Legal
Effective date: June 23, 2026
onloc is the AI transformation partner for the middle market: it connects to the systems you already run and turns your company's operational knowledge into trusted automations — connecting your operational data, building the context and rules of your business through an ontology layer, and using agents and AI reasoning to support better decisions. This Privacy Policy explains how onloc collects, uses, shares, and protects personal information in connection with our website, business communications, and platform.
onloc is a B2B company. Our services are intended for business customers and authorized users, not individual consumers acting in a personal capacity. onloc is operated by Gravity Technology, Inc.
This Policy applies to personal information we process when you visit our website, submit a demo or contact form, communicate with us, receive marketing from us, or use the onloc platform as an authorized user of a customer account.
When we process customer operational data inside the onloc platform on behalf of a customer, we generally act as a processor or service provider under our customer agreement and data processing terms. The customer controls what data is submitted to the platform and is responsible for providing any required notices to its personnel, users, and other individuals whose information may be included in that data.
This Policy does not apply to third-party websites, services, or integrations that are not owned or controlled by onloc.
We may collect your name, business email address, company, job title, phone number, and other information you provide when you contact us, request a demo, subscribe to updates, attend an event, or communicate with our team.
We may collect information about how authorized users interact with the onloc platform, including login activity, feature usage, audit logs, session metadata, error reports, support interactions, and product performance information.
Customers may submit or connect operational business data to the onloc platform, including structured and unstructured enterprise workflow data, documents, records, metadata, system outputs, and other information selected by the customer. This data may include personal information depending on how the customer uses the platform.
We may collect device, browser, IP address, log, cookie, and similar technical information when you interact with our website or platform. This helps us operate, secure, debug, and improve our services.
We may process personal information about employees, contractors, advisors, and applicants for internal business, security, compliance, hiring, and administrative purposes.
We use personal information for the following purposes:
| Purpose | Examples | GDPR lawful basis |
|---|---|---|
| Provide and operate the platform | Account access, authentication, customer support, service delivery, troubleshooting | Contract performance; legitimate interests |
| Secure and monitor the platform | Logging, abuse detection, vulnerability management, incident response | Legitimate interests; legal obligation |
| Process customer operational data | Ingesting, organizing, reasoning over, and displaying customer-selected enterprise data | Customer instructions; contract performance |
| Communicate with you | Responding to inquiries, demos, procurement, legal, and support requests | Legitimate interests; contract performance |
| Improve our services | Product analytics, reliability improvements, debugging, usability improvements | Legitimate interests |
| Marketing and business development | Sending relevant updates, event invitations, or product information | Legitimate interests; consent where required |
| Compliance and legal obligations | Tax, accounting, regulatory, security, dispute, and contractual compliance | Legal obligation; legitimate interests |
| Corporate transactions | Diligence, financing, merger, acquisition, or similar business events | Legitimate interests |
Where we rely on legitimate interests, we consider the nature of the data, the context of collection, and the potential impact on individuals. Where we rely on consent, you may withdraw that consent at any time.
We do not sell customer operational data. We may share personal information with:
We require service providers that process personal information on our behalf to protect it under appropriate contractual, confidentiality, security, and data protection obligations.
Customer trust is core to onloc. onloc does not use customer operational data to train onloc foundation models, shared models, or third-party models without the customer's explicit written consent.
We may use customer operational data to provide the contracted service to that customer, including retrieval, reasoning, classification, summarization, workflow automation, and agentic analysis within the customer's environment or account. We may also use de-identified, aggregated, or metadata-level information to maintain security, measure reliability, debug issues, and improve platform performance, provided it does not identify a customer or disclose customer confidential information.
If onloc offers optional model training, fine-tuning, benchmarking, or product-improvement programs using customer operational data, those programs will be opt-in and governed by separate written terms.
We retain personal information for as long as necessary to provide our services, operate our business, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
Customer operational data is retained according to the applicable customer agreement, data processing terms, account settings, and deletion instructions. When a customer terminates service, we will delete or return customer data as required by the applicable agreement, subject to legal, security, backup, and audit requirements.
onloc is based in the United States and uses AWS-hosted infrastructure. Personal information may be processed in the United States and other countries where onloc, its service providers, or sub-processors operate.
Where required for transfers of personal information from the EEA, UK, or Switzerland, onloc will use appropriate transfer mechanisms, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful safeguards.
onloc uses administrative, technical, and organizational safeguards designed to protect personal information and customer data. These measures may include access controls, encryption, logging, monitoring, vulnerability management, vendor review, secure development practices, and incident response procedures.
onloc is pursuing SOC 2 Type II readiness through Vanta. No system is perfectly secure, but we work to maintain enterprise-grade security practices appropriate to the nature of the data we process. You can review our current security posture in our Trust Center.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information. You may also have the right to data portability, to withdraw consent, and to lodge a complaint with a data protection authority.
If your personal information is included in customer operational data processed by onloc on behalf of a customer, we may direct your request to that customer or assist the customer in responding, consistent with our contractual obligations.
California residents may have rights under the CCPA/CPRA to know what personal information we collect, use, disclose, sell, or share; to request deletion; to correct inaccurate information; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to not be discriminated against for exercising privacy rights. onloc does not sell customer operational data. If we use advertising or analytics cookies that constitute "sharing" under California law, we will provide applicable opt-out controls.
To exercise rights, contact us at team@onloc.ai. We may need to verify your identity before responding.
We may use cookies, pixels, analytics tools, and similar technologies on our website and platform to operate services, remember preferences, understand usage, measure marketing effectiveness, and improve performance.
You can control cookies through your browser settings and, where available, through our cookie banner or preference center. Disabling cookies may affect website or platform functionality.
onloc is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by updating the effective date, posting the revised Policy, or using other appropriate means.
If you have questions about this Privacy Policy or onloc's privacy practices, contact:
onloc (operated by Gravity Technology, Inc.)
Email: team@onloc.ai
Website: onloc.ai