appresta.iq

Legal

Privacy Policy

Last updated: September 2, 2026

Who we are

appresta.iq (“we”, “us”), operated by appresta.iq LLC, provides contract-readiness assessments, reports, and discovery tools for legal and operations teams. This policy describes what information we collect through the appresta.iq website and application, how we use it, and the choices you have.

Information we collect

  • Account information — your name, email address, company name, and phone number, provided when you start an assessment, make a purchase, or are added as a seat on an enterprise license.
  • Assessment and discovery data — the answers you give in assessments and the information your organization enters into discovery tools (for example, org structure, contract systems, and workflows).
  • Payment information — payments are processed by Stripe. We receive transaction records (what was purchased and by whom) but never see or store your card number.
  • Technical and error data — standard server logs and application error reports, used to keep the service running and to diagnose problems.

How we use it

  • To provide the service: scoring assessments, generating reports, and operating your account.
  • To send transactional email — sign-in links, report links, seat invitations, and reminders about assessments you started. We do not send third-party marketing.
  • To produce anonymized, aggregated peer benchmarks across customers. No organization is identifiable in benchmark output, benchmarks only appear once the pool is large enough to be meaningful, and your organization can opt out (see below).
  • To improve the product and fix problems.

We do not sell your personal information.

Benchmarking and your choices

Peer benchmarks are reciprocal: organizations that contribute anonymized data can view benchmarks, and organizations that opt out are excluded from the pool and do not see benchmarks. An account admin can opt out (or back in) at any time from the Profile page in the app.

Service providers

We use a small number of providers to run the service, each processing data only on our instructions. The complete list, with what each one does and what it can see, is on our subprocessors page.

AI processing of your assessment

The written narrative and tailored plan in your assessment report are generated using Anthropic's Claude models. What we send is the assessment itself: the question text, the answers chosen and how they scored, and the persona lens selected for the report.

We do not send your name, your email address, or your company name. We do not send any Discovery data — your org structure, systems inventory, stakeholder list and workflow traces never leave our own infrastructure. We do not use your data to train AI models.

Discovery data

Discovery captures your organization's structure, the systems where contracts live, and the people who own them — including colleagues your team enters as stakeholders, who may not be users of our service. We treat all of it as your organization's data, held on its behalf.

Each organization's records are isolated inside the database itself rather than filtered by the application, so one customer's data cannot be returned to another. Every change is recorded in an audit log — who changed what, and when — which the application can add to but cannot alter or erase.

Cookies

We use cookies to keep you signed in. We do not use advertising or cross-site tracking cookies.

Retention and deletion

We keep your information while your account or your organization's license is active. When a license ends, we delete the organization's data within 30 days, keeping only what we must for legal and accounting purposes.

For Discovery data, an account admin can do both without asking us. From the profile page you can export everything your organization has captured — a ZIP containing one CSV per table plus a manifest — or delete all of it. Deletion is immediate and permanent: it removes every unit, system, contract population, stakeholder, workflow trace and remediation, along with the audit trail that recorded them, so no copy of the deleted rows is kept. We email a receipt listing what was removed. Your account, seats, and assessment history are not affected.

For anything else — your profile, your assessments, or your reports — email privacy@apprestaiq.com and we will action it.

Security

Data is encrypted in transit and at rest. Discovery data is isolated per organization by the database itself, using row-level security, rather than by application filtering — and the account we connect with cannot override it. Sharing links for delegated forms are stored only as a one-way hash, so a copy of our database could not be used to open one. Access to production systems is limited to what is needed to operate the service.

We do not hold SOC 2 or ISO 27001 certification. Our infrastructure providers do, and we are happy to answer a security questionnaire directly — email security@apprestaiq.com. We commit to notifying affected customers within 72 hours of confirming a breach of their data. No method of storage or transmission is completely secure, but we work to protect your information appropriately.

Changes and contact

If we make material changes to this policy, we will update this page and the date above. Questions? Reach us via the contact page or at hello@apprestaiq.com.