Contents
Forward Deployed Privacy Policy
Forward Deployed is a beta service. The Terms of Service describe what that means for availability, data and liability.
Version: 2026-10-01.2
Effective date: October 1, 2026
This Privacy Policy explains how Ockham Labs Inc. ("Forward Deployed", "we", "us" or "our"), collects, uses, discloses and protects personal information when organizations and their people use the Forward Deployed portal, application programming interfaces, Model Context Protocol ("MCP") endpoint, AI-assistant connections, live rooms and paid services (the "Services"). Capitalized terms not defined here have the meaning given in our Terms of Service.
We follow Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and, where they apply, provincial privacy laws, the EU and UK General Data Protection Regulation ("GDPR") and California privacy law, including the California Consumer Privacy Act as amended ("CCPA").
1. Our role
- Account, sign-in, billing and security information. We decide how this information is handled and are accountable for it (a "controller" under the GDPR).
- Customer Data. Content that an organization's users put into Forward Deployed, such as messages, files and deliverables, is handled on behalf of that customer organization, which controls it. We act as its service provider (a "processor"). If your question concerns Customer Data, contact the organization's administrators; we will help them respond.
2. Information we collect
Identity and account
- Your name or display name, and your email address when your sign-in provider shares it or someone invites you by email.
- The identifiers Microsoft sign-in (Microsoft Entra) issues for you: an issuer and a stable subject identifier. We use these, rather than your email address, to recognize you.
- The organizations you belong to, your role in each, and the workspaces you have been given access to.
Sign-in. Sign-in, including one-time email codes, is performed by Microsoft. We receive confirmation of who you are; we never receive a password. Microsoft processes sign-in information under its own privacy statement.
Customer Data. Messages and conversation threads; files and other resources you upload, with their name, type, size and checksum; knowledge entries; help requests; inputs you give to paid services; and the Outputs generated, including deliverables, simulation requests and results, and assessments. Customer Data may include personal information about you or other people.
AI-assistant connections. The AI Assistant you connect (for example Claude or ChatGPT) and its registration details, the organization you chose, when the connection was made, renewed and last used, and the actions it performed through MCP. Access and refresh tokens are stored only in hashed or encrypted form.
Invitations. The email address invited, the inviter, role, status and expiry. Mailbox verification codes are stored only as one-way hashes and expire within 10 minutes.
Billing and usage. Credit purchases, amounts, currency, status and payment-processor references (Stripe handles card details; we do not receive full card numbers); quotes, approvals, credit holds and charges; and usage measures for paid services, such as AI model tokens, run time and simulation requests.
Audit and security records. Membership and role changes, access grants and removals, account actions (for example changing your display name or signing out everywhere), invitation events, and your acceptance of these documents, including the version, time and context, and a keyed hash of your IP address (not the address itself).
Technical information. IP address, browser and device information (user agent), request times and error details in logs kept by our servers, reverse proxy and network edge provider.
Live rooms. Which room you joined and for how long. Audio, video and screen sharing are transmitted in real time and are not recorded or transcribed by us.
Communications. Messages you send to support, and the transactional emails we send you (invitations, verification codes and notifications). We turn off open and click tracking for our emails.
Cookies. The portal uses a strictly necessary, secure session cookie to keep you signed in. We do not use advertising or third-party analytics cookies.
3. How we use information
We use personal information to:
- provide and operate the Services, including signing you in, enforcing organization and workspace permissions, and showing your organizations and connected apps;
- deliver the features you and your organization request, including generating AI Outputs and running simulations;
- process payments, maintain credit balances and provide charge histories;
- send transactional emails, such as invitations, verification codes and join-request notices to administrators;
- secure the Services, detect and prevent abuse and fraud, scan uploads for malware and keep audit records;
- provide support, and communicate with you about the Services and changes to our terms;
- comply with legal obligations and enforce our agreements; and
- understand and improve the Services using aggregated or de-identified information.
We do not sell personal information, use it for targeted advertising or share it for cross-context behavioural advertising. We do not use Customer Data to train generative AI models.
Legal bases (GDPR). Where the GDPR applies, we rely on performance of our contract with you or your organization, our legitimate interests in operating, securing and improving the Services, compliance with legal obligations, and your consent where it is required.
4. Artificial intelligence
When you use AI features, the relevant Customer Data (for example your instructions, workspace content and uploaded files) is sent to the AI model providers listed in section 6 to generate Outputs. Those providers process it on our behalf to provide the Services. Outputs may be inaccurate; see the Terms of Service.
If you connect a third-party AI Assistant, information it retrieves from Forward Deployed is processed by that AI Assistant's provider under your or your organization's agreement with it and its privacy policy, not this one.
5. How we share information
- Within your organization, according to the permissions that its administrators and workspace managers set. For example, workspace members see messages in that workspace, and administrators see the organization's member list and access history.
- With Forward Deployed staff and advisers, when your organization gives them access to a workspace, or when necessary to provide support you request, secure the Services or comply with law. Our personnel are bound by confidentiality obligations.
- With service providers (subprocessors) listed in section 6, who process information on our behalf under contracts requiring appropriate protection.
- For legal reasons, when required by law or legal process, or to protect the rights, property or safety of our users, the public or us.
- In a business transaction, such as a merger, financing or sale of assets, subject to confidentiality and this Policy.
- With your consent or at your direction.
6. Subprocessors
We use the following service providers to deliver the Services.
- Microsoft Corporation (Microsoft Azure): cloud hosting, including compute, PostgreSQL databases, Blob storage and Key Vault; Microsoft Entra sign-in; Azure OpenAI and Azure AI Foundry hosted AI models, including Anthropic models made available through Azure; and Azure Communication Services for email delivery. Regions: Canada (Canada Central) and United States (East US and East US 2).
- Anthropic, PBC: AI models used to generate decks and documents. Region: United States.
- OpenAI OpCo, LLC: AI models used for parts of process assessments and, in some configurations, persona simulations, company intelligence reports and podcast scripts. Region: United States.
- Zep Software, Inc.: memory storage used while running world simulations. Region: United States.
- Google LLC and Google Cloud Canada Corporation (Gemini API): AI research used to produce deep research reports, and editorial illustrations for thought leadership articles. Regions: United States and other countries where Google operates.
- Jina AI GmbH (an Elastic company): reading the public web pages you ask the public source reader to read. Regions: Germany and other countries where Elastic operates.
- SideGuide Technologies, Inc. (Firecrawl): retrieving public web content for company intelligence reports and podcast audio. Region: United States.
- Eleven Labs Inc. (ElevenLabs): speech generation for voiceovers and podcast audio. Region: United States.
- Stripe, Inc. and its affiliates: payment processing for credit purchases. Regions: United States and other countries where Stripe operates.
- Cloudflare, Inc.: network edge, routing and protection against attacks. Regions: global network.
- Modal Labs, Inc.: serverless computing used to run AI deliverable generation, research and creative services, and simulations. Region: United States.
- Email delivery: Microsoft Azure Communication Services, or another email relay we name here before using it.
We will update this list before adding a subprocessor that processes Customer Data.
7. International transfers
We and our subprocessors store and process personal information in Canada and the United States, and our providers may process it in other countries where they operate. Information held outside your jurisdiction may be accessible to courts, law enforcement and national security authorities there. Where the GDPR or UK GDPR applies, we rely on appropriate safeguards for transfers, such as adequacy decisions (including the European Commission's decision for Canada under PIPEDA) and standard contractual clauses.
8. Retention
We keep personal information only as long as needed for the purposes in this Policy:
- Customer Data: for as long as the organization exists. We delete an organization's Customer Data within 30 days after the organization is closed. Copies in backups are removed as the backups expire, within 30 days.
- Account and identity information: while you have access to an organization, and for 30 days afterwards so that we can recognize you if you return and keep records accurate.
- Sign-in sessions and tokens: portal sessions last up to one hour, AI-assistant access tokens 15 minutes, and AI-assistant sign-ins last one day. Invitation verification codes expire within 10 minutes and invitations within 7 days.
- Billing records: as long as required for tax and accounting purposes, generally six years.
- Audit and security records, and acceptances of these documents: for as long as the organization exists and for two years after it is closed, as evidence of access decisions and of the terms that applied.
- Technical logs: up to 30 days, unless needed longer to investigate a security incident.
9. Security
Your data is encrypted in transit and at rest. We use technical and organizational safeguards designed to protect personal information, including encryption in transit and at rest, database row-level isolation between organizations, least-privilege access, hashing of codes and tokens, malware scanning of uploads, audit records, and secrets kept in a managed key vault. No method of transmission or storage is completely secure. We will notify affected individuals and regulators of a breach of security safeguards as required by law.
10. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you and learn how it is used and disclosed;
- correct inaccurate information;
- withdraw consent, subject to legal or contractual limits, and understand the consequences;
- ask us to delete information, restrict or object to its processing, or receive a portable copy (GDPR and UK GDPR); and
- know, delete and correct personal information, and not be discriminated against for exercising your rights (California). We do not sell or share personal information as those terms are defined in California law, and we do not use sensitive personal information to infer characteristics about you.
To make a request, email support@forwardeployed.work. We will verify your identity before responding and respond within the time the law requires. You may use an authorized agent where the law allows. If your request concerns Customer Data controlled by an organization, we may refer you to that organization.
You can change the name that organizations see and disconnect AI Assistants on your account page at any time.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca), your provincial privacy regulator, or, in the European Economic Area or United Kingdom, your local data protection authority.
11. Children
The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under the age of majority.
12. Changes to this Policy
We may update this Policy. The version and effective date appear at the top. When we make a material change, we will change the version and ask you to review and accept it the next time you sign in.
13. Contact and Privacy Officer
Our Privacy Officer is accountable for our compliance with this Policy.
Privacy Officer: Venkat Chandra
Ockham Labs Inc.
4222 Dixie Rd, Unit 145, Mississauga, ON L4W 1M6, Canada
Email: support@forwardeployed.work