Privacy Policy

Last updated: June 2026

This Privacy Policy explains how RegRails.ai collects, uses, stores, protects and shares personal data and customer data when you use our website, platform, applications, integrations and related services.

For the purposes of this Privacy Policy, "RegRails.ai", "we", "us" or "our" refers to RegRails AI Pte. Ltd. "Customer", "you" or "your" refers to the organisation or individual using our services.

RegRails.ai is an AI powered regulatory compliance execution platform. Our services help regulated firms upload regulatory documents and policies, extract obligations, identify policy gaps, track remediation, generate reports and maintain compliance evidence.

This Privacy Policy should be read together with our Terms of Use and any applicable subscription agreement, data processing agreement or service order.

1. Information We Collect

We may collect the following categories of information.

Account and Contact Information

This may include:

  • Name
  • Business email address
  • Job title
  • Company name
  • Phone number
  • Billing contact details
  • Login credentials or authentication identifiers
  • Communication preferences

Customer Content

When you use RegRails.ai, you may upload, import, generate or store content on the platform. This may include:

  • Regulatory documents
  • Notices, circulars and guidelines
  • Internal policies and procedures
  • Compliance reports
  • Board reports
  • Audit evidence
  • Remediation notes
  • Gap analysis outputs
  • Maturity assessments
  • Related files, comments or metadata

Customer Content may contain personal data depending on what you or your organisation uploads to the platform.

Usage and Technical Information

We may collect technical and usage data, such as:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • Pages visited
  • Features used
  • Login activity
  • Timestamps
  • Error logs
  • System events
  • Audit logs
  • Approximate location derived from IP address

Payment and Billing Information

Where applicable, payment information may be processed by our payment service provider. We do not store full payment card details on our own systems unless expressly stated.

Support and Communications

If you contact us, we may collect information contained in your messages, support tickets, emails, calls or meeting notes.

2. Google User Data

If you choose to connect your Google account or use Google integrations with RegRails.ai, we may access certain Google user data only after you grant permission through Google's consent process.

The specific Google user data we access depends on the permissions you approve. This may include:

  • Your Google account name
  • Your Google email address
  • Your Google profile information, such as profile image, where made available
  • Google account identifiers used for authentication
  • Google Drive file names, file metadata and folder information, where you choose to connect Google Drive
  • The content of Google Drive files that you select, import or authorise RegRails.ai to process
  • Information required to maintain, manage or revoke the Google integration

We only access Google user data for the purposes disclosed in this Privacy Policy and in the Google consent screen.

3. How We Use Information

We use information to provide, operate, improve and secure RegRails.ai.

This includes using information to:

  • Create and manage user accounts
  • Authenticate users
  • Provide access to the platform
  • Process uploaded documents
  • Extract regulatory obligations
  • Map obligations against internal policies
  • Identify compliance gaps
  • Generate reports and summaries
  • Track remediation and evidence
  • Provide dashboards, insights and analytics
  • Support customer service requests
  • Process billing and subscriptions
  • Monitor platform performance
  • Maintain security and prevent misuse
  • Comply with legal and regulatory obligations
  • Enforce our terms and protect our rights

4. How We Use Google User Data

We use Google user data only to provide the Google connected features that you request.

For example, we may use Google user data to:

  • Allow you to sign in using Google
  • Verify your identity
  • Import selected files from Google Drive into RegRails.ai
  • Process selected Google Drive documents for obligation extraction, gap analysis, report generation or related compliance workflows
  • Display file names or metadata so you can identify documents within RegRails.ai
  • Maintain the Google integration
  • Troubleshoot technical issues
  • Protect the security of your account

We do not sell Google user data.

We do not use Google user data for advertising.

We do not use Google user data to train general AI models.

We do not allow humans to read Google user data unless required for security, support, legal compliance, abuse investigation, or where you have given permission.

Our use of Google user data is intended to comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

5. AI Processing

RegRails.ai uses AI and automation to support regulatory compliance workflows.

Customer Content may be processed by AI systems to provide features such as:

  • Obligation extraction
  • Policy gap analysis
  • Compliance summaries
  • Audit-ready reports
  • Board reporting
  • Maturity scoring
  • Dashboard insights
  • Policy drafting
  • Policy version comparison
  • Quarterly review reports

Where we use third party AI service providers, we do so to provide the services requested by our customers. We do not sell Customer Content. We do not use Customer Content or Google user data to train general purpose AI models unless this is expressly agreed with the customer.

Customers are responsible for ensuring that they have the right to upload and process any personal data, confidential information or regulated information submitted to RegRails.ai.

6. How We Share Information

We may share information with the following categories of recipients.

Service Providers and Subprocessors

We may share information with trusted service providers who support our platform, such as:

  • Cloud hosting providers
  • Database and storage providers
  • AI model providers
  • Security and monitoring tools
  • Payment processors
  • Email and communication tools
  • Customer support tools
  • Analytics tools
  • Professional service providers

These providers are authorised to process information only as needed to provide services to us or to our customers, subject to contractual obligations.

Customer Authorised Users

If you use RegRails.ai as part of an organisation, your information and activity may be visible to authorised users within that organisation, such as administrators, compliance team members or other users with access rights.

Legal and Regulatory Purposes

We may disclose information where required to:

  • Comply with applicable laws
  • Respond to lawful requests from regulators, courts or public authorities
  • Enforce our terms
  • Protect our rights, users, customers or systems
  • Investigate suspected fraud, misuse or security incidents

Business Transactions

If RegRails.ai is involved in a merger, acquisition, financing, restructuring or sale of assets, information may be transferred as part of that transaction, subject to appropriate safeguards.

7. How We Share Google User Data

We do not sell Google user data.

We do not share Google user data with third parties except where necessary to:

  • Provide the RegRails.ai features requested by you
  • Process selected documents using our authorised service providers
  • Maintain security and prevent abuse
  • Comply with applicable law
  • Respond to valid legal or regulatory requests
  • Obtain your consent

Where Google user data is processed by service providers, it is used only for the purpose of providing RegRails.ai services and is subject to appropriate confidentiality, security and data protection obligations.

8. Data Storage and Protection

We take reasonable technical and organisational measures to protect information against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include:

  • Encryption in transit
  • Encryption at rest where applicable
  • Access controls
  • Role-based permissions
  • Tenant-level data separation
  • Audit logging
  • Monitoring and alerting
  • Secure cloud infrastructure
  • Vendor due diligence
  • Restricted internal access
  • Backup and recovery controls
  • Security reviews and improvements

No system can be guaranteed to be completely secure. Customers should also take care to manage user access, passwords, authentication settings and uploaded content responsibly.

9. Data Retention

We retain information for as long as necessary to provide RegRails.ai, comply with legal obligations, resolve disputes, enforce agreements and maintain security.

Customer Content is generally retained for the duration of the customer's subscription or as otherwise agreed in the applicable contract.

Google user data is retained only for as long as needed to provide the Google connected features, process authorised documents, maintain the integration, comply with legal obligations or support security and audit requirements.

After account termination or deletion request, we will delete or anonymise information within a reasonable period, unless retention is required for legal, regulatory, security, backup or contractual purposes.

Backup copies may remain for a limited period before being overwritten or securely deleted in accordance with our backup practices.

10. Deletion Requests

You may request deletion of your personal data or Google user data by contacting us at:

Email: info@regrails.ai

If you are using RegRails.ai through an organisation, we may need to refer your request to your organisation's account administrator.

You may also disconnect Google integrations through your Google account settings or within RegRails.ai where this feature is available. Disconnecting an integration may stop future access, but it may not automatically delete documents or outputs already imported into RegRails.ai. You may request deletion of those records by contacting us.

11. Your Rights

Depending on applicable law, you may have rights to:

  • Request access to your personal data
  • Request correction of inaccurate personal data
  • Request deletion of personal data
  • Withdraw consent where processing is based on consent
  • Object to certain processing
  • Request restriction of processing
  • Request a copy of your data
  • Lodge a complaint with a data protection authority

We may need to verify your identity before responding to a request.

12. International Transfers

RegRails.ai may use service providers located in different countries. This means information may be transferred to, stored in or processed outside your country.

Where required, we take steps to ensure that such transfers are subject to appropriate safeguards under applicable data protection laws.

13. Cookies and Similar Technologies

Our website and platform may use cookies or similar technologies to:

  • Keep users signed in
  • Remember preferences
  • Improve website performance
  • Analyse usage
  • Support security
  • Understand how visitors interact with our website

You may control cookies through your browser settings. Some features may not work properly if cookies are disabled.

14. Marketing Communications

We may use business contact information to send product updates, insights, event invitations or marketing communications.

You may opt out of marketing emails by using the unsubscribe link or contacting us. We may still send service related emails, such as security notices, billing updates or important account information.

15. Customer Responsibilities

Customers are responsible for:

  • Ensuring they have the right to upload data into RegRails.ai
  • Managing user access within their organisation
  • Ensuring uploaded documents do not contain unnecessary personal data
  • Reviewing AI generated outputs before relying on them
  • Complying with applicable laws and regulations in their own use of RegRails.ai

RegRails.ai is a compliance workflow tool. It does not replace legal, regulatory or professional judgement.

16. Children's Privacy

RegRails.ai is intended for business and professional use. It is not intended for children. We do not knowingly collect personal data from children.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted on our website with a revised "Last updated" date.

If we make material changes, we may notify customers through the platform, by email or through other appropriate means.

18. Contact Us

If you have questions about this Privacy Policy, our data practices or your privacy rights, please contact us at:

RegRails.ai
Legal entity: RegRails AI Pte. Ltd.
Email: info@regrails.ai