Privacy Policy
How we handle personal information.
Effective date: July 23, 2026. This policy explains what personal information IOAI Gateway, Inc. collects, how we use it, and who we share it with across our website and the CGP Gateway private beta.
1. Operator and scope
IOAI Gateway, Inc. (“IOAI Gateway,” “we,” “us”) operates a business-to-business website, private-beta CGP Gateway control plane, API, sandbox, and support process. Our headquarters and business mailing address are 30 N Gould St, Ste R, Sheridan, WY 82801, United States.
This policy covers personal information associated with business visitors, invited beta users, administrators, support contacts, and security reporters. It does not describe an employment program or a consumer advertising service.
2. Information on the website
The website may process ordinary request information such as IP address, request time, browser type, requested page, and security events to deliver and protect the site. We do not use advertising pixels, behavioral advertising, or third-party analytics on this site. A visitor’s light-or-dark theme preference is stored locally in the browser.
When you use the contact form, we collect the name, email address, organization, inquiry type, and message you choose to provide so we can respond.
3. Information in the private beta
| Category | Examples | Purpose |
|---|---|---|
| Account and identity | Name, business email, tenant, role, sign-in and security events. | Authenticate users, enforce access, operate support, and protect accounts. |
| Workspace configuration | Registered endpoints, route policies, environment labels, limits, and administrator actions. | Configure and operate the customer’s gateway workspace. |
| Transaction metadata | Transaction ID, route, time, outcome class, latency, policy decision, and receipt reference. | Route work, troubleshoot failures, meter use, and produce tenant audit events. |
| Payload content | Customer-directed content moving between authorized endpoints. | Transient routing only; not persisted or used for shared-model training by default. |
| Support and business records | Messages, ticket history, agreement contacts, billing contact, and design-partner feedback. | Respond, administer the relationship, improve the product, and keep required records. |
4. Uses and legal grounds
We use information to provide requested beta services, secure accounts and infrastructure, troubleshoot and improve the product, communicate about the relationship, comply with law, and establish or defend legal claims. The legal ground depends on location and context, and typically includes performance of a contract, legitimate interests, legal obligation, or consent.
5. AI systems and customer directions
CGP Gateway can route a request to an AI system, agent, or service selected and authorized by the customer. We do not use routed customer payloads to train a shared foundation model and do not sell personal information for advertising. Customers decide which destinations receive their content and are responsible for giving those destinations proper notice and instructions.
6. Service providers and disclosures
Our infrastructure runs on Microsoft Azure, covering edge delivery, identity integration, and API management. Azure also handles compute, messaging, operational data, encrypted artifacts, secrets, and telemetry. The website loads typefaces from Google Fonts; when a page loads, Google receives standard request information such as the visitor’s IP address. We may also use email, support, and business-system providers under appropriate contractual safeguards.
Information may also be disclosed at the customer’s direction, during a legally structured corporate transaction, to professional advisers under appropriate obligations, or where law requires it.
7. Retention schedule
| Record | Retention | Deletion rule |
|---|---|---|
| Account and tenant records | Account life plus 30 days. | Delete or de-identify after the recovery window, subject to required records. |
| Endpoint and policy configuration | Until deleted plus 30 days. | Expire recoverable copies after the restoration window. |
| Transaction metadata | 30 days standard; configurable to 7. | Automated expiry by tenant policy. |
| Customer payload content | Not persisted by default. | Processed transiently in memory for the authorized route. |
| Audit exports and security telemetry | 90 days. | Lifecycle deletion unless a documented investigation hold applies. |
| Support records | 24 months after closure. | Scheduled deletion unless contract or law requires longer retention. |
8. Security and access
Access controls include Entra ID authentication, tenant-scoped roles, and managed identities; the data layer relies on Key Vault and encryption in transit and at rest; and operations are backed by centralized telemetry, rate limiting, backup controls, and incident runbooks. No security program eliminates all risk. Details are on the Trust page.
9. International processing
Private-beta infrastructure is hosted in a United States Azure region. Business users may access the service from other locations. Where required, we apply appropriate transfer mechanisms, regional restrictions, or contractual safeguards.
10. Privacy choices and requests
Depending on applicable law, an individual may have rights to access, correct, delete, restrict, object, or obtain a copy of certain personal information. We verify the person making the request, confirm the applicable customer relationship, and respond within the limits the law allows, keeping a record of each request. Where a customer controls the information, the request may be directed to that customer.
To submit a privacy request, use the privacy inquiry type on the Contact page.
11. Children, changes, and contact
The B2B service is not directed to children. If we make a material change to this policy, we will update the effective date and provide any notice required by law or contract.
Privacy contact: Privacy Owner, IOAI Gateway, Inc., 30 N Gould St, Ste R, Sheridan, WY 82801, United States, or via the Contact page.