Global Privacy & Data Processing Policy
Effective Date: June 22, 2026 · Last Updated: June 22, 2026
Welcome to Decionis. Decionis, Inc. (“Decionis”, “we”, “us”, or “our”) provides an Execution Authority Infrastructure that acts as an execution certainty layer for modern Commerce and Enterprise Operations.
This Global Privacy Policy applies to all personal and operational data processed across our platform, including our native integrations for SAP, Microsoft Teams, Webex, and Power Automate. We are committed to data minimization, security-by-design, and absolute transparency regarding how data is handled.
1. Our Role: Data Controller vs. Data Processor
For the majority of our enterprise services, applications, and integrations (such as the Decionis Governed Execution Gate for SAP):
- Our Enterprise Customers act as the Data Controller (the entity determining the purposes and means of processing data).
- Decionis acts strictly as the Data Processor (processing data solely on behalf of, and under the strict instruction of, our enterprise customers).
If you are an employee or user of an enterprise using Decionis, your organization's privacy policy governs the processing of your data.
2. Information We Process
To enforce operational execution policies and mint tamper-proof Decision Dossiers, we process the minimum data required to evaluate risk:
A. Data Processed within ERP & Chat Integrations (SAP, Teams, Webex)
- Identity & Context Data: User identifiers provided by the platform (e.g., SAP User ID, Microsoft personId, Webex orgId), names, and corporate email addresses.
- Operational Transaction Metadata: Contextual payload parameters required to evaluate an execution rule (e.g., transaction amounts, system change requests, or routing instructions) before money moves or infrastructure changes.
B. Account & Administrative Data
- Account Credentials: Email addresses, workspace IDs, and authentication tokens required to securely link Decionis to your corporate tech stack.
- System Diagnostics: Cryptographic logs, performance metadata, and audit logs of the policy evaluation engine to ensure execution uptime.
What We Never Collect: Decionis does not store, harvest, or track end-user consumer financial data, banking passwords, or personal web-browsing behavioral telemetry outside of explicit, scoped enterprise policy checks.
3. How We Process and Retain Data
We do not sell, rent, or monetize enterprise operational data or personal metadata under any circumstances. Data is used exclusively to:
- Evaluate execution constraints against live, real-time enterprise rules.
- Generate, cryptographically sign, and deliver immutable Decision Dossiers.
- Provide an audit trail for your organization's risk, GRC, and finance teams.
Data Retention
We retain data only as long as specified by our Data Processing Agreement (DPA) with your organization, or as necessary to comply with legal audit obligations. Enterprise clients maintain the complete authority to request total data deletion or specify custom retention windows.
4. Architecture & Security: Private VPC & Cloud Isolation
Decionis is engineered from the ground up for strict data isolation and enterprise-grade security:
- Encryption-in-Transit & At-Rest: All data transmitted between SAP, integration layers, and the Decionis engine is encrypted using TLS 1.3. Data at rest is secured via AES-256 encryption.
- Cryptographic Attestation: Every Decision Dossier is minted and signed natively using cryptographic protocols (such as Ed25519) to ensure absolute tamper-evidence.
- Deployment Isolation (Private VPC): For organizations requiring complete data sovereignty, Decionis offers deployment models within the client's own Private VPC/cloud boundaries. In this architecture, operational payloads, dossiers, and custom enterprise policies never leave your network boundary.
5. Global Compliance & Cross-Border Data Transfers
Decionis complies with major global data protection frameworks governing enterprise operations.
A. General Data Protection Regulation (GDPR / UK GDPR)
We process personal data in compliance with the GDPR. Where data transfers cross European Economic Area (EEA) boundaries, we utilize Standard Contractual Clauses (SCCs) approved by the European Commission, combined with strict technical safeguards.
B. California Consumer Privacy Act (CCPA) / CPRA
Decionis acts as a “Service Provider” under the CCPA/CPRA. We process business metadata strictly to perform the execution infrastructure services outlined in our master agreements.
C. EU AI Act Compliance
Where automated policy checking constitutes an execution governance system under prevailing frameworks (such as Article 12 of the EU AI Act regarding logging and traceability), Decionis generates deterministic, audit-ready logs natively via the Decision Dossier architecture.
6. Subprocessors
To deliver our cloud services, Decionis runs on Microsoft Azure (Central US region), a tier-one infrastructure provider that maintains industry-standard physical and logical security certifications (ISO 27001, SOC 2 Type II). A full list of active subprocessors can be provided upon request to verified enterprise clients.
7. Your Rights and Contact Information
Depending on your jurisdiction, you may have rights to access, correct, restrict, or delete your personal data. Because we operate primarily as a data processor for your employer or contracting organization, we recommend directing data rights requests to your internal IT or compliance administrator.
For direct privacy inquiries, security questionnaires, or DPA execution, please contact our privacy office.
Contact
Privacy inquiries, security questionnaires, or DPA execution: privacy@decionis.com.
