Privacy policy and data governance
How MobilityCore Systems collects, processes, and protects your technical data across our AI automation and integration workflows.
This policy governs data handling across all consultancy engagements, workflow agents, custom API integrations, and system architecture audits conducted by MobilityCore Systems LLC.
Data collection & system parameters
We collect technical telemetry, API metadata, and account authentication details required to engineer and maintain enterprise AI systems.
- Technical telemetry: API endpoint calls, latency metrics, error logs, and payload structural schemas necessary for workflow diagnostics.
- Account identifiers: Corporate email addresses, technical point-of-contact names, billing credentials, and workspace configuration settings.
- Integration tokens: Securely hashed authentication tokens, OAuth refresh credentials, and webhook endpoints delegated for workflow execution.
Purpose of data processing
Data is processed strictly to deliver, optimize, and maintain contracted AI architectures, automated agent workflows, and integration pipelines.
- Provisioning custom AI agent workflows, data orchestration pipelines, and proprietary tooling environments.
- Conducting diagnostic profiling, runtime performance monitoring, and bottleneck resolution on integrated systems.
- Maintaining enterprise security compliance, audit trails, and automated failover verification.
Retention schedules & storage protocols
All operational metrics and customer credentials adhere to deterministic lifecycle limits and encrypted cold-storage retirement schedules.
- Runtime execution logs: Retained in volatile short-term buffers for 30 days before automated cryptographic purging.
- Configuration schemas and architecture graphs: Maintained for the duration of the active service contract plus 90 days of transition backup.
- Encryption standards: AES-256 at rest across all isolated storage nodes, with TLS 1.3 enforced for all inflight API data transit.
Third-party disclosure & model isolation
We never monetize client data or permit public foundation model training on proprietary enterprise information or client pipeline payloads.
- Model isolation: Client data is never routed into shared foundational AI training sets or publicly accessible language model corpora.
- Infrastructure vendors: Data processing occurs strictly within contracted hyperscale hosting environments (AWS, Azure, GCP) under dedicated SOC 2 Type II controls.
- Regulatory disclosure: Information is shared only when compelled by valid statutory obligations or enforceable legal process.
Data subject rights & compliance endpoints
Authorized client administrators hold absolute rights over access, rectification, pipeline token revocation, and permanent data deletion.
- Right to audit: Request exportable summaries of data flows, processing records, and connected API event logs.
- Right to erase: Immediate triggering of cryptographic token revocation and downstream data eradication workflows.
- Right to restrict: Designate specific enterprise pipelines or test environments as exempt from ongoing automated telemetry logging.
Privacy governance office
For security questionnaires, data deletion requests, or architecture audit inquiries, reach our compliance team directly.
Data Controller & Technical Architecture Partner