Skip to content

Privacy Notice

Last updated

Registered name
Subworkflow AI Limited
Registered in England & Wales, UK (16781125)
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Data Protection Registration: ZC013758

We are the controller of your personal data. This privacy notice tells you what to expect us to do with your personal information when you use ragextract.com and the Ragextract service at app.ragextract.com.

What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details
  • Addresses
  • Organisation name, size and description, where you give them to us
  • Usage data (including information about how you interact with and use our website, products and services)
  • Account access information
  • Website user information

We collect or use the following personal information for information updates or marketing purposes:

  • Names and contact details
  • Addresses
  • Profile information
  • Marketing preferences
  • Purchase or account history
  • Website and app user journey information

We collect or use the following personal information to keep accounts secure and detect unauthorised access:

  • Technical information about your connection, including the IP address a request came from and the network it belongs to
  • Sign-in attempts and whether they succeeded or were refused
  • Records of the API keys issued for your organisation — when one was created, changed or revoked, and when a request using it was accepted or refused
  • Records of when a shared document link was opened

We collect or use the following personal information for dealing with queries, complaints or claims:

  • Names and contact details
  • Addresses
  • Payment details
  • Account information
  • Purchase or service history
  • Customer or client accounts and records

Documents you upload

Ragextract works on documents you provide. Those documents, and anything extracted from them, are your content. We process them as a processor on your behalf, for the sole purpose of providing the service to you.

  • What we do with them. An uploaded document is read, split into pages, rendered to page images and indexed so that questions can be answered from it. When a table is run, the relevant pages are sent to a language model provider to produce an answer and a citation back to the page.
  • We do not train on your content. Your documents and the answers extracted from them are not used to train our models or our providers’ models.
  • Who can see them. Documents live inside a workspace and are private to it. Access is granted per workspace by you or your organisation’s administrators. Our staff do not access your documents except where you ask us to in order to resolve a support issue, or where we are legally required to.
  • If you upload personal or special category data belonging to other people, you are the controller of it and you are responsible for having a lawful basis to share it with us. Please see our Acceptable Usage Policy for what may not be uploaded.
  • Documents sent by email. Your organisation can create a mailhook — a private email address that adds attachments to one table. A mailhook does not exist unless someone in your organisation creates one, and it accepts mail only from the sender addresses you put on its list. Everything else is rejected. Attachments that are accepted become documents in that workspace and are treated exactly as any other document described here, including for deletion. We record the sender’s address, the time and the size of each message so that you and we can tell how a document arrived and can spot misuse of the address — but we do not store the subject line or the body of the message. If you put someone else’s address on that list, the same responsibility applies as for anything else you put into Ragextract.
  • Documents from a folder you connect. Your organisation can connect a folder in its own document store — Google Drive or Microsoft SharePoint — so that the files in it become documents. The connection uses an account you create in your own cloud tenant and share the folder with, so you decide what we can reach and can change it without us. We hold the credential for that account encrypted, and it is tied to your organisation so it cannot be used anywhere else; deleting the connection deletes it, and disabling the account in your own console ends our access whichever we do first. Files copied in are treated exactly as any other document described here, including for deletion. Folder and file names come across too and are shown as labels in the product, so a folder named after someone puts that name into the interface — worth knowing before you connect a folder whose names are themselves personal information.
  • Deleting. You can delete a document or a table at any time from within the application, and archiving a workspace can delete its documents with it. Deletion is not instantaneous: the document is withdrawn from the service immediately, and a clean-up process running twice daily then removes the stored file, the page images and the search index entries. Copies can survive in routine backups for a short time after that: up to 30 days for related records in our database, and up to 7 days for the search index, before each is overwritten in the ordinary course. Backups are not used for anything other than recovery, and what you delete from the service is not restored from them.

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights, which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

  • Your right of access — You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which mean you may not receive all the information you ask for.
  • Your right to rectification — You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete.
  • Your right to erasure — You have the right to ask us to delete your personal information.
  • Your right to restriction of processing — You have the right to ask us to limit how we can use your personal information.
  • Your right to object to processing — You have the right to object to the processing of your personal data.
  • Your right to data portability — You have the right to ask that we transfer the personal information you gave us to another organisation, or to you.
  • Your right to withdraw consent — When we use consent as our lawful basis you have the right to withdraw your consent at any time.

If you make a request, we must respond to you without undue delay and in any event within one month. To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Consent — we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract — we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

Our lawful bases for collecting or using personal information for information updates or marketing purposes are:

  • Consent — we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

Our lawful bases for collecting or using personal information to keep accounts secure and detect unauthorised access are:

  • Legitimate interests — we use this information because protecting accounts, and the documents held in them, benefits you and every other customer, and it does not create an undue risk to anyone. Our legitimate interest is detecting and investigating unauthorised access to the service. All of your data protection rights may apply, except the right to portability. That includes the right to object, which you can exercise using the contact details at the top of this notice.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

  • Consent — we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract — we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

Where we get personal information from

  • Directly from you
  • Automatically from your device when you use the service — for example the IP address a request came from
  • From your organisation’s administrator, where you are invited to a Ragextract workspace
  • From Google or GitHub, where you choose to sign in with one of those providers
  • From anyone who sends email to a mailhook address your organisation has created — we record the sender’s address whether or not the message is accepted, because an address that is refused is the thing worth being able to look at
  • From a document store your organisation connects — the files in the folder you share, together with their names, the names of the folders holding them, and the account your organisation shared them with

Who we share information with

We use the following sub-processors to run the service. Each is used only for the purpose shown, and we remain accountable for the personal data we entrust to it.

Where you choose to sign in with Google or GitHub, those providers confirm your identity to us. They are not our sub-processors for that purpose — they decide independently how they handle your use of their own accounts, and their own privacy notices govern it.

When you buy credits, the payment is taken by Stripe on its own pages. We never see or hold your card details. Stripe is not our sub-processor for this either: it decides for itself how it handles payments, and the tax calculation that goes with them, under the financial regulation that applies to it, so it is a controller of that information in its own right and its own privacy policy governs it. What reaches us is a record of the purchase — what was bought, the amount, and the tax — so that we can add the credits to your account and issue you an invoice.

You can connect an AI assistant or another tool to Ragextract using MCP, so that it can work with your data on your behalf. Nothing is connected unless someone in your organisation sets it up: you choose the tool, you authorise it, and you can disconnect it at any time from your account settings. A connection is granted for one organisation at a time and can read that organisation’s workspaces, documents, tables and extracted values — it cannot change or delete anything. A tool you connect is not our sub-processor: we do not choose it, instruct it or have any arrangement with it, in the same way that the browser you read the same information in is not. One thing worth knowing before you connect something: if the tool is a hosted service rather than software running on your own machine, then what it reads is processed on that provider’s systems under your agreement with them, not ours.

Sub-processors, what each is used for, and where it processes data.
ProviderPurposeLocation
Cloudflare, Inc.Hosting, CDN, application database, document storage, transactional emailEU (database and document storage); global network for request handling
Hetzner Online GmbHHosting for the document processing pipeline and the search indexFinland (EU)
OpenRouter, Inc.Routing extraction requests to large language model providersUS
Voyage AIGenerating embeddings from document pages so they can be searchedUS
PostHog, Inc.Product analytics and error reporting for the application (not the website)US
Google Ireland LimitedWebsite analytics for ragextract.com (Google Analytics), only where you consent to itGlobal network, including the United States

Where a sub-processor is outside the UK or EEA, transfers are made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

Where your data is stored

Your documents, the page images we generate from them, and your account, billing and extraction records are held in the European Union. Our database and our document storage are provisioned as EU-restricted resources, which is a property set when they are created and cannot be changed afterwards. Document processing and the search index run on servers in Finland.

Two things are deliberately not covered by that sentence, because they are not true of them. Our application code runs on Cloudflare’s global network, at the location nearest the person making the request — so while your data is stored in the EU, it is processed in transit wherever you are. And a small internal lookup table, holding references to stored files rather than the files themselves or any personal information, is replicated globally.

Cookies and similar technologies

A cookie is a small file that a website asks your browser to store. We use as few as we can, and they fall into two groups.

Strictly necessary cookies are set without asking, because the service cannot be provided without them. There are two. One keeps you signed in to the application. The other records the cookie choice you make, so that we do not put the question in front of you on every page.

Analytics cookies are set only if you agree. We use Google Analytics on ragextract.com to count visits and see which pages get read. The Google Analytics tag is not loaded, and no request is made to Google, unless and until you accept it. If you decline, or if you simply leave the question unanswered, nothing is loaded and nothing is stored on your device. Our lawful basis is your consent.

You can change your mind at any time using the Cookie settings link in the footer of any page. Withdrawing your consent stops the analytics immediately and deletes the analytics cookies from your device; it is as easy as giving it, and it costs you nothing — every part of this website works the same either way.

We set no advertising, personalisation or cross-site tracking cookies on this website or in the application, and we do not use cookies to build a profile of you.

We also use a product analytics service (see the sub-processor table above) to understand how the application is used and to be told when it fails. It runs on our servers rather than in your browser: it sets no cookie and stores nothing on your device.

Cookies set by this site and the Ragextract application, their provider, purpose, lifetime, and whether they are optional.
NameProviderPurposeDurationCategory
__Secure-better-auth.session_tokenRagextractKeeps you signed in to app.ragextract.com. Set only after you sign in.Until you sign out, or the session expiresStrictly necessary
ragextract_cookies_consentRagextractRecords whether you accepted or declined analytics cookies, so that you are not asked again on every page. Holds one word and no identifier.6 monthsStrictly necessary
_gaGoogle AnalyticsTells one browser from another, so that a repeat visit is not counted as a new visitor. Set only if you accept analytics.13 monthsAnalytics — optional
_ga_G0SH65WMXHGoogle AnalyticsHolds the state of your current visit for the ragextract.com property. Set only if you accept analytics.13 monthsAnalytics — optional

How long we keep information

Account and billing records are kept for as long as your account is open, and afterwards for as long as we are required to keep them for tax and accounting purposes.

Documents you upload are kept until you delete them, or until we close your account at your request. We do not delete them on a schedule of our own, so a document you leave in place stays available to you.

The security records described above — sign-in attempts, API key activity, connection details and messages received at a mailhook address — are kept for 180 days and then deleted automatically. We keep them long enough to investigate a security incident that comes to light some time after it happened, and no longer.

For more information on how long we store your personal information, or the criteria we use to determine this, please contact us using the details provided above.

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline number: 0303 123 1113
Website: ico.org.uk/make-a-complaint