Privacy Policy
Last updated: August 6, 2026
This Privacy Policy explains what information North Hammer collects through the North Hammer Policy Engine and this website, why we collect it, and the choices available to you. It applies to visitors of this site and to authorized users of the platform.
Information We Collect
Account information: the name, work email address, organization, and role supplied when an administrator provisions an account, together with the two-factor enrollment state needed to secure it. If you sign in with Google, we receive your email address, basic profile information, and the confirmation that Google authenticated you — we never receive your Google password.
Organizational content: the policies, procedures, regulatory documents, evidence, comments, and assessment decisions your organization uploads or records in the platform.
Usage and technical data: sign-in events, pages and features used, actions recorded in the audit trail, IP address, browser and device characteristics, and diagnostic logs.
Correspondence: demo requests, support messages, and other communications you send us, including the contact details in them.
How We Use Information
We use this information to authenticate users and protect accounts, to deliver and operate the assessment features, to maintain the audit trail your organization relies on, to provide support, to monitor security and service health, to meet legal obligations, and to improve the product in aggregate.
We do not sell personal information, and we do not use organizational content for advertising or profiling.
Automated Processing and AI
Extracting obligations from regulatory text and comparing them with policy language uses large language models. Document text and derived embeddings are sent to our model provider strictly to produce the assessment requested, under contractual terms that prohibit using the content to train their models.
Automated output is always presented for human review. No account-affecting decision is made about an individual solely by automated means.
How Information Is Shared
Content is segregated by organization, and access is restricted to authorized users of that organization and to the personnel who operate the platform.
We share information with the service providers that make the platform work — cloud hosting and application delivery, the managed Postgres database, the language-model provider, and the transactional email provider — each bound by confidentiality and data-protection obligations and permitted to use the data only to provide their service to us.
We may also disclose information where required by law or valid legal process, to protect our rights or the safety of users, or as part of a merger, acquisition, or sale of assets, in which case we will provide notice.
Data Retention
Organizational content is retained for as long as the subscription is active, and afterwards only for the period agreed with the organization or required by law. Audit records are retained for the retention window the organization configures, because their value depends on remaining intact.
Diagnostic logs are kept for a limited period and then discarded. On verified request, we delete or return organizational content.
Security
Access to the platform is passwordless and invite-only, with optional time-based two-factor authentication. Data is encrypted in transit and at rest, the portal and the public site are served from separate origins so a public-site script can never read a portal session, and every data operation runs through server-side, permission-checked database functions rather than direct client access.
No system is perfectly secure. If a breach affects your information, we will notify affected organizations as required by applicable law.
Your Rights and Choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete personal information about you, and to object to certain processing. For platform data, the subscribing organization is the controller and we act on its instructions, so we will route requests through it.
To exercise a right or ask a question, write to support@northhammer.com. We may need to verify your identity before acting.
International Transfers
We and our service providers may process information in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
Cookies and Similar Technologies
The portal sets a small number of strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. The public site stores your light or dark theme preference locally in your browser. We do not use advertising or cross-site tracking cookies.
Children's Privacy
The service is a business tool intended for organizations. It is not directed to children, and we do not knowingly collect information from anyone under sixteen.
Changes to This Policy
We may update this policy as the service and the law evolve. Material changes will be reflected in the date shown on this page and, where appropriate, communicated to subscribing organizations.
Contact Us
Questions about this page can be sent to support@northhammer.com.