Privacy & Data Governance Architecture
Effective Date: January 1, 2026 // Indian Jurisdiction (Kerala Operations Hub)
Clockin AI does not store, log, harvest, or monetize client enterprise data. Guest reservation details, patient health records, and industrial factory telemetry reside solely in volatile RAM during the real-time inference loop. Once the atomic write is committed to your own PMS, EHR, or ERP ledger, the memory buffer is cryptographically zeroed out.
1. Ephemeral Volatile Ingestion
When customer conversations or machine telemetries pass through Clockin AI, our neural nodes enforce strict tokenization:
- Automated PII Redaction: Credit card numbers, Aadhaar/PAN identifiers, and patient national IDs are sanitized before any neural reasoning occurs.
- RAM-Only Computation: No disk writes occur on Clockin AI nodes during conversational processing.
- Cryptographic Wiping: Residual tensor caches are purged within 100 milliseconds of transaction completion.
2. Regulatory & Statutory Alignment
Full compliance with India's Digital Personal Data Protection Act. All cloud workloads are restricted to domestic Indian data regions.
Hospital and clinic deployments execute Business Associate Agreements (BAA) with end-to-end TLS 1.3 and zero PHI persistent persistence.
3. Air-Gapped Physical Isolation
For organizations operating in defense, critical healthcare, or intellectual property-sensitive manufacturing, Clockin AI provides an on-premises hardware enclave appliance. This appliance runs with physical network isolation (air-gap) with zero outbound internet traffic.
4. Data Protection Inquiries & Grievance Redressal
For data protection audits, security questionnaire requests, or compliance inquiries, please contact our Data Governance Officer: