Privacy Policy
Effective Date: August 8, 2026 · Version 1.0
This Privacy Policy describes how DSAR Engine (operated by Ellis Intelligence LLC, "we", "us", "our") collects, uses, and shares information when you visit dsarengine.com or use the Service.
For how we process Customer Data — including consumer request records and identity-verification information — on behalf of our Customers, see §4 and the Data Processing Addendum at dsarengine.com/dpa.
- 1. Scope
- 2. Information we collect
- 3. Information we do not want
- 4. Customer data & consumer data — our role
- 5. How we use information (controller role)
- 6. Sharing and disclosure
- 7. Cookies and tracking
- 8. Retention
- 9. Security
- 10. International transfers
- 11. Your rights
- 12. Software tool — not legal advice
- 13. Children's privacy
- 14. Updates
- 15. Contact
1. Scope
This Policy covers:
- Visitors to
dsarengine.com; - Customer (business) account holders and their authorized users; and
- Consumers who submit a privacy request through a Customer's intake page — but only to explain that, for that data, the Customer is the controller and we act as the Customer's processor (see §4 and §11).
2. Information we collect
(a) Directly from Customers and visitors: Account information (name, business email, role), billing information (tokenized via Stripe), and communications you send us.
(b) Automatically: Device and connection data, usage data, and cookies (strictly necessary + functional + aggregated analytics only; no third-party advertising trackers).
(c) Customer Data — processor role: Consumer request records (type, jurisdiction, deadline and clock state, fulfillment-step status), requester contact data, identity-verification data, generated correspondence, and chain-of-custody event logs. We process this category only on the Customer's instructions to operate the Service (see §4).
3. Information we do not want
The Service is designed to process consumer-privacy-request workflow data. Through the public intake page and the Service, do not collect or upload more than is necessary, and in particular do not collect:
- Identity-verification information beyond the minimum the selected verification method requires;
- Government-issued ID numbers or full ID document images where a lighter verification method suffices for the request;
- Health information protected by the Health Insurance Portability and Accountability Act ("HIPAA") ("PHI");
- Information about a consumer that is unrelated to receiving, verifying, and fulfilling their request;
- Any data for a purpose other than receiving, verifying, tracking, fulfilling, or auditing a consumer privacy request.
If we discover such information collected or uploaded inadvertently, we will notify the responsible Customer and request deletion, and may sanitize or delete it without prior notice if necessary to prevent privacy or regulatory exposure.
4. Customer data and consumer data — our role
4.1 Processor / Service Provider. With respect to all consumer data processed through the Service to receive, verify, track, and fulfill privacy requests, the Customer is the controller (or "business") and we are the processor (or "service provider"). We process that data only on the Customer's documented instructions to provide the Service, and not for our own purposes.
4.2 The Public Intake Page. The Service includes a Customer-configurable public intake page. Although we host and render that page and collect the information a consumer enters — including identity-verification information — we do so as the Customer's processor and on the Customer's behalf. The consumer's relationship is with the Customer (the company that holds their data), not with DSAR Engine. We are not an independent controller of that data, not a consumer-reporting agency, and not an identity-verification service offered to the public.
4.3 Identity-Verification Data — Minimization. Identity-verification information is collected and retained under data-minimizing practices. The cockpit shows a non-PII display reference; only the contact email needed to deliver a response is retained; verification uses single-use tokens; and verification secrets are never written to the audit log. Per-tenant configuration (email / document / third_party) lets each Customer choose the lightest verification method that meets its needs.
4.4 No Sale, No Share. We do not sell consumer data or Customer Data, and we do not share it for cross-context behavioral advertising. We do not transmit, license, or make consumer data available to any third party except (a) to operate the Service as the Customer directs, (b) to subprocessors listed at dsarengine.com/subprocessors operating under equivalent restrictions, or (c) as required by law.
4.5 No Training on Customer Data. We do not use Customer Data or consumer data to train any model, fine-tune any shared model, or improve a Service used by other customers.
4.6 Flat Per-Tenant Isolation. Each Customer is one tenant; consumers who file requests are records within that tenant. Row-level isolation enforces that no Customer can access another Customer's data; every tenant-scoped query is scoped by tenant_id.
4.7 Audit-Log Integrity. The chain-of-custody event log is append-only and tamper-detected. We do not alter or delete audit records at Customer direction except during deletion at termination or as required by law. The audit log carries no PII beyond what the record requires; verification secrets are never logged.
5. How we use information (controller role)
For marketing-site visitors and Customer account/billing contacts, we use information to:
- Provide, operate, secure, and improve the Service;
- Authenticate users and prevent unauthorized access;
- Process payments and manage subscriptions;
- Communicate about the Service, security incidents, and Terms changes;
- Send marketing communications to Customer billing contacts (opt-out anytime);
- Produce aggregated, de-identified usage analytics; and
- Comply with legal obligations.
We do not sell personal information and do not share it for cross-context behavioral advertising.
6. Sharing and disclosure
(a) Subprocessors at dsarengine.com/subprocessors, operating under equivalent data-protection restrictions.
(b) Legal compliance: Where required by law, regulation, or court order, or to protect the rights, property, or safety of DSAR Engine, our Customers, or others.
(c) Business transfers: In connection with a merger, acquisition, or asset sale, with notice to Customers.
(d) With instruction/consent: As directed in writing by the Customer.
We do not share consumer data or Customer Data with data brokers, advertising networks, or any third party for purposes outside operating the Service.
7. Cookies and tracking
Strictly necessary, functional, and aggregated-analytics cookies only. No third-party advertising or behavioral trackers.
8. Retention
- Customer account data: while active + up to 7 years for accounting and legal purposes;
- Customer Data (consumer request records, verification data, clock state, correspondence): for the subscription term, available for export throughout; deleted within 30 days of a Customer's written deletion request. Absent such a request, upon termination we retain Customer Data for twenty-four (24) months following the effective date of termination, to preserve the evidentiary and statutory record-keeping basis for the underlying privacy-request record, and will thereafter delete it within 30 days, except in each case as required by law to retain;
- Identity-verification data: retained only as long as needed to verify the requester and deliver the response, per §4.3 — not subject to the 24-month post-termination retention period above, since this data is minimized on an ongoing basis rather than held for the subscription term;
- Chain-of-custody event logs: retained with the Customer Data they document, per the bullet above — twenty-four (24) months after termination absent an earlier Customer deletion request, to preserve an evidentiary record of request-handling while remaining bounded rather than indefinite;
- Marketing data: until opt-out;
- Aggregated, de-identified usage data: indefinitely.
9. Security
Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, with independent external uptime monitoring being brought online ahead of launch. We use tenant isolation between customers. We do not claim SOC 2, ISO 27001, or any audited certification on this pre-launch product; we will update this section as our security program and independent assessments mature. No method of transmission or storage is perfectly secure. SOC 2 Type I is tracked as an up-market gate, not a launch gate. Breach notification to affected Customers per the DPA: without undue delay, and in any event within five (5) business days of becoming aware; provided that where the strictest applicable state breach-notification law or an FCRA-specific notice trigger requires a Customer to act on a shorter timeline, we will use commercially reasonable efforts to notify the Customer within whatever shorter period is necessary for the Customer to meet that deadline.
10. International transfers
Processing occurs in the United States. For any EU/UK/Swiss data, Standard Contractual Clauses (Module 2) plus the UK Addendum apply per the DPA. The Year-1 customer base is primarily U.S.
11. Your rights
Marketing-site visitors and Customer billing contacts: You have the rights afforded by applicable law (the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA"), the Colorado Privacy Act, and other state laws; Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") / the UK GDPR where applicable) to access, correct, delete, or port your information and to opt out of sale/share and certain processing. We do not sell or share this information. Email [email protected].
Consumers whose request is processed by a Customer using DSAR Engine: The Customer (the company that holds your data) is the controller of that request and the underlying data. Direct your privacy request to that company, not to DSAR Engine. We act only as the Customer's processor. We will cooperate with the Customer to fulfill valid access, deletion, correction, or opt-out requests per the DPA and applicable law, and we do not respond directly to consumer data-subject requests unless the responsible Customer explicitly authorizes and instructs us to do so.
12. Software tool — not legal advice
DSAR Engine is a software tool. It is not a law firm and does not provide legal advice, legal representation, or compliance assurance. Use of the Service does not guarantee compliance with any privacy law. DSAR Engine does not review, interpret, or render a determination on the validity of any consumer request; your team decides and fulfills each request. Each Customer remains solely responsible for ensuring its privacy-request practices comply with applicable law. The built-in deadline clocks, reminders, rule overlays, and templates are designed to assist; they are not a substitute for legal counsel.
13. Children's privacy
The Service is for business users and is not directed to individuals under 13. We do not permit account creation by anyone under 13, and we do not knowingly collect information from children under 13 through the marketing site or account flows. The Service is not designed to process children's data; see §3. If we learn we have collected information from a child under 13, we will delete it promptly. A Customer that receives a privacy request concerning a minor is the controller of that request.
14. Updates
We will provide 30 days' email notice to Customer billing contacts for material changes to this Policy.
15. Contact
[email protected] — privacy matters
[email protected] — other legal matters