Privacy Policy
Last updated: January 12, 2026
HAIEC Inc. ("HAIEC," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI governance platform, APIs, and related services.
Our Commitment
As an AI governance company, we hold ourselves to the highest standards of data protection. We practice what we preach: your data is never used to train AI models, sold to third parties, or retained longer than necessary.
Information We Collect
Information You Provide
- Account Information: Name, email address, company name, job title when you create an account
- Payment Information: Billing details processed securely through Stripe (we never store full card numbers)
- API Usage Data: Requests made to our APIs, including input data you choose to analyze
- Communications: Messages you send us through contact forms, support tickets, or email
- Assessment Data: Responses to our AI readiness assessments and compliance checklists
Information Collected Automatically
- Usage Analytics: Pages visited, features used, time spent (via Vercel Analytics)
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, referring URLs
How We Use Your Information
- Service Delivery: To provide, maintain, and improve our AI governance tools and APIs
- Account Management: To manage your account, process payments, and provide customer support
- Communications: To send service updates, security alerts, and (with consent) marketing communications
- Analytics: To understand usage patterns and improve our services
- Compliance: To meet legal obligations and enforce our terms
What We Never Do
- ❌ We never sell your personal data to third parties
- ❌ We never use your data to train AI models
- ❌ We never share your API inputs with other customers
- ❌ We never retain data longer than necessary for service delivery
Data Retention
We retain your information only as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically:
- Account Data: Retained while your account is active, deleted within 30 days of account closure
- API Request Data: Processed in real-time, not stored unless you enable audit logging
- Audit Logs: Retained for the period you specify (default: 90 days)
- Analytics Data: Aggregated and anonymized after 26 months
Data Security
We implement enterprise-grade security measures including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- SOC 2 Type II certified infrastructure
- Regular security audits and penetration testing
- Role-based access controls and audit logging
International Data Transfers
Our services are hosted in the United States. If you access our services from outside the US, your information may be transferred to and processed in the US. We use Standard Contractual Clauses and other appropriate safeguards for international transfers.
Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Portability: Receive your data in a portable format
- Opt-out: Opt out of marketing communications
- Restriction: Request restriction of processing
To exercise these rights, contact us at privacy@haiec.com.
Email Communications
When you create an account, you may opt-in to receive email communications from us. These include:
- Compliance Updates: Regulatory changes, new framework requirements, and deadline reminders
- Product Updates: New features, improvements, and service announcements
- Monthly Digest: Summary of your compliance status and recommended actions
- Educational Content: Best practices, guides, and industry insights
Your Email Preferences
You can manage your email preferences at any time:
- ✓ Click "Manage email preferences" in any email footer
- ✓ Update settings in your account dashboard
- ✓ Contact us at support@haiec.com
Important: We will always send transactional emails (password resets, security alerts, billing notifications) regardless of your marketing preferences, as these are essential for account security.
Cookies and Tracking
We use essential cookies for authentication and session management. We use Vercel Analytics for privacy-friendly usage analytics (no personal data collected). We do not use third-party advertising cookies.
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our services. Your continued use after changes constitutes acceptance.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
See also: Terms of Service | Security