AIVILIM shield mark
Services Frameworks Insights About Request Audit
Legal

Privacy & Data Handling Policy

How AIVILIM collects, uses, and protects information shared with us — both through this website and during client engagements.

Last updated: July 2026  |  Effective for all AIVILIM LLC engagements and website interactions
1. Overview
AIVILIM LLC ("AIVILIM," "we," "us," or "our") provides AI auditing and governance advisory services. This policy explains how we handle information collected through www.aivilim.com and information shared with us during the course of a client engagement. It does not constitute legal advice, and clients with specific regulatory or contractual data requirements should refer to their signed engagement letter and any applicable Data Processing Agreement (DPA).
2. Information We Collect
We collect information in two contexts:
  • Website inquiries: When you submit our contact or audit-request form, we collect the information you provide — name, work email, phone, organization, title, industry, and any details you share about your AI program or compliance needs.
  • Client engagements: During an active engagement, we may receive system documentation, model artifacts, policies, risk assessments, organizational charts, and other materials necessary to perform the agreed-upon audit or advisory scope. The specific categories of data are defined in each engagement's Statement of Work.
3. How We Use Information
Information submitted through this website is used solely to respond to your inquiry, assess engagement fit, and schedule a discovery conversation. We do not sell, rent, or share your information with third parties for marketing purposes.
Information shared during a client engagement is used exclusively to perform the audit or advisory services described in the applicable Statement of Work, and is governed by the confidentiality terms of the signed engagement letter and any executed NDA.
Independence Commitment
AIVILIM does not sell software, platforms, or compliance tooling. We have no commercial relationship with any technology vendor that could create a conflict of interest in how client data or findings are handled.
4. Confidentiality of Engagement Materials
All materials shared during a client engagement — including system documentation, model details, internal policies, and audit findings — are treated as confidential. Specific protections include:
  • Engagement materials are accessible only to AIVILIM personnel directly assigned to the engagement.
  • A mutual or one-way Non-Disclosure Agreement (NDA) is executed prior to the exchange of any sensitive materials, where required.
  • Materials are retained only for the duration necessary to complete the engagement and any contractually agreed retention period, after which they are securely deleted or returned per client instruction.
  • AIVILIM does not use client-specific data, findings, or system details for any purpose outside the scope of the engagement, including marketing, benchmarking, or model training, without explicit written client consent.
5. Data Security
AIVILIM maintains administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle. This includes access controls limiting engagement data to assigned personnel, encrypted storage and transmission of client materials, and secure deletion practices at the conclusion of an engagement or upon client request.
6. Cookies & Website Analytics
This website does not use third-party advertising cookies. We may use minimal, privacy-respecting analytics to understand aggregate site usage (e.g., page views) for the purpose of improving the website. No personally identifiable browsing data is sold or shared.
7. Your Rights & Choices
You may request access to, correction of, or deletion of personal information you've submitted through this website by contacting us at contact@aivilim.com. We will verify and respond to requests as required by applicable law, and may retain certain information where necessary for legal or recordkeeping purposes.
Depending on where you reside, you may also have rights under the privacy laws of your jurisdiction — for example, the EU General Data Protection Regulation (GDPR) or the applicable privacy law of your U.S. state — in each case to the extent those laws apply to our processing of your information.
Personal information processed in the course of a client engagement is governed by the data protection terms of the applicable engagement letter, under which AIVILIM processes such information on the client's instructions. If you are an employee, customer, or other data subject of one of our clients, please direct rights requests to that organization; we will support our clients in fulfilling such requests as the engagement terms require.
8. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. The "last updated" date above reflects the most recent revision. Material changes affecting active client engagements will be communicated directly.
Questions About This Policy
For any questions about how AIVILIM collects, uses, or protects information, contact us directly at contact@aivilim.com.
AIVILIM — AI Auditing & Governance
Independent assurance for organizations that take AI responsibility seriously. Grounded in NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
Services
  • Risk Assessment
  • Governance Design
  • Bias Auditing
  • ISO 42001 Readiness
  • Compliance Monitoring
Frameworks
  • NIST AI RMF
  • ISO/IEC 42001
  • EU AI Act
  • BSI AIC4
  • AIUC-1
  • GDPR & AI
Company
  • About AIVILIM
  • Insights
  • Contact
© 2026 AIVILIM. All rights reserved.
Privacy & Data Handling
www.aivilim.com