1. Product Vision & Architectural Privacy Principles
BhavitramAI operates as an Enterprise AI Operating Layer connecting enterprise taxonomy, business documents, relational databases, cloud storage providers, and AI/LLM providers to omnichannel customer touchpoints. Our fundamental architectural principle is:
ONE ENTERPRISE CONFIGURATION → ONE AGENT RUNTIME → MANY DATA SOURCES → MANY CHANNELS
Because BhavitramAI is not a collection of ad-hoc chatbots but a governed operating layer, data privacy is enforced at the deterministic code level prior to any AI execution.
2. Multi-Organizational Isolation Model
The platform enforces strict resource ownership across commercial boundaries and internal organizational hierarchies:
- Tenant Scope: Represents the primary commercial boundary. All credentials, subscriptions, data stores, and taxonomy roots are logically and cryptographically partitioned per enterprise.
- Parent & Child Organization Scope: Internal organizational boundaries (e.g., Sales, HR, Finance, Support, Regional Subsidiaries). Child organizations operate within strict data permissions and cannot access resources belonging to sibling organizations unless explicitly governed by cross-organization policy.
- Deterministic Authorization: Every retrieval, Text-to-SQL query, and tool execution validates
TenantId + OrganizationId + AgentId + TaxonomyScope + ResourcePermissionbefore returning any data.
3. Information We Collect & Process
We process information strictly on behalf of our enterprise customers as a data processor / service provider:
- Account & Administrative Data: Name, work email address, company name, telephone number, role, and authentication credentials (hashed with argon2id / bcrypt).
- Ingested Enterprise Content: Documents uploaded or synchronized from connected storage connectors (Azure Blob, AWS S3, Google Cloud Storage, SharePoint, OneDrive).
- Database Schema & Query Results: Relational schema metadata and read-only query results executed through our Abstract Syntax Tree (AST) safe SQL validator. Raw database passwords and connection strings are encrypted using AES-256-GCM.
- Omnichannel Conversation Logs: Inbound and outbound messages across WhatsApp Cloud API, Telegram, Slack, Microsoft Teams, and Web Chat widgets, including delivery receipts and execution telemetry.
4. Third-Party LLM Provider Confidentiality
BhavitramAI integrates with tenant-configured cloud LLM providers (Azure OpenAI, AWS Bedrock, Google Vertex AI, Anthropic) as well as private/on-premises inference engines (Ollama, vLLM, private endpoints):
- All commercial cloud provider agreements enforce zero data retention (ZDR) and strict commitments that customer inputs/outputs are never used for model training.
- For sovereign enterprise deployments, inference requests can be routed 100% on-premises to private local LLM endpoints without transmitting any data over the public internet.
5. Data Storage, Encryption & Retention
All data is encrypted in transit using TLS 1.3 and at rest using FIPS 140-2 validated AES-256 encryption. Vector embeddings in pgvector stores are partitioned by organization ID with tenant-scoped isolation.
Enterprise administrators retain complete control over document versioning, conversation log retention windows, and automated purging policies. When an enterprise initiates deletion, data is removed deterministically across relational tables, vector stores, object storage caches, and operational audit trails.
6. Global Compliance & Subject Rights
BhavitramAI complies with applicable international data protection laws including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and readiness for SOC2 Type II and ISO/IEC 27001 certifications. Enterprise administrators may exercise data export, rectification, restriction, or erasure requests directly through the administrative console or via our dedicated privacy office.
7. Privacy Inquiries & Data Protection Officer
For questions regarding this Enterprise Privacy Policy, data processing agreements (DPA), or to contact our Data Protection Officer, please contact:
BhavitramAI Privacy & Data Governance Office
Email: privacy@bhavitramai.com
Security Inquiries: security@bhavitramai.com