Privacy & Data Protection Policy
Last Updated: August 2026 GDPR Compliant Framework
Zero AI Model Training
Your enterprise data and feature vectors are never used to train foundational AI or LLM models.
Zero-Copy In-Memory Isolation
Data transforms execute inside ephemeral GPU VRAM buffers and are purged after the pipeline run.
Sovereign Regional Storage
Deploy pipelines in specific geographic jurisdictions including US East, EU Frankfurt, and APAC nodes.
Encryption at Rest
The policy framework covers AES-256 encryption at rest and TLS 1.3 in transit across ingestion nodes.
Policy framework: This page describes the intended privacy and security model for DataSculpt. Qualified privacy and security counsel should review it against the final deployment, contract, and applicable jurisdiction before publication or reliance.
Information We Collect
We collect the information needed to operate accounts, provide support, secure the platform, and deliver contracted data workflows.
Account and contact information may include names, business email addresses, organization details, workspace settings, support correspondence, and billing administration details.
Customers may submit datasets, schemas, pipeline configurations, prompts, derived artifacts, and feature representations for processing. Customers determine the purpose and lawful basis for those submissions.
Ephemeral GPU Data Processing Architecture
The platform is designed to process transformation workloads in isolated, short-lived memory contexts.
Where the selected deployment supports it, pipeline transforms use ephemeral CPU, RAM, and GPU VRAM buffers, including Apache Arrow-compatible in-memory representations. Processing buffers are cleared after the relevant run according to the configured execution and retention policy.
Temporary operational copies may exist when required for orchestration, retries, security, backup, or audit operations. The applicable deployment and order terms define those exceptions and retention windows.
How We Use Account Telemetry
Telemetry helps operate, secure, troubleshoot, and improve the contracted service without becoming a training corpus for public models.
Account telemetry may include login and access events, pipeline execution metadata, resource utilization, error traces, configuration changes, latency, throughput, and support diagnostics.
We use telemetry to provide service visibility, detect abuse and security incidents, measure reliability, produce billing records, and improve platform operations. We do not use customer datasets, feature vectors, or private content to train public foundation models.
Data Isolation & Single-Tenant VPC Options
Enterprise deployments can use stronger isolation boundaries and region-specific operating models.
Depending on the contracted architecture, workloads may run in shared service boundaries, isolated environments, or single-tenant VPC and private-cluster deployments. Access controls, network boundaries, encryption, and administrative separation are selected during deployment review.
Regional placement may be requested for supported environments. Customers remain responsible for confirming that the selected region and deployment model satisfy their legal, regulatory, and contractual requirements.
Third-Party Integrations & Subprocessors
The service may rely on infrastructure and delivery providers to provide networking, compute, storage, and platform operations.
The reference infrastructure model may include Cloudflare for CDN and edge delivery, AWS for cloud infrastructure and storage services, and NVIDIA infrastructure or GPU technologies for accelerated workloads. Specific subprocessors and services depend on the customer deployment and contract.
We use contractual, technical, and operational controls appropriate to the service relationship. Enterprise customers may request additional subprocessor, region, and security information through the DPO or security contact.
Your Rights under GDPR & CCPA
Depending on applicable law and role, individuals may request access, correction, deletion, portability, restriction, or objection regarding personal information.
To submit a data subject access request, email info@datasculpt.lk with your identity, organization, request type, affected account or data scope, and preferred response channel. We may verify identity and authority before responding.
We will assess requests under applicable law, respond within the required period, and explain any lawful limitation or exception. Requests may also be made through an authorized representative where applicable.
Data Retention & Permanent Deletion
Retention depends on service delivery, customer configuration, security, billing, legal, and audit requirements.
Customers may request deletion of account data, submitted content, derived artifacts, or telemetry by contacting the DPO or security team. Include the workspace, data category, requested scope, and desired completion window.
Deletion requests are reviewed against backup, fraud-prevention, security, billing, dispute, and legal-retention obligations. Once required retention ends, data is deleted or irreversibly de-identified according to the applicable policy and deployment controls.
Security Officer Contact Information
Security, privacy, incident, and data-rights questions are routed to the designated privacy and security contacts.
Contact the Data Protection Officer at info@datasculpt.lk for privacy rights, DSAR, retention, and processing questions. Contact info@datasculpt.lk for suspected security incidents, access concerns, vulnerability reports, or enterprise security documentation.
When reporting an incident, include the affected workspace, approximate time, observed behavior, and a safe callback channel. Do not include secrets, credentials, or unnecessary personal data in the initial report.
DATA PROTECTION OFFICER
Privacy and security questions have a direct path.
Reference status language subject to final audit and enterprise documentation.