Privacy Policy
Last updated: February 28, 2026
1. Introduction
Strattum, Inc. ("the Company," "we," "us," or "our") operates strattumx.com and the Strattum governed-context platform (the "Service"). Strattum is an AI enterprise data-context middleware: the platform connects AI agents to enterprise data sources such as SAP, Salesforce, Workday, and SQL databases through standardized MCP (Model Context Protocol) connectors, enforces access policies on each context request, and generates a complete audit trail of every query. Our customers are engineering and compliance teams at regulated enterprises building AI agent workflows where data access cannot be uncontrolled.
This Privacy Policy explains what personal information the Company collects from visitors to strattumx.com and from individuals who contact us or use the Service, how we use it, and the choices you have. It applies to information collected through the Service and through direct communications with us.
We are based at 1370 Broadway, Floor 5, New York, NY 10018 and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide
We collect information you submit directly, including:
- Contact details (name, work email, phone number) when you fill out a contact form, request early access, or subscribe to product updates;
- Company information you choose to share (employer name, role, team size, project context);
- The content of any messages you send us through the contact form or by email.
2.2 Information Collected Automatically
When you visit strattumx.com, we automatically collect limited technical information:
- IP address and approximate location (city and region level);
- Browser type, operating system, and device class;
- Pages visited, referring URLs, and time on page;
- Cookie and similar session identifiers (see Section 5).
2.3 Platform API and Audit Log Metadata
When customers use the Strattum platform to connect AI agents to their enterprise data sources, the Service generates and processes metadata about each context request. This metadata includes:
- Agent identifier and requesting service identity;
- Query scope and connector identifier;
- Access policy rule applied (allow or deny) and resolution status;
- Timestamp of the request.
This query metadata is generated as part of delivering the Service and populates the audit trail that customers use for compliance review. Strattum connectors run within the customer's own infrastructure environment; the content of enterprise records (financial data, HR records, CRM entries, and similar) does not transit through or reside on the Company's own servers. We process query metadata only.
2.4 We Do Not Knowingly Collect Children's Data
strattumx.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
We use the information we collect to:
- Respond to inquiries from potential customers, design partners, and engineers evaluating the platform;
- Operate, maintain, and improve the Service, including the connector infrastructure and policy enforcement engine;
- Send product updates and (with your consent where required) marketing communications about Strattum connectors and platform features;
- Generate and retain the audit trail that constitutes a core part of the Service for customers in regulated industries;
- Detect, investigate, and prevent misuse or abuse of the Service;
- Comply with legal obligations.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (for example, hosting infrastructure, transactional email delivery, and web analytics) under contractual confidentiality obligations that restrict their use of the data to providing services to us;
- Authorities, when required by applicable law or when necessary to protect the rights, safety, or property of the Company or others;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to the terms of this Policy.
We do not sell personal information to third parties.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember your preferences, and measure usage patterns so we can improve the Service. For full details on what cookies we use and how to manage them, see our Cookie Policy.
6. Data Retention
We retain personal information only as long as needed for the purposes described in this Policy, to comply with legal or accounting obligations, and to resolve disputes. Specifically:
- Website contact form submissions and sales inquiry records are retained for the duration of the business relationship and purged within 24 months of last contact if no account relationship exists;
- Platform API audit log metadata is retained for the duration of the active customer subscription and purged within 90 days following account termination;
- Web server access logs are retained for 90 days and then aggregated into anonymized summary form.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption for data in transit, restricted-access databases, least-privilege access controls on internal systems, and credential isolation at the connector level so that enterprise data source credentials are scoped to individual connector configurations and are not shared across customer accounts. Strattum's connector architecture is designed so that actual enterprise record content remains within the customer's infrastructure and does not transit the Company's servers.
No system is perfectly secure; we cannot guarantee absolute security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access to, correction of, and deletion of personal information, as well as the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. New York Residents
New York does not currently have a comprehensive consumer privacy statute. As a matter of policy, we extend the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (for example, HIPAA for protected health information or GLBA for certain financial records), those laws may give you additional rights with respect to data covered by them. Strattum serves customers in financial services and healthcare; customers in those sectors remain responsible for their own obligations under HIPAA, GLBA, and other sector-specific frameworks with respect to the enterprise data their AI agents access.
9.4 California Visitors
If you are a California resident visiting from another state, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Strattum, Inc.1370 Broadway, Floor 5
New York, NY 10018
Email: [email protected]
Phone: +1 (212) 740-0268