Transparency & Privacy

Security & Data Governance

We build automations and AI agents for businesses processing sensitive client information. Here is how your data and your clients' privacy are strictly protected.

01

What data is collected during an automated workflow?

We enforce strict data minimization: only information strictly necessary to execute the task is processed (e.g., first name, phone number, party size for a restaurant reservation, or property criteria for a brokerage). No superfluous data is requested or stored.

02

Is your business data used to train public AI models?

No. We use zero-retention commercial API contracts (OpenAI Enterprise, Anthropic Claude, Google Vertex AI) with explicit contractual guarantees that your business queries and data are never used for model training.

03

Where and how is data transferred?

All data transfers occur through encrypted HTTPS / TLS 1.3 channels. Webhook endpoints and form handlers run on hardened servers with firewall rules, rate limiting, and restricted access privileges.

04

Are voice agent phone calls recorded?

By default, voice streams are processed in real-time purely to understand the caller and transcribe the action item (name, booking time, inquiry). If you choose to retain recordings for quality control, an upfront consent disclosure is systematically announced to callers in accordance with Canadian & Quebec Law 25 regulations.

05

What happens if the AI does not know the answer?

Our agents are engineered with strict anti-hallucination guardrails: they never fabricate information. If an inquiry exceeds its defined operational scope, the agent politely offers to transfer the call to your human team or takes a structured callback message dispatched instantly to your phone/email.

06

How long is data retained?

Data is retained strictly for the duration necessary to execute the service, or according to statutory retention obligations (e.g. accounting records). Automatic purge policies for transit logs are configured according to your corporate governance requirements.

07

How do users request data access, rectification, or deletion?

You or your clients may exercise your rights to access, rectify, or permanently delete personal data at any time by contacting jessy@aichronoscorp.com. Requests are processed within 48 business hours.

08

Compliance with Quebec Law 25 & European GDPR

Our workflows adhere strictly to the requirements of Quebec Law 25 (Act respecting the protection of personal information in the private sector) and European GDPR standards: transparency on automated decision-making, cookieless analytics, right to human escalation, and rapid breach notification procedures.

09

Who owns the intellectual property and code?

You do. Custom integrations and workflows built for your organization are fully owned by your company upon project completion. We do not lock your operational data behind proprietary closed platforms.

10

Can we conduct our security audit in English?

Yes. Our security evaluations and operational discussions are available fluently in English and French.

Specific questions regarding your data flow?

We can address all aspects of data governance, security, and regulatory compliance applicable to your industry during your free 30-min audit.