GoInsight.AI is an enterprise-class collaborative AI platform provided by SAND STUDIO PTE. LTD., a Singapore company (registered in Unit 30-15, Level 30, Singapore Land Tower, No.50 Raffles Pl, Сингапур 048623), and/or its affiliates (hereinafter referred to as “SAND STUDIO,” “the Company,” or “we”), offering GoInsight.AI SaaS services to business entities.
If you have any questions or concerns about this privacy policy, or if you want to exercise your legal rights, please contact us at dpo@goinsight.ai.
The GoInsight.AI Privacy Policy (hereinafter referred to as “these Rules”) outlines how we collect, use, process, and protect personal data from users and employees and/or other users who are authorized to use GoInsight.AI (hereinafter referred to as “you”) through our website (hereinafter referred to as “Website”) and/or GoInsight.AI services (hereinafter referred to as “Services”).
By using the website and services, or interacting with our business, you agree to our collection, use, processing, and protection of your personal data as described in this privacy policy.
This privacy policy does not apply to third-party products or services developed through the use of our website and/or services, nor to scenarios where third-party products or services integrate our website and/or services to process end-user personal data. We are not aware of the specific user behaviors of third-party products and/or services and are not responsible for their actions. We recommend that you carefully read the privacy policies and relevant rules of third-party product and/or service providers, and ensure that you fully understand and agree to how they collect and use end-users' personal data before using third-party products and/or services.
1.1 We collect personal data directly from you, as well as data that is collected through our websites, services, and other sources, as described below.
1.1.1 This subsection applies to visitors of this website, cloud-hosted services, and exclusive cloud-hosted services. If you fall into any of these scenarios, we collect the following categories of data:
| Personal data directly from you | ||
|---|---|---|
| What we collect | How we use it | |
During registration, setup, and login, we collect the following account information from you:
|
| |
Order and Transaction Data
|
| |
When you use our website and services, the user content you provide includes:
|
| |
When you use our support channels, we collect the following information:
|
| |
When you visit our website, we also collect:
|
| |
| Data automatically collected through our websites and services | ||
| What we collect | How we use it | |
When you use this website or service, we automatically collect the following information:
|
| |
When you use this website or service, we automatically collect the following information:
|
| |
| Personal data collected from other sources | ||
| What we collect | How we use it | |
|
| |
|
| |
|
| |
|
| |
1.1.2 This subsection applies to self-hosted services. If you fall into any of these scenarios, we collect the following categories of data:
| Data you provide directly and data we automatically collect from our cloud | ||
|---|---|---|
| What we collect | How we use it | |
During registration, setup, and login, we collect the following account information from you:
We collect the following account authorization information:
|
| |
(Optional) If you use our cloud-based LLM service, we automatically collect:
|
| |
In self-hosted mode, we do not collect: knowledge base content stored in your local environment; AI interaction data generated using your self-deployed LLM. For users of our cloud-based LLM service, we do not collect AI interaction data such as queries and responses. We only collect metadata necessary for calculating tokens and quotas. | ||
1.1.3 For on-premises services, we do not collect any data unless you make a specific request.
Under the on-premises service model, GoInsight.AI operates as a software system entirely controlled by your company within its organizational environment. As the system is fully deployed within your company's local infrastructure, we neither access nor collect your personal data—including account information, business content, and data used—as all such data remains under your company's complete control. Data collection may occur solely in response to your request for technical support or upon making special requests, with such interactions governed by a separately executed support agreement. Furthermore, your use of the service is subject to your organization’s policies. We disclaim any responsibility for your organization’s privacy or security practices, which may differ from this policy.
1.2 Model Provider's Personal Data Collection and Rules of Use. In relation to any service model—including cloud-hosted, dedicated cloud-hosted, self-hosted services, or on-premises services—please be advised that upon your selection of artificial intelligence large models (including large language models, LLMs), the data processing activities between you and the model provider, as well as the rules governing the collection, use, transmission, and storage of personal data, will be governed by the model provider's terms of service, privacy policies, data processing agreements, and other legal documents of similar nature (collectively referred to as the “Model Provider's Legal Documents”). As we are not the developer of these LLMs, we cannot be held liable for the Model Provider's Legal Documents, the content they provide, or their privacy and data security practices. We strongly advise you to carefully read and understand these legal documents prior to using third-party AI large models (including LLMs). To maintain transparency and protect your personal data:
1.2.1 Cloud-Based LLMs. Cloud-based LLMs refer to third-party AI large models (including LLMs) that are directly integrated and provided as part of our service for your selection. You may view the list of model providers we employ and provide, along with their privacy rules, via (link).
1.2.2 Enterprise-Owned LLMs. Enterprise-Owned LLMs refer to all AI large models (including LLMs) independently selected, deployed, configured, and integrated into this service by your company. Sources may include, but are not limited to, models developed in-house by your company, models co-developed by your company and third parties, or large language models licensed from other model providers. Given our inability to ascertain the specific types of LLMs selected by your company or associated operation details, we cannot provide a comprehensive list of enterprise-owned LLM types or corresponding privacy policy links. It is important to note that the integration of these enterprise-owned LLMs into our platform is entirely determined by your company, and such LLMs may not be listed among the cloud-based LLM providers. For privacy protection rules concerning enterprise-owned LLMs, please contact your company based on your specific circumstances or independently review the publicly available official privacy policies of such enterprise-owned LLMs.
We may share or disclose personal data we collect under the following circumstances:
If you use any third-party products and services, including third-party plugins or APIs, on this website or within our services, you agree that we are not responsible for those third-party products and services, whether they are provided by us or chosen voluntarily by you. Third-party products and services are governed by their own privacy policies, which are independent and separate from our policies. By continuing to use such services, you agree that the privacy policies of these third parties will also apply to you during the service process. We strongly recommend that you carefully read and understand the terms and practices of any third-party products and services regarding personal data protection.
To maintain transparency and protect your personal data, please visit (link) to view the list of third-party products and services we use or provide, along with their respective privacy policy links.
If you choose to use any third-party products and services not listed in the above link during your use of our services, please ensure that you read and understand the privacy policy of those third parties before proceeding.
We are dedicated to safeguarding the security of your personal data. We implement reasonable and appropriate technical and organizational measures in accordance with applicable laws. These measures include, but are not limited to: HTTPS encrypted transmission, AES-256 encrypted algorithm to protect databases and file storage, penetration testing and other security measures to protect your data from accidental or unlawful destruction, damage, loss, alteration, and unauthorized access, disclosure, or misuse. However, it is important to note that no application, system, software, network, or transmission method is completely secure, error-free, or indestructible. While we cannot guarantee absolute security for our services or your personal data, we are committed to maintaining data security at a commercially and technically reasonable level.
5.1 Our core servers and databases are located in the United States. Specifically, this means:
| Service mode | Where is the data transmitted and stored |
|---|---|
| Cloud-hosted service | All data generated through your use of this service will be transmitted to our servers located in the United States for processing and storage. |
| Exclusive cloud-hosted service | All data generated through your use of this service will be transmitted to our servers located in the United States for processing and storage. Your data will be stored in a separate, logically or physically isolated environment specifically designed for your company. |
| Self-hosted services | A. We collect only the account information and authorization data necessary for the performance of our services, along with any metadata used by our cloud-based language models. Only this data will be transmitted and stored on our servers in the United States. B. Except as described in Section A, all other data you generate in the service (such as knowledge base content, AI interaction data, etc.) will be stored and processed in an environment controlled by your company. As the data controller, your company retains complete control over this data and is responsible for establishing data transmission rules and storage locations in compliance with applicable laws. |
| On-premise service | A. In the normal course of service operation, we do not collect, transmit, or store any personal data. B. All data you generate in the service will be stored and processed in an environment controlled by your company. As the data controller, your company retains complete control over this data and is responsible for establishing data transmission rules and storage locations in compliance with applicable laws. |
5.2 Data from Third-Party Services. When using products and/or services, website, or content from third parties, your personal data may be transferred to and processed in the countries or regions where these third-party service providers and partners are located. The data protection laws in these jurisdictions may differ from those in your country or region. Particularly, if you opt to use a large language model (LLM), the location of data transmission and storage will depend on the service mode selected by your company, the specific language model chosen, and the transmission and storage mechanisms established by the model provider. If you choose a third-party large language model, your data will be transmitted to the server of the model provider, with the specific storage location determined by that provider, which may be situated in the United States or other countries or regions. This data transmission and storage process is entirely independent of SAND STUDIO and is governed by the agreements between you and/or your company and the model provider.
5.3 International Transmission. In instances of transferring personal data through cloud-hosted services, exclusive cloud-hosted services, and/or self-hosted services on this website, we will adhere to applicable data protection laws. When your data transfer is subject to the regulations of the European Economic Area (EEA), the United Kingdom, or Switzerland, we will implement appropriate protective measures to safeguard your personal data. This may include employing standard contractual clauses for corporate clients, adopting applicable cross-border data transfer mechanisms, or implementing other necessary legal protections. For personal data transmitted under on-premise services, your company bears full responsibility for developing and implementing appropriate protective measures. We encourage you to contact your company administrator for further consultation.
We will retain the personal data we collect from you for a reasonable period of time necessary to achieve the purpose of collection, fulfill legal obligations, and resolve disputes.
6.1 For this website, under the mode of cloud-hosted services, exclusive cloud-hosted services, and/or self-hosted services, we adopt the following rules of storage:
6.1.1 Data while the account is active: as long as your account is valid and active, we will retain the data necessary to provide and maintain our services, including your account information, configuration settings, and data of service use.
6.1.2 Data after account termination: Following the termination of your account, we will retain certain data for a reasonable period for the following purposes:
A. To maintain appropriate business and financial records.
B. To comply with applicable laws, such as those related to finance, taxation, or auditing.
C. To resolve potential disputes, enforce our agreements, or protect our legitimate interests.
D. To send you marketing promotional materials and seek commercial cooperation until you withdraw your consent or refuse further communication.
6.1.3 Handling After the Expiration of the Retention Period. After the expiration of the aforementioned retention period, we will securely delete or irreversibly anonymize your personal data. If technological limitations or unreasonable economic costs prevent us from doing so, we will implement appropriate security measures to isolate the data and cease further processing until deletion or destruction becomes feasible.
6.2 Mode of On-premise Service. If we provide on-premise services to your company, all data within that service is under the control of your company. Consequently, your company is responsible for establishing its own data protection and retention policies. Please consult your company administrator for any related questions, as we cannot directly address them.
7.1 Depending on your country/region and applicable laws, you may have the right to:
7.2 If you want to exercise your rights related to this service, you may access and control your personal data through a visual interface. However, if you are employed by a company or become a team member, your ability to exercise certain rights may be limited by the permissions granted to you by your employer, as well as the company’s privacy policies and internal regulations. Please note that for company users, your data is managed by the organization to which you belong, and their privacy and security practices may differ from this policy. For any data and privacy concerns, please contact the administrator of your company. We will not process requests directly and will first notify your company, following their instructions.
7.3 If you want to exercise your rights related to this website, please send an email to dpo@goinsight.ai. When submitting a request, ensure you provide sufficient information to verify your identity and clearly explain the nature of your request. We will comply with applicable laws and respond to your request after appropriate verification.
Our website and services are exclusively available to corporate clients. We do not offer services specifically for children. If you are aware, or have reason to believe, that children have provided us with personal data through our website or services, please contact us immediately at dpo@goinsight.ai. Upon receiving such information, we will take prompt action to delete any personal data we control that pertains to children.
We will regularly review this privacy policy and may post updates on this webpage without prior notice. The effective date of the new policy will be indicated at the top of this section.
If any modification or update to this policy affects your rights, your continued access and use of the website or services after the publication of the revised policy constitutes your acceptance of the modified terms. If you do not agree with the revised privacy policy, please discontinue access to and use of the website and services.
If you have any questions regarding this privacy policy, you can reach us through the following methods:
Email: dpo@goinsight.ai
Registered address: Unit 30-15, Level 30, Singapore Land Tower, No.50 Raffles Pl, Сингапур 048623
In the event of a conflict between the relevant supplementary terms applicable to the jurisdiction where you access and use the website and services and the provisions in this privacy policy, the supplementary terms for that specific jurisdiction will take precedence over the conflicting parts. The non-conflicting provisions will remain in effect.
If you use our website and services in the following states, the additional terms outlined below will apply: California, Iowa, Nebraska, Delaware, New Hampshire, New Jersey, Virginia, Montana, Texas, Oregon, and Utah.
If the applicable laws of the state where you use our website and services provide relevant regulations, you may have one or more of the following rights concerning your personal data:
To exercise your rights or submit inquiries, please contact us via email. We will verify your identity according to applicable laws before processing your request. Requests must be sent from and verified using the email address associated with your registered account. If you are employed by a company or become a team member, certain rights may be subject to permissions granted by that organization. We will notify the organization and act according to its instructions.
If we make a decision regarding your request, you may respond via email to file an appeal. We will not discriminate against you for exercising your rights. However, please note that certain features or functionalities of our website or services may change as a result, and you may no longer be able to use specific services.
If you use our website and services in Canada, the additional terms outlined below will apply:
If the applicable laws of the federal or provincial jurisdiction where you use our website and services provide relevant regulations, you may have one or more of the following rights concerning your personal data:
To exercise your rights or submit inquiries, please contact us via email. We will verify your identity according to applicable laws before processing your request. Requests must be sent from and verified using the email address associated with your registered account. If you are employed by a company or become a team member, certain rights may be subject to permissions granted by that organization. We will notify the organization and act according to its instructions.
If you use our website and services in Canada, the additional terms outlined below will apply:
If you use our website and services in Brazil, we will respond to and fulfill your requests to exercise your rights in accordance with Brazil's General Data Protection Law (LGPD):
We will verify your identity according to applicable laws before processing your request. Requests must be sent from and verified using the email address associated with your registered account. If you are employed by a company or are a team member of a company, certain rights may be subject to permissions granted by that organization. We will notify the organization and act according to its instructions.
In some cases, we may have legitimate reasons not to comply with certain requests you make regarding your rights. For example, we may choose not to disclose information if doing so could negatively impact our business or risk infringing on our confidential information or intellectual property. If you intend to exercise your rights or have any questions regarding this process, please contact us via email.
If you use our website and services in the European Economic Area, the UK, and Switzerland, the additional terms outlined below will apply:
We only collect, use, and store your personal data within the minimum scope permitted by applicable law.
A. The following table outlines the legal bases for processing your personal data by visitors, cloud-hosted services, and/or exclusive cloud-hosted services on this website:
| Personal data category | How to use | Legal basis |
|---|---|---|
During registration, setup, and login, we collect the following account information from you:
|
|
|
We automatically collect the following equipment and network information:
| Observe and supervise the usage of this website.
|
|
Order and Transaction Data
|
|
|
Account settings information:
|
|
|
Information About the Use of Websites and Services:
|
|
|
Customer Support Information:
|
|
|
Third-Party Data:
|
|
|
B. The following table outlines the legal bases for processing your personal data by self-hosted services on this website:
| Personal data category | How to use | Legal basis |
|---|---|---|
During registration, setup, and login, we collect the following account information from you:
We collect the following account authorization information:
|
|
|
(Optional) If you use our cloud-based LLM service, we automatically collect:
|
|
|
C. The following table outlines the legal bases for processing your personal data by on-premise services on this website:
| Personal data category | How to use | Legal basis |
|---|---|---|
| We do not collect your personal data. Personal data is fully controlled by your company. | For information on how your personal data is used, please contact the administrator of your company. | For information on how your personal data is used, please contact the administrator of your company. |
If you use our website and services in the European Economic Area, the UK, and Switzerland, we will respond to and fulfill your requests to exercise your rights in accordance with Brazil's General Data Protection Law (LGPD):
If you are employed by a company or are a team member of a company, that company is the data controller for your personal data. We act as a data processor processing data on behalf of the data controller, in accordance with the controller’s instructions and applicable law. Before processing your personal data, the data controller must obtain your consent or a lawful basis. If you exercise your rights regarding this service, we will verify your identity, notify the data controller of any relevant matters, and process your request in accordance with applicable laws, the data processing agreement, and the data controller’s instructions.
If you intend to exercise your rights or have questions about exercising them, please contact us.