NGS CORE

Privacy Policy

Last updated: 20 August 2026

NGS CORE Ltd (“NGS CORE”, “we”, “us”) provides an AI onboarding assistant that client organisations (“Customers”) use to answer their employees’ (“Users”) questions about internal policies. This policy explains what personal data we collect, why, and what rights you have over it. It’s written to comply with UK GDPR and the Data Protection Act 2018.

1. Who this applies to

This policy covers two groups of people, and it’s worth being clear about the difference:

  • Customer admins — the people at a client organisation who sign up for NGS CORE, upload documents, and manage billing.
  • Users — employees of a Customer who are invited to ask the assistant questions. For these people, the Customer is the data controller and NGS CORE is a data processor acting on their instructions (see our Data Processing Agreement). If you’re a User and have questions about how your data is handled, your first point of contact should be your employer, not us.

Put another way: NGS CORE acts as controller for certain information relating to Customer admins, and as processor for personal data contained in Customer Data.

2. What we collect

  • Account data: name, email address, and authentication details, handled on our behalf by Clerk (our identity provider).
  • Company data: organisation name, logo, pricing plan, and billing details (billing details are held by Stripe — we don’t store card numbers ourselves).
  • Uploaded documents: the policy handbooks and documents a Customer uploads, which may contain personal data about that Customer’s own staff (e.g. named contacts in a handbook).
  • Questions and answers: the questions Users ask the assistant, the answers given, and which document each answer was sourced from. We keep this so Customer admins can see what their staff are asking and where their documentation has gaps.
  • Usage data: standard technical logs (IP address, browser type, timestamps) generated by using the service, and product analytics about which features are used.

We don’t intentionally request special category data (such as health, disability, or other sensitive information) through the Service. However, documents a Customer uploads may incidentally contain it — for example, a handbook that references an employee’s health condition. Where that happens, that data remains subject to the protections in this policy and our Data Processing Agreement.

3. Why we process personal data, and our legal bases

Where NGS CORE acts as a controller, we rely on the following legal bases:

  • Contract: we process Customer account and administration information where this is necessary to provide the NGS CORE service, manage accounts, and administer our contractual relationship.
  • Legitimate interests: we process certain information, such as service usage information and technical logs, where necessary for legitimate interests including maintaining security, troubleshooting, improving and developing the service, preventing misuse, and understanding how the service is used. We consider the impact on individuals before relying on this basis, and we don’t use Customer content to train third-party AI models.
  • Legal obligation: we process information where necessary to comply with legal, accounting, tax, or regulatory obligations.

Customer Data: where NGS CORE processes personal data contained in Customer documents, User questions, answers, or other Customer Data on behalf of a Customer, the Customer is the controller and NGS CORE acts as processor. The Customer determines the purposes and lawful basis for that processing, and NGS CORE processes the data in accordance with the Customer’s documented instructions and our Data Processing Agreement.

4. Who we share data with

We use a small number of sub-processors to run the service. None of them are permitted to use Customer data for their own purposes. A current list of our sub-processors, including the services they provide and the applicable international transfer mechanisms, is maintained in our Data Processing Agreement.

We do not sell personal data, and we do not share it with third parties for their own marketing.

5. How long we keep it

We keep account and content data for as long as a Customer’s account is active. If an account is closed, we retain data for 30 days (in case of accidental cancellation) and then delete it, except where we’re required to keep records for longer — for example, we may retain billing and financial records for up to seven years where necessary for tax, accounting, audit, legal, or regulatory purposes.

Where data is held in backups, it may remain in those backups until the relevant backup cycle expires, after which it will be securely overwritten.

6. Your rights

Under the UK GDPR, you may have rights including the right to:

  • access your personal data;
  • have inaccurate personal data corrected;
  • request erasure of your personal data;
  • request restriction of processing;
  • object to certain processing, including processing based on legitimate interests;
  • receive personal data in a portable format where the right to data portability applies; and
  • withdraw consent where we rely on consent as our lawful basis.

These rights are subject to applicable legal conditions and exemptions. We will normally respond to a valid rights request within one month, although this period may be extended where permitted by law, and we may need to verify your identity before acting on a request.

Where we process personal data on behalf of a Customer, we will generally refer the request to that Customer and provide reasonable assistance in accordance with our Data Processing Agreement. If you’re a User, please contact your employer first, since they control your account. Customer admins can reach us directly at the address below, and can also self-serve a full export of their organisation’s data from Settings at any time.

7. Security

Data is encrypted in transit (TLS) and at rest. Access to Customer data is restricted by organisation-level access controls enforced both in our application logic and at the database level. We regularly review and improve our technical and organisational security measures; a more detailed Security & Technical Organisational Measures document is available to Customers on request.

8. AI and automated processing

NGS CORE uses artificial intelligence to generate answers to questions based on Customer-provided content. NGS CORE does not use the Service to make decisions about individuals relating to employment, recruitment, dismissal, promotion, disciplinary action, performance assessment, or other similarly significant matters.

AI-generated answers may be incomplete or inaccurate and should be checked against the Customer’s source documentation where appropriate. Customers remain responsible for decisions made using information provided through the Service.

Customer Content is not used by NGS CORE to train third-party AI models.

9. Cookies

CookiePurposeProviderEssential?
Session / authenticationKeeps you signed inClerkYes

We currently use only this essential cookie, which keeps you signed in and can’t be switched off, since the service won’t work without it. We don’t use analytics or third-party advertising cookies. If that changes, we’ll update this table and, where a new cookie isn’t essential, ask for your consent before setting it.

10. Children

NGS CORE is a workplace tool and is not directed at, or intended for use by, children.

11. Changes to this policy

We’ll update this page if how we handle data changes, and update the “last updated” date above. For material changes, we’ll notify Customer admins directly.

12. Contact us

For any question about this policy or your data, contact us at help@ngs-core.com. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

NGS CORE Ltd is registered with the ICO under registration reference ZC226781.