Privacy notice
How Adhera handles your information
This notice covers adheraworks.com and the Adhera product. It says what we collect, why, who sees it, and how long we keep it.
1. Who we are
Adhera Compliance, Inc. is a Florida corporation. We make compliance software for IT teams. In this notice, "we" and "Adhera" mean the company; "you" means a visitor to this site or a person who uses the product.
For the product, our customer (the organization that signed up) decides what goes into Adhera and who may see it. We process that information on the customer's instructions. If you use Adhera through your employer, your employer's own privacy policy also applies, and questions about their data should go to them first.
2. This website
What we collect
- Form submissions. If you apply to be a design partner, we collect your work email, your company, and the time you submitted. If you ask for demo access, we collect your work email. Each submission is emailed to us together with the IP address and country it came from, so we can tell real applications from automated ones.
- Server logs. Our hosting provider records the usual request details: IP address, country, browser type, pages requested, and timestamps. We use these only to keep the site running and to investigate abuse.
What we do not do
- We do not run analytics or advertising trackers on this site.
- We do not set cookies. If that changes, this notice will say so.
- The interactive examples on the home page run in your browser. Nothing you type into them is sent to us.
The site loads fonts from Google Fonts. Your browser sends your IP address to Google to fetch them, as it does for any web resource. Google's handling of that request is covered by Google's privacy policy.
3. The Adhera product
When an organization uses Adhera, we process the following on its behalf.
- Account information. Names, work email addresses, roles, and sign-in records for the people the customer invites, including any auditors it chooses to give access to.
- Content the customer puts in. Descriptions of controls and procedures, recorded walkthroughs, the files uploaded as evidence, knowledge-base documents, audit request lists, and the comments and notes people add. This content can include personal information about the customer's staff or systems, such as names on an access list. The customer decides what to upload and agrees to upload only what it is allowed to share with a service provider.
- Activity records. Adhera keeps an audit trail of who did what and when: uploads, reviews, status changes, exports, and access that was refused. This trail is part of the customer's compliance record and is visible to the customer's administrators and, where the customer allows, its auditors.
- Technical data. IP addresses, browser type, and error logs, used to keep the service secure and working.
Why we process it
- To provide the service: writing up controls, assigning and tracking tasks, checking evidence, producing reports and exports for auditors.
- To keep the service secure and to prevent abuse.
- To support the customer when they ask for help.
- To improve Adhera. During the pilot we learn from how teams use the product. We do this from usage patterns and from feedback people give us, not by reading customer evidence for our own purposes.
4. How we use AI
Adhera uses large language models to do some of its work: turning a described or recorded procedure into a written control, reading an evidence file to check it matches the task, drafting task instructions, and reading audit request lists into structured requests. For this, the relevant content is sent to Google's Gemini API and the result is returned to Adhera.
- We use the Gemini API under its paid service terms, which do not allow Google to use the content we send to train or improve its models.
- Only the content needed for the specific job is sent: the file being checked, the control it belongs to, and the knowledge-base documents in scope for that control's entities and frameworks.
- Model output is advisory. A person on the customer's side can override any verdict, and the audit trail records both the model's result and the person's decision.
- Some file types, such as video, are never sent to a model and are routed to a person instead.
5. Who we share information with
We do not sell personal information and we do not share it for advertising. We share it only as follows.
Service providers
These companies process information for us, under contracts that limit what they may do with it.
| Provider | What for | Where |
|---|---|---|
| Google Cloud | Hosting the product, its database, and uploaded files | United States |
| Google (Gemini API) | AI processing described in section 4 | United States |
| Cloudflare | Serving this website, DNS, and sending the emails generated by the site's forms | Global network; United States |
| Google Workspace | Our company email | United States |
People the customer chooses
Within the product, the customer controls who sees what: its own staff, and any auditors it invites. Auditors see only the scope the customer gives them.
When the law requires
We will disclose information if a court or regulator with proper authority requires it, and we will tell the customer first unless we are legally prevented from doing so.
If the company changes hands
If Adhera is acquired or merges with another company, information may transfer to the new owner, who will be bound by this notice until they publish a new one with notice to you.
6. How long we keep it
- Form submissions on this site: up to 12 months after we last hear from you, then deleted. If you become a customer, the information moves to your account record.
- Server logs for this site: up to 30 days.
- Product content and account information: for as long as the customer's account is active. When a pilot or subscription ends, the customer can export its data, and we delete it within 30 days of the end date, or sooner on request. Backups are overwritten within a further 30 days.
- Audit trail: kept with the rest of the customer's data and deleted with it, since it is the customer's record, not ours.
7. Security
Information is encrypted in transit and at rest. Access to production systems is limited to the people who need it to run the service, and that access is logged. Within the product, every record is scoped to the customer's organization, and every change is written to the audit trail. No system is perfectly secure. If we learn of a breach that affects your information, we will tell you without undue delay and explain what happened and what we are doing about it.
8. Your choices
You can ask us to tell you what personal information we hold about you, correct it, delete it, or send you a copy. If you sent us a form on this site, email us and we will handle it directly. If your information is in a customer's Adhera account, we will usually pass your request to that customer, because they decide what is kept, and help them act on it.
Depending on where you live, you may have rights under laws such as the GDPR in Europe or state privacy laws in the United States. We honor those rights for everyone, regardless of location, as far as we are able. To exercise them, write to hello@adheraworks.com. We will reply within 30 days. If you think we have not handled your information properly, you can also complain to the data protection authority where you live.
9. Other things to know
- Location. We are based in the United States and process information there. If you use the site or product from elsewhere, your information is transferred to the United States.
- Age. This site and the product are for working professionals. We do not knowingly collect information from anyone under 18.
- Links. This site links to other sites. Their privacy practices are their own.
- Changes. We will update this notice as the product and our practices change. The effective date at the top tells you when it last changed. For material changes we will tell customers by email before they take effect.
10. Contact
Adhera Compliance, Inc.
Florida, United States
hello@adheraworks.com