Data Handling & Security Policy
This Data Handling and Security Policy (the "Data Policy") forms part of the Upside PR Terms of Service (the "Terms") between Upside Financial Technologies Inc. ("Upside") and the Customer, and is incorporated into the Terms by reference. Capitalized terms not defined here have the meanings in the Terms. It describes what Upside does with Customer Content, the safeguards applied to it, the third parties involved, the retention and deletion schedule, and the risk factors and responsibility allocation that Customer accepts by using the Service. In case of conflict between this Data Policy and the Terms, the Terms govern with respect to liability and remedies, and this Data Policy governs with respect to data handling practices.
1. What Data the Service Handles
1.1 Categories.
- Draft materials (highest sensitivity): unpublished draft press releases, uploaded documents, pasted text, iteration instructions, and the Output generated from them. Until publicly disclosed, these ordinarily constitute material non-public information ("MNPI") of Customer and are treated at Upside's highest data classification.
- Corpus and baseline data: Customer's historical, publicly issued press releases and the analyses derived from them (baseline report, voice profile). These are derived largely from public materials but are treated as Customer's Confidential Information in their compiled and analyzed form.
- Account and usage data: user accounts, authentication data, billing records, job metadata (mode, timestamps, status), and audit logs. Personal information within this category is governed by the Upside PR Privacy Policy.
- Market data: third-party market data (prices, index levels, regime snapshots) used to contextualize analysis. This is not Customer data.
1.2 What Upside does with Customer Content. Upside processes Customer Content solely to provide, maintain, secure, and support the Service for Customer, as licensed under the Terms. Specifically, Upside uses draft materials to generate the analysis, comments, rewrites, and redlines Customer requests; uses the corpus to build Customer's baseline report and voice profile; and uses account and usage data to operate, bill, and secure the platform.
1.3 What Upside does not do with Customer Content. Upside does not:
- use Customer Content or Output to train or fine-tune any machine learning model, its own or any third party's, and prohibits its subprocessors from doing so;
- sell, rent, or trade Customer Content;
- use one customer's content in processing, analysis, or output for any other customer (see Section 3.3, Tenant Isolation);
- permit its personnel to access draft materials except where required to provide, support, or secure the Service or to perform sampled quality review as described in the Terms, in each case under confidentiality and trading restrictions covering MNPI;
- include draft text in URLs, page titles, application logs, error reports, or third-party telemetry.
Aggregated, de-identified operational metrics that contain no Customer Content (feature usage counts, latency, error rates) are used to operate and improve the Service.
2. Model Processing Architecture (LLM Handling)
The Service uses large language models. The architecture is designed so that unpublished draft materials are never exposed to a model provider and are never retained by model infrastructure.
2.1 Draft path: in-environment, zero data retention. All processing of draft materials (analyze, comment, rewrite, iterate, and related operations) runs on model infrastructure operating inside Upside's own cloud environment on Amazon Web Services (AWS Bedrock). This path is configured with AWS Bedrock's zero-data-retention control, under which no request or response data is written to durable storage by AWS and none is shared with the model developer. The model developer has no access to this traffic as a matter of platform architecture, not merely contract. Upside verifies at deployment, and monitors on an ongoing basis, that the zero-data-retention mode is in force and that model invocation logging of content is disabled on this path.
2.2 Public-information path. Certain features that require live public-web lookups (for example, research on publicly disclosed information about market participants) run on a separate external model API. By technical control, draft materials and other unpublished Customer Content are never sent on this path; it processes public information only.
2.3 Processing location. Model inference on the draft path currently runs in AWS regions in the United States. Customer Content on this path is encrypted in transit, processed transiently, and not durably stored in those regions. Primary storage of Customer Content resides in Upside's production cloud environment. Customer acknowledges the United States processing described here and in the Privacy Policy.
2.4 Output labeling. AI-generated Output is identified as such in the portal and in exports, and carries the standing legend required by the Terms ("Draft for internal review. Not disclosure advice. Route to counsel and your Qualified Person before release." or equivalent).
3. Security Program
Upside maintains a written information security program aligned with SOC 2 Trust Services Criteria, documented in the Upside Information Security Policy Manual and reviewed at least annually. Its core controls as applied to the Service:
3.1 Encryption. All data in transit is encrypted using TLS 1.2 or higher. All data at rest, including databases, file storage, and backups, is encrypted using AES-256 or equivalent. Credentials and keys are held in a dedicated secrets management system; encryption keys are managed through cloud provider key management services and rotated on schedule.
3.2 Access control. Access follows least privilege and need-to-know. Multi-factor authentication is required for all access to production systems, cloud consoles, code repositories, and administrative tools. Production access to Customer Content is restricted to designated personnel with a documented business need; privileged sessions are logged. Access reviews run quarterly, and departing personnel are deprovisioned within 24 hours.
3.3 Tenant isolation. The platform enforces strict per-customer isolation at the database and application layers: tenant identifiers on all customer data, tenant-context authorization checks on every request, per-tenant processing in all AI pipelines with no cross-tenant aggregation, caching, or embedding leakage, and automated testing that tenant boundaries cannot be bypassed. Multiple public companies using the platform cannot access one another's drafts, jobs, or Output.
3.4 Confidentiality surfaces. Every screen displaying draft materials shows its confidentiality state. Share links, where offered, are access-logged and expiring. No third-party analytics or telemetry runs on draft-bearing screens.
3.5 Logging and monitoring. Authentication, authorization, data access, administrative, and AI-processing events are logged (metadata only, never raw draft text), retained for at least 12 months in an append-only system, and monitored with alerting for anomalous activity.
3.6 Secure development and operations. Changes reach production through peer-reviewed pull requests and automated CI/CD pipelines with dependency and security scanning. Production data is not used in development or test environments without anonymization. Infrastructure runs across multiple availability zones; encrypted backups are taken at least daily with tested restoration, targeting a recovery time objective of 4 hours and a recovery point objective of 1 hour.
3.7 Personnel. All personnel complete security awareness training at hire and annually, are bound by confidentiality obligations, and are subject to internal policies prohibiting trading in the securities of any customer while in possession of that customer's MNPI and prohibiting tipping or other misuse.
3.8 Vulnerability management. Automated dependency scanning runs on every build, infrastructure scanning at least monthly, and third-party penetration testing at least annually, with remediation on defined timelines by severity.
4. Subprocessors
4.1 Current subprocessors.
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, and model inference (AWS Bedrock, zero-data-retention mode on the draft path) | Canada/United States (hosting); United States (model inference) |
| [Payment processor, e.g. Stripe, Inc.] | Subscription billing and card processing | United States/Canada |
| [Email/support tooling] | Transactional email and customer support | [confirm] |
External model API providers used on the public-information path (Section 2.2) do not receive Customer Content and are therefore not subprocessors of Customer Content; they are listed here for transparency: [x.ai / confirm current provider].
4.2 Requirements and changes. Each subprocessor that processes Customer Content is bound by a written agreement imposing data protection obligations consistent with this Data Policy, including prohibition of training on Customer Content, breach notification, and deletion on termination. Upside evaluates subprocessor security documentation (SOC 2 or equivalent) before onboarding and annually. Upside will update the subprocessor list and notify customers through the portal or by email at least 15 days before adding a subprocessor that will process draft materials; if Customer reasonably objects on data protection grounds and Upside cannot offer an alternative, Customer may cancel under the Terms.
5. Retention, Purge, and Deletion
5.1 Draft materials purge. Draft materials and associated Output for a given job are purged from production systems on the earliest of:
- 30 days after Customer marks the related release as publicly issued (or Upside otherwise confirms public issuance);
- Customer's on-demand deletion of the job through the portal, effected promptly and verifiable in the portal; or
- deletion under Section 5.3.
5.2 Corpus, baseline, and account data. Customer's corpus, baseline report, voice profile, and job history (excluding purged draft materials) are retained for the duration of the subscription to operate the Service's history and evidence features.
5.3 Offboarding. Following termination or expiry of the Terms, Customer has until the end of its access period to export its data. Upside deletes Customer Content and Output from production systems within 90 days of termination, except where retention is required by law. Billing and audit records are retained as required by law.
5.4 Backups. Deleted and purged content ages out of encrypted backups on the backup rotation schedule (daily backups retained 30 days; monthly backups retained 12 months) and is not restored to production except transiently, and subject to re-deletion, in the course of disaster recovery.
5.5 Media disposal. Storage media disposal follows NIST 800-88 guidelines.
6. Incident Response and Breach Notification
Upside maintains a documented incident response process with defined severity levels, escalation, containment, forensics preservation, and post-incident review. If Upside confirms unauthorized access to or disclosure of Customer Content, Upside will notify affected customers without undue delay and in any event within 72 hours of confirmation, describing the nature of the incident, the data involved, the actions taken, and recommended steps. Upside will cooperate reasonably with Customer's own assessment, including where the incident may bear on Customer's disclosure obligations. Notification is not an admission of fault or liability.
7. Customer Responsibilities (Shared Responsibility)
Security of Customer Content is shared. Customer is responsible for:
- controlling who becomes an Authorized User, promptly removing users who should no longer have access, and requiring strong credentials and, where offered, multi-factor authentication;
- the security of its own networks, devices, and email, including the channels through which its personnel access the Service and receive exports;
- what it uploads, including ensuring it is authorized to share the content and that uploads do not include unnecessary personal information or third-party MNPI it is not entitled to share;
- handling of exports: once Output or Customer Content is downloaded or shared outside the Service, its security is Customer's responsibility;
- marking releases public (or requesting deletion) so the purge schedule in Section 5 can operate, and exporting anything it needs before purge or offboarding; and
- its own disclosure controls, insider lists, and blackout procedures, which the Service does not replace.
Upside is not responsible for incidents to the extent arising from compromise of Customer's credentials, devices, or systems, from Customer's sharing of exports, or from Customer's failure to meet the responsibilities above.
8. Risk Factors and Allocation of Responsibility
Customer acknowledges the following risks, which no provider can eliminate, and agrees that the Terms allocate them as stated there:
- No absolute security. Upside applies the industry-standard safeguards described in this Data Policy, including encryption in transit and at rest, zero-data-retention model processing, tenant isolation, and independent security testing. Nevertheless, no method of transmission, processing, or storage is completely secure. Sophisticated attacks, novel vulnerabilities (including in widely used third-party software), insider misuse, and force majeure events can defeat even well-designed controls.
- Third-party dependency. The Service depends on third-party infrastructure and services. Their failures, breaches, or changes can affect the Service notwithstanding Upside's vendor diligence.
- Transmission risk. Data in transit over the public internet, and content transmitted by Customer outside the Service (for example, exported documents sent by email), are exposed to interception risks outside Upside's control.
- Model behaviour risk. Large language model output can be wrong, incomplete, or misleading despite safeguards; the review obligations in the Terms exist for this reason.
- MNPI risk. A breach involving unpublished drafts could have market consequences for Customer. The purge schedule, zero-data-retention architecture, and minimal-retention design of the Service exist to shrink this exposure window, but the residual risk cannot be reduced to zero.
Responsibility allocation. UPSIDE'S RESPONSIBILITY AND LIABILITY IN CONNECTION WITH ANY SECURITY INCIDENT, DATA LOSS, DATA CORRUPTION, OR UNAUTHORIZED ACCESS TO OR DISCLOSURE OF CUSTOMER CONTENT, HOWEVER ARISING, ARE LIMITED AS SET OUT IN THE TERMS, INCLUDING THE EXCLUSION OF INDIRECT AND CONSEQUENTIAL DAMAGES AND THE AGGREGATE LIABILITY CAP IN SECTION 13 OF THE TERMS. UPSIDE'S COMMITMENTS REGARDING SECURITY ARE TO MAINTAIN THE PROGRAM AND CONTROLS DESCRIBED IN THIS DATA POLICY, NOT TO GUARANTEE THAT INCIDENTS WILL NEVER OCCUR. THIS ALLOCATION IS A BARGAINED-FOR TERM REFLECTED IN THE PRICE OF THE SERVICE.
9. Audits and Documentation
Upon reasonable written request, no more than once annually, Upside will make available to Customer its then-current security documentation (security policy summaries, penetration test attestations, and, when available, SOC 2 reports) under confidentiality. On-site or technical audits are not offered at the Service's standard pricing but may be agreed in an Order Form.
10. Changes
Upside may update this Data Policy as its practices and infrastructure evolve, provided updates do not materially reduce the protections for Customer Content during a paid subscription period. Material changes follow the notice mechanics in the Terms.
Contact: hello@upsidepr.ai (security reports: mark "Security" in the subject line).