HighSigndocs

Privacy and data use

This page summarises what HighSign collects and how it's used. The full statement is the live /privacy page, which this summarises and does not exceed.

What's collected

  • Account information for your governance-team users: name, work email, role and authentication identifiers. Sign-in is by one-time email link, Google, or a password you choose to set; where you set a password HighSign stores only a cryptographic hash, never the password itself.
  • Workspace content you enter: your organisation name, policy rules, tool register, requests, exceptions, attestations and incidents.
  • Technical data: basic logs needed to run and secure the service. HighSign does not run advertising trackers.

Anonymous staff lookups

When staff use a shared link to check a tool, HighSign records that a lookup happened, for adoption metrics, but not who made it. Requests and reports carry only the name a person chooses to provide, so your organisation can reply. This is deliberate: it's what lets your whole team use the tool without being watched. See Security and hosting for the wider declared-signals boundary this sits inside.

De-identified, aggregated benchmarks

HighSign creates de-identified, aggregated statistics from governance metadata across customers, for example which AI tools are commonly assessed, approved or restricted, by sector and organisation-size band. These are used to produce benchmarks, improve the service and report on market trends.

These aggregates never include your client data, staff identities, your policy text, or anything that identifies your organisation, and are only ever shared in a form that cannot reasonably be re-identified.

Where it's hosted

Customer data is hosted in Australia (Supabase, Sydney region). Some sub-processors that support the service, for example payment, email, identity or AI providers, may process limited data overseas; where they do, HighSign takes reasonable steps to ensure comparable protection consistent with the Australian Privacy Principles.

HighSign is offered to customers internationally. If you are outside Australia, including in the EU or United Kingdom, you can request a data processing agreement and details of how your data is handled by contacting us.

AI processing

Verdicts are computed deterministically from your policy rules; no AI model sits in the answer path. Optional AI features only run when you enable them, produce drafts a human confirms, and never set a verdict. HighSign does not use your workspace content to train third-party models.

Access, correction and deletion

You can request access to, or correction of, the personal information HighSign holds about you, and you can request export or deletion of your workspace data, by contacting hello@howll.ai.

This page is a summary for convenience, not legal advice. Privacy enquiries: hello@howll.ai.