Privacy policy
What we collect when we act as a controller, why, and the rights you have over it.
Autograff, Inc. · Version 1.0 · Last updated July 13, 2026
This Privacy Policy explains how Autograff, Inc. (“Autograff,” “we,” “us,” “our”) collects, uses, and shares personal information when we act as a controller of that information — for example, in relation to our website, our business customers and prospects, and the individuals who use our products on their behalf.
Important — who controls your data. When a repair shop, fleet operator, or other business customer uses Autograff to process information about their own customers (for example vehicle owners), that business is the controller of that information and Autograff acts as a processor on their behalf. This Policy does not govern that processing — it is governed by our Data Processing Addendum and by the privacy notice of the business you dealt with. If you are a vehicle owner or other end customer asking how your data is used, please contact the repair shop or fleet operator you dealt with.
1. Who This Policy Covers
This Policy applies to personal information we handle as a controller, including information about:
- Visitors and prospects: people who visit our website, contact us, or express interest in our products.
- Business customers and their users: our customers’ personnel and authorised users who set up or use the Platform, and the account, billing, and support information associated with them.
Where we process information on behalf of a business customer (such as end-customer or vehicle-owner data submitted into the Platform), we do so as a processor under our Data Processing Addendum, not under this Policy.
2. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Contact and identity | Name, business email, phone, company, role. | You; your employer; our customers. |
| Account and authentication | Login credentials, account settings, roles and permissions. | You; the Platform. |
| Billing | Billing contact, transaction history, and payment status (payment-card details are handled by our payment processor). | You; our payment processor. |
| Usage and device | Log data, IP address, device and browser type, pages and features used, and similar analytics data. | Automatically, via the Platform and our website. |
| Communications | Messages, support requests, and feedback you send us. | You. |
| Marketing | Preferences and engagement with our communications and events. | You; analytics providers. |
We do not seek to collect special categories of personal data through our website or in our controller capacity. Please do not send us sensitive information except where specifically requested.
3. How We Use Information
We use personal information to:
- provide, operate, secure, and support our website and the Platform, and administer accounts;
- process billing and manage our business relationship with customers;
- communicate with you, including service messages and, where permitted, marketing;
- understand and improve our products, including capacity planning, product analytics, and feature development, using aggregated and de-identified data wherever practical;
- detect, prevent, and investigate security incidents, fraud, and misuse;
- comply with law and enforce our agreements; and
- with your consent where required, for other purposes we describe to you.
Where the EU or UK GDPR applies, we rely on the following legal bases: performance of a contract; our legitimate interests (such as operating, securing, and improving our business and products) balanced against your rights; your consent (which you may withdraw); and compliance with legal obligations.
4. AI Features and Product Improvement
Our products include AI features. Where we improve our AI and other models, we use aggregated and de-identified information, consistent with our agreements and applicable law, in a way that does not identify you, any individual driver, vehicle, end customer, or repair shop. We do not use the content a business customer processes through the Platform to train models in a way that would identify that customer’s data, except as permitted under our Data Processing Addendum.
5. Cookies and Analytics
Our website uses cookies and similar technologies for functionality, analytics, and (where applicable) marketing. You can control cookies through your browser settings and, where required, through the consent options we present. For more detail, see our Cookie Notice at autograff.ai/cookies or the cookie settings on our website.
6. How We Share Information
We share personal information with:
- Service providers and subprocessors: vendors who process data on our behalf to provide the Platform and run our business (for example cloud-infrastructure, AI and model, telephony and messaging, payment, analytics, and support providers), under appropriate contractual obligations.
- Business customers: where you are an authorised user, with the customer that operates your account.
- Professional advisors and authorities: where reasonably necessary, or to comply with law, legal process, or a lawful government request, or to protect rights, safety, and the integrity of our services.
- Corporate transactions: in connection with a merger, financing, acquisition, or sale of assets, subject to appropriate protections.
We do not sell personal information for money. To the extent “sale” or “share” has a broad meaning under US state privacy laws (for example certain advertising cookies), we honour opt-out rights as described in Section 9.
7. International Transfers
We operate globally and may transfer personal information to, and process it in, the United States and other countries that may have different data-protection laws than your own. Where we transfer personal information subject to the EU or UK GDPR to a country without an adequacy decision, we use an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses and the UK Addendum. You may contact us for more information about these safeguards.
8. Retention and Security
We keep personal information for as long as needed for the purposes described in this Policy, to provide our products, to comply with legal obligations, to resolve disputes, and to enforce our agreements, after which we delete or de-identify it. We maintain commercially reasonable administrative, technical, and organisational safeguards designed to protect personal information; however, no method of transmission or storage is completely secure.
9. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information; to object to or restrict certain processing; to withdraw consent; and to opt out of certain uses. We will respond consistent with applicable law and may need to verify your identity.
If your personal information was provided to us by, or is processed by us on behalf of, a business customer (for example as an end customer of a repair shop or fleet), please direct your request to that business; we will assist them as a processor under our Data Processing Addendum.
To exercise rights regarding information we control, contact us at contact@autograff.ai. You also have the right to complain to a supervisory authority, and — in the EEA or UK — to lodge a complaint with your local data-protection authority.
10. Children
Our products are for business use and are not directed to children, and we do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Policy from time to time. We will post the updated version and revise the “Last updated” date, and where required by law we will provide additional notice.
12. How to Contact Us
Autograff, Inc., 131 Continental Dr, Suite 305, Newark, New Castle County, Delaware 19713, USA. Privacy contact: contact@autograff.ai.
Autograff has not appointed an EU or UK representative or a data protection officer. If we are required to appoint one, or choose to, we will update this section with their contact details.
End of Privacy Policy
Questions about your data: contact@autograff.ai