1. Introduction & Commitment
Robluz (operating as an independent professional artificial intelligence engineering and consulting practice, "we", "our") respects the critical confidentiality and privacy of our commercial and institutional clients ("Client", "you"). This Privacy Policy details how we collect, process, isolate, and safeguard data in the course of delivering high-ticket artificial intelligence engineering, custom LLM fine-tuning, and multi-agent infrastructure services.
2. Types of Data We Process
In providing professional AI services, we may interact with the following categories of information:
- Client Account & Billing Information: Contact names, professional email addresses, telephone numbers, billing addresses, and payment tokens processed through Stripe, Inc.
- Technical Architecture & Infrastructure Credentials: API keys, staging environment endpoints, and container deployment specifications provided under Mutual Non-Disclosure Agreements for system integration.
- Fine-Tuning & Knowledge Base Datasets: Unstructured client documents, vector embeddings, and synthetic question-answer pairs supplied specifically for model training or autonomous agent retrieval.
3. The Zero-Data Retention Protocol
To eliminate security risk, Robluz operates under strict data sovereignty controls:
- No Public Model Training: Client datasets are never utilized to improve or fine-tune public models, third-party foundation models, or services offered to other clients.
- Private Cloud & On-Premise Enclaves: Model training and agent orchestration pipelines are executed directly within Client's private cloud (AWS, Azure, GCP) or dedicated, air-gapped private compute clusters.
- Immediate Dataset Purge Upon Handover: Following completion and formal acceptance of a fine-tuning milestone, any temporary staging copies of training data stored on staging systems are cryptographically deleted within forty-eight (48) hours.
4. Institutional Security Safeguards
We implement institutional-grade physical, administrative, and technical safeguards:
- Encryption in Transit & at Rest: All communications, API requests, and data transfers utilize TLS 1.3 encryption. Stored vectors, model checkpoints, and database volumes are encrypted using AES-256.
- Access Control: Only vetted senior research engineers assigned to your specific Statement of Work are granted access to staging environments, subject to biometric multi-factor authentication (MFA).
- Audit Logs & Telemetry: Comprehensive audit logs are maintained for all data access events during active engineering sprints.
5. Stripe Payment Processing & Financial Data
We do not directly store or process raw credit card numbers or banking account credentials on our servers. All transaction billing is processed through Stripe, Inc. in compliance with the Payment Card Industry Data Security Standard (PCI-DSS Level 1).
6. International Data Transfers & Regulatory Compliance
Our data handling practices comply with the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the emerging EU AI Act governance guidelines. Standard Contractual Clauses (SCCs) and Data Processing Addendums (DPAs) are available upon request for active client engagements.
7. Privacy & Practice Contact
For inquiries or to request an executive Data Processing Addendum (DPA), please contact:
Data Protection & Privacy Administration
100 Montgomery Street, Suite 2200
San Francisco, CA 94104, United States
Email: privacy@robluz.com | contact@robluz.com
Direct Inquiries: +1 (415) 890-3490