LEGAL & COMPLIANCE
LAST UPDATED: OCTOBER 2024

Privacy policy

RapidCore Systems LLC delivers architectural-grade AI optimization and workflow automation for enterprise environments. This policy outlines our rigorous technical standards for data governance, zero-trust infrastructure, and confidential client data handling.

SECTION 01

Information we collect

POLICY CL. 01

We collect operational and telemetry data required to configure, test, and optimize AI workflows and API connections.

Account & organizational data

Business contact details, corporate email addresses, authorized technical administrator names, billing information, and verified enterprise identification.

Technical & telemetry logs

System access logs, API response times, payload throughput metrics, error traces, and operational parameters processed during architectural evaluations and workflow automation runs.

Communications & project records

Requirements documentation, technical specifications, and written correspondence exchanged between your team and our systems engineers during active project engagements.

SECTION 02

How we use data

POLICY CL. 02

Your data is processed strictly to deliver our consulting, optimization, and integration services.

Service delivery & optimization

Analyzing existing IT bottlenecks, configuring tailored AI agents, integrating CRM systems, and measuring workflow performance gains.

Security & infrastructure monitoring

Detecting unauthorized API access, verifying credential hygiene, preventing anomalous data access, and confirming end-to-end encryption compliance.

SLA compliance & technical support

Fulfilling contractual service level commitments, troubleshooting interface failures, and providing responsive engineering support.

SECTION 03

Enterprise data architecture & storage

POLICY CL. 03

We follow zero-trust architectural principles to isolate client workloads and safeguard proprietary data.

Encryption standards

All data at rest is encrypted using AES-256 standard. All data in transit across public or internal networks is secured with TLS 1.3.

Zero-trust client isolation

Client datasets, sandbox configurations, and API testing environments reside in strictly segmented, private cloud virtual private clouds (VPCs) with role-based access control (RBAC).

Compliance alignment

Our data handling procedures align with SOC 2 Type II controls and ISO/IEC 27001 security standards to protect your operational assets.

SECTION 04

Third-party integrations & sub-processors

POLICY CL. 04

We maintain strict vendor governance and never sell, rent, or trade your enterprise data.

Authorized cloud hosting

We partner with SOC 2 certified cloud infrastructure providers located within the United States to host sandbox environments and automated pipelines.

AI model providers & API brokers

When integrating client workflows with frontier AI providers, we mandate zero-data-retention (ZDR) enterprise agreements to ensure your data is never used for foundation model training.

Non-disclosure agreements

All sub-processors, subcontractors, and staff operate under binding NDAs and data protection agreements (DPAs) that match our primary security commitments.

SECTION 05

Cookies & telemetry

POLICY CL. 05

We utilize essential session tokens and technical telemetry to ensure website stability and secure client portal authentication.

Essential cookies

Required for core site navigation, CSRF protection, and load balancing across our consulting infrastructure.

Performance telemetry

Aggregated, anonymized latency measurements that allow our engineering team to maintain high platform availability.

Managing preferences

You can adjust browser settings to reject non-essential cookies without affecting your access to public architectural documentation.

SECTION 06

User rights & data subject access

POLICY CL. 06

We support global privacy frameworks including GDPR, CCPA, and CPRA, granting you direct authority over your information.

Right to access & export

Request a complete, machine-readable export of all operational records and personal information associated with your organization.

Right to rectification & erasure

Instruct us to correct outdated records or permanently wipe technical logs and test configurations upon project completion.

Submitting a formal request

Email your data subject access request to our Data Protection Officer. We verify requests and provide a complete response within 30 days.

SECTION 07

Data retention & erasure

POLICY CL. 07

We store technical artifacts only as long as necessary to fulfill active consulting contracts and legal obligations.

Active project lifecycles

Diagnostic logs and sandbox telemetry are retained during the consulting engagement and automatically scrubbed 90 days after formal delivery.

Contractual & financial records

Invoices, signed statement-of-work (SOW) documents, and legal records are retained for seven years in compliance with standard regulatory requirements.

Automated de-identification

Historical benchmark metrics used to optimize our automation algorithms are irreversibly anonymized and stripped of client identifiers.

SECTION 08

Contact & Data Protection Officer

POLICY CL. 08

Direct your privacy questions, compliance assessments, or security disclosures to our team.

Electronic correspondence

Send inquiries directly to RapidCoreSystemsLLC@proton.me with 'Privacy & Compliance' in the subject line.

Postal address

RapidCore Systems LLC, 301 W 148th St, Apt 5C, New York, NY 10039, USA.

Security vulnerability disclosures

We welcome responsible vulnerability reporting and acknowledge verified disclosures within 48 hours.

CONFIDENTIALITY ASSURANCE

Enterprise security questions?

Review our technical architecture documents or request our standard mutual Non-Disclosure Agreement (NDA).