Privacy Policy
This Privacy Policy describes how Ockem, a Base22 company (“Ockem,” “we,” “us”), collects, uses, and protects information when you use ockem.com, proof.ockem.com, and the Ockem products and services (the “Services”). Questions or requests can be sent to [email protected] at any time.
1. Information we collect
Information you give us.
- Contact and waitlist forms — your name, email address, organization, and message when you contact us or join an early-access waitlist.
- Documents you submit — PDF files you upload or send us for checking, remediation, or certification, which may themselves contain personal data.
- Account and billing details — if you create an account or purchase paid services, the information needed to provide and bill them.
Information collected automatically.
- Technical logs — standard server logs such as IP address, browser type, requested pages, and timestamps, used for security and operations.
- Document metadata during assessments — when we assess a website’s published documents, we record metadata about each document (URL, page count, file size, tagging status, encryption flag, producing software, and HTTP caching headers). Most documents are processed in memory and discarded, leaving only that metadata. The exception is the triage sample — at most a dozen documents — which is stored under your organization’s own prefix and kept under the same 30-day auto-delete policy as free-trial files.
2. What we use it for
- providing the Services — checking, remediating, and certifying the documents you submit;
- responding to inquiries and managing waitlists;
- operating, securing, and improving the Services;
- billing and account administration;
- complying with legal obligations.
We do not sell personal data, and we do not use your documents to train machine-learning models or for any purpose other than providing the Services to you.
3. Cookies and analytics
Our public pages — ockem.com and the free-trial pages on proof.ockem.com — use Google Analytics to understand how visitors find and use them: which pages are viewed, where visits come from, and where the free-trial flow is abandoned. We configure it with IP anonymization and without Google advertising signals, and we use it for no advertising purpose. If you are visiting from a region whose law requires consent, no analytics run until you allow them in the banner; everyone can decline or change their choice at any time via the Analytics preferences link in the page footer. Analytics never run on the signed-in application surfaces, and Google never receives your documents.
Beyond that, we use no advertising trackers or social-media pixels, and the only other cookies set are strictly necessary ones — for example, a session cookie when you sign in to the application.
4. How long we keep it
- Free-trial files and assessment triage samples — automatically deleted within 30 days.
- Assessment metadata — retained for the duration of the engagement so re-crawls can skip unchanged files, then deleted on request.
- Form submissions — kept as long as needed to respond and maintain our business records; deleted on request.
- Paid-service documents and certificates — retained as agreed in your order or engagement; certificates and their verification records are retained so issued certificates remain verifiable.
- Server logs — retained for a limited period for security and troubleshooting.
5. Who we share it with
We share personal data only with service providers who process it on our behalf to run the Services. The current list is:
- Stripe — payments and checkout. Receives your name, email and billing address. Stripe never receives your documents.
- Microsoft 365 — our email. Receives your email address and the content of messages you send to @ockem.com addresses. Microsoft never receives your documents.
- Anthropic — AI inference for Ockem Read only. For Ockem Proof, document content does not leave Ockem infrastructure: all Proof model inference runs on hardware we own and operate, and the external provider is not in the Proof inference path. For Ockem Read, generation uses Anthropic’s API, which receives the prompt and, where the task requires it, a rendered image of the page.
- Sentry — error reporting, where enabled. Receives diagnostic context that can incidentally include identifiers.
- Google (Google Analytics) — visitor analytics on our public pages only, as described in section 3. Receives technical usage data such as pages viewed, referrer, and an anonymized IP address. Google never receives your documents, your account data, or anything from signed-in surfaces.
Your documents are not hosted by a third party. The Services run on infrastructure Ockem owns and operates in our own offices, and document storage happens there — there is no cloud hosting provider in this list because there is not one in the path. The single exception in which document content can leave our infrastructure is Ockem Read’s generation, described above; Ockem Proof documents do not leave it.
We will update this list before adding a new subprocessor. We may also disclose information if required by law, or as part of a corporate transaction involving Ockem or Base22, in which case this policy continues to apply to previously collected data. We do not sell your data, and we do not share it for anyone else’s advertising or model training.
6. Security
Traffic to the Services is encrypted in transit (TLS). Access to submitted documents and personal data is restricted to personnel who need it to provide the Services. No method of transmission or storage is 100% secure, but we work to protect your information with measures appropriate to the risk.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise any of these rights, email [email protected] — we will respond within the timeframe required by applicable law. If you are a customer’s end user and your data appears in a document a customer submitted to us, we will refer your request to that customer, who controls the document.
8. International transfers
We are based in the United States, and the Services are provided from there. If you use the Services from elsewhere, your information will be transferred to and processed in the United States.
9. Children
The Services are for business use and not directed to children under 16. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy from time to time. The “Last updated” date above reflects the current version, and material changes will be posted on this page.
11. Contact
Privacy questions and requests: [email protected], or through the contact form.