
AILok — Privacy Policy
All legal, operational, and data processing responsibilities for AILok are managed by EvinceDev Inc. (“Company”, “Legal Entity”). This policy outlines how your business data, vendor details, and personal information are collected, safeguarded, and retained.
1. Introduction
AILok (“AILok”, “we”, “our”, “us”) is an assessment and advisory platform that helps business owners, CXOs, and consultants understand their dependency, vendor, and AI-readiness risk through a short questionnaire, an automated score, and expert-reviewed strategic reports.
AILok operates as a service interface. All legal, operational, and data processing responsibilities are managed by EvinceDev Inc. (“Company”, “Legal Entity”).
Because AILok collects information about your business, your vendors, and your systems, this Policy explains in detail how that information is handled, who can access it, and how long we keep it.
By using this website, submitting an assessment, requesting a score or report, or booking a consultation, you agree to the terms outlined in this Privacy Policy.
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to the AILok website
- Users who complete the free score assessment
- Customers who purchase a Strategic Report or consultation
- Individuals who contact us, subscribe to updates, or book a call
3. Information We Collect
a. Information You Provide
- Full name
- Business email address
- Company name and website URL
- Role or job title
- Your responses to the AILok questionnaire
- Details about your software vendors, contracts, renewal timelines, and pricing
- Details about your internal systems, platforms, integrations, and technical stack
- Information about team structure, capacity, and operational workflows
- Documents, screenshots, exports, or files you choose to upload
- Any additional context you share during a consultation
- Purchase and transaction records
- Billing name, billing address, and invoice details
- Support and correspondence history
b. Information Collected Automatically
- IP address and approximate location derived from IP
- Device and browser type, operating system
- Browser user agent string
- Pages requested and request timestamps
- Cookie identifiers
c. Information We Generate
- Your dependency and AI-readiness score
- Risk findings, registers, and analysis produced from your inputs
- Publicly available research about your business, market, or named vendors gathered from public sources to add context to your report
- Internal notes recorded by our analysts and experts
4. Payment Information
Paid reports and consultations are processed securely through certified third-party payment processors, primarily Stripe, Inc.
- Stripe, Inc. Processing: Payment card processing is managed directly by Stripe, Inc. under its own privacy policy. Stripe is certified as a PCI-DSS Level 1 Service Provider, the highest security classification in the payment industry.
- No Storage of Sensitive Cardholder Data: We do not collect, transmit, or store complete payment card numbers, CVV codes, or bank account credentials on our infrastructure.
- Limited Transaction Records: We receive only limited transaction metadata from Stripe, such as confirmation of payment, transaction timestamps, the last four digits of the card, card brand, billing name, and invoice records required for financial accounting, fraud prevention, and tax compliance.
5. Information About Third Parties
Your assessment may include information about other parties, such as vendors, service providers, contractors, or employees.
By submitting this information, you confirm that:
- You have the authority to share it
- Sharing it does not breach any confidentiality agreement, non-disclosure agreement, or contract you are bound by
- You will not upload personal information about individuals beyond what is necessary for the assessment
6. How We Use Your Information
We use collected information for legitimate business purposes, including to:
7. AI Processing and Human Review
AILok combines automated analysis with human expert judgment. You should understand how both work:
Automated Processing
Your questionnaire responses and related inputs are analyzed by automated systems, including artificial intelligence and machine learning models, to surface patterns, calculate your score, and draft candidate findings.
Named AI Processing Provider: Anthropic (Claude API)
We currently use Anthropic, Inc. (Claude API) as our AI processing provider. AI processing is performed under enterprise commercial terms where your questionnaire inputs, uploaded materials, and diagnostic findings are processed via API solely to generate your assessment results and are strictly never used to train Anthropic's models.
No Training on Your Confidential Business Data
We do not permit your assessment inputs, uploaded documents, or report content to be used to train publicly available AI models. Where a provider offers a training opt-out or zero-retention configuration, we enforce it.
Human Review Required for Paid Reports
Automated output is never delivered as a final answer. Strategic Reports are reviewed, corrected, and shaped by human experts before delivery. The free score is automated and provided as an indicative read, not a professional opinion.
No Consequential Automated Decisions
We do not use automated processing alone to make decisions that produce legal or similarly significant effects for you.
Model and Methodology Improvement
We may use de-identified, aggregated, or anonymized data-data that cannot reasonably be linked back to you or your company; to improve our internal scoring methodology, benchmarks, and internal models.
8. Confidentiality of Your Assessment and Report
We treat your assessment inputs and your report as confidential business information:
- Limited Access: Access is limited to authorized personnel and senior analysts who need it to deliver your score, report, or consultation.
- Exclusively For You: Your report is prepared specifically for you. We do not publish it, share it with your vendors, or disclose it to competitors.
- No Marketing Usage Without Consent: We will not name you, your company, or your vendors in marketing materials, case studies, or public content without your prior written permission.
- Anonymized Benchmarks: Anonymized, aggregated insights that do not identify you or your business may be used in benchmarks, research, or published intelligence.
9. Consultations and Recordings
Consultations conducted outside the platform (video call, telephone) are scheduled advisory engagements. The AILok web application does not provide embedded in-app video conferencing; consultations are arranged and conducted using established external teleconferencing platforms.
- Calls may be recorded or transcribed only where we have obtained your consent, or where consent is not required under applicable law and you have been notified in advance.
- You will be informed before recording begins and may decline. Declining does not affect your entitlement to the consultation.
- Recordings, transcripts, and notes are used to prepare deliverables, maintain service records, and support quality assurance.
- You may request deletion of a recording at any time by emailing support@ailok.io.
10. Communication Consent
By submitting your information through this website, you consent to being contacted by AILok and EvinceDev Inc. via email, phone, SMS or messaging tools, and CRM-based outreach systems.
You may receive service-related updates, delivery notifications, follow-up communication, or relevant offers.
Opting Out: You can opt out of marketing communications at any time by using the unsubscribe link in any message or by contacting support@ailok.io. Service and transactional messages related to a purchase or an active assessment will continue.
12. Marketing and Remarketing
We do not operate advertising, remarketing or audience-building technology on this website. There are no ad pixels, no conversion tags and no third-party advertising cookies, and we do not share website visit data with advertising platforms. Marketing contact happens only where you have given us your details directly, such as the newsletter you can subscribe to and unsubscribe from at any time.
13. CRM and Data Processing
Your information may be stored and processed in secure Customer Relationship Management (CRM) and project delivery systems for the purposes of managing leads, tracking correspondence, coordinating report delivery, and maintaining billing records.
We implement appropriate administrative, technical, and physical safeguards to protect all data housed within these systems.
15. Group Companies and Cross-Border Data Processing
EvinceDev Inc. operates as part of a global delivery and operations structure. Certain technical delivery, research, analysis, report production, support, analytics, and internal operational processing may be performed by our affiliated entity:
India
Authorized personnel of Evince Development Pvt. Ltd. access information solely for legitimate delivery, analysis, and operational tasks, bound by internal confidentiality obligations, access controls, and intra-group data protection agreements.
EvinceDev Inc. remains fully responsible for personal and business information collected through this website.
16. International Visitors
EvinceDev Inc. is headquartered in the United States. If you access this website from outside the United States, your information may be transferred to, stored, or processed in the United States, India, or other jurisdictions where our affiliated entities or service providers operate.
Data protection laws in these jurisdictions may differ from those in your country of residence. By using the website, you consent to such transfers with established contractual safeguards.
17. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction, including:
- Enterprise cloud security architecture hosted within Amazon Web Services (AWS) data centers with SOC 1, SOC 2, and ISO 27001 certifications
- Encryption of data in transit using TLS 1.2/1.3 and at rest using AES-256 on AWS Aurora and Amazon S3
- Secrets and credential isolation via AWS Secrets Manager and Systems Manager Parameter Store
- Role-based access controls (RBAC) and least-privilege principles across all production environments
- Strict confidentiality agreements for all employees, analysts, and contractors
- Continuous vendor risk assessment, security logging, and due diligence
Please note that no internet-based system can be guaranteed to be 100% impenetrable. Transmission over the internet carries inherent risk, which you acknowledge when using our services.
18. Data Retention
We retain information only for as long as necessary to deliver your score, complete reports, provide ongoing advisory support, and fulfill statutory tax and legal obligations.
| Data Type | Retention Period |
|---|---|
| Free score submissions with no further activity | 12 months |
| Assessment inputs and delivered reports | 24 months after delivery, unless a longer engagement is active |
| Call recordings and transcripts | 6 months |
| Billing and transaction records | As required by statutory tax and accounting laws |
| Marketing contact records | Until you unsubscribe or request deletion |
Information no longer required is securely deleted or anonymized. You may request earlier deletion at any time by contacting our support team.
19. Your Rights
Depending on your jurisdiction, you may hold statutory privacy rights, including:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete records
- Request deletion of your personal information
- Withdraw consent, including consent to marketing or recording
- Object to or restrict certain processing activities
- Request a portable copy of your data
- Opt out of marketing communications
Rights to know, delete, correct, and opt out of sale/sharing. We do not sell or share personal data as defined under CCPA.
Rights of access, rectification, erasure, portability, and restriction under standard European supervisory authorities.
Rights to access, correction, erasure, and grievance redressal under the Digital Personal Data Protection Act.
Requests may be submitted to support@ailok.io. Identity verification may be required. We will never discriminate against you for exercising your rights.
20. Additional Provisions (Third-Party Links, Children & Deliverables)
Third-Party Links & Platforms
This website may contain links to third-party tools, platforms, or websites. AILok and EvinceDev Inc. are not responsible for the privacy practices, content, or security of external websites. We encourage you to review their policies independently.
Children's Privacy
Our services are designed exclusively for business users. They are not intended for individuals under the age of 18, and we do not knowingly collect data from minors. Any such data discovered will be deleted promptly.
Nature of Our Deliverables
Scores, reports, findings, and consultations provided by AILok are advisory business assessments. They do not constitute legal, financial, tax, accounting, audit, or regulatory compliance advice, and should not be relied upon as a substitute for professional counsel.
21. Limitation of Liability
To the maximum extent permitted by applicable law:
- AILok acts as a service interface only. EvinceDev Inc. provides operational delivery.
- Our findings are based on the information you provide and on publicly available sources; accuracy depends directly on the completeness of that data.
We are not responsible for:
- Commercial decisions made on the basis of website content, scores, or reports
- Losses arising from third-party vendor platforms or tools
- Technical outages outside our reasonable control
- Inaccuracies caused by incomplete, outdated, or incorrect input data supplied to us
22. Policy Updates & Contact Information
We may update this Privacy Policy periodically. Changes will be posted on this page with a revised “Last Updated” date. Continued use of our website or services constitutes acceptance of the updated Policy.
