Data & privacy approach
The questions privacy teams actually ask, answered directly: what we touch, where it lives, how long we keep it, and what never happens to it.
Data flows & minimization
- Engagement data: workflow documentation, samples, and system metadata needed for diagnosis and build — processed in your environment wherever practical.
- Website data: form submissions (name, work email, company, role, message) go to our CRM (Pipedrive) to respond to you; analytics per the cookie policy, consent-aware.
- Minimization: production integrations move only required fields; discovery prefers samples and redacted sets where they suffice.
- Residency considerations: tool selection accounts for your residency obligations (US, Brazil, sector rules); constraints are documented in the architecture review.
Client data and AI models
We do not use client data to train models — ours or anyone's. Olyra builds no products on client data. Third-party AI tools are configured so client data is excluded from provider model training wherever the provider supports it, and that support is a selection criterion when we recommend tools. Data-use terms per tool are documented in plain language in your governance pack, so counsel can verify rather than trust.
Retention, deletion & rights
- Retention: engagement working data is retained only as long as the engagement and its warranty period require, per your DPA; deliverables belong to you.
- Deletion: on request or at engagement end, working copies are deleted and deletion is confirmed in writing.
- GDPR & LGPD-aware: we operate across the Americas with attention to LGPD (Brazil) and GDPR-derived expectations — lawful basis, purpose limitation, data-subject rights support.
- Agreements: NDA available before sensitive discussions; DPA available for engagements. Healthcare engagements are designed within your compliance framework — BAAs are addressed case-by-case with counsel, and we don't claim blanket HIPAA coverage.
This page describes practice; the privacy policy is the formal notice. Both are subject to counsel review — see the Trust Centre note.
Find out what AI can actually do for your operations.
Start with an AI Operations Audit — a fixed-scope diagnostic that maps your workflows, scores your AI readiness, and hands you a prioritized 120-day roadmap. If we don't find real opportunities, you'll know that too.
Request an AI Operations Audit → Prefer to talk first? Book a 30-minute scoping call.