Legal
Privacy policy
What we hold, why, and for how long. Last updated [date].
The short version: the documents your firm uploads are yours, stored encrypted in the EU with a key per deal, and read only to do the work you ask for. We never use them for anything else, never train on them, and delete them completely when you leave.
Two roles
For what your firm puts into the workspace, your firm is the controller and Navent is the processor. We act only on your instructions, under a data processing agreement. For the small amount of data we need to run our own business (who to invoice, who wrote to us), Navent is the controller, and the rest of this page describes that.
Who we are
[Navent legal entity], [organisation number], [address], Stockholm. Contact: [email protected].
What the workspace holds for your firm
| Data | Why | Kept for |
|---|---|---|
| Documents you upload, their extracted text and labels | To do the work: search, questions, findings, memos | Until you delete them, or the agreement ends plus 30 days |
| Findings, memos, notes, chat | Your work product | As above |
| Name, work email, role, two-factor setup | To run your seat | Life of the seat |
| Audit and egress log | Records who approved what, what each model call read, and what it cost. It never records the prompt itself. | With the deal it belongs to |
| Usage analytics | None. Neither this site nor the workspace uses analytics or tracking. | — |
How documents are protected
Each deal's content is encrypted with a key of its own. Deleting a deal destroys that key, so every copy becomes unreadable at once, including copies in backups. Uploaded files are opened in an isolated reader with no network access. See the security overview.
Models
When your firm asks the workspace to work on documents, the parts its settings allow are sent to a language model. Those models run on provider accounts your firm connects and is billed for. Documents are read by Berget AI in Sweden; open-web research goes to a provider in the United States and is sent search terms only, never a document. Every document has a sensitivity label, and nothing is sent to a model that is not cleared for that label. Restricted material does not go to a cloud model in raw form, and Sealed material goes to no model at all. A US provider (Anthropic) is used only if your firm's administrator switches it on.
Where data is hosted
In the European Union: [hosting provider], [country]. Backups are encrypted and stored in a second EU location. The current list of sub-processors is available on request and in our data processing agreement. We give 30 days' notice before changing it.
Personal data inside your documents
Bank statements, employment files and founder references contain personal data about people who are not our customers. Your firm is the controller for that data. Navent gives you the controls (labels, clearances, export and deletion) and a DPIA template to assess the processing.
What we hold as controller
| Data | Why | Kept for |
|---|---|---|
| Billing contact, invoices | To invoice, and because accounting law requires it | 7 years (Swedish Accounting Act) |
| Emails and form submissions | To reply to you | 12 months |
Your rights
You can ask for a copy of your data, correct it, or have it deleted, by writing to [email protected]. We answer within thirty days. For data in your firm's workspace, we pass your request to your firm and help it answer. You may also complain to the Swedish Authority for Privacy Protection (IMY).
Cookies
This site sets no cookies. The workspace sets one session cookie so that you stay signed in, and nothing else.
See also the terms of service and the security overview.