AdvisorOS Privacy Notice
AdvisorOS helps advisors manage leads, client workflow, appointments, follow-ups, calculator cases, product-library notes and client-safe presentation snapshots. The workspace is designed for data minimisation and controlled access.
Data we process
AdvisorOS may process advisor account details, organization/workspace details, lead names and contact details, client profile context, appointment notes, follow-up tasks, calculator inputs/outputs, product-library entries, client-safe snapshots, activity logs and security/session records.
Restricted data
Users must not store NRIC/FIN, passport numbers, bank login details, medical records, claim documents, official product application forms, passwords, or other unnecessary sensitive personal data in AdvisorOS.
Purpose of use
Data is used to operate the workspace, authenticate users, maintain owner/team access controls, support advisor preparation, generate discussion-support views, record follow-up work, maintain audit evidence, and respond to security or data-protection requests.
Access control
Advisor records are scoped to the logged-in user and their approved organization. Manager/admin roles may view team records for supervision and operations. Authorised platform staff may access account-level metadata (record counts, billing and support diagnostics) to provide support, security monitoring and billing; platform staff do not access individual client records except where needed to resolve a support request you raise, and such access is logged.
AI-assisted features
If you use the Portfolio Snapshot feature, the document images you upload are sent to our AI provider (OpenAI, United States) solely to extract policy details into structured fields. These images are not used to train AI models. Do not upload documents showing NRIC/FIN, passport numbers, medical diagnoses or other prohibited identifiers — redact them before uploading. Other AI-assisted features process only the specific inputs you provide for that feature.
Sub-processors
We use the following third-party providers to operate AdvisorOS. A current list is available on request from the Data Protection Contact below.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Application database, authentication and file storage | Confirm project region before publishing |
| Vercel | Application hosting and delivery | Global edge / configured region |
| Stripe | Subscription billing and payment processing | Global (Stripe) |
| OpenAI | AI-assisted extraction of policy data from documents you upload to Portfolio Snapshot | United States |
| Resend | Transactional and notification email | Global |
| PostHog | Product analytics on logged-out marketing pages | European Union |
| Sentry | Error monitoring (sanitised — no client data) | Configured region |
| Meta | Advertising conversion measurement on public marketing pages only | Global (Meta) |
Retention, correction and deletion
Unless a longer period is required by law, client records are retained while the organization’s account is active and for up to 90 days after cancellation to allow for export, after which they are deleted. Each organization remains responsible for handling access, correction, deletion and withdrawal requests for its own clients consistently with its legal, compliance and dispute-handling obligations. To request an export or deletion, contact the Data Protection Contact below.
Data breach
If a data breach affecting your data occurs, we will notify you without undue delay after confirming it, and cooperate with any notification you are required to make to the PDPC or your clients.
Contact
Organization: AdvisorOS
Data Protection Contact: AdvisorOS Data Protection Contact
Email: admin@advisoros.space