Skip to main content
AI Employees for Business Answer customers, find company information, and automate everyday workflows across your channels. Explore Solutions →
Data Privacy & Sovereignty

Enterprise Privacy Policy

Effective Date: January 1, 2026 • Last Updated: September 2026 • Version: 2.5 Enterprise
Zero-Training Guarantee: BhavitramAI never uses, trains, fine-tunes, or evaluates any proprietary foundation models or public algorithms on your enterprise data, uploaded documents, database schemas, or conversation logs.

1. Product Vision & Architectural Privacy Principles

BhavitramAI operates as an Enterprise AI Operating Layer connecting enterprise taxonomy, business documents, relational databases, cloud storage providers, and AI/LLM providers to omnichannel customer touchpoints. Our fundamental architectural principle is:

ONE ENTERPRISE CONFIGURATION → ONE AGENT RUNTIME → MANY DATA SOURCES → MANY CHANNELS

Because BhavitramAI is not a collection of ad-hoc chatbots but a governed operating layer, data privacy is enforced at the deterministic code level prior to any AI execution.

2. Multi-Organizational Isolation Model

The platform enforces strict resource ownership across commercial boundaries and internal organizational hierarchies:

  • Tenant Scope: Represents the primary commercial boundary. All credentials, subscriptions, data stores, and taxonomy roots are logically and cryptographically partitioned per enterprise.
  • Parent & Child Organization Scope: Internal organizational boundaries (e.g., Sales, HR, Finance, Support, Regional Subsidiaries). Child organizations operate within strict data permissions and cannot access resources belonging to sibling organizations unless explicitly governed by cross-organization policy.
  • Deterministic Authorization: Every retrieval, Text-to-SQL query, and tool execution validates TenantId + OrganizationId + AgentId + TaxonomyScope + ResourcePermission before returning any data.

3. Information We Collect & Process

We process information strictly on behalf of our enterprise customers as a data processor / service provider:

  • Account & Administrative Data: Name, work email address, company name, telephone number, role, and authentication credentials (hashed with argon2id / bcrypt).
  • Ingested Enterprise Content: Documents uploaded or synchronized from connected storage connectors (Azure Blob, AWS S3, Google Cloud Storage, SharePoint, OneDrive).
  • Database Schema & Query Results: Relational schema metadata and read-only query results executed through our Abstract Syntax Tree (AST) safe SQL validator. Raw database passwords and connection strings are encrypted using AES-256-GCM.
  • Omnichannel Conversation Logs: Inbound and outbound messages across WhatsApp Cloud API, Telegram, Slack, Microsoft Teams, and Web Chat widgets, including delivery receipts and execution telemetry.

4. Third-Party LLM Provider Confidentiality

BhavitramAI integrates with tenant-configured cloud LLM providers (Azure OpenAI, AWS Bedrock, Google Vertex AI, Anthropic) as well as private/on-premises inference engines (Ollama, vLLM, private endpoints):

  • All commercial cloud provider agreements enforce zero data retention (ZDR) and strict commitments that customer inputs/outputs are never used for model training.
  • For sovereign enterprise deployments, inference requests can be routed 100% on-premises to private local LLM endpoints without transmitting any data over the public internet.

5. Data Storage, Encryption & Retention

All data is encrypted in transit using TLS 1.3 and at rest using FIPS 140-2 validated AES-256 encryption. Vector embeddings in pgvector stores are partitioned by organization ID with tenant-scoped isolation.

Enterprise administrators retain complete control over document versioning, conversation log retention windows, and automated purging policies. When an enterprise initiates deletion, data is removed deterministically across relational tables, vector stores, object storage caches, and operational audit trails.

6. Global Compliance & Subject Rights

BhavitramAI complies with applicable international data protection laws including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and readiness for SOC2 Type II and ISO/IEC 27001 certifications. Enterprise administrators may exercise data export, rectification, restriction, or erasure requests directly through the administrative console or via our dedicated privacy office.

7. Privacy Inquiries & Data Protection Officer

For questions regarding this Enterprise Privacy Policy, data processing agreements (DPA), or to contact our Data Protection Officer, please contact:

BhavitramAI Privacy & Data Governance Office
Email: privacy@bhavitramai.com
Security Inquiries: security@bhavitramai.com