1. Scope and ownership
Customer data includes product facts, versions, classification, decisions, schedules, regulatory, quality and clinical plans, documents, evidence, claims, external-QMS references, and other work material. The customer retains its rights and grants only limited processing authority for the service.
2. Relationship to personal data
Customer data is broader than personal data. Privacy terms also apply to portions linked to identifiable staff, researchers, or business contacts. The Privacy Policy governs HÉDÉONIX-controlled account and operations data; the DPA governs customer-instructed processing.
3. Classification and customer responsibility
Customers must have authority to provide data and must minimize it. Patient and study-subject health information is prohibited unless a separate written scope expressly permits it.
- Public
- Internal
- Confidential
- Restricted
- Prohibited under the paid-beta data catalog
4. Support access
Operators do not receive default access to customer content. Customer-scoped purpose, action, object, and expiry are required, and access is logged. Approved records cannot be silently overwritten.
5. AI processing
Customer material may not be used for provider training or another customer's output. Approved AI functions log allowed inputs, source, and model settings and return candidates only. Providers and retention will be disclosed before activation.
6. Export, deletion, and incidents
Organization owners may request export. Deletion distinguishes audit tombstones, legal hold, statutory retention, and backup expiry. Material confidentiality, integrity, or availability events are investigated and notified under contract and applicable law.