CONTROLLED EARLY ACCESS RELEASE — Authorized Test Users OnlyRequest access
Legal

Privacy Policy

How Sirat Bridge handles tenant data, customer records, communications data, AI-assisted workflows, and operational telemetry across the platform.

Last updated: September 3, 2026Version: 1.4.0

Data controller / business contact

Sirat Bridge LLC
18429 Veterans Memorial Drive E, Bonney Lake, WA 98392, United States
Mailing: P.O. Box 7024, Bonney Lake, WA 98391
Phone: (253) 386-3355 · Monday – Friday, 8:00 AM – 5:00 PM Pacific Time
Privacy & data requests: compliance@siratbridge.net

Scope

Sirat Bridge is a managed, multi-tenant AI communications and operations platform that helps businesses manage customer conversations, AI-assisted receptionist workflows, operational workflows, and governed tenant workspaces. This policy applies to the tenant workspaces and platform surfaces we operate.

Depending on the workspace, processing may involve customer communications, AI Receptionist interactions, calls, transcripts, lead and intake information, workflow activity, tenant configuration, operational and support information, documents where enabled, messaging where enabled, provider-generated identifiers and metadata, and audit or security evidence. Logistics and customer-operations workflows remain supported as one operational configuration among others, not as the defining scope of the platform.

Not every capability or data category applies to every tenant. Available capabilities depend on tenant configuration, enabled modules, plan and entitlements, provider integrations, and industry requirements.

Platform Provider vs Tenant Organization responsibilities

Sirat Bridge LLC ("Platform Provider") operates a managed service. Portions of hosting, authentication, telephony, AI processing, communications delivery, and related infrastructure are supplied by third-party providers acting as subprocessors; Sirat Bridge does not own every underlying infrastructure component.

Depending on the processing activity and applicable law, a Tenant Organization may act as the controller or business for customer data it provides to Sirat Bridge, while Sirat Bridge may process that data on the tenant's behalf as a processor or service provider. This description is informational and does not itself constitute a data processing agreement.

  • Platform Provider — managed platform operation, tenant-aware application controls, AI communications orchestration, access-control enforcement, audit and evidence mechanisms, configured provider integrations, Service Desk and support capabilities, and operational monitoring as implemented.
  • Tenant Organization — determining appropriate purposes for customer communications; providing accurate business information and approved scripts; managing authorized users and assigning least-privilege tenant roles; completing required MFA enrollment; obtaining legally required customer consent; maintaining applicable do-not-contact and contact preferences; approving calling windows and communication rules; determining appropriate human escalation; satisfying industry-specific licensing or professional obligations; responding to customer or data-subject requests for which the tenant is responsible; and reviewing AI-assisted output before consequential business decisions.

Tenant isolation

Tenant-scoped business data is protected through organization-aware authorization in the application and database Row-Level Security policies where applicable. Sirat Bridge also maintains platform-level configuration, governance, control-plane and operational records, which are held under separate authorization controls rather than tenant ownership.

Access across organizations is restricted to authorized platform roles and to the tenant roles a Tenant Organization assigns; it is not available to ordinary tenant users through the application or API.

Customer data handling

Customer-facing data (names, contact details, operational records, attached documents) remains the Tenant Organization's data. Sirat Bridge processes it to provide, secure, operate, support and improve the contracted service, and to meet legal obligations, subject to the applicable tenant agreement and privacy obligations. Sirat Bridge does not sell or rent tenant customer data, and does not use it for advertising.

Communications data

Phone numbers and email addresses collected for notifications, invitations, and operational alerts are scoped to the Tenant Organization and held under the access controls described in this policy. Different message types follow different rules: consent-based outbound communications require consent captured by the Tenant Organization, while transactional and service messages, invitations, operational notifications, support correspondence and legally required notices are sent as part of providing the service. All communications are subject to applicable consent, opt-out, tenant configuration and legal requirements, and recipients may opt out of non-essential messaging. See our SMS Consent & Communications Policy for full details.

Automated & AI-assisted communications

Where enabled for a Tenant Organization, Sirat Bridge may use automated systems and AI-assisted models to summarize records, draft messages, transcribe calls, route workflows, and place outbound voice or messaging communications on the tenant's behalf. Availability of each capability depends on tenant configuration, enabled modules, provider integrations, plan and industry requirements. When you interact with a Sirat Bridge-powered conversation:

  • You may be communicating with an AI assistant or a recorded automated system. Identification at the start of the interaction, and recording disclosure, are provided where configured and where required by applicable law.
  • Where configured, recipients may request a human handoff, opt out of further contact, or request a copy of a transcript through the responsible Tenant Organization.
  • AI processing is performed by third-party providers acting as subprocessors. Contractual terms with each provider are being verified as part of our subprocessor disclosure work; this policy does not represent that verification as complete.
  • AI-generated output is intended to assist, not replace, human judgement. Tenant Organizations are responsible for human review before consequential business decisions.

Data Subject Rights

Depending on applicable law and the nature of the processing, individuals whose personal data is processed through Sirat Bridge may have rights such as those below. Not every right applies to every individual, tenant or jurisdiction, and regimes such as the GDPR, UK GDPR or CCPA/CPRA apply only where their conditions are met:

  • Access — request a copy of personal data held about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion where retention is no longer required by law or contract
  • Restriction — request that processing be limited pending review
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — at any time, for processing that relies on consent
  • Non-discrimination — exercise rights without retaliation or degraded service

Customers should direct requests first to the Tenant Organization that holds their record. Platform-level requests may be submitted to privacy@siratbridge.net or compliance@siratbridge.net, and we assist Tenant Organizations with requests they are responsible for. Requests are handled through administrative review rather than an automated self-service workflow. We respond to verified privacy requests within the time required by applicable law.

Data Retention & Deletion

Sirat Bridge retains information for as long as reasonably necessary to provide and secure the service, satisfy applicable legal or contractual requirements, resolve disputes, maintain appropriate business and security records, and support authorized tenant operations. Retention periods may vary by data category, tenant configuration and applicable requirements, and remain subject to legal-hold obligations.

Where a retention control is technically implemented, we describe it specifically: platform operational metrics captured for monitoring are purged automatically after 365 days. Other categories — including operational records, communications metadata, recordings and transcripts held by communications providers, audit records, authentication logs and backups — are currently governed by operational and contractual practice rather than a published fixed schedule. A formal, technically enforced retention schedule is a planned governance deliverable and is not represented here as already implemented.

Deletion requests are handled administratively and confirmed in writing once executed. Anonymized or aggregated analytics that cannot be re-identified may be retained.

Governance & Compliance

Security and governance practices are informed by recognized frameworks and control principles, including, where relevant, the SOC 2 Trust Services Criteria, the NIST Cybersecurity Framework and CIS Controls. Sirat Bridge is not certified, attested or audited against these frameworks, and referencing them is not a claim of compliance.

Controls implemented in the platform today include:

  • MFA required for privileged administrative actions
  • Audit logging — append-only at the database layer, tenant-scoped and platform-scoped
  • Least-privilege access — role-based access control with Row-Level Security policies at the database layer

Communications governance is informed by applicable legal, carrier and industry requirements — including the TCPA, CTIA Messaging Principles & Best Practices and carrier 10DLC registration requirements. These are obligations that inform how tenants and Sirat Bridge configure messaging; they are not certifications, and this policy does not represent that each requirement is enforced technically by the platform.

Current posture is described in our Security Overview.

Audit records

Material actions across organizations, users, roles, records, communications, and documents are recorded in an audit log that is append-only: update and delete operations on audit records are rejected at the database layer. Audit entries are organization-scoped or platform-scoped, and are readable only by administrators authorized for that scope.

Secure file storage

Files uploaded to Sirat Bridge-managed tenant file storage are held in private object storage with organization-prefixed paths, and access is mediated by short-lived signed URLs. These buckets are not configured for public access. Content held by third-party communications or AI providers is governed by those providers' storage arrangements.

Report a Vulnerability

Responsible security disclosures are welcomed and reviewed through the published security contact: security@siratbridge.net. Please include a clear reproduction, the affected URL or component, and any relevant logs. A formal safe-harbour statement is pending legal review and is intentionally not published here.

Contact

Release scope

This policy describes the Controlled Early Access Release posture. A general-availability privacy notice will replace this document at public launch. Material updates may be communicated through the platform, published notices, email where configured, or other appropriate channels.