🛡 The dAutomata Zero-Training Guarantee: We never train, fine-tune, or calibrate any machine learning or foundation models (proprietary or public) on customer data, prompt contexts, API schemas, or execution logs. Your data remains strictly your intellectual property.
1. Introduction & Scope
This Privacy Policy describes how dAutomata Inc. ("dAutomata", "we", "us", or "our") processes, protects, and respects personal data and operational information when you access our deterministic coworker platform, website (dautomata.com), and related enterprise developer services.
In accordance with global privacy frameworks including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the UK Data Protection Act, dAutomata generally functions as a Data Processor on behalf of our enterprise customers (the Data Controllers).
2. Categories of Information We Collect
A. Customer Account & Administrative Data
When you register for an enterprise account, book an architecture review, or request a Sandbox deployment, we collect:
- Contact details (name, corporate email, job title, company name).
- Authentication credentials via SAML 2.0 / Okta / Azure AD SSO tokens.
- Commercial billing information processed via our PCI-DSS compliant payment gateway (Stripe).
B. Operational Telemetry & Performance Metrics
To ensure 99.99% platform availability and verify sub-millisecond SLAs, we collect anonymized performance telemetry:
- P99 latency metrics for webhook ingress, EAV context hydration, and CEL rule evaluation.
- Error status codes, daemon heartbeat counts, and worker node resource utilization.
- Cryptographic Ed25519 execution receipt hashes (which verify mathematical state correctness without containing plaintext payload data).
C. Information We Explicitly DO NOT Collect
- Raw Database Records: Customer databases connected via VPC endpoints are accessed only in-memory during deterministic tasks and are never copied to dAutomata cloud storage.
- Plaintext Secrets: API keys and secrets stored in AWS Secrets Manager or HashiCorp Vault are accessed by daemon nodes via IAM roles; dAutomata engineers never have access to cleartext credentials.
3. How We Use and Process Information
dAutomata processes information strictly for the following purposes:
- To provision, maintain, and secure your in-VPC or dedicated coworker daemons.
- To execute deterministic state machine playbooks authorized by your organization.
- To enforce Google CEL policy guardrails and generate cryptographic audit logs for your compliance teams.
- To bill for platform capacity based on active managed endpoints and SLA tiering.
4. Data Retention & Cryptographic Zeroization
Our runtime architecture is built around ephemeral execution lifetimes:
- Transient Payload Data: Exists in volatile memory (RAM) exclusively while an automated task is being processed (typically < 500ms). Upon task completion or exception, memory buffers are overwritten with zeros (cryptographic zeroization).
- Account Records: Kept for the duration of your active enterprise master services agreement (MSA) plus 30 days for backup reconciliation.
- Audit Trails: In BYOC mode, all execution logs stream directly into your own Amazon CloudWatch, Datadog, or Splunk instances and are governed by your corporate retention policies.
5. Authorized Sub-processors
dAutomata maintains contractual Data Processing Addendums (DPAs) containing Standard Contractual Clauses (SCCs) with all vetted infrastructure sub-processors:
- Amazon Web Services (AWS): Cloud infrastructure for multi-tenant control plane (us-east-1, eu-west-1).
- Google Cloud Platform (GCP): CEL policy compilation services and global DNS.
- Cloudflare: Edge network routing, DDoS mitigation, and SSL/TLS termination.
- Stripe, Inc.: Enterprise billing processing and PCI-DSS compliant payment handling.
6. Your Rights Under GDPR & CCPA/CPRA
Depending on your geographic location, you possess statutory data protection rights, including:
- Right of Access & Portability: Request confirmation of whether we process your personal data and obtain a machine-readable copy.
- Right to Rectification: Request correction of incomplete or inaccurate account records.
- Right to Erasure ("Right to be Forgotten"): Request immediate deletion of administrative personal data.
- Right to Object & Restrict Processing: Restrict certain administrative processing activities.
- Non-Discrimination: Exercise your privacy rights without penalty or service alteration.
7. Privacy Contact & Data Protection Officer (DPO)
To exercise your data protection rights or submit an inquiry to our privacy engineering team, please contact:
- Data Protection Officer:
dpo@dautomata.com - General Privacy Requests:
privacy@dautomata.com - Corporate Headquarters: dAutomata Inc., 548 Market St, Suite 94000, San Francisco, CA 94104