Skip to content
OneCloud Applied AI
Consulting Engagements Platforms FAQ
Book a call
Legal

Privacy policy

How OneCloud handles personal information across this website, our consulting engagements and the ERAG and Stratum platforms.

Effective 20 September 2026 Last updated 20 September 2026 Entity OneCloud, LLC

On this page

  1. 01 · Who we are
  2. 02 · Two different roles
  3. 03 · What we collect
  4. 04 · Customer content and AI models
  5. 05 · Why we use it, and on what basis
  6. 06 · Who we share it with
  7. 07 · International transfers
  8. 08 · How long we keep it
  9. 09 · Your rights
  10. 10 · Security
  11. 11 · Children
  12. 12 · Changes to this policy
  13. 13 · Contact us

01Who we are

OneCloud, LLC, a limited liability company registered in the State of Florida, United States (“OneCloud”, “we”, “us”) operates onecloudops.com and provides AI consulting services and two platforms: ERAG, an enterprise retrieval and agent platform, and Stratum, an AI-native legacy modernization platform.

This policy explains what personal information we handle, why, and what you can do about it. For questions or to exercise a right, write to [email protected].

02Two different roles

We handle personal information in two distinct capacities, and your rights differ depending on which applies.

  • As a controller — for our own website visitors, prospects, customer contacts and job applicants. We decide why and how that information is used, and this policy governs it.
  • As a processor — for the documents, source code and records a customer loads into ERAG or Stratum. That content belongs to the customer; we process it only on their instructions under our Data Processing Addendum. If you are an employee or customer of one of our customers, contact them directly — they control that data, not us.

If you run ERAG yourself — it is Apache-2.0 licensed and self-hostable — your data never touches our systems at all, and this policy does not apply to that deployment.

03What we collect

When you visit this website

This site carries no analytics, no advertising pixels and no third-party tracking cookies. We do not profile visitors.

  • Server logs — IP address, timestamp, page requested, user agent. Used to keep the site up and to spot abuse. Retained for 30 days.
  • Local storage — a single key, oc-theme, remembering whether you chose the light or dark theme. It never leaves your browser and we cannot read it.
  • Fonts — the typeface is served by Google Fonts, which receives your IP address as part of that request. If you would rather avoid it, self-hosting the font files removes the call entirely.

When you contact us

The contact form collects your name, work email, company and whatever you write in the message. It is delivered to us by email through Resend, our transactional email provider, and stored in our mailbox and CRM.

When you become a customer

  • Account data — names, work emails, roles and authentication identifiers for the people you authorise.
  • Billing data — company details, addresses and tax identifiers. Card details are handled by our payment processor; we never see or store full card numbers.
  • Usage and audit records — sign-ins, queries run, scans started, jobs executed. These exist for security, billing and support.
  • Support correspondence — tickets, emails and call notes.

04Customer content and AI models

The documents and source code you load into our platforms are customer content. We treat them as confidential and process them only to deliver the service you asked for.

  • We do not train models on your data. Neither your documents nor your source code are used to train, fine-tune or improve any model, ours or anyone else’s.
  • Model providers. When you use hosted models, the relevant content is sent to the provider routed for that workload under agreements that prohibit training on it. You can bring your own provider keys, or run local models on vLLM or Ollama so nothing leaves your network.
  • Isolation. Hosted storage is isolated per organisation and encrypted at rest. Secrets are encrypted and never returned unmasked.
  • Deployment choice. The Stratum VPC runner and self-hosted ERAG keep content entirely inside your own infrastructure.

05Why we use it, and on what basis

PurposeInformationLawful basis (UK/EU GDPR)
Run and secure the websiteServer logsLegitimate interests — keeping the service available and safe
Answer enquiries and send proposalsForm and email contentLegitimate interests / steps before a contract
Deliver the servicesAccount, usage, customer contentPerformance of a contract
Invoice and collect paymentBilling dataPerformance of a contract; legal obligation
Security monitoring and fraud preventionLogs, audit recordsLegitimate interests; legal obligation
Product and service improvementAggregated usage metricsLegitimate interests
Occasional updates to existing customersWork emailLegitimate interests, with opt-out in every message

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not make decisions producing legal effects about you by automated means.

06Who we share it with

We share personal information only with service providers who need it to help us operate, each under contract and each prohibited from using it for their own purposes.

ProviderWhat forWhere
Cloud infrastructure providerHosting the platforms and this websiteCustomer-selected region
ResendTransactional and contact-form emailUnited States
Model providers (Anthropic, OpenAI, Azure OpenAI, AWS Bedrock, Google Vertex AI and others you route to)Inference, only where you use hosted modelsProvider region
Payment processorCard processing and invoicingUnited States / EU

The current subprocessor list for customer content is maintained in Annex III of the DPA. We may also disclose information where required by law, to enforce our agreements, or as part of a merger or acquisition — in which case we will tell affected customers.

07International transfers

We are established in the United States, so information from the UK, EEA or Switzerland may be transferred there and to other countries where our providers operate.

Where required, those transfers rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and technical measures including encryption in transit and at rest. Customers may also pin processing to a chosen region, or deploy entirely inside their own infrastructure so no transfer occurs.

08How long we keep it

  • Server logs — 30 days.
  • Enquiries that do not become customers — 24 months, then deleted.
  • Customer account and usage records — for the life of the contract and 12 months after.
  • Customer content — for the life of the contract. On termination it is deleted within 30 days unless you ask for it sooner, or ask us in writing to hold it longer.
  • Invoices and financial records — seven years, as tax law requires.

Customers can also configure their own retention policies and right-to-be-forgotten workflows inside the platforms.

09Your rights

Depending on where you live, you may have some or all of the following rights over the information we hold as a controller.

  • Access — get a copy of what we hold about you.
  • Correction — fix anything inaccurate or incomplete.
  • Deletion — ask us to erase it, where no legal obligation requires us to keep it.
  • Portability — receive it in a machine-readable format.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to pause it while a dispute is resolved.
  • Withdraw consent — where we relied on consent, at any time, without affecting what came before.
  • Non-discrimination — we will not treat you worse for exercising any of these.

Write to [email protected]. We answer within 30 days and may need to verify your identity first. Florida and other US state residents may exercise equivalent rights, including the right to know and to opt out of sale or sharing — we do neither. If you are in the UK or EEA and are unhappy with our response, you can complain to your supervisory authority, though we would rather you came to us first.

10Security

We encrypt data in transit and at rest, enforce access control inside retrieval rather than after it, support SSO, SCIM and MFA, and keep an audit trail that can be exported to your SIEM. The full picture is on our security page, including how to report a vulnerability.

No system is perfectly secure. If a breach affects your personal information we will notify you and any relevant regulator within the timeframes the law requires.

11Children

Our services are built for organisations, not consumers, and are not directed at anyone under 16. We do not knowingly collect information from children. If you believe we have, tell us and we will delete it.

12Changes to this policy

We will update this page when our practices change, and we will move the “last updated” date at the top. For material changes affecting customers we will give notice by email or in-product before they take effect.

13Contact us

OneCloud, LLC, a limited liability company registered in the State of Florida, United States

Privacy: [email protected]
Security: [email protected]
Everything else: [email protected]

Privacy policy Terms of service Security Data processing addendum ← Back to onecloudops.com
© 2026 OneCloud, LLC. Understand → prove → ship → run. Questions? [email protected]