Sierrainet, LLC Privacy Policy Summary

Effective Date: May 11, 2026 Commitment to Privacy: Sierrainet views privacy as an architectural principle built into every product and AI development lifecycle, not just a compliance checkbox.

 

1. Information We Collect

We collect various types of data to provide and improve our AI Digital Transformation and Program Management services:

 
  • Client Contact Data: Names, business emails, phone numbers, job titles, and physical addresses of authorized users.

     
  • Organizational Data: Org charts, project roles, and vendor relationships necessary for delivering our services.

     
  • Usage & Technical Data: IP addresses, browser types, page visits, session durations, and workflow states to ensure security and improve platform performance.

     
  • AI Interaction Data: Prompts, queries, and generated outputs used in our AI features.

     
  • Program Management Metadata: Milestone records, budget tracking, and risk registers.

     

2. How We Use Your Information

  • Service Delivery: To provision platform access, configure AI tools, and enable reporting.

     
  • AI Model Improvement: We use de-identified, aggregated data to improve our AI models. Clients can opt out of this by emailing privacy@sierrainet.com.

     
  • Analytics & Security: To generate program performance analytics for clients and continuously monitor for unauthorized access or security anomalies.

     
  • Compliance: To fulfill legal obligations, including HIPAA and GDPR requirements.

     

3. Data Sharing & Disclosure

  • No Sale of Data: Sierrainet strictly prohibits the sale, rental, or trading of personal data.

     
  • Sub-Processors & Advisors: We share data only with approved third-party sub-processors and professional advisors (e.g., auditors, attorneys) strictly bound by data protection agreements.

     
  • Legal Disclosures: We may disclose information if required by law, court order, or to protect the safety and rights of Sierrainet or the public.

     

4. AI-Specific Data Practices

  • Scoping: Client data used in AI features is strictly scoped to that specific client’s environment.

     
  • Human Oversight: AI outputs are reviewed for accuracy and bias, and any high-stakes decisions require human confirmation before action is taken.

     

5. Security Measures

  • Technical Safeguards: We implement industry-leading controls, including AES-256 encryption for data at rest, TLS 1.3 for data in transit, and Multi-Factor Authentication (MFA).

     
  • Audits & Compliance: Our security policies align with SOC 2 Type II criteria, utilizing role-based access controls and mandatory security training for personnel.

     

6. Data Retention

We retain data only as long as necessary:

 
  • Usage & Technical Data: Retained for 2 years and 90 days, respectively.

     
  • Client & Organizational Data: Retained for the duration of the engagement plus 3 to 5 years.

     
  • Financial Records: Retained for 7 years for tax and accounting purposes.

     
  • Destruction: Expired data is securely destroyed using NIST SP 800-88 guidelines or archived in an encrypted state.

     

7. Cookies & Tracking

  • We use a privacy-first, minimal tracking approach and do not deploy invasive advertising or cross-site trackers.

     
  • Non-essential cookies (Functional and Analytics) require affirmative consent through our platform’s cookie preference center.

     

8. Your Data Rights

Depending on your jurisdiction (such as under the GDPR), you have the right to:

 
  • Access your personal data.

     
  • Correct inaccurate data.

     
  • Delete your data (“Right to be Forgotten”).

     
  • Portability to transfer your data.

     
  • Object to or Restrict certain processing.

     

To exercise these rights, email privacy@sierrainet.com. Verified requests are typically fulfilled within 30 days.

 

9. International Transfers

For clients in the EEA, UK, or Switzerland, data transfers to the US are protected by Standard Contractual Clauses (SCCs) and supplementary measures like end-to-end encryption and pseudonymization (Schrems II compliance). Data localization options are also available.

 

Contact Information

For privacy inquiries, rights requests, or to reach our Data Protection Officer (DPO), please contact:

  • Email: privacy@sierrainet.com

     
  • Legal Escalation: legal@sierrainet.com

     

  1. Note: This privacy policy is part of the Sierrainet Legal Document Suite, which also includes our Terms of Service, HIPAA Business Associate Agreement, and GDPR Data Processing Agreement.