Legal

PRIVACY
POLICY

Last updated: July 2, 2026

RGX Systems ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect about our Partners, how we use it, and your rights. By using our infrastructure, you agree to this policy.

1. Who We Are

RGX Systems provides Automated AI Data Leakage Protection — a compliance and workspace infrastructure layer — to approved Partners (Value-Added Resellers and MSPs). Partners build their own products and services on top of our infrastructure and are solely responsible for their relationships with their own clients.

This policy covers data RGX Systems collects about its Partners. It does not govern the data Partners process on behalf of their own clients — Partners are independently responsible for their data practices and compliance obligations toward their end users.

2. Data We Collect

Partner Account Information

Usage Data

Every request authenticated against your workspace is logged for billing and operational purposes:

We do not log the content of your payloads — message text, contact names, and other payload data are processed in memory and not persisted to our database unless you explicitly pass them as metadata fields.

Application Data

3. How We Use Your Data

We do not sell your data. We do not use payload data for model training or third-party profiling. Your business data is yours.

4. PHI Handling and HIPAA Compliance

Zero PHI Persistence. When the healthcare industry profile is active, Protected Health Information is scrubbed from input text in-memory before any LLM call or database write. Raw PHI is never written to our database, log files, or transmitted to any LLM provider.

How PHI Is Processed

When a Partner submits a request to /api/v1/process with config.industry: "healthcare":

Business Associate Agreement (BAA)

RGX Systems will execute a Business Associate Agreement with any Partner whose clients operate in the healthcare sector. Render Services, Inc. (our infrastructure provider) has executed a HIPAA BAA with RGX Systems, establishing the required chain of agreements. To request a BAA, contact legal@rgxsystems.com or visit /baa.

PII Scrubbing — Professional Services, Finance, and Legal

When config.industry is set to "professional_services" or "finance", our Compliance Engine additionally redacts EINs, SSNs, account numbers, routing numbers, and payment card numbers before any LLM call, replacing them with {{REDACTED_FIN_N}} tokens; "legal" redacts privilege markers and case identifiers as {{REDACTED_LEG_N}}. Same zero-persistence guarantee applies, and person names are tokenized as described above regardless of which of these applies.

Technical Reference

For a full technical description of data movement through each processing stage, see the RGX Data Flow Diagram.

5. Non-Training Data Policy

RGX Systems does not use Partner payload data to train machine learning models. Specifically:

6. Pipeline Processing

When you call the /process endpoint with gateway routing enabled (by providing config.industry and config.routing_profile), input data is scrubbed of PHI/PII and person names before it is forwarded to our LLM provider under a data processing agreement that prohibits use of submitted data for model training.

If you use passthrough: true to run your own AI model instead of ours, we do not forward your data to any LLM ourselves — but the same scrubbing still applies before we hand the text back to you: PHI/PII patterns for your configured industry are replaced with numbered tokens, and person names are separately tokenized. This is so that no party's model, ours or yours, ever receives a raw name or a raw regulated identifier. In this mode, RGX Systems never reverses a name token back to the original value — the temporary, in-memory mapping used to keep the same name consistent across a conversation is purged automatically (30 minutes of inactivity, or immediately for a single-turn request) and is never written to disk, logs, or our database. See Section 4 for the equivalent detail on PHI/PII tokens.

7. Data Storage and Security

9. Subprocessors and Data Sharing

We share data only with the following trusted subprocessors necessary to operate our infrastructure. Each subprocessor operates under a data processing agreement with RGX Systems:

We do not share your data with any other third parties, advertisers, or data brokers. Our full subprocessor list is available on request at security@rgxsystems.com.

10. Data Retention

11. Seat-Metering Audit Rights

Partner audit rights for seat billing are guaranteed. Partners have the right to audit their seat-metering data at any time via API or by requesting a formal billing export. RGX Systems will not dispute a billing discrepancy without providing machine-readable evidence.

What Is Metered

The Seat Metering Ledger (GET /api/v1/usage, GET /api/v1/billing/summary) records the following per tenant workspace:

Partner Audit API Access

Partners may query their seat ledger at any time:

All billing responses are returned as structured JSON and may be downloaded by Partners for independent verification. Responses include a billing_period, seat_count, per_seat_rate, and a line_items array with one entry per active seat.

Dispute Resolution

If you believe your seat count is incorrect, contact billing@rgxsystems.com within 14 days of invoice with the disputed month and your independently counted seat list. RGX Systems will respond within 5 business days with a line-item billing export. If the export confirms a metering error, a credit will be applied to the following invoice. RGX Systems will not charge a disputed seat without providing log-level evidence of authenticated activity.

12. Your Rights

As a Partner, you have the right to:

To exercise any of these rights, contact us at privacy@rgxsystems.com.

13. Cookies

Our public website uses minimal cookies necessary for session management. The API does not use cookies — all authentication is via the Workspace Security Token in the X-Api-Key header. We do not use tracking cookies or third-party advertising cookies.

14. Business-to-Business Service

RGX Systems is a strictly business-to-business infrastructure service. We do not knowingly collect or process data from individuals under 18, and we do not provide consumer-facing products or services.

15. Changes to This Policy

We may update this policy from time to time. We will notify Partners of material changes via email. Continued use of the infrastructure after changes constitutes acceptance of the updated policy.

16. Contact

For privacy-related questions or requests, contact us at:

Email: privacy@rgxsystems.com
Website: rgxsystems.com