Trust

Data handling & security

RafiHive is built for a regulated audience, so where your data lives and how it is used is a first-class concern. This page summarises our current posture.

EU processing

Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1).

No model training

Questions and answers are processed to generate your response and are not used to train foundation models. The same applies to documents you upload.

Encrypted and workspace-isolated

Encryption in transit (TLS) and at rest, and a person outside your team cannot browse, search, attach or receive citations from your documents.

Delete anytime

The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.

EU data residency

Application data (accounts, conversation history, generated exports) is stored and processed in the EU (AWS eu-west-1). AI responses are generated by Amazon Bedrock in an EU region. We do not move regulated content to non-EU regions.

Your data is not used to train models

Questions and answers are processed to generate your response and are not used to train foundation models. The same applies to documents you upload. Amazon Bedrock does not use inputs or outputs to train its base models.

Your uploaded documents

Private documents stay in the workspace you choose.

Your documents are protected while they are sent to RafiHive and while they are kept for you. They are separated from every other team and personal workspace, and RafiHive checks that separation again whenever a document is listed, used in an answer or removed.

You choose where it can be used

Keep a file inside one conversation, or deliberately make it available to your private team or personal knowledge.

Other workspaces cannot see it

A person outside your team cannot browse, search, attach or receive citations from your documents. Personal admin documents are visible only to that admin.

It is used to answer, not to train

Your file is used only to provide the RafiHive features you selected. It is not advertising data and is not used to train foundation models.

You remain in control

The uploader can remove a document. RafiHive stops using it in answers immediately and completes removal from private storage and searchable knowledge.

This chat only

The document can be used only in that conversation. It remains in My uploads until you remove it, but it cannot appear in another chat.

Personal or team knowledge

The document can support future chats in the private workspace you selected. It stays available until its uploader removes it.

Uploaded documents are never sent to optional web search, and private document locations are never shown in answers.

Confidentiality, storage, deletion & export

Submitted questions, assistant answers, thread history and generated exports may be stored while your account is active so you can resume work and create audit-ready research trails. Export links are short-lived. Account deletion or export requests can be sent to info@rafihive.com; deletion is handled under the retention policy below and any signed customer agreement.

Confidential queries & web fallback

Retrieval is grounded in a curated knowledge base of official EU/EEA sources. An optional “safe web fallback” can be disabled, and confidential details are redacted from any query before it leaves the trusted source set. Do not submit personal data you are not permitted to share.

Encryption & access

  • Encryption in transit (TLS) and at rest (server-side encryption on S3 and DynamoDB).
  • Authentication via AWS Cognito; admin functions are role-gated at the API layer.
  • Exports are delivered as short-lived, pre-signed URLs.
  • A web application firewall (WAF) and rate limiting protect the public endpoints.

Retention

Conversation history and account data are retained while your account is active, then deleted or anonymised within 90 days of account closure — except where longer retention is legally required (e.g. billing and tax records). See our Privacy Policy for details and your GDPR rights.

Sub-processors

Amazon Web Services (hosting, AI, storage), Stripe (payments), LinkedIn (optional sign-in).

DPA & procurement review

Team and enterprise evaluations can request a data-processing agreement, security FAQ, sub-processor summary, source coverage snapshot and AI governance statement. Contractual commitments should be confirmed in the signed customer agreement.