Phase 0 · Pre-launch. Commercial activity has not commenced.
DSAR Engine ← Back to site

Privacy Policy

Effective Date: August 8, 2026 · Version 1.0

This Privacy Policy describes how DSAR Engine (operated by Ellis Intelligence LLC, "we", "us", "our") collects, uses, and shares information when you visit dsarengine.com or use the Service.

For how we process Customer Data — including consumer request records and identity-verification information — on behalf of our Customers, see §4 and the Data Processing Addendum at dsarengine.com/dpa.

1. Scope

This Policy covers:

2. Information we collect

(a) Directly from Customers and visitors: Account information (name, business email, role), billing information (tokenized via Stripe), and communications you send us.

(b) Automatically: Device and connection data, usage data, and cookies (strictly necessary + functional + aggregated analytics only; no third-party advertising trackers).

(c) Customer Data — processor role: Consumer request records (type, jurisdiction, deadline and clock state, fulfillment-step status), requester contact data, identity-verification data, generated correspondence, and chain-of-custody event logs. We process this category only on the Customer's instructions to operate the Service (see §4).

3. Information we do not want

The Service is designed to process consumer-privacy-request workflow data. Through the public intake page and the Service, do not collect or upload more than is necessary, and in particular do not collect:

If we discover such information collected or uploaded inadvertently, we will notify the responsible Customer and request deletion, and may sanitize or delete it without prior notice if necessary to prevent privacy or regulatory exposure.

4. Customer data and consumer data — our role

4.1 Processor / Service Provider. With respect to all consumer data processed through the Service to receive, verify, track, and fulfill privacy requests, the Customer is the controller (or "business") and we are the processor (or "service provider"). We process that data only on the Customer's documented instructions to provide the Service, and not for our own purposes.

4.2 The Public Intake Page. The Service includes a Customer-configurable public intake page. Although we host and render that page and collect the information a consumer enters — including identity-verification information — we do so as the Customer's processor and on the Customer's behalf. The consumer's relationship is with the Customer (the company that holds their data), not with DSAR Engine. We are not an independent controller of that data, not a consumer-reporting agency, and not an identity-verification service offered to the public.

4.3 Identity-Verification Data — Minimization. Identity-verification information is collected and retained under data-minimizing practices. The cockpit shows a non-PII display reference; only the contact email needed to deliver a response is retained; verification uses single-use tokens; and verification secrets are never written to the audit log. Per-tenant configuration (email / document / third_party) lets each Customer choose the lightest verification method that meets its needs.

4.4 No Sale, No Share. We do not sell consumer data or Customer Data, and we do not share it for cross-context behavioral advertising. We do not transmit, license, or make consumer data available to any third party except (a) to operate the Service as the Customer directs, (b) to subprocessors listed at dsarengine.com/subprocessors operating under equivalent restrictions, or (c) as required by law.

4.5 No Training on Customer Data. We do not use Customer Data or consumer data to train any model, fine-tune any shared model, or improve a Service used by other customers.

4.6 Flat Per-Tenant Isolation. Each Customer is one tenant; consumers who file requests are records within that tenant. Row-level isolation enforces that no Customer can access another Customer's data; every tenant-scoped query is scoped by tenant_id.

4.7 Audit-Log Integrity. The chain-of-custody event log is append-only and tamper-detected. We do not alter or delete audit records at Customer direction except during deletion at termination or as required by law. The audit log carries no PII beyond what the record requires; verification secrets are never logged.

5. How we use information (controller role)

For marketing-site visitors and Customer account/billing contacts, we use information to:

We do not sell personal information and do not share it for cross-context behavioral advertising.

6. Sharing and disclosure

(a) Subprocessors at dsarengine.com/subprocessors, operating under equivalent data-protection restrictions.
(b) Legal compliance: Where required by law, regulation, or court order, or to protect the rights, property, or safety of DSAR Engine, our Customers, or others.
(c) Business transfers: In connection with a merger, acquisition, or asset sale, with notice to Customers.
(d) With instruction/consent: As directed in writing by the Customer.

We do not share consumer data or Customer Data with data brokers, advertising networks, or any third party for purposes outside operating the Service.

7. Cookies and tracking

Strictly necessary, functional, and aggregated-analytics cookies only. No third-party advertising or behavioral trackers.

8. Retention

9. Security

Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, with independent external uptime monitoring being brought online ahead of launch. We use tenant isolation between customers. We do not claim SOC 2, ISO 27001, or any audited certification on this pre-launch product; we will update this section as our security program and independent assessments mature. No method of transmission or storage is perfectly secure. SOC 2 Type I is tracked as an up-market gate, not a launch gate. Breach notification to affected Customers per the DPA: without undue delay, and in any event within five (5) business days of becoming aware; provided that where the strictest applicable state breach-notification law or an FCRA-specific notice trigger requires a Customer to act on a shorter timeline, we will use commercially reasonable efforts to notify the Customer within whatever shorter period is necessary for the Customer to meet that deadline.

10. International transfers

Processing occurs in the United States. For any EU/UK/Swiss data, Standard Contractual Clauses (Module 2) plus the UK Addendum apply per the DPA. The Year-1 customer base is primarily U.S.

11. Your rights

Marketing-site visitors and Customer billing contacts: You have the rights afforded by applicable law (the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA"), the Colorado Privacy Act, and other state laws; Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") / the UK GDPR where applicable) to access, correct, delete, or port your information and to opt out of sale/share and certain processing. We do not sell or share this information. Email [email protected].

Consumers whose request is processed by a Customer using DSAR Engine: The Customer (the company that holds your data) is the controller of that request and the underlying data. Direct your privacy request to that company, not to DSAR Engine. We act only as the Customer's processor. We will cooperate with the Customer to fulfill valid access, deletion, correction, or opt-out requests per the DPA and applicable law, and we do not respond directly to consumer data-subject requests unless the responsible Customer explicitly authorizes and instructs us to do so.

12. Software tool — not legal advice

DSAR Engine is a software tool. It is not a law firm and does not provide legal advice, legal representation, or compliance assurance. Use of the Service does not guarantee compliance with any privacy law. DSAR Engine does not review, interpret, or render a determination on the validity of any consumer request; your team decides and fulfills each request. Each Customer remains solely responsible for ensuring its privacy-request practices comply with applicable law. The built-in deadline clocks, reminders, rule overlays, and templates are designed to assist; they are not a substitute for legal counsel.

13. Children's privacy

The Service is for business users and is not directed to individuals under 13. We do not permit account creation by anyone under 13, and we do not knowingly collect information from children under 13 through the marketing site or account flows. The Service is not designed to process children's data; see §3. If we learn we have collected information from a child under 13, we will delete it promptly. A Customer that receives a privacy request concerning a minor is the controller of that request.

14. Updates

We will provide 30 days' email notice to Customer billing contacts for material changes to this Policy.

15. Contact

[email protected] — privacy matters
[email protected] — other legal matters

DSAR Engine is a product of Ellis Intelligence LLC. This page is posted for transparency and is not legal advice. See also our Terms of Service. Questions about this document: [email protected].