Privacy Policy
Why Forward-Looking Firms Choose Latitude
This Policy explains how we collect, use, share, and protect personal data when you:
- visit latitude.ai and related pages;
- contact us, book a call, or download resources;
- work with us on data & AI engagements, pilots, or production systems.
It applies to visitors, prospects, clients, vendors, and job applicants.
If a separate agreement or Data Processing Addendum (DPA) applies to your project, it prevails in case of conflict.
Data We Collect
Data you provide
- Contact & identity: name, email, phone, company, role.
- Business context: project details, goals, requirements, messages.
- Legal: signatures, NDAs, contract details.
- Support: tickets, feedback, survey responses.
Data collected automatically (website/app)
- Technical: IP address, device, browser, OS, language.
- Usage: pages viewed, clicks, time on page, referrer/UTM.
- Cookies/SDKs: necessary, analytics, optional marketing (see §8).
Project & AI delivery data
- Client-provided data (documents, databases, logs, schemas, content).
- Operational metadata (pipeline/job IDs, error logs, performance metrics).
- Cookies/SDKs: necessary, analytics, optional marketing (see §8).
Please avoid sending special-category data unless explicitly required and contractually governed.
Purpose & Legal Bases (GDPR Art. 6)
| Purpose | Examples | Legal basis |
| Provide website & replies | contact forms, demos, scheduling | Legitimate interests or consent |
| Sales & customer success | proposals, onboarding, account comms | Contract or legitimate interests |
| Service delivery (Data & AI) | discovery, prototyping, deployment, support | Contract |
| Analytics & improvement | site/product performance, QA | Legitimate interests |
| Marketing (optional) | newsletters, case studies | Consent (opt-out anytime) |
| Legal & security | compliance, audits, fraud prevention | Legal obligation/legitimate interests |
How We Use AI, LLMs & Agents
- We build custom AI solutions & agents (LLMs, RAG, ML pipelines).
- Client data is used only to deliver the contracted service and not to train our models for unrelated purposes without written consent.
- We engage vetted sub-processors (e.g., cloud/model providers) under DPA; they act on our instructions only.
- Controls: RBAC, least-privilege access, encryption in transit/at rest, audit logs, environment isolation, data minimization, retention limits.
- Human-in-the-loop reviews may occur for quality/safety under confidentiality.
- We do not make legally significant automated decisions about you via the website; project-specific logic is governed in the SOW/DPA with safeguards.
Sharing & Disclosure
We share personal data with:
- Service providers/sub-processors: hosting (AWS/Azure/GCP), analytics, email/CRM, project tools, CI/CD.
- Professional advisers: legal, accounting, security auditors.
- Legal/compliance: when required by law/court order or to protect rights/security.
- Business transfers: in M&A or reorganization, under confidentiality.
We do not sell personal information.
International Transfers
When transferring data internationally (e.g., EEA → non-EEA), we use safeguards such as EU Standard Contractual Clauses (SCCs) and vendor due diligence.
Data Retention
- Website & inquiries: typically 12–24 months after last interaction.
- Contracts/billing: as required by law (usually 5–10 years).
- Project/AI logs: 90–365 days unless otherwise agreed in your SOW/DPA.
We delete or anonymize data when no longer needed.
Cookies & Similar Technologies
- Strictly necessary: security, load balancing, consent.
- Analytics (optional): usage patterns to improve the site (aggregated).
- Marketing (optional): only with consent.
Manage preferences via our cookie banner or your browser settings. See our Cookie Notice for details.
Your Rights
Depending on your location (e.g., EEA/UK under GDPR; certain US states under CCPA/CPRA), you may have rights to:
- Access, correct, delete data
- Object/restrict processing
- Data portability
- Withdraw consent (where applicable)
- Lodge a complaint with your supervisory authority
Request these at privacy@latitude.ai. We may need to verify your identity. We respond within legal timeframes.
Security
We apply administrative, technical, and organizational measures including encryption, RBAC, logging/monitoring, backups, vendor security reviews, and incident response. No system is 100% secure; report any issues to security@latitude.ai.
Children’s Privacy
Our services and site are not directed to children. We do not knowingly collect children’s data. If you believe a child provided data, contact privacy@latitude.ai for deletion.
Third-Party Links
Our site may link to third-party sites/services. We are not responsible for their privacy practices. Review their policies before submitting data.
Changes to This Policy
We may update this Policy periodically. The “Last updated” date shows the latest version. Material changes will be highlighted here and, where appropriate, notified to you.
Contact
Questions or requests about this Policy or your data:
Email: privacy@latitude.ai
Postal: Latitude AI B.V., Prins Hendrikkade 26, 1012 TM Amsterdam, Netherlands
DPO: dpo@latitude.ai