AdvisorOSAdviser WorkspacePrivacy Notice
Data Protection Operations · pdpa-2026-06-public-beta

AdvisorOS Data Protection Operating Notes

This page documents the operating controls expected inside an AdvisorOS workspace.

Collect lessUse minimum lead/client workflow data. Avoid NRIC/FIN, passport numbers, bank login details, passwords, and unnecessary sensitive details.
Show lessUse Client Mode snapshots for screen sharing. Snapshots hide internal notes, lead status and admin metrics.
Access lessAdvisors see own records; managers see team records; platform owners administer platform operations.
Keep evidenceUse audit logs for login, account approval, client view, snapshot creation, imports and admin actions.

Data request workflow

  1. Record the request type: access, correction, export, deletion or withdrawal.
  2. Verify requester authority before disclosing or changing data.
  3. Review legitimate retention, compliance, dispute-handling and business needs.
  4. Complete or reject the request with a documented resolution note.

Incident workflow

  1. Contain the issue by revoking affected sessions, access and keys.
  2. Assess affected records, affected persons, likely harm and timeline.
  3. Document evidence, remedial action and follow-up ownership.
  4. Escalate to the configured data-protection contact and follow applicable notification requirements.

AI-assisted features

If you use the Portfolio Snapshot feature, the document images you upload are sent to our AI provider (OpenAI, United States) solely to extract policy details into structured fields. These images are not used to train AI models. Do not upload documents showing NRIC/FIN, passport numbers, medical diagnoses or other prohibited identifiers — redact them before uploading. Other AI-assisted features process only the specific inputs you provide for that feature.

Sub-processors

Third-party providers that may process data on our behalf:

ProviderPurposeRegion
SupabaseApplication database, authentication and file storageConfirm project region before publishing
VercelApplication hosting and deliveryGlobal edge / configured region
StripeSubscription billing and payment processingGlobal (Stripe)
OpenAIAI-assisted extraction of policy data from documents you upload to Portfolio SnapshotUnited States
ResendTransactional and notification emailGlobal
PostHogProduct analytics on logged-out marketing pagesEuropean Union
SentryError monitoring (sanitised — no client data)Configured region
MetaAdvertising conversion measurement on public marketing pages onlyGlobal (Meta)

Data processing agreement

A Data Processing Agreement is available for organizations that require one for their own compliance. Request it from the data-protection contact below.

Contact

AdvisorOS · AdvisorOS Data Protection Contact · admin@advisoros.space