← EasyFixProblem

Privacy Policy

Version 2026-08-25 · Last updated 25 August 2026

Informational document. This notice describes how the product is actually built and is written against general EU/EDPB transparency principles. It is not legal advice and makes no claim of certification or guaranteed GDPR compliance. The service owner must have it reviewed by a qualified adviser, and must complete the items marked [confirm before launch], before it is relied on commercially.

1. Who is responsible

EasyFixProblem (the “Service”) is operated by the service owner, referred to here as “we”. The legal entity name, registered address and contact email for privacy requests are [confirm before launch]. Where you use the Service to record investigations on behalf of your employer or a client, that organisation normally decides why and how the content is processed; we process it on their behalf as part of providing the Service.

2. What data we handle

  • Account and profile data — email address, display name, optional avatar, authentication identifiers, and (if you sign in with Google) the basic profile information that provider returns.
  • Workspace and membership data — workspaces you create or join, your role in them, and invitations you send or receive (including the invited email).
  • RCA and equipment content you submit — problem statements, areas, equipment identifiers, fishbone causes, why-why chains, verdicts, actions, owners, dates, metrics, and methodology fields (PDCA, DMAIC, 8D, A3). This is free text: whatever you type is stored as written.
  • Evidence and attachments — files you upload (images, PDFs, spreadsheets, documents) stored in a private evidence bucket scoped to your workspace, plus file name, type and size.
  • Security and audit data — case activity logs, acceptance records for this policy and the Terms, deletion requests, and standard server/security logs generated by our hosting and database providers.
  • Billing and subscription data — plan, tier, trial and subscription status, and identifiers returned by our payment processor. Card details are handled by the payment processor and are never stored by us.
  • Support and feedback data — messages you submit through the in-app feedback control, with the page context and your user id.
  • AI usage records — when AI assistance is used, we record the workspace, the user who invoked it, the feature, model, token counts, an estimated internal credit figure, the outcome (success or failure) and the time, for metering and abuse prevention. We do not store the text of your prompts or the AI reply in these usage records.

We do not ask for special-category personal data. Please keep investigation content limited to what is needed for the analysis — avoid personal details about named individuals where an initial, role or asset reference would do.

3. Why we handle it

  • To create and secure your account and workspaces, and to provide the Service you asked for.
  • To store, display and export the investigations you create.
  • To operate billing, trials and subscriptions.
  • To keep the Service secure, prevent abuse, and meter AI usage fairly.
  • To answer support requests and act on feedback.

We use your data only for these purposes. We do not sell it, and we do not use your investigation content for advertising or profiling. The lawful bases we rely on (typically performance of a contract, legitimate interests in security, and legal obligations for accounting) should be confirmed for your jurisdiction — [confirm before launch].

4. AI assistance

AI assistance is optional and is off by default for new workspaces. Only a workspace owner can switch it on, in Privacy & data controls, and the setting is enforced on our servers: if it is off, an AI request is refused before any content leaves the Service. The Service is fully usable without AI.

When AI is enabled and you actively invoke an AI feature, only the minimum context that feature needs is sent to the configured AI provider — the problem statement, the analysis text of the step you are working on, and your question. Workspace member lists, email addresses, billing data and uploaded evidence files are not sent. Nothing is sent in the background. Suggestions are advisory drafts: they are not a root cause, decision or engineering approval, and must be reviewed and verified by a competent engineer.

Do not submit information you are not authorised to share for processing by a third-party AI service. We do not claim that AI providers never retain data; retention and training practices are governed by the provider’s own terms. The provider list and their published data-handling terms are [confirm before launch] and will be listed here and kept current as providers change.

5. Service providers and international transfers

We rely on a small number of processors to run the Service: application hosting and edge delivery, the managed database/authentication/storage platform, the payment processor, and the AI provider(s) used for optional AI assistance. Their identities, the regions where data is stored, and the transfer mechanism used for any processing outside the EEA/UK (for example standard contractual clauses) are [confirm before launch] — we will not state provider locations or transfer safeguards we have not verified.

6. Retention

Workspace content is kept for as long as the workspace exists, because it is the record you came here to build. When you delete a workspace or your account, the associated cases, child records, evidence objects, memberships and invitations are removed from the live system; an auditable deletion record (who requested what, and when) is retained. Backups held by our infrastructure providers may retain copies for a limited rolling window before expiring. Billing records may need to be kept longer to meet accounting obligations — the exact periods are [confirm before launch].

7. Security

Every workspace is isolated at the database level by row-level security tied to your identity and membership — not to company names or client-side checks. Evidence files live in a private bucket with server-side size and type restrictions and are served through short-lived signed links. Privileged operations run server-side only. No system is perfectly secure, but access is designed to be denied by default.

8. Your rights and controls

Subject to local law, you can request access, correction, deletion, restriction, objection, and data portability, and you may lodge a complaint with your supervisory authority. In the product you can already:

  • Update your profile details.
  • Export a full JSON bundle of any workspace you own, including short-lived evidence links.
  • Delete a workspace you own, or delete your account and its data, with typed confirmation.
  • Switch AI assistance off for a workspace.
  • See which versions of this policy and the Terms you have accepted.

These controls are in Profile → Privacy & data controls. For anything not covered there, contact us at [confirm before launch].

9. Changes

This document is versioned. When we make a material change we increase the version and ask you to review and accept it the next time you sign in. Your acceptance is recorded with the version and timestamp.

See also the Terms of Service.