may use an authorised agent, and we may need to verify their authority.
Residents of other states with comparable privacy laws — including Colorado, Connecticut, Virginia, Utah and Texas — have similar rights, exercised the same way, through privacy@example.com.
11. Cookies
We keep cookie use to a minimum. See the Cookie Policy for the full list and how to control them.
12. International transfers
We operate in the United States, and our providers may process data there. If you are in the EEA or UK, transfers rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses.
13. Children
The Service is for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us data, write to privacy@example.com and we will delete it.
14. Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we use your personal data, we will give notice before it takes effect.
15. Contact us
Privacy questions and rights requests: privacy@example.com. Anything else: hello@example.com.