Privacy Policy — Disruptivv.AI
Legal & Compliance · DAI-PRV-001

Privacy
Policy

Effective April 18, 2026
Revised April 18, 2026
Version 1.0
Classification Public
Disruptivv.AI LLC  ·  Peoria, Arizona  ·  disruptivv.ai
01

Introduction and Scope

Disruptivv.AI LLC ("Disruptivv.AI," "we," "us," or "our") is an AI-powered cybersecurity services company headquartered in Peoria, Arizona. We provide virtual Chief Information Security Officer (vCISO) services, AI-driven Security Operations Center (SOC) capabilities, cyber risk assessments, and compliance advisory services to small and medium-sized businesses, with specialized expertise in healthcare organizations subject to the Health Insurance Portability and Accountability Act (HIPAA).

This Privacy Policy ("Policy") describes how Disruptivv.AI collects, processes, stores, transmits, and protects personal information and non-public business information obtained through our website (disruptivv.ai), client engagements, digital platforms, and AI-assisted service delivery infrastructure. This Policy applies to all data subjects whose information we process, including website visitors, prospective clients, active clients, and authorized personnel.

This Policy is published in accordance with applicable U.S. federal and state privacy statutes, including HIPAA, HITECH, and applicable provisions of the Arizona Revised Statutes, Title 18 (Cybersecurity).

02

Categories of Information Collected

2.1 Information You Provide Directly

We collect information that you voluntarily provide when engaging with our services or communications infrastructure, including but not limited to:

  • Contact and identity data: full name, job title, organizational role, business email address, phone number, and mailing address
  • Organizational data: company name, industry classification, employee headcount, IT/security environment details, and existing security control inventories
  • Assessment and audit data: network topology information, asset inventories, vulnerability scan outputs, security incident histories, and compliance posture documentation
  • Account credentials: usernames, access tokens, and authentication data for client portal access
  • Payment and billing data: invoicing details processed through our payment processors (we do not store full payment card data on our systems)
  • Communications: electronic correspondence, meeting notes, and support tickets submitted via our platforms

2.2 Information Collected Automatically

When you access our website or digital platforms, our systems may automatically collect:

  • Network and device identifiers: IP addresses, browser user-agent strings, device types, and operating system versions
  • Usage telemetry: page views, session durations, clickstream data, referral sources, and feature utilization metrics
  • Cookie and tracking data: session cookies, persistent cookies, and similar tracking technologies as described in Section 8
  • Log data: web server access logs, application error logs, and security event logs retained for intrusion detection and forensic purposes

2.3 Information Received from Third Parties

In the course of delivering AI-assisted cybersecurity services, we may receive information from authorized third-party sources, including:

  • Threat intelligence feeds and open-source intelligence (OSINT) repositories
  • Identity and access management (IAM) platforms integrated into client environments
  • SIEM systems, endpoint detection and response (EDR) platforms, and managed security service integrations
  • Business associates and subprocessors operating under executed Data Processing Agreements (DPAs) or Business Associate Agreements (BAAs)
03

Legal Basis and Purposes of Processing

Disruptivv.AI processes personal and organizational information under the following legal bases and for the following operational purposes:

  • Service delivery: to provide contracted cybersecurity assessments, vCISO advisory services, SOC monitoring, and compliance gap analysis
  • Contractual obligation: to fulfill obligations under executed MSAs, Statements of Work (SOWs), and Business Associate Agreements (BAAs)
  • Legal compliance: to satisfy obligations under HIPAA, HITECH, and applicable state law, including mandatory breach notification requirements under 45 C.F.R. §§ 164.400–414
  • Legitimate business interest: to improve our AI models, service delivery workflows, and security detection capabilities through anonymized, aggregated telemetry
  • Consent: for marketing communications, newsletter subscriptions, and voluntary feedback programs where explicit opt-in consent has been obtained
04

Protected Health Information (PHI) and HIPAA Compliance

⚕ HIPAA Business Associate
Where Disruptivv.AI acts as a Business Associate as defined under 45 C.F.R. § 160.103, we handle PHI and ePHI solely in accordance with an executed Business Associate Agreement (BAA) and in compliance with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

Disruptivv.AI does not access, process, or retain PHI beyond what is minimally necessary to fulfill the contracted service scope. All AI agents deployed in environments containing PHI operate under access controls, audit logging, and data minimization protocols consistent with the HIPAA Minimum Necessary Standard (45 C.F.R. § 164.502(b)).

In the event of a Breach of Unsecured PHI as defined under 45 C.F.R. § 164.402, Disruptivv.AI will notify the applicable Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days following discovery, in accordance with 45 C.F.R. § 164.410.

05

AI Agent Data Handling and Automated Processing

// AI Workforce
Disruptivv.AI delivers services through a proprietary AI agent workforce — ARIA, NOVA, HECTOR, REX, and IRIS — orchestrated by the Nexus governance framework. All agent activities are governed by our AI Agent Registration and Workforce Governance Policy (AIG-003).

Key data handling commitments for AI-assisted processing include:

  • Data isolation: client data is logically segregated across all AI processing pipelines; cross-client data commingling is prohibited by architectural design
  • Purpose limitation: AI agents process client data solely for the contracted service scope and are technically constrained from processing data outside defined operational parameters
  • Audit logging: all AI agent interactions with client data are recorded in append-only audit logs retained for a minimum of twelve (12) months
  • Human oversight: all high-risk AI-generated outputs are subject to Principal AI Officer (PAO) review prior to client delivery
  • No training on client data: client-specific data is not used to train or fine-tune AI models without explicit written consent
06

Data Sharing, Disclosure, and Third-Party Processors

Disruptivv.AI does not sell, rent, or trade personal information or client data to third parties. We may disclose information under the following limited circumstances:

6.1 Authorized Subprocessors

We engage vetted subprocessors to support our service delivery infrastructure, including cloud hosting providers, SIEM platforms, and AI inference services. All subprocessors are evaluated against our Third-Party Risk Management (TPRM) framework and are contractually bound to data protection obligations no less restrictive than those set forth in this Policy.

6.2 Legal and Regulatory Disclosure

We may disclose information when required by applicable law, regulation, court order, or governmental authority. Where legally permissible, we will provide advance notice to affected clients prior to such disclosure.

6.3 Business Continuity and Corporate Transactions

In the event of a merger, acquisition, asset sale, or reorganization, client data may be transferred to a successor entity, subject to the successor entity's assumption of the data protection obligations set forth in this Policy and any applicable BAAs.

07

Data Retention and Disposal

Disruptivv.AI retains personal and organizational data only for the duration necessary to fulfill contracted service obligations and to satisfy applicable legal, regulatory, and audit requirements. Default retention periods are as follows:

  • Client assessment data and deliverables: minimum three (3) years following contract termination
  • Security event logs and incident records: minimum twelve (12) months; forensic-grade evidence preserved for minimum three (3) years for confirmed breach incidents
  • PHI processed under BAA: retained and disposed of in accordance with the applicable BAA and 45 C.F.R. § 164.530(j)
  • Website visitor data and analytics: up to twenty-four (24) months
  • Marketing contact data: retained until consent withdrawal or opt-out, whichever occurs first

Upon expiration of applicable retention periods, data is disposed of using NIST SP 800-88 Rev. 1-compliant media sanitization and destruction procedures. Certificate of Destruction documentation is available upon written request.

08

Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to support site functionality, analytics, and security monitoring:

  • Strictly necessary cookies: required for core website functionality, session management, and security controls; these cannot be disabled
  • Analytics cookies: aggregate, anonymized usage data used to improve site performance
  • Marketing cookies: deployed only where explicit consent has been obtained; used to measure the effectiveness of our digital marketing programs

You may manage cookie preferences through your browser settings or our cookie consent manager. Disabling non-essential cookies will not impair access to our primary website content or client portal functions.

09

Information Security Controls

Disruptivv.AI implements a defense-in-depth security program to protect the confidentiality, integrity, and availability of information under our control:

  • Encryption in transit: all data transmissions are protected using TLS 1.2 or higher; unencrypted transmission of sensitive data is prohibited
  • Encryption at rest: sensitive data stores are encrypted using AES-256 or equivalent FIPS 140-2 validated cryptographic modules
  • Access controls: role-based access control (RBAC) and least-privilege policies govern all system access; MFA is enforced for all privileged accounts and remote access
  • Vulnerability management: AI SOC infrastructure undergoes continuous scanning and periodic penetration testing; findings are remediated per risk-tiered SLAs
  • Incident response: documented IRP aligned to NIST SP 800-61 Rev. 2 with defined escalation paths, containment procedures, and breach notification workflows
  • Security awareness: all personnel with access to client data complete annual security awareness and role-specific compliance training
⚠ Notice
No information security program can guarantee absolute protection against all threat actors. In the event of a confirmed data breach affecting your personal or organizational information, Disruptivv.AI will notify you in accordance with applicable law and our contractual obligations.
10

Data Subject Rights and Access Requests

Subject to applicable law and contractual limitations, individuals whose personal information Disruptivv.AI processes may exercise the following rights:

  • Right to access: request a copy of personal information held about you, including categories of data, purposes of processing, and any third-party disclosures
  • Right to correction: request correction of inaccurate or incomplete personal information
  • Right to deletion: request erasure of personal information where retention is no longer legally required or operationally necessary
  • Right to restrict processing: request limitation of processing activities in certain circumstances, such as pending accuracy verification
  • Right to data portability: request transmission of your personal information in a structured, machine-readable format where technically feasible
  • Right to withdraw consent: withdraw previously granted consent for optional processing activities at any time without prejudice to prior lawful processing

To exercise any of the above rights, submit a written request to privacy@disruptivv.ai. We will acknowledge receipt within five (5) business days and respond substantively within thirty (30) calendar days.

11

Data Residency and Cross-Border Transfers

Disruptivv.AI's primary operations are conducted within the continental United States. Client data is processed and stored within U.S.-based infrastructure. In the event that any subprocessor or AI inference service provider processes data outside the United States, Disruptivv.AI will implement appropriate safeguards, including contractual data transfer mechanisms, to ensure equivalent data protection standards are maintained.

12

Minors and Children's Privacy

Our services are directed exclusively at business entities and organizational clients. Disruptivv.AI does not knowingly collect personal information from individuals under the age of eighteen (18). If we become aware that personal information of a minor has been inadvertently collected, we will promptly delete such information and notify the applicable data controller.

13

Policy Updates and Version Control

Disruptivv.AI reserves the right to update this Privacy Policy to reflect changes in our data processing practices, applicable law, or regulatory guidance. Material changes will be communicated to active clients via electronic notification at least thirty (30) calendar days prior to the effective date of the revised Policy.

Continued use of our services following the effective date of any Policy revision constitutes acceptance of the updated terms. Version history is maintained internally under Disruptivv.AI's Document Control Policy (GOV-001).

14

Contact Information and Data Protection Inquiries

For questions, concerns, or formal inquiries regarding this Privacy Policy or Disruptivv.AI's data protection practices, contact our Privacy and Compliance function:

Disruptivv.AI LLC
Attn Privacy Officer / Principal AI Officer
Location Peoria, Arizona 85383

If you believe your privacy rights have been violated and you have not received a satisfactory response from Disruptivv.AI, you may lodge a complaint with the applicable data protection authority or, for HIPAA-related matters, the U.S. Department of Health and Human Services Office for Civil Rights (OCR).

Disruptivv.AI

AI-Powered Cybersecurity · Peoria, AZ

Document ID: DAI-PRV-001 Rev 1.0

Effective: April 18, 2026

Classification: Public

↑ Back to top