Privacy Policy & Data Governance
Effective Date: July 1, 2026 • Compliant with GDPR, CCPA/CPRA, and DPDPA 2023
1. Personal Data Collection Classes
To power advanced conversational support bots and seamless merchant integrations, ochreshift AI architecture systematically categorizes and governs five principal customer data classes:
- Authentication & Account Identity: Better Auth JSON Web Tokens (JWTs), email addresses, cryptographic password salts, and role authorization markers.
- Billing & Corporate KYC Metadata: Stripe customer tokens, Razorpay plan subscriptions, company PAN/GSTIN identifiers, and invoice transaction ledgers (credit card full primary account numbers are never processed directly by our backend servers).
- Uploaded Corporate Knowledge Bases: Text corpora, markdown files, custom system behavioral directives, and website ingestion vectors submitted via
/ingest-fileor URL sitemaps. - Visitor Conversation Transcripts: Real-time message exchanges stored within PostgreSQL
chatstables, including AI model selection history and RAG confidence scores. - Lead Acquisition Records: Visitor names, mobile phone numbers, verified emails, and interactive intent scores captured within the chat widget and synced across CRM Webhooks or Google Sheets pipelines.
2. Jurisdictional Statutory Compliance & Consumer Rights
Our data architectures strictly operationalize global privacy legal frameworks across multi-region tenant boundaries:
🇪🇺 European Union (GDPR)
Full adherence to GDPR Articles 13, 14, and 17. European residents retain unrestricted rights to data access, rectifying AI inferences, and exercising total erasure ("Right to be Forgotten").
🇺🇸 California (CCPA / CPRA)
We do not sell or commercialize consumer personal information or visitor conversational transcripts to data marketing syndicates under California Consumer Privacy Act regulations.
🇮🇳 India (DPDPA 2023)
Aligned with the Digital Personal Data Protection Act of India. We enforce explicit operational purpose limitation, secure domestic encryption controls, and accessible customer grievance resolution.
3. Subject Erasure & Data Portability Execution
ochreshift empowers tenant administrators and privacy officers with self-serve algorithmic governance controls directly integrated within our Studio panel:
- Instant GDPR Subject Erasure (Right to be Forgotten): Using our secure endpoint
POST /api/privacy/erasure-request, bot owners can submit a target individual's email address, phone number, or formal identifier to permanently purge all associated lead entries and conversation logs across PostgreSQL and backup databases within seconds. - 1-Click JSON Data Portability Archive: Inside Account & Security configuration screens, subscribers can click "📦 Export Account & Customer Data" to instantly download a verifiable JSON bundle containing their complete account configuration, active bot prompts, customer interaction transcripts, and captured leads.
4. Subprocessor Transparency Registry
In compliance with global disclosure rules, we publish and continuously maintain our inventory of verified cloud subprocessors handling platform telemetry or commercial AI payloads:
| Entity / Partner | Processing Role & Scope | Data Sovereignty & Residency |
|---|---|---|
| Neon Inc. / AWS | Managed PostgreSQL Database Server Hosting | USA & European Regions (Encrypted At Rest) |
| OpenRouter / OpenAI | Generative Chat Inference & LLM Failover Chains | USA (Zero-Retention; No Model Training) |
| Stripe Inc. & Razorpay Software Pvt. Ltd. | Global (USD) & Domestic India (INR/UPI) Checkout | USA & India (PCI-DSS Level 1 Certified) |
| Vercel / Cloudflare | Application Edge Runtime, DNS Security & Asset Delivery | Global Content Delivery Edge Network |
5. Security Architecture & Attestations Roadmap (SOC 2 Type II)
ochreshift engineering operations adhere to defense-in-depth cybersecurity protocols designed to satisfy institutional auditing requirements (SOC 2 Type II and ISO 27001 readiness):
- Multi-Tenant Row-Level Security (RLS): Our database tier employs strict relational filtering and owner tenancy binding. Tenant data is isolated down to the database session level, ensuring no bot owner can inspect or query another tenant's customer communications.
- Dedicated PII Scrubbing & Redaction Interceptors: Prior to writing application logs or transmitting prompts across cloud inference APIs, our centralized sanitization module (
logger.py) applies automated regular expression filters to redact credit card sequences ([REDACTED_CARD]), social security numbers ([REDACTED_SSN]), and banking tokens. - Cryptographic Field Encryption: Sensitive customer communications and internal notes are protected using symmetrical encryption cipher suites (AES-256 / Fernet) in transit via TLS 1.3 and at rest across high-availability cloud storage volumes.
6. Data Processing Addendum (DPA) & Contractual Roles
For B2B Enterprise subscribers operating in regulated industries, ochreshift acts as a dedicated Data Processor, while the subscribing merchant or business enterprise retains exclusive ownership as the governing Data Controller. Our platform Standard Contractual Clauses (SCCs) are embedded by reference within every commercial subscription agreement.
To request a signed copy of our formal institutional Data Processing Addendum (DPA), please contact our legal compliance team at legal@ochreshift.com.