1. Who we are
BVECrew is operated by Black Vault Engineering Group LLC ("BVE", "we", "us"), [REGISTERED ADDRESS] . This policy explains what personal data we collect, why, and what we do with it, across the website at bvecrew.com, the Front Office client portal, and the AI Staff Members we place with clients.
2. Two roles: controller and processor
2.1 For the website and for Front Office accounts, BVE is the controller: we decide what is collected and why. Sections 3, 4 and 11 to 13 apply.
2.2 For Client Data that an AI Staff Member handles on a client's behalf, the client is the controller and BVE is the processor. We act only on the client's documented instructions, which are the Charter, the Overlay and the Placement Order. Sections 5 to 10 apply, and where a Data Processing Agreement is signed it governs.
2.3 If you are an end customer, employee or contact of one of our clients and an AI Staff Member has communicated with you, the client is responsible for your data. Contact them first; we will help them respond. The AI Staff Member will have told you it is AI-operated; see the AI Disclosure Statement.
3. Data we collect on the website
3.1 The website is static and served through Cloudflare. We collect:
- Server and edge logs. IP address, user agent, requested page, timestamp, kept by Cloudflare and by us for security and capacity, for [N] days.
- What you send us. If you request a quote or contact us, the name, organisation, email, and message you provide, used to reply and to prepare a quote.
3.2 [CONFIRM: NO THIRD-PARTY ANALYTICS OR ADVERTISING SCRIPTS ARE LOADED] . If that changes, this section will name each script and its purpose.
4. Data we collect in the Front Office
- Account data. Name, work email, organisation, role, and the approver designations you configure.
- Access records. Sign-in events through Cloudflare Access, and every approval decision, with who made it and when. These are part of the audit log.
- Configuration. Your Overlays, your connected systems (Anchor configuration), your residency and model-policy selections.
- Support correspondence. Tickets and messages with BVE personnel.
Legal basis where one is required: performance of a contract with you or your organisation, and our legitimate interest in running a secure service. [COUNSEL TO CONFIRM LEGAL BASES PER JURISDICTION]
5. Client Data handled by AI Staff Members
5.1 An AI Staff Member sees only the data sources its Charter allows and its Overlay has not removed. What it sees is set by the client, who is the controller.
5.2 Everything an AI Staff Member does with Client Data is written to a hash-chained, tamper-evident audit log. The client can export that log.
5.3 BVE personnel supervising a Placement may view Client Data as needed to review scorecards, approve actions the client has delegated, investigate incidents, or provide support. Such access is itself logged.
5.4 BVE does not use Client Data to train models, to build profiles, or for any purpose other than providing the service to that client.
6. Model providers and redaction
6.1 Placements have a model policy of standard or confidential, chosen on the Placement Order.
6.2 Under confidential, and under Vault residency regardless of policy, no Client Data is sent to any cloud model provider. Inference runs on BVE-controlled or client-controlled hardware.
6.3 Under standard, context may be sent to the model provider the client selected, and only after BVE has redacted it locally, on the same host, before it leaves. BVE never uses a third-party redaction or data-loss-prevention API for this step. The provider receives redacted context only and is bound by a written agreement.
7. Subprocessors
| Subprocessor | Purpose | Scope |
|---|---|---|
| Cloudflare | DNS, CDN, Access, Tunnel | Website and portal edge. Sees connection metadata and access events, not Placement data. |
| Client-selected model provider | Language-model inference on locally redacted context | Standard-policy Placements only. Never Confidential policy, never Vault residency. |
That is the full list. We give clients at least [30] days' notice before adding or changing a subprocessor that touches Client Data. The client's own cloud account (Tenant residency) and own premises (Vault residency, Keyed connector host) are the client's infrastructure, not our subprocessors.
8. Where data lives
Each Placement has a residency level chosen by the client:
- Keyed (level 1): Your storage, your keys.
- Tenant (level 2): Runs inside your own cloud account.
- Vault (level 3): Nothing leaves your building.
Website and Front Office account data is stored in [COUNTRY / REGION] . Vertical compliance packs may add a location rule; for example the tax pack requires US-only processing. Cross-border transfer mechanisms, where required: [TRANSFER MECHANISM, E.G. SCCS] .
9. Retention and deletion
- Website logs: [N] days.
- Quote and contact enquiries: [N] months after our last exchange, unless a contract follows.
- Front Office account data: for the life of the account plus [N] months.
- Client Data and Placement audit logs: for the Placement term, then an export window of [30] days, then deletion by crypto-shred.
Crypto-shred means we destroy the dedicated encryption key under which everything for that client, including backups, was encrypted. Without the key the data is permanently unrecoverable everywhere. We issue a signed Deletion Certificate identifying the Placement and the destroyed key identifiers. We keep only the certificate itself and the minimum billing and legal records the law requires.
10. Security
Mutual TLS between all internal services with short-lived certificates from our own PKI; per-client encryption keys; local-only redaction; a hash-chained audit log; identity-gated portal access with no inbound ports on our hosts; and human approval enforced by the runtime for external and irreversible actions. Details, and our current certification status (SOC 2 in progress, not certified), are at /trust.
If a breach affects your personal data we will notify you without undue delay and within any period the law or your contract sets. Financial-services placements carry a contractual 72-hour maximum. [COUNSEL TO CONFIRM BREACH-NOTICE WINDOWS BY JURISDICTION]
11. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or port your personal data, to object to processing, and to complain to a supervisory authority. To exercise a right for data we control, contact us at the address in section 15. We will verify your identity and respond within [30] days.
For data an AI Staff Member handled on a client's behalf, we will forward your request to that client and assist them. [ADD JURISDICTION-SPECIFIC RIGHTS NOTICES: CCPA/CPRA, GDPR/UK GDPR, OTHERS AS APPLICABLE]
12. Cookies and local storage
The website sets no advertising or tracking cookies. It stores your light/dark theme preference in your browser's local storage; that value never leaves your browser. Cloudflare may set strictly necessary cookies for security and, on the Front Office, for Access sign-in. If we ever add anything else, this section will list it and, where required, ask first.
13. Children
Our services are for organisations. We do not knowingly collect personal data from anyone under [16 / 13] . If you believe we have, contact us and we will delete it.
14. Changes
We will post any update at /legal/privacy with a new version and effective date, and notify Front Office account holders of material changes at least [N] days before they take effect.
15. Contact
Privacy questions and rights requests: [email protected] (placeholder -- HUMAN_ACTIONS: confirm real legal/privacy contact address)
Data protection contact: [NAME / TITLE, IF ONE IS APPOINTED]
Postal: Black Vault Engineering Group LLC, [REGISTERED ADDRESS]