Skip to main content

    Trust Center

    Privacy Policy

    This policy explains how ZAUBERN handles the data involved in decision execution infrastructure, evidence handling, and customer-operated workflows. Last updated: April 11, 2025.

    Data stewardship principles

    ZAUBERN provides decision execution infrastructure for highly regulated industries. The platform minimizes data collection, aligns with customer instructions, and enforces jurisdiction-aware data controls at the execution boundary.

    We deploy infrastructure in customer-selected regions and apply encryption in transit and at rest with audited key rotation policies.

    Purpose limitation

    We only process data required to deliver contractual services and never repurpose customer data for model training without explicit, revocable consent.

    Data minimization

    Default retention windows are 30 days unless extended by the customer to meet regulatory evidence requirements.

    Shared responsibility

    Flight Recorder enforces least-privilege policies while allowing customers to configure their own roles, audit schedules, and evidence exports.

    Information we collect

    ZAUBERN collects only the information needed to provide secure, compliant services. This includes account metadata, telemetry required for availability, and optional integrations configured by customers.

    • Account identifiers, billing contacts, and role assignments provided during onboarding.
    • Flight Recorder artifacts uploaded by customer systems, such as prompts, model outputs, feedback signals, and control plane events.
    • Support communications, including security questionnaires, incident reports, and compliance attestations.

    We do not collect or sell personal data from public sources, brokers, or marketing databases.

    How we use information

    Information is processed to deliver services, enhance safety controls, and fulfill legal obligations. We rely on contractual necessity, legitimate interest in platform security, or explicit consent as our processing bases.

    • Operating and securing decision execution infrastructure, including monitoring for abuse and performance anomalies.
    • Providing support, incident response, and compliance deliverables requested by customers.
    • Improving platform reliability, documentation, and user experience while respecting customer configuration boundaries.

    How we share information

    ZAUBERN never sells customer data. We only disclose information to subprocessors under written agreements, to regulators when legally required, or to third parties the customer designates.

    • Audited infrastructure partners who provide hosting, storage, or secure communications.
    • Specialist vendors engaged for penetration testing, compliance assessments, or managed support services.
    • Regulators, law enforcement, or courts when mandated by applicable law and with customer notice whenever permitted.

    All subprocessors are listed in our Trust Center with geographic scope, data types, and audit certifications.

    Your rights and choices

    Individuals interacting with systems that use ZAUBERN maintain the rights granted by their jurisdiction. ZAUBERN supports access, correction, deletion, and objection requests through coordinated workflows with our customers.

    • Access records of processing that identify how Flight Recorder handled your data.
    • Request corrections to inaccurate information or submit deletion requests where legally permissible.
    • Escalate concerns to our Data Protection Officer or appeal a decision with an independent review.

    To exercise these rights, contact your organization’s administrator or email [email protected]. We respond within 30 days unless the applicable law requires a shorter period.

    Security controls

    Security is embedded into every layer of the Flight Recorder stack. We blend automated policy enforcement with human oversight to uphold confidentiality, integrity, and availability commitments.

    Zero trust architecture

    All internal and external access is authenticated, authorized, and logged. We apply hardware-backed keys, just-in-time access, and tamper-resistant audit trails.

    Continuous validation

    Runtime scanners verify compliance against HIPAA, SOC 2, ISO 27001, and EU AI Act guardrails. Deviations trigger automated containment and customer alerts.

    Incident response

    A 24/7 security desk coordinates containment, forensic analysis, and regulatory notifications in partnership with customer response teams.

    Policy changes

    We update this Privacy Policy when introducing new capabilities or responding to regulatory guidance. Material changes are communicated to administrators and published in the Trust Center before they take effect.

    Continued use of ZAUBERN services after an update constitutes acceptance of the revised terms.

    Contact us

    For questions about this policy or ZAUBERN’s data governance program, please reach out to our Privacy Office.

    Mail

    ZAUBERN Privacy Office, 548 Market St PMB 62321, San Francisco, CA 94104

    DPO

    EU Data Protection Officer: [email protected]

    We also maintain regional representatives in the EU, UK, and Singapore for jurisdiction-specific obligations.

    Need a data processing agreement?

    ZAUBERN delivers decision execution infrastructure for regulated workflows. Our legal and security teams can review your regulatory requirements, map them to the relevant controls, and provide the supporting materials needed for diligence.

    Talk to our compliance team
    Contact ZAUBERN

    Talk with the team behind the decision boundary

    Use WhatsApp or email for category briefings, technical reviews, and scoped pilot conversations.

    WhatsApp Briefing Line

    Use WhatsApp for category briefings, pilot scoping, and quick review of a workflow that needs a governed decision boundary.

    +1 404 624 6871

    Message on WhatsApp
    Email the ZAUBERN Team

    Send technical context, procurement questions, or pilot notes when the conversation needs more structure than chat.

    [email protected]

    Email [email protected]

    Category clarity

    We can help separate runtime authorization, observability, and policy process from the actual decision execution problem.

    Pilot scoping

    The best first conversation is usually one workflow where allow, block, escalate, and replay all matter.

    Cross-functional review

    Product, security, legal, and procurement can use the same conversation if the proof boundary needs to be clear early.