Privacy Policy
Last updated · Lash Digital Solutions LLC
In short
- Process Ladder is software for organizations. Your organization decides what goes into its workspace and controls it; we store and process it on the organization’s behalf.
- We collect what we need to run your account and your workspace: your name, your email address, a one-way hash of your password, what your organization records in its workspace, and security records such as the IP address a sign-in came from.
- When someone in your workspace uses AI onboarding, the documents and answers they give it are sent to Anthropic’s Claude to draft your map. Anthropic does not use this data to train its models by default, and we never opt in. Nothing the AI drafts counts until a person confirms it.
- Uploaded files are stored encrypted. When someone deletes one, the stored file and the text read from it are deleted too.
- We do not sell personal information, we show no advertising, and we use no analytics or advertising trackers. The one cookie we set keeps you signed in.
This summary is here to help you read the full text below; the full text is what applies.
This Privacy Policy explains how Lash Digital Solutions LLC (“Lash Digital Solutions,” “we,” “us”) collects, uses, shares and protects information when you visit processladder.com or use Process Ladder at an organization’s workspace address (for example your-organization.processladder.com). Together, these are the “Service.”
Two roles matter throughout this policy. For the information about the people who sign up and sign in — accounts, sessions and security records — we decide how it is used, and this policy governs it. For the information an organization and its members put into their workspace — the process map, assessments, risks, people records, documents and everything else described as “Customer Data” in our Terms of Service — the organization decides, and we process it on the organization’s behalf. If your name appears in an organization’s workspace and you have a question about it, contact that organization; we will help it answer.
1.Information we collect
Information you give us
- Your account. Your full name, your email address, and your password — stored only as a bcrypt hash, so we never keep the password itself. We also keep whether you have confirmed your email address, when you last signed in, the workspaces you belong to, and your role in each (owner, administrator, editor, assessor or viewer).
- Signing up. The name of the workspace and the address you choose for it. Until you confirm your email address, that address is held for you for 48 hours, recorded against a one-way hash of your email address. A workspace is created only once its owner confirms the email address. If nobody confirms it, the hold and the unconfirmed account are deleted after the 48 hours.
- Workspace content (Customer Data). What your organization records in its workspace: its departments, functions, processes and sub-processes; process facts such as owners, performers, systems, written procedures and review dates; maturity, importance and risk assessments and the evidence notes that go with them; risk scenarios, safeguards and their ratings; treatment actions; metrics and their readings; disputes, comments and endorsements; and the workspace’s settings. It includes people records — the names, job titles and departments, and where entered, the email addresses of the people who own or carry out processes. Those people do not need an account, and the organization is responsible for having a lawful basis to record them.
- Documents. Links to documents, and files members upload (PDF, Word, Excel, CSV, plain text, Markdown, PNG and JPEG, up to 25 MB each). For each file we keep its name, its size and a fingerprint (SHA-256) used to notice the same file being uploaded twice.
- Onboarding. The files given to AI onboarding, the text we extract from them, the onboarding interview (the questions asked and the answers typed), and the drafts it produces with the passages they quote. We also record the size and cost of every AI request, so administrators can see their workspace’s AI usage.
- Workspace branding. The workspace’s name, logo, colour and tagline. These appear on the workspace’s sign-in page, which anyone who visits the workspace address can see.
- Messages to us. What you send when you email us.
Information collected automatically
- Sessions. When you sign in, we create a session record holding the IP address and browser description (user agent) it was opened from, when it started, when it was last used and when it expires.
- Audit log. A record of security events and changes — sign-ins and failed sign-ins, invitations, role changes, and edits to a workspace — with the account that acted, the time, the IP address, the browser description and a request identifier. Entries cannot be edited or removed through the Service.
- Abuse protection. Counters that limit how often a request can be repeated, keyed by IP address or, after failed sign-ins, by a one-way hash of the email address that was tried. They expire on their own.
- Error reports. When something breaks, our error-monitoring provider (Sentry) receives technical details of the failure. We configure it to leave out request bodies (so nothing you typed), cookies, session replays, and the codes and tokens carried in sign-in and email links; on our servers it also leaves out query strings and all but a few technical request headers.
Cookies and browser storage
We set one cookie and keep a few preferences in your browser’s own storage. None of them track you across other websites.
| Name | Where | What it is for | How long |
|---|---|---|---|
session | Cookie, sent only to your workspace’s address and unreadable by page scripts (HttpOnly) | Keeps you signed in. Strictly necessary. | 7 days, or until you sign out |
processladder.theme | Local storage | Remembers light or dark theme, if you pick one | Until you switch back to your system setting or clear your browser data |
processladder.map.… | Local storage | Remembers how you left the map in each workspace (the lens and which parts were open) | Until you clear your browser data |
processladder.assess.… | Local and session storage | Saves an unfinished assessment on this browser so your answers are not lost, and which processes you have finished in an assessment run | Removed when you submit it, discard it or start over, and whenever you sign out; never restored after 30 days |
- Name
session- Where
- Cookie, sent only to your workspace’s address and unreadable by page scripts (HttpOnly)
- What it is for
- Keeps you signed in. Strictly necessary.
- How long
- 7 days, or until you sign out
- Name
processladder.theme- Where
- Local storage
- What it is for
- Remembers light or dark theme, if you pick one
- How long
- Until you switch back to your system setting or clear your browser data
- Name
processladder.map.…- Where
- Local storage
- What it is for
- Remembers how you left the map in each workspace (the lens and which parts were open)
- How long
- Until you clear your browser data
- Name
processladder.assess.…- Where
- Local and session storage
- What it is for
- Saves an unfinished assessment on this browser so your answers are not lost, and which processes you have finished in an assessment run
- How long
- Removed when you submit it, discard it or start over, and whenever you sign out; never restored after 30 days
The sign-up page uses Cloudflare Turnstile to tell people from bots. It runs only on that page, and Cloudflare reads technical signals from your browser — such as your IP address and browser type — to make that check, under Cloudflare’s own Turnstile privacy terms. We use no analytics, advertising or cross-site tracking tools anywhere on the Service.
2.How we use information
We use information to:
- provide, run and support the Service, including keeping each workspace separate from every other;
- send the emails the Service depends on: confirming your email address, password resets, invitations to a workspace, and notices about sign-up attempts made with your address;
- show in-app notifications, such as an assessment waiting for your endorsement or a process due for review;
- draft a workspace’s map, risks and assessments with AI when a member runs onboarding (see section 3);
- detect, investigate and prevent abuse, fraud and security incidents;
- find and fix faults; and
- comply with the law and enforce our agreements.
We do not sell personal information, share it for targeted advertising, or use it to build advertising profiles. We do not train AI models on Customer Data.
3.AI onboarding
Process Ladder can draft a workspace’s map — its departments, functions, processes and people — and suggest risks, safeguards and assessments from documents and a short interview. It uses Anthropic’s Claude models to do this. AI runs only when a member of the workspace with permission to edit uses onboarding.
What is sent to Anthropic
- the answers typed into the onboarding interview;
- when someone starts a build: the text we extracted from the uploaded documents, and for images and scanned pages, the images themselves;
- the workspace’s name, sector, industry and size, and the role the person onboarding gave for themselves;
- the names already on the map (departments, functions and processes) and the names of people who appear in the document being read, so the draft reuses them instead of inventing duplicates; and, when drafting risks, the names of the workspace’s existing safeguards, risk scenarios and impact categories.
Uploading a file does not send it anywhere: we extract its text on our own servers, and nothing goes to Anthropic until someone starts a build or answers the interview. Beyond the workspace details listed above, we do not send your account details, your email address, or any user ID, workspace ID or workspace web address with the request.
How Anthropic handles it
Anthropic processes this content as our service provider. Anthropic states that, by default, it does not use inputs or outputs from its commercial API to train its models; the exceptions are when a customer reports feedback or chooses to allow it. The Service never sends feedback to Anthropic and has not opted in to any data sharing.
Drafts are suggestions
AI output can be wrong or incomplete. Everything onboarding drafts is marked as unconfirmed and shown for review, with the passage it was drawn from where there is one; quotes from text documents are checked against the document, and anything read from an image is labelled as not text-verified. Drafts do not count toward any score until a person confirms them, and a person can edit or reject any of them.
An organization that prefers not to use AI can build its map by hand; nothing is sent to Anthropic unless someone runs onboarding.
5.Where information is stored
The Service is run from the United States. Its database and files are stored with Amazon Web Services in the US East region. Requests reach it through Vercel’s network, and the providers listed in section 4 may process information in the United States. If you use the Service from outside the United States, your information is transferred to and processed in the United States.
6.How long we keep information
- Workspace content is kept while the workspace exists. Assessments and risk assessments are permanent dated records: a correction adds a new record, and the earlier one stays in the workspace’s history.
- Uploaded files are kept until someone in the workspace deletes them. Deleting a file removes the stored file — every stored version of it — and the text we extracted from it, and removes its quotes from any AI draft. A record that the document existed (its title, file name, who deleted it and when) stays in the workspace’s history.
- Onboarding interviews are kept with the workspace’s onboarding record while the workspace exists.
- Unconfirmed sign-ups are deleted once their 48-hour hold expires.
- Email links expire: email confirmation after 48 hours, password reset after 60 minutes, and invitations after 7 days. The one-time code that carries a sign-in to your workspace address expires after 60 seconds.
- Sessions end 7 days after you sign in, when you sign out, or when your password is reset (which ends every session). The record of a session is kept with the security records below.
- Audit log and session records are kept as long as we need them to secure the Service, keep a workspace’s history explainable, resolve disputes and meet legal obligations.
- Abuse-protection counters expire on their own: most within an hour, and a count of failed sign-ins for an email address a year after the last failure.
- Closing a workspace or an account. To close a workspace or delete your account, email privacy@processladder.com. We will delete the information except what the law requires us to keep. Deleted information can remain in encrypted database backups until those backups expire.
7.Security
We protect information with:
- encryption in transit (HTTPS) and encryption at rest for uploaded files (server-side encryption in Amazon S3);
- bcrypt password hashing, a temporary lock after repeated failed sign-ins, and limits on how often requests can be repeated;
- a session cookie that only your workspace’s address receives and page scripts cannot read, sessions that end on the server when you sign out, and a password reset that ends every session;
- separation between organizations enforced twice — in the application and again by row-level security in the database — so one workspace’s data cannot be read from another;
- roles that limit who can change what, and an audit log that cannot be edited through the Service; and
- checks on every upload: its real file type is verified, not just its name, and size limits apply.
No system is perfectly secure. If you think your account has been compromised, or you have found a vulnerability, email security@processladder.com. If we learn of a breach affecting your personal information, we will notify you and the affected organization as the law requires.
8.Your choices and rights
- In the Service. Anyone can reset their password from the sign-in page. In a workspace, members who can edit (editors, administrators and the owner) can correct its people records and delete its documents and uploads, and administrators can remove members.
- By email. To see the information we hold about you, correct it (including the name or email address on your account), get a copy, or have it deleted, email privacy@processladder.com from the address on your account. If your information is in a workspace you do not belong to, contact the organization that runs it; we will help it respond.
- Emails. The Service sends only emails it needs to work — confirmations, password resets, invitations and sign-up notices. It sends no marketing email.
- Browser storage. You can clear what the Service keeps in your browser at any time through your browser’s settings. Signing out clears saved assessment answers.
State privacy rights
Depending on where you live in the United States — for example California, Colorado, Connecticut, Virginia, Utah, Texas or Oregon — you may have the right to know what personal information we hold about you, to correct or delete it, to get a copy, and to opt out of its sale, of targeted advertising and of certain profiling. We do not sell personal information or use it for targeted advertising. To use any of these rights, email privacy@processladder.com. We will verify the request and respond within the time the law requires; you can appeal our decision by replying to it. We will not treat you differently for using your rights.
Outside the United States
Where the GDPR or UK GDPR applies, we rely on these legal bases: performing our contract with your organization (providing the Service), our legitimate interests (security, support and fixing faults), and our legal obligations. You have the rights described above, and the right to complain to your data-protection authority.
9.Children
The Service is for organizations and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.
10.Changes to this policy
We will update this policy when the Service changes what it collects, shares or keeps. When we do, we will change the date at the top; for a significant change we will tell workspace owners and administrators by email or in the Service before it takes effect. Using the Service after that date means the updated policy applies.
11.Contact us
Lash Digital Solutions LLC
330 3rd St S, Unit 1516
St. Petersburg, FL 33701
United States
Privacy requests: privacy@processladder.com
Security: security@processladder.com
Everything else: hello@processladder.com