Legal

Privacy Policy

Effective date: June 23, 2026

Introduction / Who We Are

onloc is the AI transformation partner for the middle market: it connects to the systems you already run and turns your company's operational knowledge into trusted automations — connecting your operational data, building the context and rules of your business through an ontology layer, and using agents and AI reasoning to support better decisions. This Privacy Policy explains how onloc collects, uses, shares, and protects personal information in connection with our website, business communications, and platform.

onloc is a B2B company. Our services are intended for business customers and authorized users, not individual consumers acting in a personal capacity. onloc is operated by Gravity Technology, Inc.

Scope

This Policy applies to personal information we process when you visit our website, submit a demo or contact form, communicate with us, receive marketing from us, or use the onloc platform as an authorized user of a customer account.

When we process customer operational data inside the onloc platform on behalf of a customer, we generally act as a processor or service provider under our customer agreement and data processing terms. The customer controls what data is submitted to the platform and is responsible for providing any required notices to its personnel, users, and other individuals whose information may be included in that data.

This Policy does not apply to third-party websites, services, or integrations that are not owned or controlled by onloc.

Information We Collect

Contact and Identity Data

We may collect your name, business email address, company, job title, phone number, and other information you provide when you contact us, request a demo, subscribe to updates, attend an event, or communicate with our team.

Usage and Analytics Data

We may collect information about how authorized users interact with the onloc platform, including login activity, feature usage, audit logs, session metadata, error reports, support interactions, and product performance information.

Platform and Operational Data

Customers may submit or connect operational business data to the onloc platform, including structured and unstructured enterprise workflow data, documents, records, metadata, system outputs, and other information selected by the customer. This data may include personal information depending on how the customer uses the platform.

Technical Data

We may collect device, browser, IP address, log, cookie, and similar technical information when you interact with our website or platform. This helps us operate, secure, debug, and improve our services.

Internal Team Data

We may process personal information about employees, contractors, advisors, and applicants for internal business, security, compliance, hiring, and administrative purposes.

How We Use Your Information

We use personal information for the following purposes:

PurposeExamplesGDPR lawful basis
Provide and operate the platformAccount access, authentication, customer support, service delivery, troubleshootingContract performance; legitimate interests
Secure and monitor the platformLogging, abuse detection, vulnerability management, incident responseLegitimate interests; legal obligation
Process customer operational dataIngesting, organizing, reasoning over, and displaying customer-selected enterprise dataCustomer instructions; contract performance
Communicate with youResponding to inquiries, demos, procurement, legal, and support requestsLegitimate interests; contract performance
Improve our servicesProduct analytics, reliability improvements, debugging, usability improvementsLegitimate interests
Marketing and business developmentSending relevant updates, event invitations, or product informationLegitimate interests; consent where required
Compliance and legal obligationsTax, accounting, regulatory, security, dispute, and contractual complianceLegal obligation; legitimate interests
Corporate transactionsDiligence, financing, merger, acquisition, or similar business eventsLegitimate interests

Where we rely on legitimate interests, we consider the nature of the data, the context of collection, and the potential impact on individuals. Where we rely on consent, you may withdraw that consent at any time.

How We Share Your Information

We do not sell customer operational data. We may share personal information with:

We require service providers that process personal information on our behalf to protect it under appropriate contractual, confidentiality, security, and data protection obligations.

AI and Machine Learning

Customer trust is core to onloc. onloc does not use customer operational data to train onloc foundation models, shared models, or third-party models without the customer's explicit written consent.

We may use customer operational data to provide the contracted service to that customer, including retrieval, reasoning, classification, summarization, workflow automation, and agentic analysis within the customer's environment or account. We may also use de-identified, aggregated, or metadata-level information to maintain security, measure reliability, debug issues, and improve platform performance, provided it does not identify a customer or disclose customer confidential information.

If onloc offers optional model training, fine-tuning, benchmarking, or product-improvement programs using customer operational data, those programs will be opt-in and governed by separate written terms.

Data Retention

We retain personal information for as long as necessary to provide our services, operate our business, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Customer operational data is retained according to the applicable customer agreement, data processing terms, account settings, and deletion instructions. When a customer terminates service, we will delete or return customer data as required by the applicable agreement, subject to legal, security, backup, and audit requirements.

International Data Transfers

onloc is based in the United States and uses AWS-hosted infrastructure. Personal information may be processed in the United States and other countries where onloc, its service providers, or sub-processors operate.

Where required for transfers of personal information from the EEA, UK, or Switzerland, onloc will use appropriate transfer mechanisms, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful safeguards.

Security

onloc uses administrative, technical, and organizational safeguards designed to protect personal information and customer data. These measures may include access controls, encryption, logging, monitoring, vulnerability management, vendor review, secure development practices, and incident response procedures.

onloc is pursuing SOC 2 Type II readiness through Vanta. No system is perfectly secure, but we work to maintain enterprise-grade security practices appropriate to the nature of the data we process. You can review our current security posture in our Trust Center.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information. You may also have the right to data portability, to withdraw consent, and to lodge a complaint with a data protection authority.

If your personal information is included in customer operational data processed by onloc on behalf of a customer, we may direct your request to that customer or assist the customer in responding, consistent with our contractual obligations.

California residents may have rights under the CCPA/CPRA to know what personal information we collect, use, disclose, sell, or share; to request deletion; to correct inaccurate information; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to not be discriminated against for exercising privacy rights. onloc does not sell customer operational data. If we use advertising or analytics cookies that constitute "sharing" under California law, we will provide applicable opt-out controls.

To exercise rights, contact us at team@onloc.ai. We may need to verify your identity before responding.

Cookies and Tracking Technologies

We may use cookies, pixels, analytics tools, and similar technologies on our website and platform to operate services, remember preferences, understand usage, measure marketing effectiveness, and improve performance.

You can control cookies through your browser settings and, where available, through our cookie banner or preference center. Disabling cookies may affect website or platform functionality.

Children's Data

onloc is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by updating the effective date, posting the revised Policy, or using other appropriate means.

Contact Us

If you have questions about this Privacy Policy or onloc's privacy practices, contact:

onloc (operated by Gravity Technology, Inc.)
Email: team@onloc.ai
Website: onloc.ai