プライバシーポリシー
最終更新:2026年8月20日。
This Privacy Policy describes how EDGE Sword Inc.("EDGE Sword", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit our websites, use our knowledge base, interact with our documentation assistant, or use the EDGE Sword platform and related services (collectively, the "Services").
EDGE Sword is a product of AYSHX Inc.(and its affiliates, including AYSHX (Private) Limited) (together, "AYSHX"). Where AYSHX provides development, support, or infrastructure services for EDGE Sword, it may process personal information on our behalf as described below.
By using the Services, you acknowledge this Privacy Policy. If you do not agree, please do not use the Services. For our contractual terms, see the Terms of Service.
1. Who we are and scope
1.1 Controller
For personal information we collect through our marketing site (https://www.edgesword.com), documentation / knowledge base, newsletter and contact forms, cookie preferences, and account administration for our own customers, EDGE Sword Inc. is the data controller (or equivalent under applicable law).
1.2 Processor role (Customer Data)
When a business customer ("Customer") uploads or generates data in their EDGE Sword workspace ("Customer Data"), we generally act as a processor(or service provider) on the Customer's behalf. The Customer is the controller of that data. Processing of Customer Data is governed by the Customer's agreement with us, including any Data Processing Addendum ("DPA") we enter into with the Customer.
1.3 Contact
- Privacy requests: privacy@edgesword.com
- Data Protection Officer: dpo@edgesword.com
- Legal: legal@edgesword.com
- AYSHX licensing: legal@ayshx.com
- Postal: EDGE Sword Inc · 548 Market St · San Francisco, CA, United States
2. Information we collect
2.1 Information you provide
- Account and workspace data: name, email, phone, role, authentication credentials (including passkeys / WebAuthn where enabled), company or workspace identifiers, and billing contacts.
- Customer Data: CRM, sales, HR, inventory, messaging, calendar, tickets, media, and other business records you or your Users enter into the platform.
- Communications: support requests, documentation bot tickets (name, email, message, and conversation summary), sales or contact inquiries, and email correspondence.
- Marketing preferences: newsletter signup email and marketing consent choices where offered.
- Payment information: processed by third-party payment providers; we do not store full card numbers on our servers.
2.2 Information collected automatically
- Usage and device data: pages viewed, features used, approximate location derived from IP, browser type, device and OS, referrer, timestamps, and error logs.
- Cookies and similar technologies: essential preferences (for example, cookie consent stored in local storage) and, if you opt in, analytics cookies / tags.
- Local and session storage: site preferences such as documentation theme, module filters, and cookie consent state (`edge.consent.v1`). Guest booking details may be stored locally in the product for convenience.
2.3 Information from integrations you connect
If a Customer connects third-party services, we process data those services provide as authorized by the Customer, which may include:
- Meta (Facebook) Lead Ads and Pages: page lists, lead form responses (name, email, phone, custom fields), and related metadata.
- WhatsApp Business / Meta messaging: message content, phone numbers, delivery status, media, and business profile data.
- Twilio (SMS / voice / WhatsApp where configured): message and call metadata needed to deliver communications.
- Google (Calendar, Meet, Maps / geocoding, OAuth, Wallet where configured): calendar events, attendees, location lookups, and account identifiers.
- Slack OAuth: workspace and user identifiers needed for connected features.
- Clearbit or similar enrichment: company enrichment attributes.
- Accounting / ERP (e.g. Sage 200): financial and master data sync fields configured by the Customer.
- Firebase Cloud Messaging: device push tokens for notifications.
2.4 Meridian desktop agent (Customer Data)
If a Customer enables the Meridiandesktop app for time tracking, we process additional Customer Data generated on the User's device while they are clocked in, as configured by the Customer (organization-wide, by department, or by person):
- App activity: active application name, window title, URL where available, idle vs active time, and related session metadata. On macOS this requires the Accessibility permission the User grants to the app.
- Screenshots: periodic images of connected displays, attached to the activity report for that shift (capped per session). On macOS this requires Screen Recording permission. Optional on-device OCR may black out detected card numbers, emails, phone numbers, and similar identifiers before upload if the Customer enables PII redaction.
- Connection tests: optional internet speed measurements (download, upload, latency) attached to the activity report.
The Customer is the controller of Meridian capture data. EDGE Sword is the processor. Employees cannot turn capture off in the desktop app; they can refuse OS permissions, which means those features will not run. Capture is intended to stay off when the User is clocked out. Screenshots may include whatever is visible on screen, including personal or third-party content, especially on a personal (BYOD) device.
3. How we use information
We use personal information to:
- Provide, operate, secure, and improve the Services
- Authenticate users, enforce access controls, and prevent abuse or fraud
- Process subscriptions, invoices, and usage-based charges
- Respond to support tickets and documentation questions (including via AI assistants)
- Send service, security, and (with consent where required) marketing communications
- Translate or localize documentation content for non-English locales
- Analyze aggregated usage to improve reliability and product design
- Comply with law, enforce agreements, and protect rights and safety
We do notsell personal information. We do not use Customer Data to train general-purpose AI models for unrelated third parties without the Customer's explicit permission.
4. Legal bases (EEA, UK, and similar laws)
Where the GDPR or UK GDPR applies, we rely on one or more of the following bases:
- Contract: to provide the Services you or your organization requested
- Legitimate interests: to secure and improve the Services, prevent abuse, and communicate about product updates, balanced against your rights
- Consent: for non-essential cookies / analytics (e.g. Google Analytics GA4), certain marketing emails, and optional AI features where consent is required
- Legal obligation: to meet tax, accounting, or regulatory requirements
Where we act as a processor for Customer Data, the Customer is responsible for establishing a lawful basis for processing end-user or employee data within their workspace — including workplace monitoring via Meridian (screenshots and app activity). In employment, "consent" is often not a valid GDPR basis because of the imbalance of power; Customers should not rely on a checkbox in Meridian as their only lawful basis.
5. Cookies and analytics
Our marketing and documentation sites use essential storage so the site functions (including remembering your cookie preferences). If you choose "Allow analytics," we load Google Analytics 4 to measure traffic and improve the site. You can change your choice anytime via Cookie settings in the footer.
Analytics providers may set their own cookies and process IP addresses and device data under their policies. Rejecting analytics does not disable essential site functionality.
6. AI-assisted features
- Documentation / knowledge bot (EDGEWeb): questions and recent chat context may be sent to our AI provider (currently OpenAI) to generate answers. Support tickets opened from the bot may include your name, email, message, and a conversation summary emailed to our support team (operated with AYSHX support).
- In-product AI: depending on Customer configuration, features may use OpenAI, Anthropic, Google Gemini, or similar providers for tasks such as search, document understanding, or automation. Prompts and necessary context are transmitted to those providers solely to deliver the feature.
- Translation: English knowledge-base content may be sent to DeepL (or a similar provider) to produce localized articles.
AI providers process data under their terms and our contracts with them. Do not submit sensitive personal data to AI features unless necessary and permitted by your organization.
7. Sharing and sub-processors
We share personal information with vetted service providers who process it on our instructions, under appropriate confidentiality and data-protection terms. Categories include:
| Category | Examples | Purpose |
|---|---|---|
| Website hosting | Vercel | Host marketing site, docs, and related edge functions |
| Application hosting | Railway (API, workers, cron, ingestion services) | Run application servers and background jobs |
| Databases & cache | MongoDB, Redis | Store application and tenant data; queues and caching |
| Object storage & CDN | MinIO-compatible storage (e.g. storage.edgesword.com), CDN (e.g. cdn.edgesword.com) | Store and deliver media, attachments, and static assets |
| Email delivery | Resend; SMTP / SendGrid where configured | Transactional and support email |
| Analytics | Google Analytics (opt-in); PostHog (product / API telemetry) | Traffic and product analytics |
| AI & translation | OpenAI, Anthropic, Google Gemini, DeepL | Docs bot, in-product AI, localization |
| Communications | Meta, Twilio, Firebase Cloud Messaging | Messaging, SMS/voice, push notifications |
| Identity & maps | Google OAuth / Maps; Slack OAuth | Sign-in and location features you enable |
| Payments | Stripe or other gateways selected by Customer | Billing and invoicing |
| Parent / affiliate support | AYSHX Inc. and affiliates | Engineering, support, and operations for EDGE Sword |
We may also disclose information:
- To other users in your tenant according to roles and permissions
- To comply with law, lawful requests, or to protect rights, safety, and security
- In connection with a merger, acquisition, financing, or sale of assets
- With your or the Customer's direction or consent
8. International transfers
We and our sub-processors may process personal information in the United States and other countries. Where we transfer personal information from the EEA, UK, or Switzerland to a country not deemed adequate, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) (and UK addenda where applicable), plus supplementary measures as needed.
Enterprise Customers may discuss regional hosting options and DPIA support with us under a DPA. Availability of a specific region depends on the Customer's order form or enterprise agreement.
9. Retention
- Account and Customer Data: retained while the subscription is active. After termination or verified deletion, we generally delete or anonymize within about 30 days, except data we must keep for legal, tax, or security purposes (for example, limited audit logs).
- Self-service deletion: Customers / users may request account or data deletion via the product termination flow (typically emailed verification; deletion begins after confirmation and completes within approximately 7–30 days).
- Integration data: when you disconnect Meta / WhatsApp or similar integrations, associated data is typically retained up to 30 days for recovery, then deleted unless law requires longer retention.
- Meridian activity reports:app sessions, screenshots, and optional speed tests are retained with the Customer's time-card / activity records for as long as the Customer keeps that workspace data (and any shorter product caps, such as a maximum number of screenshots per shift). After workspace termination, the same ~30-day recovery then deletion window applies unless law requires longer retention.
- Docs chat: conversational context is used to generate replies and is not intended as a long-term personal archive; ticket summaries emailed to support are retained as support records.
10. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS) and encryption at rest for stored data where applicable
- Authentication controls (including JWT sessions, optional MFA / WebAuthn passkeys, SSO where enabled)
- Role-based access control and multi-tenant isolation
- Access logging, backups, and operational monitoring
- Vendor due diligence for sub-processors
No method of transmission or storage is perfectly secure. Please use strong credentials and report suspected incidents to privacy@edgesword.com.
11. Your rights
11.1 General
Depending on your location, you may have rights to access, correct, update, export, restrict, object to, or delete personal information, and to withdraw consent where processing is consent-based. Email privacy@edgesword.com. We respond within 30 days where required (or sooner if local law requires).
11.2 EEA / UK GDPR
You may also have the right to lodge a complaint with your local supervisory authority. You may contact our DPO at dpo@edgesword.com.
If we process your data solely as a processor for a Customer, please contact that Customer (your employer or service provider) first; we will assist them in responding as required by our DPA.
11.3 California (CCPA / CPRA) and similar US state laws
We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined. California residents may request know, delete, and correct rights, and may designate an authorized agent. We will not discriminate against you for exercising privacy rights.
11.4 Marketing and cookies
- Unsubscribe from marketing emails via the link in the message or by contacting us
- Manage analytics cookies via Cookie settings in the site footer
12. Children
The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us and we will take appropriate steps to delete it.
13. Third-party sites and embedded content
The Services may link to third-party websites or embed content (for example, video players). Those parties' privacy practices are governed by their own policies. We are not responsible for their content or practices.
14. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page will change when we do. Material changes may be communicated by email, in-product notice, or a notice on our website. Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.
15. Contact
EDGE Sword Inc. · 548 Market St · San Francisco, CA, United States
Privacy: privacy@edgesword.com
DPO: dpo@edgesword.com
General: hello@edgesword.com
EDGE Sword is a product of AYSHX Inc. For AYSHX licensing inquiries: legal@ayshx.com.