Last updated September 5, 2026
Privacy Policy
This Privacy Policy explains how Lens Software LLC (“Company,” “we,” “us”), the provider of Cutova, handles data in connection with the Cutova service (the “Service”). Cutova is a hosted Model Context Protocol server that connects the AI client you choose to your Epicor Kinetic or Epicor Classic environment.
Cutova is a business-to-business service. This policy is informational. It describes our current practices; it is not a contract and it is not incorporated into the Cutova Software-as-a-Service Agreement. Our binding data commitments are in Section 8 of that Agreement and, where applicable, in our Data Processing Addendum.
Roles. For personal information contained in your data, you are the controller (or business) and we act as your processor (or service provider). We process your data only on your documented instructions, which are the Agreement, your Order, and the choices you make when you configure the Service.
Your Epicor data does not live here
Cutova is an access and integration layer, not a database of record, a backup, or an archive. Your ERP data resides in, and remains the responsibility of, your own Epicor environment. Cutova reads from and writes to Epicor on your behalf; it does not maintain an ERP record repository. Temporary uploaded or generated files may contain Epicor records.
The substantive contents of Epicor query results and Outputs are processed to complete your requests. We do not maintain a separate ERP record repository. Ordinary query responses pass through for the duration of the response. Uploaded and generated files are an exception: they are temporarily retained and deleted within thirty (30) days, or sooner where the Documentation specifies.
What we store
To provide the Service, we store:
- Account and organization records: your organization, users and invitations, and the identity of the person who accepts the Agreement.
- Epicor connection configuration: the instance URLs and settings you enter, and your Epicor service-account credentials, which are encrypted with AES-256-GCM at rest and decrypted only in memory at the moment we make a call for you.
- Tool and resource definitions, gateway registrations, and your subscription and billing records.
- Usage data: technical and operational metadata such as request counts, tool names, response sizes, row counts, timestamps, error codes and performance metrics. Usage data excludes the substantive contents or values of your data and Outputs.
- Operational logs: request values and credentials are excluded from diagnostic logging. Epicor error details are redacted before logging. Logs contain operational metadata and redacted diagnostic details. They are access-controlled and retained for no more than thirty (30) days.
- Uploaded and generated files: retained only transiently and deleted on the schedule described on our security page.
On the server, refresh tokens and gateway API keys are stored as SHA-256 hashes. The installed gateway protects its connection key with Windows data protection and restricted local access. Authentication uses OAuth 2.1 with PKCE and OpenID Connect. Every tool call executes under Epicor’s impersonation of the signed-in user, so Epicor records the operation against that user.
How we use data
We use the data we store to operate, secure, support, meter, bill for, and improve the Service. We may publish or disclose usage data only in aggregated and de-identified form that does not identify you, any user, or any natural person.
We do not train on your content, ever. We do not use your data to train, fine-tune, evaluate or otherwise develop any AI or machine-learning model, and we do not sell, rent or license your data to anyone. We do not permit any subprocessor to do so. This commitment is permanent and survives the end of your subscription. It is stated as a binding term in Section 3.7 of the Agreement.
Website analytics and cookies
Our public marketing website and documentation use Google Analytics to understand aggregate traffic, such as page views and referral sources. Analytics run under Google Consent Mode with storage denied by default, so no analytics or advertising cookies are placed on your device unless and until you consent; until then Google receives only cookieless, aggregated measurement signals. We do not use this analytics to identify you, and we do not combine it with the account data described above. The authenticated Cutova console and the Service itself do not run this analytics; it is limited to our public website and documentation. Google acts as our analytics provider for the website only.
AI clients you connect are not controlled by us
When you use the Service, your requests and the results are transmitted to the AI client you have chosen to connect (for example Claude, ChatGPT, Microsoft Copilot Studio, or another). From that point, that data is handled under your AI provider’s terms and privacy practices, not ours. Your AI client is a third party you select and engage directly. It is not our subprocessor. You are responsible for reading and complying with your AI provider’s terms, including what that provider may do with the data you transmit to it.
Optional AI schema descriptions
The optional description helper uses OpenAI by default. Deployments using a different compatible provider show that destination in the approval notice; its data terms apply. Before each request, an administrator reviews the provider, configured model, transmitted fields, and applicable data terms, then approves sending them. The helper sends the tool name, type and existing description, plus input and output field names, types and existing descriptions. Existing descriptions provide business context for the generated text. It does not automatically send query results. Names and descriptions can contain proprietary information. Administrators should review them before sending. Manual description editing does not use OpenAI.
This processing is separate from your connected AI client. OpenAI is our provider for this optional service, subject to our applicable subprocessor obligations. Our no-training commitment continues to apply. Provider retention follows the applicable OpenAI API data controls; this is not a promise of zero retention. See OpenAI data use and retention.
Subprocessors
We engage a small number of subprocessors to provide the Service, including infrastructure hosting, transactional email, and payment processing. Our current subprocessor list is published on our security page. We remain responsible for our subprocessors’ handling of your data. Section 8.4 of the Agreement governs advance notice, reasonable objections and the applicable termination/refund remedy for new subprocessors. Payment card processing is performed by a third-party payment processor under its own terms; we do not store full card numbers.
Security
We maintain administrative, physical and technical safeguards designed to protect your data, including encryption at rest (AES-256-GCM) for sensitive stored values, TLS 1.2/1.3 in transit with HSTS, tenant isolation, and least-privilege access. Our current practices are described on our security page. No security measure is perfect, and we cannot guarantee that data will never be accessed by unauthorized means. We do not claim any third-party security certification (such as SOC 2 or ISO 27001) unless we have stated so in a signed agreement.
Security incidents
If we become aware of unauthorized access to or acquisition of your data, or of your Epicor connection or service-account credentials, in our possession, we will notify your designated contact by email without undue delay and in any event within seventy-two (72) hours. Where we are acting as a third-party agent within the meaning of Fla. Stat. § 501.171, notice will in no event be later than ten (10) days after we determine the incident occurred or have reason to believe it occurred. We will investigate, contain and mitigate the incident and give you the information you reasonably need to meet your own notification obligations. As the controller of your data, you decide whether any notification to individuals or regulators is required.
Retention and deletion
You can export your configured tool definitions at any time during your subscription through the administration console. After your subscription ends, we retain your account and configuration data for thirty (30) days, then we delete it, subject to the retention exceptions below. You may request deletion of your account data at any time by emailing support@cutova.ai; we will action the request within thirty (30) days. Deletion is irreversible.
We may retain, beyond those periods, (a) usage data and aggregated or de-identified data, (b) billing, tax and audit records for as long as the law requires, and (c) data in routine backups until those backups expire in the ordinary course.
Your choices and rights
- Access and portability: export your configured tool definitions through the console.
- Deletion: email support@cutova.ai.
- State privacy rights: where a United States state privacy law gives you rights in personal information, we act as a processor or service provider and will support your controller-directed requests as described in our DPA.
- Marketing: we use your name, logo or case study only with your prior written consent. You may withdraw consent by emailing support@cutova.ai. We will remove the material from marketing channels we control within thirty (30) days.
Data we ask you not to send
The Service is not designed for certain sensitive categories. You should not transmit protected health information subject to HIPAA, cardholder data subject to PCI DSS, government classified or controlled unclassified information, biometric identifiers, or personal information of children under 13. If you need to handle any of these, contact us first at support@cutova.ai and we will tell you plainly whether we can support it.
International
We are based in the United States and our infrastructure and subprocessors are located in the United States. If you access the Service from outside the United States, you understand that the data you send is processed in the United States.
Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new date. Material changes to our binding data commitments are governed by the change process in the Agreement.
Contact
Lens Software LLC, 12234 Meadowcrest Lane, Jacksonville, FL 32246. Privacy and data questions: support@cutova.ai. Legal notices: legal@cutova.ai.
Cutova is a product of Lens Software LLC, Jacksonville, Florida.