Privacy Policy
Effective Date: August 6, 2026 · Version 2.1
Erayaha Inc ("Erayaha", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy details how we collect, process, and safeguard personal information across our website (erayaha.ai), Microsoft Word 365 add-in, Google Docs add-on, and developer APIs.
1. Our Dual Role & GDPR Article 6 Legal Bases
Under European Data Protection Law (GDPR / UK GDPR) and applicable international privacy frameworks:
- Erayaha as Data Controller: We act as a Data Controller for Account Registration PII, customer billing information, business inquiries, and aggregated platform telemetry.
- Erayaha as Data Processor: We act as a Data Processor on behalf of our enterprise and individual customers regarding any Customer Document Content or personal data contained within agreements uploaded or analyzed via the Service. All such processing is governed by our Data Processing Agreement (DPA).
GDPR Article 6 Legal Bases for Controller Processing
- Contractual Necessity (Art. 6(1)(b)): Provisioning user accounts, authenticating sessions, managing subscription tiers, billing, and providing core Document Intelligence features.
- Legitimate Interests (Art. 6(1)(f)): Protecting platform security, detecting and preventing fraud or abuse, maintaining edge infrastructure, and diagnosing service availability.
- Legal Compliance (Art. 6(1)(c)): Complying with statutory corporate, tax, financial recordkeeping, and legal reporting obligations.
- Processor Operations: For Customer Document Content processed as a Processor, processing is executed under Customer's documented instructions pursuant to Article 28 of the GDPR and the DPA.
2. Information We Collect & Process
We strictly categorize the data processed by our systems into three separate tiers:
Tier 1: Customer Document Content (Zero Retention)
Documents analyzed via our Microsoft Word or Google Docs taskpane remain in your connected cloud storage (OneDrive, SharePoint, or Google Drive). During analysis, document snippets are transferred via encrypted TLS 1.3 to volatile RAM memory solely for prompt inference and logical reasoning. We retain zero document text on persistent disk storage, and all transient memory buffers are purged immediately upon request fulfillment.
Tier 2: User Account & Identity PII
When you authenticate using Microsoft Entra ID (Office SSO) or Google Workspace OAuth, we receive and store your name, email address, profile avatar, and organizational tenant identifier in our secure identity database (Google Cloud Firebase Auth / Cloudflare D1) to manage active sessions and access permissions.
Tier 3: Plan Usage Telemetry & Quota Metrics
To meter your usage against your chosen subscription tier (e.g. Starter, Professional, Enterprise) and ensure platform health, we collect structured metadata including timestamps, feature triggers, token usage counts, document classification categories, and API latency. Telemetry contains zero confidential document text.
3. Zero Model Training Warranty
We strictly warrant that we do not use Customer Inputs, Customer Outputs, or confidential contract data to train, fine-tune, or calibrate foundational AI models. Our downstream inference providers (such as AWS Bedrock) operate under binding enterprise B2B covenants prohibiting any training or data logging on user prompts.
4. Zero Website Tracking, Cookie Disclosure & Opt-Out Signals
Our website (erayaha.ai) is statically hosted on Cloudflare's global edge network. We maintain a strict privacy-first posture:
- Zero Tracking Scripts & No Analytics Cookies: We do NOT use Google Analytics, tracking pixels, behavioral advertising cookies, Facebook Pixels, or cross-site tracking scripts. Our marketing pages do not track visitors or build behavioral profiles.
- Universal Opt-Out & GPC Signals: We honor the Global Privacy Control (GPC) and universal browser opt-out signals automatically across all endpoints.
- Direct Inquiry Submissions: When you submit an optional pilot or enterprise inquiry, your submission is transmitted directly over encrypted TLS 1.3 solely to communicate with you regarding your inquiry. We never sell, rent, or broker contact data.
Cookie & Security Token Disclosure
| Identifier / Token | Category & Purpose | Duration |
|---|---|---|
| Firebase Auth JWT | Strictly necessary user authentication token for taskpane sessions | Active session (1 hr / auto-refresh) |
| __cf_bm / cf_clearance | Strictly necessary Cloudflare edge bot mitigation & DDoS protection | 30 minutes / session |
| Third-Party Trackers | None. Zero behavioral, remarketing, or third-party advertising cookies used | None |
Strictly necessary tokens are exempt from consent requirements under UK PECR Regulation 6(4) and EU ePrivacy rules.
5. Authorized Subprocessors
We engage the following trusted infrastructure subprocessors to provide core hosting, identity, and AI reasoning capabilities with minimum operational overhead and maximum security compliance:
| Subprocessor | Processing Activity | Location / Region |
|---|---|---|
| Cloudflare, Inc. | Edge DNS, Static CDN, Edge Workers, D1 session store | Global Edge / USA / EU |
| Amazon Web Services (AWS Bedrock) | Stateless LLM inference runtime (Zero data retention) | USA / EU Regions |
| Google Cloud Platform (Firebase) | Authentication synchronization & user profile store | USA / EU Multi-Region |
| Microsoft Corporation | Microsoft 365 OAuth SSO & Graph Connected-Storage API | Customer-Configured Tenant |
| Google LLC | Google Workspace OAuth & Docs Integration Runtime | Customer-Configured Tenant |
6. International Data Transfers & Standard Contractual Clauses
When personal data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, Erayaha relies on the European Commission's approved Standard Contractual Clauses (EU SCCs 2021/914) and the UK International Data Transfer Addendum, supplemented by technical safeguards including AES-256 encryption in transit and at rest.
7. Your Privacy Rights & Supervisory Authorities (GDPR, UK GDPR, CCPA/CPRA, India DPDP)
Depending on your jurisdiction, you possess the following rights regarding your personal account data:
- Right of Access & Portability: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your user account records within thirty (30) days without charge.
- Right to Restrict or Object to Processing: Object to processing based on legitimate interests.
- No Sale or Targeted Advertising: We certify that Erayaha does NOT "sell" or "share" personal data or conduct cross-context behavioral advertising.
- No Automated Profiling: We do NOT subject consumers to automated decision-making or profiling producing legal effects.
- India DPDP Act 2023 Rights: For users in India, Erayaha acts as a Data Fiduciary regarding user account PII and authentication credentials, and as Data Processor for Customer Document Content. Data Principals may exercise statutory rights to access, correction, and grievance redressal via privacy@erayaha.ai, with right to escalate to the Data Protection Board of India.
- Non-Discrimination: We will never discriminate against you for exercising any applicable privacy rights.
- Right to Lodge Complaints with Supervisory Authorities: You have the right to lodge a complaint with a competent supervisory authority:
- European Union / EEA: The Data Protection Commission of Ireland (Irish DPC) as our lead supervisory authority, or your local national Data Protection Authority.
- United Kingdom: The Information Commissioner's Office (UK ICO).
- India: The Data Protection Board of India (DPBI).
- Appeals Process: If we decline to take action regarding your request, you may appeal within thirty (30) days by contacting our Legal Department at legal@erayaha.ai.
To exercise any of these rights, contact our Data Protection Office at privacy@erayaha.ai.
8. Data Retention Schedule, Sensitive Data & Children's Privacy
We enforce strict data retention schedules across all operational data stores:
| Data Category | Processing Purpose | Retention Period | Disposal Method |
|---|---|---|---|
| Customer Document Content | Ephemeral inference & redlining | 0 Days (Volatile RAM) | Immediate in-memory purge |
| Account & Identity PII | Authentication & seat management | Active subscription + 30 days | Cryptographic DB erasure |
| OAuth Session Tokens | Connected storage access | Active session duration | Token revocation & deletion |
| Billing & Tax Records | Payment processing & statutory compliance | 7 Years | Archival & secure deletion |
| Plan Usage Telemetry | Quota metering & capacity modeling | 12 Months (Anonymized) | Automated rolling purge |
| Security & Edge Audit Logs | DDoS defense & tamper-evident logging | 90 Days | Automated log rotation |
- No Sensitive, Biometric or Health Data: Erayaha does not knowingly collect, process, or sell sensitive personal information, biometric identifiers (under Illinois BIPA or similar laws), or consumer health data (under Washington MHMDA or Nevada SB 370).
- Children's Privacy (COPPA): The Service is an enterprise B2B platform intended solely for business users aged 18 and older, and does not knowingly collect personal data from children under 16.
9. Contact Privacy & Data Protection Officer
Erayaha has designated a dedicated Privacy & Data Protection Officer. Pursuant to GDPR and UK GDPR Article 27, our processing is non-systematic, does not involve special category data, and does not present high risks to individuals; all inquiries from data subjects and supervisory authorities are managed directly by our Data Protection Office:
Erayaha Inc · Data Protection Office
2261 Market Street, San Francisco, CA 94114, USA
Privacy & DPO Inquiries: privacy@erayaha.ai
General Legal & Appeals: legal@erayaha.ai
Live Trust Center: security.erayaha.ai ↗