Privacy Policy & Enterprise Data Protection | CCPA, SOC 2 & GDPR
Esaholic enforces a strict Zero Data Retention (ZDR) architecture for client inference payloads and AI workloads. We process business contact data solely for technical audit inquiries under US CCPA/CPRA, HIPAA BAA standards, UK GDPR, and the EU AI Act (Regulation EU 2024/1689). We never sell user data or train models on client inputs.
- → 1. Data Controller & Compliance Scope
- → 2. Zero Data Retention (ZDR) for AI Workloads
- → 3. Personal Data Collection & Legal Bases
- → 4. US Privacy Rights (CCPA / CPRA & HIPAA BAA)
- → 5. Cookie Consent & Analytics Disclosures
- → 6. Security Architecture & Data Transfers
- → 7. Data Subject Rights & Contact Details
1. Data Controller & Compliance Scope
This Privacy Policy applies to all services, websites, and technical audit engagements provided by Esaholic ("Esaholic", "we", "us", "our"). Esaholic designs and deploys AI systems aligned with US Federal and State privacy regulations, including the California Consumer Privacy Act (CCPA/CPRA), HIPAA BAA requirements, SOC 2 Type II controls, UK GDPR, and EU GDPR (2016/679).
Organization: Esaholic (Enterprise AI Engineering & Architecture)
Operations: Distributed engineering team working across UK and US business hours
Privacy & Data Inquiries: contact@esaholic.com
Direct Phone: +1 (986) 256-8580 (Mon–Fri, 9:00 AM – 6:00 PM EST)
2. Zero Data Retention (ZDR) for Enterprise AI Workloads
Esaholic enforces a foundational Zero Data Retention (ZDR) policy across all enterprise AI engagements, multi-agent swarms, RAG knowledge pipelines, and custom fine-tuning evaluations:
- Transient In-Memory Processing: Client prompts, vector context chunks, document embeddings, and model output tokens are held transiently in volatility-cleared RAM during inference and immediately discarded upon response delivery.
- Zero Training Clause: We strictly prohibit using client inputs, proprietary datasets, model outputs, or prompt tokens to train, fine-tune, or align foundational models, public weights, or any third-party AI services.
- Air-Gapped Private VPC Deployment: For enterprise clients, inference endpoints are deployed within dedicated, isolated AWS/Azure/GCP virtual private clouds under client-managed encryption keys (KMS/HSM).
3. Personal Data Collection & Legal Bases
We collect minimal personal data required to evaluate technical feasibility requests, process job applications, and fulfill software development contracts:
A. Technical Audit & Contact Inquiries
Data Collected: Full name, work email address, company name, technical workload specifications, and target timelines.
Legal Basis: Contractual Necessity (Art. 6(1)(b) UK GDPR) and Legitimate Interest (Art. 6(1)(f)) in assessing commercial software projects.
B. Server & Network Diagnostics
Data Collected: IP addresses, HTTP headers, browser user agents, and page response latencies.
Legal Basis: Legitimate Interest (Art. 6(1)(f)) in protecting network infrastructure against denial-of-service (DDoS) attacks and security threats.
4. EU AI Act (Regulation 2024/1689) Compliance
Esaholic designs and deploys AI systems in strict alignment with the European Union Artificial Intelligence Act (Regulation EU 2024/1689):
- Transparency Obligations (Article 50): Where automated multi-agent conversational interfaces or synthetic content generation systems interact with natural persons, systems provide explicit, unambiguous notice of AI interaction.
- High-Risk AI Systems Governance: For client applications categorized under Annex III (e.g. credit scoring, biometric evaluation, critical infrastructure), Esaholic implements ISO 42001 risk management, data lineage logging, and human-in-the-loop (HITL) oversight protocols.
- Prohibited AI Practices (Article 5): Esaholic strictly refuses projects involving subliminal manipulation, social scoring systems, or untargeted facial scraping.
6. Security Architecture & Data Transfers
All communications with esaholic.com and client API endpoints are encrypted in transit using TLS 1.3 and at rest using AES-256. International transfers of administrative data outside the UK or European Economic Area (EEA) execute under UK International Data Transfer Agreements (IDTA) and EU Standard Contractual Clauses (SCCs).
7. Data Subject Rights & Contact Details
Under UK GDPR and EU GDPR, you have the right to request access to, rectification of, portability of, or erasure ("Right to be Forgotten") of your personal data.
To exercise any data subject rights, submit a formal request to our Data Protection Officer at dpo@esaholic.com. You also maintain the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.