Legal

Privacy Policy

Last updated:

At Enclavia ("we", "our", or "us"), we prioritize the privacy and security of our enterprise clients. This Privacy Policy outlines how we handle data processed through our AI Orchestration Platform, custom integrations, and related services.

ON THIS PAGE

1. Enterprise Data Sovereignty & Isolation

Enclavia is built on a zero-trust architecture. We do not use your proprietary business data, vector embeddings, or chat histories to train foundational LLMs (Large Language Models). Your data remains strictly isolated within your designated tenant environment.

2. Information Processed by Our Services

Our platform processes the following data types to provide our services:

  • Integration Data: Information ingested via our Connector Services from your internal systems (e.g., CRM, ERP, clinical databases).
  • Vector Embeddings: Mathematical representations of your documents generated by our Embedding Service for semantic search and Retrieval-Augmented Generation (RAG).
  • Access Control Data: Identity metadata processed by our Open Policy Agent (OPA) engine to enforce Role-Based Access Control (RBAC).

3. How We Secure Your Data

We employ military-grade security measures across our stack:

  • Encryption: All data is encrypted at rest in our PostgreSQL databases and in transit using TLS 1.3 and AES-256 standards.
  • Strict Access Control: Fine-grained authorization is evaluated in real-time by our centralized OPA (Open Policy Agent) infrastructure, ensuring users only access permitted data.
  • Ephemeral Processing: In-memory processing via Redis is configured for ephemeral session management and rapid cache invalidation.

4. Third-Party Sub-processors

We may engage trusted third-party sub-processors (such as secure cloud infrastructure providers) to operate our platform. All sub-processors are bound by strict Data Processing Agreements (DPAs) that mandate security standards equal to or exceeding our own.

5. Compliance and Data Rights

Enclavia is committed to supporting your compliance with global data protection frameworks (including GDPR, CCPA, and HIPAA where applicable). Platform administrators retain full capability to execute data subject access requests, deletion protocols, and data exports via our administrative APIs.