← Back to AuditShield AI
🔒 Privacy & Sovereign Data

Enterprise Privacy Policy & Zero-Data Retention

Effective Date: August 17, 2026 • Version 2.4 Sovereign
🛡️ ZERO-DATA EXFILTRATION & AI TRAINING GUARANTEE

AuditShield AI does not scrape, log, or train foundational AI models on your private corporate repositories, AWS credentials, or customer data. All infrastructure compliance checks and Terraform scripts run locally within your isolated environments.

1. Information We Collect

We collect minimal business information necessary to process transactions and provide commercial support:

  • Transactional Information: Corporate billing name, email address, company domain, and transaction records handled via our payment gateway (Stripe). We do not store raw credit card numbers.
  • Technical Telemetry: Anonymized HTTP response status codes, browser client user agents, and IP addresses logged strictly for denial-of-service prevention and fraud detection.

2. B2B Communications & Legitimate Interest (GDPR / PECR)

When conducting direct B2B executive communications with technical leadership (CTOs, VPs of Engineering), AuditShield AI relies on the lawful basis of Legitimate Interest under GDPR Article 6(1)(f) and UK PECR Regulation 22. Every outbound communication includes our physical corporate address and a 1-click immediate opt-out mechanism.

3. 1-Click Opt-Out & Right to Erasure (GDPR Article 17)

Any recipient may opt out of future communications immediately by clicking the unsubscribe link present in all emails, or by submitting a request to privacy@auditshield.ai. Opt-out requests are processed instantaneously and logged immutably to our cryptographic block ledger.

4. Sub-Processors

We utilize tier-1 sovereign infrastructure providers including Vercel (Cloud Hosting), Stripe (PCI-DSS Level 1 Billing), and Google Workspace (Enterprise Communications). All sub-processors maintain certified SOC 2 Type II and ISO 27001 attestations.

Terms of Service Data Processing Agreement (DPA) Checkout Home