Auralius
GLOBAL DATA GOVERNANCE & PRIVACY STANDARDISO 27001 & SOC2 TYPE II COMPLIANT

Enterprise Privacy Policy

Effective Date: August 18, 2026 | Version 2026.4
Corporate Entity: Kolerr Lab, Inc. USA (Delaware Corporation ID: 2026-KL-AURALIUS)

1. Corporate Entity & Scope of Policy

This Global Enterprise Privacy Policy ("Policy") governs all data processing operations conducted by Kolerr Lab, Inc. USA ("Company", "Kolerr Lab", "we", "us", or "our") in connection with the Auralius sub-50ms conversational AI voice platform. This includes our primary marketing websites, developer documentation portals, RESTful API endpoints, WebSocket media gateways, client SDKs, mobile applications, and omnichannel telephony ingress sockets.

This Policy applies universally to all workspace administrators, developer accounts, enterprise end-users, and individuals whose voice audio streams or metadata are processed through our voice agent infrastructure.

2. Multi-Tenant Architectural Data Isolation

Auralius is engineered from the ground up on strict zero-trust, multi-tenant isolation principles. All customer data—including agent prompts, knowledge base vector embeddings, conversation logs, and credential vaults—is strictly isolated at the database level utilizing PostgreSQL Row-Level Security (RLS) schemas bound to unique cryptographic tenant UUIDs.

No tenant workspace can inspect, query, or leak data into another workspace. Cross-tenant data boundary violations are architecturally impossible at the query layer.

3. In-Memory PCM Audio Processing & Zero-Disk Buffering

Our proprietary Blazil Rust Media Gateway processes incoming speech audio in-memory as uncompressed PCM audio frames to guarantee sub-50ms conversational turn-taking latency.

// IN-MEMORY VOICE STREAMING GUARANTEE

1. Raw voice audio packets are held exclusively in RAM during active WebSocket streaming sessions.
2. Audio frames are automatically discarded from volatile memory immediately upon turn completion.
3. No persistent audio files are written to non-volatile disk drives unless explicit call recording is configured by the workspace administrator.

4. Categories of Data Collected & Processed

CategorySpecific Data ElementsPrimary Purpose
Account IdentityFull name, corporate email address, encrypted password hashes (Argon2id), company name, billing addresses.Account authentication, tenant provisioning, and subscription billing.
Telephony & NetworkE.164 phone numbers, SIP call headers, client IP addresses, WebRTC latency telemetry, packet loss metrics.Real-time voice stream routing and sub-50ms gateway optimization.
Agent Instructions & DocsSystem prompts, custom tool definitions, policy PDFs, FAQs, and generated vector embeddings.Fact-grounded RAG retrieval and autonomous agent execution.
Cryptographic Audit LogsSHA-256 Merkle tree root hashes, timestamped tool call payload signatures, execution receipts.Immutable governance audit trails and legal non-repudiation.

5. Strict Non-Usage Warranty for AI Model Training

Kolerr Lab provides an explicit, legally binding warranty that customer audio streams, speech transcripts, system prompts, and knowledge base documents are NEVER used to train, fine-tune, or benchmark public foundation models (whether owned by Kolerr Lab or third-party AI model providers).

All data submitted to Auralius remains 100% the exclusive property of the customer workspace.

6. SHA-256 Merkle Ledger Cryptographic Governance

Every autonomous action executed by an Auralius voice agent (such as database updates, SMS dispatch, or external webhooks) is cryptographically signed using SHA-256 hashing algorithms and appended to an immutable Merkle Ledger.

This architecture ensures complete transparency, allowing enterprise compliance officers to verify every single turn taken by a voice agent with cryptographic proof.

7. Trusted Sub-processors & Infrastructure Partners

To deliver global voice telephony and frontier LLM reasoning, Kolerr Lab engages trusted third-party sub-processors under rigorous Data Protection Addendums (DPAs):

  • Twilio Inc. — E.164 telephony PSTN ingress and SMS dispatch.
  • Amazon Web Services (AWS) — SOC2 Type II certified cloud infrastructure & PostgreSQL RDS.
  • ElevenLabs Inc. — Ultra-realistic speech synthesis & voice cloning models.
  • OpenAI OpCo LLC — High-capacity LLM reasoning engines (zero data retention API pipelines).

8. International Data Privacy Rights (GDPR & CCPA/CPRA)

Under global privacy frameworks, users possess the following enforceable rights:

  • Right to Access & Data Portability: Export complete workspace archives in standard JSON formats directly from the Account Settings dashboard.
  • Right to Irreversible Erasure (Right to be Forgotten): Permanently delete all account credentials, agents, transcripts, and vectors. Account deletion requires mandatory TOTP MFA step-up authentication.
  • Right to Opt-Out of Non-Essential Telemetry: Control analytics and performance cookie preferences via our interactive Cookie Preference Manager.

9. Enterprise Encryption & Security Standards

All data in transit across public networks is encrypted using TLS 1.3 / HTTPS / Secure WebSockets (WSS) with strong cipher suites. Data at rest (including PostgreSQL database volumes and vector storage) is encrypted utilizing AES-256 bit encryption managed by AWS KMS key rings.

10. Automated Data Retention & Deletion Schedules

Call logs and transcripts are retained for 90 days by default, after which they are automatically purged from active database tables. Enterprise customers on Scale tiers may configure custom retention schedules ranging from 1 day to 7 years to align with corporate record retention policies.

11. Children's Privacy (COPPA Compliance)

Auralius is an enterprise business application and is not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 13 years of age. If we learn that personal data of a child has been collected without parental consent, we will purge such data immediately.

12. Legal Contact & Corporate Office

For formal privacy inquiries, Data Protection Addendum (DPA) execution, or HIPAA Business Associate Agreement (BAA) requests, please contact our Legal & Privacy Office:

Kolerr Lab, Inc. USA — Global Legal & Privacy Division
Corporate Jurisdiction: State of Delaware, United States of America
Delaware Entity File Number: 2026-KL-AURALIUS
Official Privacy Email: privacy@kolerrlab.com
Legal Inquiries: legal@auralius.ai