Privacy Policy
Effective Date: April 1, 2026
Gradeum Technologies, LLC ("Gradeum," "we," "us," or "our") provides a software platform purpose-built for engineering firms and government agencies. Our products include Praxis (for firms) and Civitas(for agencies). This Privacy Policy describes how we collect, use, store, and protect information when you use our websites, applications, and services (collectively, the "Services").
By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Services.
1. Information We Collect
Account Information. When you create an account or your organization provisions access, we collect your name, email address, organization name, and role.
Usage Data. We collect anonymized, aggregated data about how the Services are used, including feature usage, session duration, and error reports. This data does not identify individual users.
Support Communications. If you contact us for support, we retain the correspondence and any information you voluntarily provide.
Payment Information. Payment processing is handled by third-party processors. We do not store credit card numbers or bank account details on our servers.
2. How We Use Your Data
We use the information we collect to:
- Provide, maintain, and improve the Services.
- Authenticate users and manage organizational access controls.
- Respond to support requests and communicate important updates.
- Generate anonymized, aggregate analytics to guide product development.
- Comply with legal obligations.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
3. On-Premise Architecture & Data Sovereignty
Data sovereignty is a core design principle of Gradeum. The Gradeum Nexusruns on-premise on your organization's own hardware. Documents are indexed locally on your servers. Full documents never leave your network.
When a user submits a query that requires AI-assisted answer synthesis, only narrowly scoped excerpts relevant to that specific query are transmitted to the AI provider. These excerpts represent the minimum context necessary to generate a response — complete documents, project files, and broader datasets remain on your infrastructure at all times.
This architecture means your organization retains full custody of its data. Gradeum does not have standing access to the documents stored on your servers.
4. AI Provider Data Handling
Gradeum uses multiple AI providers for answer synthesis. These providers process the query-scoped excerpts described in Section 3. Under our agreements with these providers:
- Neither provider retains customer data after processing.
- Neither provider uses customer data to train or improve their models.
- Data is transmitted over encrypted connections (TLS 1.2+).
No full documents are ever sent to any AI provider. Only minimal, query-scoped excerpts are transmitted, and they are not stored or retained by the provider.
5. Data Storage & Security
Customer Documents.As described above, customer documents are stored exclusively on the customer's own on-premise hardware. Gradeum does not host, copy, or have persistent access to these files.
Account & Usage Data. Account information and aggregated usage data are stored in secure, encrypted cloud infrastructure. We implement industry-standard security measures including encryption at rest and in transit, access controls, and regular security audits.
While no method of transmission or storage is completely secure, we take commercially reasonable steps to protect your information from unauthorized access, alteration, or destruction.
6. Cookies & Tracking Technologies
Our websites use cookies and similar technologies for essential functions such as authentication, session management, and security. We may also use analytics cookies to understand how visitors interact with our website.
You can control cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Services.
7. Third-Party Services
We may use third-party service providers for payment processing, analytics, and infrastructure hosting. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
Our Services may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies.
8. Data Retention
We retain account information for as long as your account is active or as needed to provide you the Services. If you or your organization terminates an account, we will delete or anonymize personal data within 90 days, except where retention is required by law.
On-premise data managed by the Gradeum Nexus is under your organization's sole control. Gradeum does not determine the retention period for documents stored on your hardware.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate data.
- Request deletion of your personal data.
- Object to or restrict certain processing activities.
- Receive your data in a portable format.
To exercise any of these rights, please contact us at info@gradeum.io. We will respond to verified requests within 30 days.
10. Children's Privacy
The Services are designed for professional use by engineering firms and government agencies. We do not knowingly collect personal information from individuals under the age of 16. If you believe we have inadvertently collected such information, please contact us so we can promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the revised policy on our website and updating the effective date above. Your continued use of the Services after such changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Gradeum Technologies, LLC
Email: info@gradeum.io