Skip to policy content

HUCKSTER POLICY DRAFTS

Privacy, terms, DPA, subprocessor, retention, and AI disclosure drafts.

These are customer-evaluation drafts designed to answer buyer diligence questions without overstating legal readiness. They are not final contractual terms until reviewed and approved.

Important review boundary

Huckster can publish conservative policy drafts and disclose current technical posture. Final privacy policy, terms, DPA, subprocessor list, retention/deletion commitments, and AI data-use commitments still require legal/privacy/security review before contractual reliance.

Download the consolidated lawyer-review packet

Privacy policy draft

Draft for review
  • Huckster processes account information, tenant-scoped vendor review records, uploaded vendor evidence, AI-assisted findings, reviewer decisions, exports, and audit events.
  • Data is used to operate the compliance workspace, generate review assistance, preserve source context, support human decisions, and provide buyer-ready exports.
  • Admins can delete active review evidence from the workspace. Deletion actions are recorded in the audit trail.
  • Backup retention, legal hold, post-termination deletion, and customer-specific retention commitments require final policy approval before contractual use.

Terms of service draft

Draft for review
  • Huckster provides AI-assisted vendor compliance review workflow software; it does not provide legal, insurance, procurement, or security advice by itself.
  • Customers remain responsible for final vendor approval, rejection, escalation, accepted-risk decisions, and use of exported materials.
  • Users must not upload unlawful content or use Huckster to make automated vendor approval decisions without human review.
  • Availability, support, service credits, indemnity, liability limits, and enterprise identity commitments require approved commercial terms.

Data processing addendum outline

Draft outline
  • Processing purpose: operate a tenant-scoped vendor evidence review workspace and related exports.
  • Data categories: account data, vendor evidence, findings, source excerpts, decisions, notes, exports, and audit events.
  • Security measures: authenticated access, role-based permissions, tenant scoping, password hashing, private evidence storage design, audit logging, and human approval control.
  • Open items: approved subprocessors, transfer terms, audit assistance, breach-notification language, retention, deletion, legal hold, and customer return/export obligations.

Subprocessor disclosure draft

Deployment-dependent
  • Hosting and managed database provider: Render-hosted frontend/API and database services in the current deployed environment.
  • Private object storage provider: configured AWS S3 bucket for uploaded vendor evidence; latest storage proof shows region and security posture in retained evidence artifacts.
  • AI processing provider: AI-assisted analysis uses the configured AI provider only when assessment features are enabled.
  • Final customer-facing subprocessor commitments must include active provider names, regions, roles, transfer posture, and legal review.

Retention and deletion draft

Draft for review
  • Active workspace review evidence can be deleted by admins through the app when storage deletion succeeds.
  • Deletion produces an audit event and deletion receipt so the workspace can prove the action occurred.
  • Audit events may remain after active review deletion to preserve security and compliance history.
  • Backup purge timing, legal hold exceptions, post-termination deletion, and customer-specific retention windows require final policy approval.

AI and data-use disclosure draft

Draft for review
  • Huckster uses AI to assist evidence review by extracting signals, drafting findings, identifying gaps, and preserving source context when readable evidence exists.
  • AI output is not an approval decision. A human reviewer owns approval, rejection, escalation, accepted-risk, and evidence-request decisions.
  • Findings should be reviewed against source evidence; weak or missing source support is labeled for manual verification.
  • Provider-specific data-use, model-training, retention, and subprocessor language must be reviewed against the active AI provider terms before contractual reliance.