Legal
Privacy policy
1. Who we are
PourOverAI (“PourOverAI”, “we”, “us”) is an AI systems studio based in Taipei, Taiwan. We design and build AI agents, automations and supporting infrastructure for business clients.
This policy explains what personal data we handle, why, and what you can ask us to do about it. It covers this website and our commercial relationships. Where we process data on behalf of a client under a signed agreement, that agreement and its data processing terms take precedence over this policy.
For any privacy question, write to privacy@pouroverai.com.
2. Two kinds of data
We separate the data we hold for our own purposes from the data a client puts into a system we build. The rules are different, so we describe them separately.
Our own data (we are the controller)
Website visitors, enquiries, prospective clients, and the day-to-day administration of a client relationship. We decide why and how this is processed.
Client data (we are the processor)
Records, documents, transcripts and other content that a client connects to a system we build or operate. The client decides why and how it is processed; we act on their instructions.
3. What we collect
- Enquiry details. Your name, email address, company, and whatever you choose to write to us, when you contact us or book a call.
- Engagement records. Contracts, scoping notes, meeting notes, invoices and correspondence for as long as we work together.
- Technical logs. Our web server records the requesting IP address, user agent, requested path, response status and timestamp. These logs exist for security and troubleshooting.
- Client data. Whatever a client connects to a system during a build. We do not choose this content, and we ask clients to connect the minimum needed for the system to work.
This website does not use advertising cookies, tracking pixels, or third-party analytics that profile you across sites. We set no cookies for marketing purposes.
4. Why we process it, and on what basis
- To answer you and quote work — on the basis of taking steps at your request before entering a contract.
- To deliver the engagement and get paid — on the basis of performing our contract with you.
- To keep the site and our systems secure — on the basis of our legitimate interest in preventing abuse, balanced against your rights.
- To meet accounting and tax obligations — on the basis of legal obligation.
We do not sell personal data, we do not share it with data brokers, and we do not use it for automated decisions that produce legal or similarly significant effects on you.
5. Client data in AI systems
This is the part clients ask about most, so we state it plainly.
- We do not train models on client data. Client content is never used to train, fine-tune or improve a model for us, for another client, or for anyone else.
- Zero-retention where available. When a system calls a third-party model provider, we use zero-retention or no-training API tiers wherever the provider offers them, and we name the provider and tier in the engagement documentation.
- Your accounts first. Wherever the architecture allows, systems run on the client’s own cloud, database and model-provider accounts, so client data stays inside infrastructure the client controls.
- Least access. Our access to a client environment is scoped to what the build requires, is held by named individuals, and is revoked at handover unless the client has retained us for ongoing support.
- Deletion on request. On written request at or after handover, we delete working copies, exports and evaluation sets that contain client data, subject to the retention rules in section 8.
6. Who else sees the data
We use a small number of service providers, each bound by contract to process data only on our instructions:
- Hosting and infrastructure for this website and for internal tooling.
- Email and calendar for correspondence and scheduling.
- Accounting and payments for invoicing and statutory records.
- Model and API providers named in the relevant engagement, only where a system we build calls them.
We will also disclose data where we are legally required to, and to professional advisers where necessary to establish or defend legal claims. A current list of sub-processors is available to clients on request.
7. International transfers
We operate from Taiwan and use providers that may store or process data outside it, including in the United States, the European Union, Japan and Singapore. Where we transfer personal data out of a jurisdiction that restricts transfers, we rely on an approved mechanism such as standard contractual clauses, and we assess whether the destination offers adequate protection before we transfer.
8. How long we keep things
- Enquiries that do not become engagements — 24 months, then deleted.
- Engagement records — for the life of the relationship and 7 years afterwards, to meet Taiwanese accounting and tax requirements.
- Web server logs — 90 days.
- Client data — for the term of the engagement, then deleted on request or within 90 days of the engagement ending, whichever comes first, except where the client asks us to retain it for ongoing support.
9. Security
We use encryption in transit for all traffic, encryption at rest for stored data, multi-factor authentication on every account that touches client systems, hardware-backed credential storage, and access scoped to the individuals on the engagement. Credentials are rotated at handover. No system is perfectly secure, and we will notify affected clients and, where required, the relevant supervisory authority without undue delay if a breach occurs.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive a portable copy, and to withdraw consent where consent was the basis for processing. Taiwanese residents hold these rights under the Personal Data Protection Act; residents of the European Economic Area and the United Kingdom under the GDPR; residents of California under the CCPA as amended.
Write to privacy@pouroverai.com and we will respond within 30 days. We will not charge you for exercising a right or treat you differently for doing so. If we hold the data as a processor for a client, we will pass your request to that client and support them in answering it.
If you are unsatisfied with our response, you may complain to your local data protection authority.
11. Children
Our services are sold to businesses. This website is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, write to us and we will delete it.
12. Changes to this policy
When this policy changes we update the effective date and version at the top of the page. For changes that materially affect how we handle personal data, we notify active clients by email before the change takes effect.
Contact. PourOverAI, Taipei, Taiwan — privacy@pouroverai.com. General enquiries: hello@pouroverai.com.