AdvisorOSAdviser WorkspaceRequest Access
Privacy Notice · privacy-2026-06-public-beta

AdvisorOS Privacy Notice

AdvisorOS helps advisors manage leads, client workflow, appointments, follow-ups, calculator cases, product-library notes and client-safe presentation snapshots. The workspace is designed for data minimisation and controlled access.

Data we process

AdvisorOS may process advisor account details, organization/workspace details, lead names and contact details, client profile context, appointment notes, follow-up tasks, calculator inputs/outputs, product-library entries, client-safe snapshots, activity logs and security/session records.

Restricted data

Users must not store NRIC/FIN, passport numbers, bank login details, medical records, claim documents, official product application forms, passwords, or other unnecessary sensitive personal data in AdvisorOS.

Purpose of use

Data is used to operate the workspace, authenticate users, maintain owner/team access controls, support advisor preparation, generate discussion-support views, record follow-up work, maintain audit evidence, and respond to security or data-protection requests.

Access control

Advisor records are scoped to the logged-in user and their approved organization. Manager/admin roles may view team records for supervision and operations. Authorised platform staff may access account-level metadata (record counts, billing and support diagnostics) to provide support, security monitoring and billing; platform staff do not access individual client records except where needed to resolve a support request you raise, and such access is logged.

AI-assisted features

If you use the Portfolio Snapshot feature, the document images you upload are sent to our AI provider (OpenAI, United States) solely to extract policy details into structured fields. These images are not used to train AI models. Do not upload documents showing NRIC/FIN, passport numbers, medical diagnoses or other prohibited identifiers — redact them before uploading. Other AI-assisted features process only the specific inputs you provide for that feature.

Sub-processors

We use the following third-party providers to operate AdvisorOS. A current list is available on request from the Data Protection Contact below.

ProviderPurposeRegion
SupabaseApplication database, authentication and file storageConfirm project region before publishing
VercelApplication hosting and deliveryGlobal edge / configured region
StripeSubscription billing and payment processingGlobal (Stripe)
OpenAIAI-assisted extraction of policy data from documents you upload to Portfolio SnapshotUnited States
ResendTransactional and notification emailGlobal
PostHogProduct analytics on logged-out marketing pagesEuropean Union
SentryError monitoring (sanitised — no client data)Configured region
MetaAdvertising conversion measurement on public marketing pages onlyGlobal (Meta)

Retention, correction and deletion

Unless a longer period is required by law, client records are retained while the organization’s account is active and for up to 90 days after cancellation to allow for export, after which they are deleted. Each organization remains responsible for handling access, correction, deletion and withdrawal requests for its own clients consistently with its legal, compliance and dispute-handling obligations. To request an export or deletion, contact the Data Protection Contact below.

Data breach

If a data breach affecting your data occurs, we will notify you without undue delay after confirming it, and cooperate with any notification you are required to make to the PDPC or your clients.

Contact

Organization: AdvisorOS
Data Protection Contact: AdvisorOS Data Protection Contact
Email: admin@advisoros.space