Privacy Policy

Last updated: February 18, 2026

EPM Agent ("we", "our", or "us") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered Oracle EPM assistant service.

1. Information We Collect

Account Information: When you create an account or request a demo, we collect your name, email address, company name, job title, and phone number.

Usage Data: We collect information about how you interact with EPM Agent, including queries made, features used, and session duration. This data is used to improve the service and is not shared with third parties.

EPM Metadata: To provide our service, we store EPM metadata (dimension names, member names, hierarchies, and aliases) in your dedicated instance. This metadata is used exclusively for your organization's queries.

Technical Data: We automatically collect IP addresses, browser type, device information, and access timestamps for security and performance monitoring.

2. Information We Do NOT Collect

Financial Data: EPM Agent queries your Oracle EPM environment in real-time and returns results directly to you. We do not store, persist, or log your financial data values. Query results are transient and not retained after your session.

EPM Credentials: Your Oracle EPM credentials are encrypted using Fernet (AES-128) encryption and stored in your isolated instance. We do not have access to your plaintext credentials.

3. How We Use Your Information

  • To provide and maintain the EPM Agent service
  • To process your demo requests and communicate with you
  • To improve our AI models and service accuracy (using anonymized, aggregated data only)
  • To monitor and prevent security threats
  • To comply with legal obligations

4. Data Sharing

We do not sell, trade, or rent your personal information. We may share data with:

  • Service Providers: Cloud hosting providers, analytics services, and email delivery services that help us operate our business, bound by confidentiality agreements.
  • AI Model Provider: Queries are processed by Anthropic's Claude AI. Anthropic does not use customer data to train models. See Anthropic's privacy policy for details.
  • Legal Requirements: We may disclose information if required by law, regulation, or legal process.

5. Data Security

We implement industry-standard security measures including:

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Single-tenant architecture with isolated instances per client
  • Role-based access control and two-factor authentication
  • Regular security audits and monitoring
  • Comprehensive audit trails for all sensitive operations

6. Data Retention

Account Data: Retained for the duration of your subscription plus 30 days after termination.

Usage Data: Retained for 12 months in anonymized form for service improvement.

EPM Metadata: Retained in your isolated instance for the duration of your subscription. Deleted within 30 days of subscription termination.

Conversation History: Retained for 30 days within your instance for context continuity, then automatically purged.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability
  • Withdraw consent at any time

To exercise these rights, contact us at privacy@epmagent.com.

8. Cookies

Our marketing website uses minimal cookies for essential functionality (session management, form submissions). We do not use third-party tracking cookies. The EPM Agent application uses JWT tokens stored in local storage for authentication.

9. International Data Transfers

Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required.

10. Children's Privacy

EPM Agent is a business-to-business service and is not directed at individuals under 18. We do not knowingly collect information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy, please contact us:

  • Email: privacy@epmagent.com
  • Website: epmagent.com/contact