Skip to main content
Erayaha Logo
Data Privacy · GDPR · CPRA · DPDP

Privacy Policy

Effective Date: August 6, 2026 · Version 2.1

Privacy Principles & Governance

Erayaha Inc ("Erayaha", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy details how we collect, process, and safeguard personal information across our website (erayaha.ai), Microsoft Word 365 add-in, Google Docs add-on, and developer APIs.

1. Our Dual Role & GDPR Article 6 Legal Bases

Under European Data Protection Law (GDPR / UK GDPR) and applicable international privacy frameworks:

  • Erayaha as Data Controller: We act as a Data Controller for Account Registration PII, customer billing information, business inquiries, and aggregated platform telemetry.
  • Erayaha as Data Processor: We act as a Data Processor on behalf of our enterprise and individual customers regarding any Customer Document Content or personal data contained within agreements uploaded or analyzed via the Service. All such processing is governed by our Data Processing Agreement (DPA).

GDPR Article 6 Legal Bases for Controller Processing

  • Contractual Necessity (Art. 6(1)(b)): Provisioning user accounts, authenticating sessions, managing subscription tiers, billing, and providing core Document Intelligence features.
  • Legitimate Interests (Art. 6(1)(f)): Protecting platform security, detecting and preventing fraud or abuse, maintaining edge infrastructure, and diagnosing service availability.
  • Legal Compliance (Art. 6(1)(c)): Complying with statutory corporate, tax, financial recordkeeping, and legal reporting obligations.
  • Processor Operations: For Customer Document Content processed as a Processor, processing is executed under Customer's documented instructions pursuant to Article 28 of the GDPR and the DPA.

2. Information We Collect & Process

We strictly categorize the data processed by our systems into three separate tiers:

Tier 1: Customer Document Content (Zero Retention)

Documents analyzed via our Microsoft Word or Google Docs taskpane remain in your connected cloud storage (OneDrive, SharePoint, or Google Drive). During analysis, document snippets are transferred via encrypted TLS 1.3 to volatile RAM memory solely for prompt inference and logical reasoning. We retain zero document text on persistent disk storage, and all transient memory buffers are purged immediately upon request fulfillment.

Tier 2: User Account & Identity PII

When you authenticate using Microsoft Entra ID (Office SSO) or Google Workspace OAuth, we receive and store your name, email address, profile avatar, and organizational tenant identifier in our secure identity database (Google Cloud Firebase Auth / Cloudflare D1) to manage active sessions and access permissions.

Tier 3: Plan Usage Telemetry & Quota Metrics

To meter your usage against your chosen subscription tier (e.g. Starter, Professional, Enterprise) and ensure platform health, we collect structured metadata including timestamps, feature triggers, token usage counts, document classification categories, and API latency. Telemetry contains zero confidential document text.

3. Zero Model Training Warranty

We strictly warrant that we do not use Customer Inputs, Customer Outputs, or confidential contract data to train, fine-tune, or calibrate foundational AI models. Our downstream inference providers (such as AWS Bedrock) operate under binding enterprise B2B covenants prohibiting any training or data logging on user prompts.

4. Zero Website Tracking, Cookie Disclosure & Opt-Out Signals

Our website (erayaha.ai) is statically hosted on Cloudflare's global edge network. We maintain a strict privacy-first posture:

  • Zero Tracking Scripts & No Analytics Cookies: We do NOT use Google Analytics, tracking pixels, behavioral advertising cookies, Facebook Pixels, or cross-site tracking scripts. Our marketing pages do not track visitors or build behavioral profiles.
  • Universal Opt-Out & GPC Signals: We honor the Global Privacy Control (GPC) and universal browser opt-out signals automatically across all endpoints.
  • Direct Inquiry Submissions: When you submit an optional pilot or enterprise inquiry, your submission is transmitted directly over encrypted TLS 1.3 solely to communicate with you regarding your inquiry. We never sell, rent, or broker contact data.

Cookie & Security Token Disclosure

Identifier / TokenCategory & PurposeDuration
Firebase Auth JWTStrictly necessary user authentication token for taskpane sessionsActive session (1 hr / auto-refresh)
__cf_bm / cf_clearanceStrictly necessary Cloudflare edge bot mitigation & DDoS protection30 minutes / session
Third-Party TrackersNone. Zero behavioral, remarketing, or third-party advertising cookies usedNone

Strictly necessary tokens are exempt from consent requirements under UK PECR Regulation 6(4) and EU ePrivacy rules.

5. Authorized Subprocessors

We engage the following trusted infrastructure subprocessors to provide core hosting, identity, and AI reasoning capabilities with minimum operational overhead and maximum security compliance:

SubprocessorProcessing ActivityLocation / Region
Cloudflare, Inc.Edge DNS, Static CDN, Edge Workers, D1 session storeGlobal Edge / USA / EU
Amazon Web Services (AWS Bedrock)Stateless LLM inference runtime (Zero data retention)USA / EU Regions
Google Cloud Platform (Firebase)Authentication synchronization & user profile storeUSA / EU Multi-Region
Microsoft CorporationMicrosoft 365 OAuth SSO & Graph Connected-Storage APICustomer-Configured Tenant
Google LLCGoogle Workspace OAuth & Docs Integration RuntimeCustomer-Configured Tenant

6. International Data Transfers & Standard Contractual Clauses

When personal data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, Erayaha relies on the European Commission's approved Standard Contractual Clauses (EU SCCs 2021/914) and the UK International Data Transfer Addendum, supplemented by technical safeguards including AES-256 encryption in transit and at rest.

7. Your Privacy Rights & Supervisory Authorities (GDPR, UK GDPR, CCPA/CPRA, India DPDP)

Depending on your jurisdiction, you possess the following rights regarding your personal account data:

  • Right of Access & Portability: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your user account records within thirty (30) days without charge.
  • Right to Restrict or Object to Processing: Object to processing based on legitimate interests.
  • No Sale or Targeted Advertising: We certify that Erayaha does NOT "sell" or "share" personal data or conduct cross-context behavioral advertising.
  • No Automated Profiling: We do NOT subject consumers to automated decision-making or profiling producing legal effects.
  • India DPDP Act 2023 Rights: For users in India, Erayaha acts as a Data Fiduciary regarding user account PII and authentication credentials, and as Data Processor for Customer Document Content. Data Principals may exercise statutory rights to access, correction, and grievance redressal via privacy@erayaha.ai, with right to escalate to the Data Protection Board of India.
  • Non-Discrimination: We will never discriminate against you for exercising any applicable privacy rights.
  • Right to Lodge Complaints with Supervisory Authorities: You have the right to lodge a complaint with a competent supervisory authority:
    • European Union / EEA: The Data Protection Commission of Ireland (Irish DPC) as our lead supervisory authority, or your local national Data Protection Authority.
    • United Kingdom: The Information Commissioner's Office (UK ICO).
    • India: The Data Protection Board of India (DPBI).
  • Appeals Process: If we decline to take action regarding your request, you may appeal within thirty (30) days by contacting our Legal Department at legal@erayaha.ai.

To exercise any of these rights, contact our Data Protection Office at privacy@erayaha.ai.

8. Data Retention Schedule, Sensitive Data & Children's Privacy

We enforce strict data retention schedules across all operational data stores:

Data CategoryProcessing PurposeRetention PeriodDisposal Method
Customer Document ContentEphemeral inference & redlining0 Days (Volatile RAM)Immediate in-memory purge
Account & Identity PIIAuthentication & seat managementActive subscription + 30 daysCryptographic DB erasure
OAuth Session TokensConnected storage accessActive session durationToken revocation & deletion
Billing & Tax RecordsPayment processing & statutory compliance7 YearsArchival & secure deletion
Plan Usage TelemetryQuota metering & capacity modeling12 Months (Anonymized)Automated rolling purge
Security & Edge Audit LogsDDoS defense & tamper-evident logging90 DaysAutomated log rotation
  • No Sensitive, Biometric or Health Data: Erayaha does not knowingly collect, process, or sell sensitive personal information, biometric identifiers (under Illinois BIPA or similar laws), or consumer health data (under Washington MHMDA or Nevada SB 370).
  • Children's Privacy (COPPA): The Service is an enterprise B2B platform intended solely for business users aged 18 and older, and does not knowingly collect personal data from children under 16.

9. Contact Privacy & Data Protection Officer

Erayaha has designated a dedicated Privacy & Data Protection Officer. Pursuant to GDPR and UK GDPR Article 27, our processing is non-systematic, does not involve special category data, and does not present high risks to individuals; all inquiries from data subjects and supervisory authorities are managed directly by our Data Protection Office:

Erayaha Inc · Data Protection Office

2261 Market Street, San Francisco, CA 94114, USA

Privacy & DPO Inquiries: privacy@erayaha.ai

General Legal & Appeals: legal@erayaha.ai

Live Trust Center: security.erayaha.ai ↗