Documentation développeur Demander une démo
Demander une démo

Global Privacy Policy Notice

Version: 2.0 (Enterprise) Entrée en vigueur: September 1, 2026
Retour au résumé

Ces documents sont publiés en anglais. Le texte anglais fait foi dans toutes les juridictions.

1Executive Summary and Operational Scope

1.1Data Controller and Processor Identification

This Privacy Policy (the "Policy") governs the data processing activities of Traffelo AI Inc. ("Traffelo AI", "Company", "we", "us", or "our"), operating the traffelo.ai domain and associated enterprise sovereign artificial intelligence infrastructure. This Policy sets forth our obligations under applicable global data protection frameworks, including without limitation:

  • Regulation (EU) 2016/679 (General Data Protection Regulation / "GDPR") and the UK Data Protection Act 2018;
  • Turkish Law No. 6698 on the Protection of Personal Data ("KVKK");
  • UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data ("PDPL") and Qatar Law No. 13 of 2016; and
  • Singapore Personal Data Protection Act 2012 ("SG PDPA") and Malaysia Personal Data Protection Act 2010 ("MY PDPA", as amended).

1.2Dual Operational Scope and B2B Limitation

Traffelo AI maintains a strict operational bifurcation between marketing/corporate interactions and enterprise platform execution:

  • Website & Commercial Operations (Controller Role): Traffelo AI acts as a Data Controller for personal data collected via website forms, executive briefing requests, whitepaper downloads, and commercial inquiries.
  • Sovereign Platform Architecture (Processor Role): When enterprise customers deploy Traffelo AI's Model Context Protocol (MCP) and sovereign edge routing engine, the customer remains the Data Controller. Traffelo AI acts exclusively as a Data Processor or Sub-processor pursuant to an executed Data Processing Agreement ("DPA").
Business-to-Business (B2B) Restriction: Our web properties, corporate interfaces, and platform services are intended exclusively for commercial enterprise entities. We do not solicit, market to, or knowingly collect personal data from individuals under eighteen (18) years of age.

2Enterprise Sovereign Platform Data Handling

2.1Local Sovereign Edge Processing & Zero Leakage

The Traffelo AI platform is architected to guarantee that raw Personal Identifiers ("PII") never breach the customer's defined security perimeter. PII is detected, masked, and tokenized locally at the client's sovereign edge node utilizing quantized WASM/ONNX models in sub-5ms total execution time prior to payload transmission to external inference models. The memory buffers holding in-flight API payloads are cleared post-execution (volatile RAM execution) immediately.

2.2Prohibition of Model Training

Traffelo AI does not store, retain, monetize, or utilize enterprise client datasets, prompts, or output payloads to train public foundation models or third-party algorithms. All telemetry generated within the customer's isolated environment remains under the direct governance of the customer's enterprise DPA.

3Categories of Personal Data Collected

3.1Information Provided Directly by Users

When engaging with our corporate interfaces, we may collect:

  • Contact Identifiers: Full name, business email address, corporate telephone number, job title, and organization name.
  • Inquiry Context: Regional deployment preferences (e.g., hybrid, air-gapped, GCC local zone) and specific briefing requirements submitted via forms.

3.2Technical & Session Data

  • Strictly Necessary Metadata: IP address (truncated), operating system, browser type, language settings, and theme configuration state.
  • Optional Analytics: Loaded strictly subject to prior opt-in consent. If accepted, Google Analytics processes truncated IP addresses and navigation paths outside Traffelo AI's sovereign boundary. Selecting "Necessary Only" completely blocks external analytics initialization.

3.3Subprocessors and Infrastructure Vendors

Traffelo AI engages vetted third-party service providers ("Subprocessors") to support website hosting, security logging, and transactional communications. All Subprocessors are bound by contract to uphold security standards equivalent to this Policy and are restricted from utilizing personal data for independent processing. A current list of third-party infrastructure Subprocessors is available upon request.

4Legal Bases for Processing

Traffelo AI processes personal data only where a lawful basis exists:

  • Performance of Contract / Pre-contractual Steps: Processing executive briefing requests to facilitate commercial demonstrations.
  • Legitimate Interests: Fulfilling business-to-business (B2B) commercial communications, maintaining web infrastructure security, and preventing fraudulent requests.
  • Explicit Consent: Optional performance analytics and non-essential cookie deployment. Consent may be revoked at any time via the web preference portal.
  • Legal Compliance: Satisfying statutory recordkeeping and lawful regulatory mandates under KVKK, GDPR, PDPL, or PDPA frameworks.

Users can object to legitimate interest processing at any time without affecting contract performance.

5International Data Transfers & Sovereign Boundaries

5.1Transfer Safeguards

Where cross-border data transfer is required for website inquiry data, Traffelo AI enforces lawful transfer mechanisms:

  • European Economic Area (EEA): EU Standard Contractual Clauses (SCCs), UK IDTA, (Modules 1 and 2) supplemented by Transfer Impact Assessments.
  • Republic of Turkey: Adherence to KVKK Article 9 cross-border transfer provisions and standard contractual terms recognized by the Personal Data Protection Board (Kişisel Verileri Koruma Kurumu).
  • GCC Region (UAE/Qatar): Localized sovereign cloud storage options to preserve in-region residency requirements.
  • S.E. Asia (MY/SG): Compliance with SG PDPA and MY PDPA cross-border transfer equivalence mandates.

6Data Retention and Destruction

6.1Retention Schedules

  • Executive Briefing & Commercial Inquiry Records: Retained for twenty-four (24) months from the date of last active communication, following which records are permanently deleted or irreversibly anonymized through secure, unrecoverable deletion protocols (e.g., NIST SP 800-88 cryptographic wipe standard).
  • Technical Security Logs: Retained for ninety (90) days.
  • Consensual Analytics Data: Purged or aggregated after fourteen (14) months.

7Data Subject Rights

7.1Statutory Rights

Subject to regional statutory limits, individuals possess the right to request access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing.

7.2Regional Declarations

KVKK Declarations: Pursuant to KVKK Article 11, Turkish data subjects may inquire whether personal data is processed, request information regarding transfers, demand correction, and request compensation for unlawful handling.

Exercising Rights: Direct all Data Subject Access Requests (DSARs) to the Data Protection Office using the privacy contact in Section 8. Responses are issued within thirty (30) calendar days or the applicable statutory window.

8Contact Information and Data Protection Office

8.1Primary Contact Details

Traffelo AI Inc. — Data Protection Office. Use the contacts below to reach the Data Protection Office, general executive enquiries, or the security team. Mailbox addresses are deliberately not published on this page; each contact opens a routed form.

8.2Enterprise Security & Vulnerability Reporting

For inquiries regarding our SOC 2 Type II controls, ISO/IEC compliance frameworks, or to report a technical vulnerability, please use the security contact above.

9Additional Mandatory Disclosures

9.1Supervisory Authority Rights

Data subjects in the EU/UK, Turkey, GCC, and S.E. Asia retain the statutory right to lodge a complaint with their respective supervisory authority, including the Kişisel Verileri Koruma Kurumu (Turkey), the Personal Data Protection Commission (Singapore), and relevant EU Data Protection Authorities.

9.2Automated Decision-Making & Profiling

Traffelo AI does not utilize personal data collected via website or commercial interfaces for automated decision-making, profiling, or credit evaluation under GDPR Article 22 or regional equivalents.

9.3Children's Privacy

Our website and platform solutions are exclusively targeted to commercial enterprise entities (B2B). We do not knowingly collect personal data from individuals under eighteen (18) years of age.

Haut de page