Privacy Policy
Nisol AI is committed to enterprise data protection, privacy compliance, and absolute customer data sovereignty across all our AI transformation solutions, agent orchestrations, and cloud deployments.
Enterprise Privacy Guarantees
Zero Model Training
Your business data, code, prompts, vector embeddings, and outputs are NEVER used to train public foundational AI models.
100% Data Sovereignty
All custom models, fine-tuned adapters, codebases, and RAG vector store assets remain 100% owned by your enterprise.
Azure & AWS Enterprise Security
Hosted on Microsoft Azure and AWS cloud-native architecture with TLS 1.3 in-transit and AES-256 at-rest KMS encryption.
GDPR & CCPA Compliant
Full support for access, deletion, data portability, and audit telemetry requests.
01.Scope & Entity Information
This Privacy Policy applies to personal data and enterprise technical information collected by Nisol AI ("Nisol AI", "Nisol Labs", "we", "us", or "our") when you access our website at www.nisolai.com, utilize our client discovery portal, engage our AI engineering consulting services, or interact with our proprietary AI frameworks (such as RoSense AI and stateful multi-agent workflows).
As an enterprise AI transformation partner, Nisol AI acts both as a Data Controller (for website visitor details and customer administrative accounts) and as a Data Processor/Service Provider (when processing client datasets, prompts, and vector embeddings during AI system deployment).
02.Information We Collect
We collect information necessary to deliver production-grade AI solutions, manage executive discovery engagements, and ensure cloud system security:
A. Information Provided Directly by You
- Contact & Account Details: Name, work email address, company name, job title, phone number, and discovery call bookings.
- Diagnostic Inputs & Questionnaires: Enterprise AI readiness inputs, cloud infrastructure parameters, token usage metrics, and business process automation requirements submitted via Nisol 360™.
- Billing & Contractual Information: Corporate invoicing details, enterprise agreement terms, and payment transaction metadata.
B. Technical & System Telemetry (Automated Collection)
- Interaction & Network Logs: IP address, browser type, operating system, referrer URLs, and device identifiers.
- LLMOps & Agent Telemetry: Model invocation latencies, sub-200ms evaluation scores, token consumption rates, and error traces captured in anonymized observability logs.
3. AI Model Data Protection & Non-Training
Nisol AI recognizes that proprietary enterprise data, internal documentation, source code, and customer records represent your most sensitive competitive assets. We enforce strict technical and operational safeguards around LLM usage:
Customer data processed through Nisol AI agents, Azure OpenAI Service, or AWS Bedrock integration pipelines is never transmitted to third parties for public model training or fine-tuning without your explicit written authorization.
Vector stores (pgvector, OpenSearch, Pinecone) and RAG document indexes are partitioned per enterprise tenant with strict Row Level Security (RLS) and encrypted keys.
Transient LLM prompt contexts are held in memory only for the duration required to execute agent tasks and produce deterministic system output.
Automated pre-processing guardrails scan inputs to prevent PII exposure, confidential token leaks, or malicious prompt injection vectors.
04.How We Use Information
We process collected data exclusively for explicit, legitimate business and technical purposes:
- Executing AI Transformation Engagements: Delivering board-ready discovery reports, ROI financial models, architecture blueprints, and autonomous AI workflow deployments.
- Operating Client Discovery Portal: Authenticating users, providing portal analytics, storing project documentation, and tracking 9-Stage Transformation progress.
- LLMOps Monitoring & Telemetry: Tracking system performance, sub-200ms evaluation loops, API response times, model accuracy, and token optimization.
- Communication & Support: Responding to inquiry forms, conducting executive strategy calls, and sending critical administrative/security notices.
- Legal & Security Governance: Auditing access logs, detecting security anomalies, and ensuring compliance with enterprise customer NDAs and contracts.
05.Cloud Sub-Processors (Azure & AWS Infrastructure)
Nisol AI leverages enterprise-grade cloud sub-processors with SOC 2 Type II, ISO 27001, and ISO 42001 certifications. Key sub-processors include:
| Sub-Processor | Role / Function | Data Location | Security Standards |
|---|---|---|---|
| Microsoft Corporation (Azure) | Enterprise Cloud Infrastructure, Azure OpenAI Service, Azure Key Vault, VNets | Primary: Azure Central India (Mumbai) / South India (Chennai) | SOC 1/2/3, ISO 27001, MeitY Empaneled, HIPAA Ready |
| Amazon Web Services (AWS) | Cloud Infrastructure, AWS Bedrock, Lambda, KMS, S3, ECS | Primary: AWS Asia Pacific (Mumbai - ap-south-1) | SOC 1/2/3, ISO 27001, MeitY Empaneled, HIPAA Ready |
| Supabase Inc. | Database hosting (PostgreSQL), Vector Store (pgvector), Authentication | AWS ap-south-1 (Mumbai, India) | SOC 2 Type II, Encrypted at Rest (AES-256) |
| Resend Inc. | Transactional System Email Delivery | Global / US East | SOC 2 Compliant, TLS 1.3 Enforced |
06.Security & Encryption Standards
Nisol AI implements zero-trust defense-in-depth protocols to safeguard client data against unauthorized access, loss, or manipulation:
Encryption In Transit
All web traffic, API payloads, and database connections enforce TLS 1.3 protocols with HSTS preloading.
Encryption At Rest
Database tables, vector stores, and object backups are encrypted using AES-256 via AWS KMS managed keys.
Access Controls & RBAC
Strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), and least-privilege policies.
Vulnerability Scanning
Automated dependency security audits, CI/CD static code analysis, and periodic penetration testing.
For detailed security specs, review our dedicated Security & Compliance Whitepaper.
07.Data Retention & Deletion
We retain personal and technical data only as long as necessary to fulfill contract obligations, maintain service operations, and comply with legal requirements:
- Active Engagement Datasets: Retained during the active engagement term and deleted or exported to client within 30 days of contract conclusion upon written request.
- Observability Telemetry: Model evaluation metrics and system logs are retained for a default of 90 days before automated rotation/purging.
- Executive Discovery Portal Accounts: Retained until account closure request or 12 months of inactivity.
08.Your Privacy Rights (DPDP Act India, GDPR & CCPA/CPRA)
Nisol AI complies fully with India's Digital Personal Data Protection Act (DPDP Act 2023) as well as global standards (GDPR, CCPA/CPRA). As a data principal, you possess specific statutory rights:
Request a complete machine-readable copy of your personal data held by Nisol AI.
Correct inaccurate or incomplete personal contact details in our records.
Request the complete deletion of your account and personal records.
Opt out of non-essential communications without impact on core services.
10.Data Residency & Mumbai Cloud Sovereignty
Our primary cloud infrastructure for client data, RAG vector stores, relational databases, and AI model endpoints is hosted locally in Mumbai, India (Azure Central India & AWS Asia Pacific ap-south-1).
This guarantees sub-millisecond network latency across India, full data residency compliance under the Indian DPDP Act 2023, and adherence to CERT-In cybersecurity directives. For international clients, multi-region deployments (EU, US) remain available upon request.
11. Contact Our Data Protection Officer
If you have questions, data subject requests, or privacy inquiries regarding this Privacy Policy or Nisol AI's enterprise data governance standards, please reach out to our legal and security leadership:
