This policy explains what personal data Insigo — operated by Hyperhire Co., Ltd. — collects, how we use and protect it, and the rights you have, including under the EU General Data Protection Regulation (GDPR).
1Who we are, and our roles
Insigo is a business intelligence tool used by teams. Hyperhire Co., Ltd. operates it. We act in two distinct roles:
- Controller — for account, billing, and service-operations data (your name, work email, login and usage records): we decide how this data is handled, as described in this policy.
- Processor — for the content of your workspace (the sources and subjects you configure, the facts you teach the system, your questions, and the outputs generated for you): your organisation is the controller and we process it only to provide the service. A Data Processing Agreement (DPA) meeting Article 28 GDPR — including our named sub-processor list — is available to customers on request at privacy@insigo.ai.
2Information we collect
- Account data — name, work email, workspace membership and role, and authentication data (passwords are only ever stored as a salted hash).
- Workspace content — the sources, competitors, subjects, and scenarios you configure, and the facts, corrections, and instructions you teach the system.
- Usage & device data — service logs, actions taken, timestamps, IP address, and browser/device details, used to run and secure the service.
- Billing data — handled by our payment processor (merchant of record); we receive subscription status and limited transaction metadata, not full card details.
- Product analytics — usage events and session recordings of signed-in use (EU-hosted, see section 3), used to understand and improve the product.
- Public-source material — our collection reads public and primary-source records (news, registries, filings). These may incidentally name public-facing individuals, such as executives in press coverage.
3Analytics & tracking
We run no advertising trackers and no cross-site tracking — on the product or this website. To understand how the product is used, we run EU-hosted product analytics (PostHog EU, Frankfurt): usage events and session recordings tied to your signed-in account, kept in the EU, and never sold or shared for advertising. Our analytics runs cookieless — we set no non-essential cookies, which is why you won't see a cookie banner here. Signing in uses secure storage in your own browser.
4Purposes and legal bases
Where GDPR applies, we process personal data on these legal bases:
- Performance of a contract (Art. 6(1)(b)) — providing and operating the service, support, and billing.
- Legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, and improving the product using aggregate information.
- Legal obligation (Art. 6(1)(c)) — accounting, tax, and lawful requests.
- Consent (Art. 6(1)(a)) — only where we ask for it (for example, optional communications); you can withdraw it at any time.
5AI processing
Your prompts and workspace content are processed to generate your intelligence. This processing is performed under enterprise terms, and your content is not used to train foundation models. The system reasons only from evidence it collected or facts you taught it, and its outputs cite the sources behind them.
6Where your data lives, and transfers
Customer workspaces — including the database and backups — are hosted on enterprise cloud infrastructure in the Republic of Korea, a country the European Commission has recognised with an adequacy decision (Decision (EU) 2022/254): personal data may flow there from the EEA without additional safeguards, because its protection has been found essentially equivalent to EU law. Our product analytics is hosted in the EU (Frankfurt, Germany). Where any other service provider processes data outside the EEA in a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses.
7Sharing & service providers
We share personal data only with vetted service providers (sub-processors) acting on our behalf under contract — for cloud infrastructure, AI inference, payment processing, email delivery, and product analytics — and only as needed to run the service. The current named list is published on our security page and forms part of our DPA. We may disclose data where required by law or to protect the service and its users. We do not sell or rent personal data.
8Retention & deletion
We keep personal data for as long as your account is active and as needed to provide the service, comply with legal obligations, and resolve disputes. On termination, you may request deletion or return of your workspace data: we action deletion requests within 30 days, with remaining backup copies removed within 90 days as backups rotate, unless retention is required by law. You can request an export of your data at any time.
9Security
We protect your data with tenant isolation, encryption in transit and at rest, invite-only role-based access, and least-privilege service design. A fuller summary is on our security page, and our technical and organisational measures are documented in the DPA. No system is perfectly secure, but security is built into how the product works, not added on.
10Your rights
Where GDPR applies, you have the right to access, rectify, erase, and export your personal data, to object to or restrict certain processing, and to withdraw consent at any time. To exercise any of these, contact privacy@insigo.ai — we respond within one month. If your organisation is the controller of your workspace, we'll route your request to it. You also have the right to lodge a complaint with your local supervisory authority (in Germany, the data-protection authority of your Land).
11Children
Insigo is a workplace tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
12Changes to this policy
We may update this policy as the product and law evolve. For material changes we'll provide reasonable notice. The “last updated” date above reflects the current version.
13Contact
Privacy questions or requests: privacy@insigo.ai · Hyperhire Co., Ltd.