AuromindAI
AuromindAI
Official Legal Document

Privacy Policy

Last Updated & Effective Date: September 5, 2026 · AuromindAI, Inc.

Core Privacy Principle: Zero Data Retention (ZDR) Guarantee

At AuromindAI, we adhere to a strict Zero Data Retention (ZDR) policy for foundation AI models. Your proprietary customer conversations, healthcare records, financial metrics, and company databases are never used to train, retrain, or improve public AI models (such as OpenAI, Anthropic, or Meta models). All enterprise processing occurs in isolated, ephemeral tenant sandboxes.

1. Information We Collect

When you interact with AuromindAI services, platforms, and autonomous swarms, we may collect the following categories of information:

  • Account & Profile Data: Name, business email, organization name, phone number, and billing details when signing up.
  • Inbound Channel Telemetry: Customer messages submitted via WhatsApp Business API, SMS, website chat widgets, or webhook endpoints configured on your account.
  • Operational Metadata: IP addresses, browser types, session timestamps, latency logs, and autonomous agent tool execution records for auditing and security purposes.
  • Integration Credentials: Encrypted OAuth tokens and API secrets (e.g. Shopify, PostgreSQL, Google Calendar, HubSpot) required to execute autonomous business tasks on your behalf.

2. How We Use Your Information

We process collected data strictly to execute agreed-upon autonomous workflows and deliver contractual enterprise services:

Autonomous lead qualification & WhatsApp appointment booking
Sub-second RAG search against your uploaded documentation
Real-time transaction & cart recovery alerts
HIPAA-compliant pre-consultation patient intake
Detecting security anomalies and preventing system abuse
Generating transparent audit trails for executive compliance

3. Data Encryption & Cryptographic Controls

Security is engineered directly into our infrastructure architecture:

  • Data in Transit: Encrypted using TLS 1.3 with Perfect Forward Secrecy (PFS) and strict HSTS headers across all public and internal service boundaries.
  • Data at Rest: Encrypted using AES-256 GCM. Encryption keys are managed via AWS Key Management Service (KMS) or dedicated Hardware Security Modules (HSM).
  • Database Row-Level Security (RLS): Multi-tenant segregation ensures that tenant data is cryptographically and logically isolated from other accounts.

For deeper architectural details, please review our comprehensive Data Encryption & Security Architecture document.

4. Sub-Processors & Third-Party Services

AuromindAI engages vetted enterprise sub-processors to assist in infrastructure hosting, database storage, and AI inferencing. All sub-processors are subject to rigorous Data Processing Agreements (DPAs) with strict confidentiality and security warranties:

Sub-ProcessorRole & ActivityLocationCompliance Safeguards
Amazon Web Services (AWS)Cloud Hosting, KMS, RDSUS & EU RegionsSOC-2 Type II, ISO 27001
Meta WhatsApp Cloud APIWhatsApp Messaging GatewayGlobal EdgeEnd-to-End Enterprise Encryption
Dedicated LLM VPC InferenceZero Data Retention LLM InferenceUS Isolated VPCZero Retention & No Model Training
Stripe, Inc.Payment Processing & BillingUnited StatesPCI-DSS Level 1 Certified

5. Your Rights Under GDPR, CCPA & Global Frameworks

Depending on your jurisdiction, you have statutory rights regarding your personal data:

  • Right to Access: Request a complete copy of personal records held by AuromindAI in a structured JSON format.
  • Right to Erasure (Right to be Forgotten): Request the permanent deletion of your account, conversation transcripts, and indexing data.
  • Right to Rectification: Update or correct inaccurate personal or business details.
  • Right to Restrict Processing: Suspend autonomous processing or revoke third-party API tokens at any time.
  • Right to Opt-Out of Automated Profiling: Configure mandatory Human-in-the-Loop approval for any sensitive agent decision.

6. Data Retention & Deletion

We retain your operational data only for as long as your account is active or as required by statutory accounting and legal obligations. Upon termination of service, all tenant databases, vector embeddings, and temporary credentials are cryptographically scrubbed within thirty (30) business days.

7. Contact Our Data Protection Officer (DPO)

For privacy inquiries, Data Protection Agreements (DPA), or to exercise your GDPR/CCPA rights, please contact our dedicated security team:

AuromindAI Trust & Privacy Office

Email: privacy@auromind.ai

Security Portal: security@auromind.ai

Physical Address: AuromindAI Global Operations, San Francisco, CA & Bangalore, India