Get the APP now on Web, Apple App Store or Google Play Store

  • Home
  • Solutions
  • Governance
  • Newsletter
  • Blog
  • More
    • Home
    • Solutions
    • Governance
    • Newsletter
    • Blog
  • Home
  • Solutions
  • Governance
  • Newsletter
  • Blog

 

Last Updated: 11 July 2026

Welcome to Non-Exec.AI ("we," "our," or "us"). We are committed to protecting your privacy and ensuring that your personal information is handled in a safe and responsible manner. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website www.non-exec.ai and use our AI-driven corporate governance services and platform.

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the site.

1. Information We Collect

We may collect information about you in a variety of ways when you interact with Non-Exec.AI. The information we may collect includes:

a. Personal Data

Personally identifiable information that you voluntarily give to us when registering with the site or when choosing to participate in various activities related to the site. This may include:

  • Name and Job Title
  • Company Name
  • Email Address
  • Phone Number
  • Billing and Payment Information

Lawful Basis: We process this Personal Data to fulfill our contract with you (service delivery) and for our legitimate interests (security and fraud prevention).

b. AI Interaction Data

When you use our AI tools, we process the inputs, prompts, and documents you submit to generate insights for your account and your use of the Service. This processing is limited to providing user-facing features within Non-Exec.AI. We do not use content you submit to train, develop, or improve generalized or non-personalized artificial intelligence or machine learning models.

c. Usage and Derivative Data

Information is processed from our website hosting, cloud and AI provider automatically when you access the site, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the site.

d. Cookies and Tracking Technologies

We may use cookies, web beacons, tracking pixels, and other tracking technologies to help customize the Site and improve your experience.

e. Connected Calendar Data

If you choose to connect Google Calendar or Microsoft Outlook, we access calendar events read-only to display them in the Non-Exec.AI calendar view alongside your governance activities. For Google Calendar, this access uses the Google Calendar API under your authorization. We do not modify or delete events in your Google or Microsoft calendar.

2. How We Use Your Information

Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the site to:

  • Provide, operate, and maintain the Non-Exec.AI platform.
  • Process transactions and send related information, including confirmations and invoices.
  • Provide personalized AI-generated insights and governance support features that are visible and prominent in the Non-Exec.AI application for your account. We do not use your data to create, train, improve, or develop generalized or non-personalized artificial intelligence or machine learning models.
  • If you connect Google Calendar, use imported calendar events only to display your schedule in the app, sync events you choose to keep, and operate the calendar connection (including secure storage of OAuth tokens on our servers). Google Calendar data obtained via Google Workspace APIs is not used for AI training, generalized model improvement, advertising, or resale.
  • Understand and analyze how you use our platform to enhance user experience.
  • Communicate with you, either directly or through one of our partners, for customer service, to provide you with updates and other information relating to the website, and for marketing and promotional purposes (Note: user data is not sold or used for unrelated third-party marketing purposes).
  • Send you technical notices, updates, security alerts, and support and administrative messages.
  • Find and prevent fraud or security breaches.

3. Disclosure of Your Information

We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

  • By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others.
  • Third-Party Service Providers: We may share your information with third parties that perform services for us or on our behalf, including payment processing, data analysis, email delivery, hosting services, including our primary enterprise-grade cloud hosting infrastructure and scalable, real-time backend and database management platforms, and customer service. 
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • We utilize Google Cloud Platform (GCP) to host and store our data. Google Cloud acts as a 'Service Provider' under applicable US privacy laws and a 'Data Processor' under the GDPR. Google Cloud processes your data solely on our behalf and is contractually prohibited from selling, sharing, or using your personal data for their own commercial purposes. 
  • Our platform is hosted on Google Cloud, which means your personal data may be transferred to, and processed in, the United States or other jurisdictions where Google operates. For users within the European Economic Area (EEA) or the UK, we ensure your data is adequately protected by relying on Google Cloud’s Data Processing Addendum, which incorporates Standard Contractual Clauses (SCCs) and adherence to the EU-US Data Privacy Framework. 

4. Data Security, Retention and Deletion

We use administrative, technical, and physical security measures — including hosting our application infrastructure on an industry-leading, highly secure cloud platform and managing our data via a robust, encrypted cloud-based backend service — to help protect your personal information and sensitive corporate data. To ensure the highest level of performance, reliability, and security, our platform is hosted on globally recognized, secure cloud infrastructure. Furthermore, our application backend—including user authentication, real-time data syncing, and NoSQL database management—is powered by a highly secure, scalable cloud-based backend service provider. These environments utilize robust encryption and industry-standard security protocols to protect your data both at rest and in transit. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.

All data stored within our Google Cloud environment is encrypted both in transit and at rest. We rely on Google Cloud’s enterprise-grade security infrastructure, which complies with strict industry standards and certifications (such as ISO 27001 and SOC 2), to protect your personal and corporate data against unauthorized access, loss, or alteration.

We retain your personal and AI interaction data within our Google Cloud databases only for as long as necessary to fulfill the purposes outlined in this policy or to comply with legal obligations. Upon requesting deletion or account termination, your data will be securely purged from our active Google Cloud storage systems in accordance with Google's secure data deletion protocols. 

If you disconnect Google Calendar or Microsoft Outlook in Settings, we stop further API access and remove imported external calendar events from our systems in accordance with our deletion practices. OAuth tokens are stored server-side and are not exposed to other users.

5. Children’s Privacy

We do not knowingly solicit information from or market to children under the age of 18. If we learn that we have collected personal information from a child under age 18 without verification of parental consent, we will delete that information as quickly as possible.

6. Your Privacy Rights

Depending on your location (such as if you reside in the European Economic Area, UK, or California), you may have certain rights regarding your personal information, including the right to:

  • Request access to the personal data we hold about you.
  • Request that we correct any inaccurate or incomplete personal data.
  • Request that we delete your personal data.
  • Object to or restrict the processing of your personal data.
  • Request the transfer of your personal data to another party.

To exercise any of these rights, please contact us using the information provided below.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.

8. User Data Isolation and Access Controls 

To protect your personal information and ensure strict data isolation between users, our platform utilizes robust access controls within our Google Cloud and Firebase architecture. We employ multi-tenant security strategies to guarantee that you can only access your own data and files. This is enforced through the following mechanisms:

  • Secure Authentication: Upon logging in, our system generates a secure, cryptographic token that continuously verifies your identity during all interactions with our platform.
  • Database Isolation: For application data stored in our databases, server-side security rules evaluate every single read and write request. These rules strictly match your unique user ID against the data's ownership records, immediately blocking unauthorized access.
  • File Storage Protection: Any documents or media you upload are protected by targeted storage rules, restricting access solely to directories linked to your verified identity.

Because these protocols are enforced directly on our secure servers, they cannot be bypassed, ensuring your data remains completely invisible and inaccessible to other users.

9. AI Processing, Capabilities, and Transparency

We are committed to honest and transparent communication regarding our use of artificial intelligence (AI) and machine learning technologies. To ensure compliance with consumer protection standards and to prevent deceptive claims regarding AI capabilities, we expressly disclose the following regarding our AI-driven corporate governance tools (refer to Non-Exec.AI - Privacy Nutrition Label below):

  • Scope of AI Utility: Our AI tools are utilized solely to assist, analyze, and generate insights based on the documents, prompts, and inputs you submit. We do not represent or warrant that our systems possess artificial general intelligence, nor do they operate completely autonomously.
  • Decision-Making and Human Oversight: Our platform is a decision-support tool, not a substitute for human governance. The AI does not make autonomous, legally binding corporate, financial, or legal decisions on behalf of your organization. All AI-generated outputs must be independently reviewed and verified by qualified professionals (e.g., your Board of Directors or legal counsel).
  • Accuracy and Limitations: While we strive to provide highly effective AI services, machine learning models are inherently probabilistic and subject to limitations, including potential inaccuracies, biases, or "hallucinations." We make no exaggerated claims regarding the absolute accuracy or predictive certainty of the AI-generated insights.
  • Automated Decision-Making: We do not make solely automated decisions producing legal or similarly significant effects on individuals without meaningful human involvement.

10. Google API Services - Limited Use Disclosure

Non-Exec.AI Limited uses Google API Services, including the Google Calendar API, when you optionally connect a Google account to import calendar events into Non-Exec.AI. Access is read-only; we do not write to or change your Google Calendar}

Limited Use compliance: The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically:

  • We use Google Workspace API data only to provide or improve user-facing

features that are visible in the Non-Exec.AI application - for example, displaying imported calendar events alongside board and governance activities.}

  • We do not use Google Workspace API data to create, train, improve, or develop generalized or non-personalized artificial intelligence or machine learning models.}
  • We do not use Google Workspace API data for advertising, determining creditworthiness or lending, or selling data to data brokers or other third parties.}
  • Human access to Google user data is limited to what is necessary for security, support you request, or compliance with applicable law.
  • If we change how we use Google user data, we will update this Privacy Policy
  • and obtain any required user consent before using the data in a new way or for
  • a different purpose than originally disclosed
  • AI and Google Calendar data : Where Non-Exec.AI uses AI to generate insights from content you submit directly in the app (for example, governance prompts or documents), that processing is separate from Google Calendar import. Google Calendar data obtained via Google Workspace APIs is not fed into AI models for training or for generalized model improvement.

11. Compliance Notes on GDPR and ISO / SOC 

Non-Exec.AI Limited protects personal and corporate data on web, iOS, and Android.

Where the GDPR and UK GDPR apply, we process data lawfully, honour access, correction, deletion, and related rights, and use safeguards for international transfers - including Google Cloud's Data Processing Addendum, Standard Contractual Clauses, and the EU-US Data Privacy Framework. California residents and others may have additional privacy rights described in Section 6 of this policy; we do not sell personal information.

Data is hosted on Google Cloud Platform and Firebase, which meet standards including ISO 27001 and SOC 2; we encrypt data in transit and at rest and enforce per-user access controls. Google's certifications cover infrastructure; Non-Exec.AI Limited does not claim independent SOC 2 or ISO 27001 certification unless agreed in writing.

  • GDPR & UK-GDPR. Non-Exec.AI handles personal data in accordance with the GDPR   and UK GDPR. You have the rights in Section 6 of this Privacy Policy. Where   we transfer data outside the EEA or UK, we use Google Cloud's DPA, Standard   Contractual Clauses, and the EU-US Data Privacy Framework. Contact info@non-exec.ai or director@non-exec.ai to exercise your rights.
  • Security standards (SOC 2 / ISO 27001). Non-Exec.AI hosts data on Google Cloud   Platform, which maintains certifications including ISO 27001 and SOC 2. We encrypt   data in transit and at rest and enforce per-user access controls. Google Cloud's certifications apply to the underlying infrastructure; Non-Exec.AI Limited does   not claim an independent SOC 2 or ISO 27001 certification unless separately agreed.

 

11. Security standards (ISO 27001, SOC 2, and related terms)

Security standards (ISO 27001 / SOC 2). ISO 27001 is an international information-security management standard; SOC 2 is an independent auditor’s report on a service provider’s security and related controls. Non-Exec.AI hosts data on Google Cloud Platform and Firebase, which maintain certifications and reports including ISO 27001 and SOC 2 for applicable infrastructure. We encrypt data in transit and at rest and enforce per-user access controls. Those Google certifications cover the underlying infrastructure; Non-Exec.AI Limited does not claim an independent ISO 27001 or SOC 2 certification unless agreed in writing.

12. Contact Us

If you have questions or comments about this Privacy Policy, including questions about Google Calendar connection, OAuth, this Limited Use disclosure, or this Privacy Policy, please contact us at:

  • Email: info@non-exec.ai, director@non-exec.ai 

Non-Exec.AI - Privacy Nutrition Label (for Privacy Policy)

============================================================

Applies to: www.non-exec.ai, app.non-exec.ai, and Non-Exec.AI on Google Play and Apple App Store

Full policy: https://www.non-exec.ai/privacy-policy

This summary gives an at-a-glance view of what data we collect, how we use it,

and what we do NOT collect. It supplements our Privacy Policy and reflects the

same practices described there.

AT A GLANCE

-----------

 Ads         We do not show ads or sell your data to advertisers.

 Tracking    We do not track you across other companies' apps or websites.

 Encryption  Data is encrypted in transit and at rest on Google Cloud.

 Deletion    Delete your account in-app (My Profile -> Account) or contact us.

 Children    Our service is not directed at anyone under 18.

DATA LINKED TO YOU

------------------

We collect the following when you use Non-Exec.AI. It is linked to your account

and used to provide and secure the service - NOT for third-party advertising.

CONTACT INFORMATION

 Name              When you register or sign in          Account setup, profile

 Email address     Required for an account               Sign-in, communications, billing

 Phone number      Optional (profile)                    Profile preferences

 Other profile     Optional - job title, timezone,       Personalise your experience

                   location (city/region text),

                   notification settings

USER CONTENT YOU PROVIDE

 Photos & videos   Uploads, profile photos, video links  Analysis and transcription

 Documents & files PDFs, spreadsheets, Word files, etc.  AI-assisted risk analysis

 Audio             Audio uploads                         Transcription and analysis

 Company & board   Financial data, reports, notes        Governance and risk features

                   you enter

 AI interactions   Prompts, chat, documents to AI tools  Generate insights (Policy 1b)

 Calendar events   Only if you connect Google, Outlook,  Portfolio calendar (read-only)

                   or Apple Calendar

IDENTIFIERS & ACCOUNT DATA

 User ID           When you sign in                      Secure access across devices

 Device / app IDs  Automatically (security checks)       Fraud prevention - NOT for ads

PURCHASES

 Purchase history  When you subscribe                    Manage subscription

 Payment cards: Processed by Stripe, PayPal, Apple Pay, or Google Pay.

 Non-Exec.AI does NOT store full card numbers.

DIAGNOSTICS & SECURITY

 Diagnostic data   Automatically                         Platform protection (App Check,

                                                         authenticated server logs)

USAGE & TECHNICAL DATA (WEB)

 Usage data        When you access web or app            Operate and secure the service

                   (IP, browser/device type, OS,         (Privacy Policy Section 1c)

                   access times)

 Cookies           When you use our website              Sessions and site operation

                                                         (Privacy Policy Section 1d)

DATA USED TO TRACK YOU

----------------------

 NONE.

We do not link your data with third-party data for advertising or share it with

data brokers for cross-app tracking.

DATA WE DO NOT COLLECT

----------------------

 - Precise or approximate GPS location

 - Contacts or address book

 - SMS or in-app messages from other apps

 - Health or fitness data

 - Web browsing history outside our service

 - Advertising identifiers for targeted ads (we do not run ads)

WHO WE SHARE DATA WITH

----------------------

We share data only with service providers under contract. We do NOT sell personal data.

 Google Cloud / Firebase / Vertex AI (Gemini)   Hosting, auth, storage, AI

 Stripe, PayPal                                 Subscription payments

 Google Calendar, Microsoft Outlook, Apple      Read-only calendar - only if you connect

 Apple, Google, Microsoft, LinkedIn             Sign-in - where available on your platform

Google Cloud acts as our service provider / data processor. See Section 3 of our

Privacy Policy for GDPR and international transfer safeguards.

YOUR CHOICES & RIGHTS

---------------------

 Optional data     Phone, profile fields, calendar, uploads - unless a feature needs them

 Calendar          Connect or disconnect anytime in Settings

 Account deletion  In-app or contact us (Policy Section 4)

 Privacy rights    Access, correct, delete, restrict, port - Policy Section 6

Contact:

 info@non-exec.ai

 director@non-exec.ai

 support@non-exec.ai

PLATFORM NOTES

--------------

Practices are consistent across web, Android, and iOS. Sign-in and calendar

options differ by platform (e.g. Sign in with Apple on iOS, Google on Android).

Google Play and Apple App Store may show platform-specific summaries that align

with this label.

Copyright © 2026 Non-Exec.AI - All Rights Reserved.

  • Newsletter
  • Blog
  • Resource Centre
  • Terms of Service
  • Privacy Policy
  • Support

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept