Privacy Policy
How CAIBots collects, processes, and protects data in enterprise deployments — and what your rights are.
Overview and Scope
This Privacy Policy governs the collection, processing, storage, and transfer of personal data by CAIBots ("CAIBots", "we", "our") in connection with our Autonomous Enterprise Execution System platform and associated services. CAIBots operates as both a data controller (for information collected directly through our website and marketing activities) and a data processor (for client data processed through the CAIBots execution platform under a Business Associate Agreement or Data Processing Agreement).
This policy applies to: visitors to caibots.com, prospective clients who engage with our sales and marketing processes, and enterprise clients who deploy the CAIBots platform in their organizations.
Data We Collect
Through our website and marketing activities, we collect: contact information provided through forms or direct outreach (name, email, company, title), interaction data (pages visited, session duration, referral source), and communications history.
Through the CAIBots execution platform deployed in client environments, we process data on behalf of our clients as a data processor. The categories of data processed depend on the workflows deployed and are defined in the applicable Data Processing Agreement or Business Associate Agreement. We do not use client execution data for any purpose other than delivering the contracted service.
GDPR — European Data Subjects
For individuals in the European Economic Area, CAIBots processes personal data on the following legal bases: (1) Performance of contract — for processing necessary to deliver contracted services; (2) Legitimate interests — for marketing communications to business contacts; (3) Consent — for optional data collection activities.
EEA data subjects have the following rights: Right to access, Right to rectification, Right to erasure ("right to be forgotten"), Right to restrict processing, Right to data portability, and Right to object. To exercise any of these rights, contact: contact@caibots.com. For enterprise deployments, EEA personal data is processed in EU-hosted infrastructure by default.
Credit Underwriting deployments. For the Credit Underwriting AI platform, CAIBots acts as processor and the client institution as controller. Source-system credentials (bureau, LOS, valuation, and government data connections) are institution-held: API keys are vaulted in the customer's own secrets manager and are never persisted in CAIBots systems. Documents processed in the CAIBots runtime are deleted within 30 days per the DPA (audit-log retention follows the separate schedule in Data Retention below). All demonstration environments run exclusively on synthetic borrower data — no real consumer data is used in any demo. Where automated analysis contributes to credit decisions affecting EU data subjects, the workflow is designed around Article 22's framework: human review is a structural gate in the pipeline, not an optional overlay, and adverse outcomes carry documented, reviewable reasons.
HIPAA — Protected Health Information
For Healthcare clients, CAIBots operates as a Business Associate under HIPAA. We sign a Business Associate Agreement (BAA) with every Healthcare client before accessing or processing any Protected Health Information (PHI). All PHI processing follows the HIPAA minimum-necessary standard.
PHI handling in CAIBots deployments: Zero PHI egress — all processing occurs within the client's network perimeter. Every PHI access is logged with user identity, timestamp, data accessed, and purpose. Role-based access control governs who within the client organization can access PHI audit logs. We maintain policies and safeguards required under 45 CFR Part 164 (HIPAA Security Rule).
SR 11-7 — Model Risk Management Support
SR 11-7 (Federal Reserve) and OCC 2011-12 place the obligation to validate models on the institution that uses them — no vendor can be "SR 11-7 compliant" on a bank's behalf, and CAIBots does not claim to be. What CAIBots provides is validation support: the artifacts, determinism, and evidence trail your Model Risk Management function needs to perform its own validation efficiently.
For the Credit Underwriting platform specifically, that support is structural: every displayed financial ratio is computed by a deterministic, versioned calculation engine (identical inputs always produce identical outputs, with formula versions recorded per artifact); every statutory and policy check runs through a citable guardrail rule pack whose version and fingerprint are stamped into each decision record; every pipeline event — including agent abstentions, verification holds, officer overrides, and SLA escalations — is written to a hash-chained audit ledger; and officer-versus-agent disagreements are captured as override telemetry for ongoing-monitoring review, supporting the SR 11-7 expectation of outcomes analysis over time.
For validation exercises, CAIBots supports challenger replay: your MRM team can re-run historical application files through the pipeline and compare outputs against original human decisions, with artifact-level evidence for each divergence. Documentation packages (model description, input specifications, formula registry, rule citations, monitoring design, and platform governance-matrix configuration records) are provided under the pilot agreement.
SOC 2 — Alignment Status
Plain statement of status: CAIBots is SOC 2-aligned, not yet SOC 2-certified. Our controls are designed against the AICPA Trust Services Criteria (Security, Availability, Confidentiality), and a formal Type II examination is on our compliance roadmap; we will update this page — and our product claims — when an examination report exists. Until then, no CAIBots material should be read as claiming a completed SOC 2 attestation, and if you find one that does, we want to know: contact@caibots.com.
Alignment today means: encryption at rest (AES-256) and in transit (TLS 1.3); access control with least-privilege principles; customer-held credentials for all regulated data sources; segregated demo environments running synthetic data only; hash-chained, tamper-evident audit logging of decision events; continuous monitoring and anomaly detection; incident response procedures with defined SLAs; and annual penetration testing by an independent firm. Security documentation, including the Security Architecture Supplement referenced in our product materials, is available to prospective customers under NDA.
Data Retention and Deletion
Website and marketing data is retained for 36 months from last interaction, after which it is deleted or anonymized. Execution audit logs are retained for the period specified in the client's Data Processing Agreement — typically 7 years for Financial Services clients (BSA/AML requirements) and 6 years for Healthcare clients (HIPAA requirements). Enterprise clients may request deletion of all personal data associated with their account at any time by contacting contact@caibots.com, subject to legal retention obligations.
U.S. State Privacy — CCPA / CPRA and Analogous Laws
For residents of California and other U.S. states with comprehensive privacy laws, CAIBots does not sell or share personal information as those terms are defined under the CCPA/CPRA, and does not use personal information for cross-context behavioral advertising. Categories collected through our website are limited to those described in "Data We Collect"; client data processed through the platform is handled solely as a service provider/processor under contract. State residents may exercise access, deletion, and correction rights by contacting contact@caibots.com; we do not discriminate against individuals for exercising privacy rights. Authorized agents may submit requests with verifiable authorization.
OCC / FRB — Examination Readiness
Bank examiners increasingly ask a specific question about AI in credit workflows: show us how you know what it did, and show us who was in charge. The CAIBots Credit Underwriting platform is designed so those answers are generated by the workflow itself rather than reconstructed after the fact.
For institutions supervised by the OCC, Federal Reserve, FDIC, and state banking regulators, the platform produces: a per-decision evidence file (inputs, computed artifacts with formula versions, policy rule results with regulatory citations, and the human action taken); statutory guardrails enforced as hard stops — flood insurance mandatory purchase, legal lending limits, Regulation O insider restrictions — that no officer or model can override in-workflow; Regulation B pathways covering approval, adverse action, counteroffer, and notice of incompleteness; fair-lending screening with dual sign-off routing on flagged files; and abstention behavior under degraded data conditions, where missing inputs are surfaced to a human rather than imputed by a model.
These capabilities are demonstrated today in a synthetic-data environment and are validated within each institution's own control framework during pilot. CAIBots does not represent that use of the platform constitutes regulatory compliance; it is designed to make your compliance demonstrable.
Note: this section's anchor (#finra) is retained from earlier materials for link compatibility. The Credit Underwriting platform is oriented to banking supervision; it is not a FINRA-regulated broker-dealer product.
Contact and Complaints
Privacy inquiries: contact@caibots.com · CAIBots · Princeton, New Jersey, USA. EEA data subjects who believe their privacy rights have been violated may lodge a complaint with their national data protection authority. UK data subjects may contact the Information Commissioner's Office (ICO).