PALCYAI • PRIVATE FINANCIAL DISCOVERY

Privacy Notice

This notice explains how the PALCIDUSAI advisor experience is designed to collect, use, protect and route information. It is an implementation notice, not legal advice. Applicable legal requirements and final retention periods should be reviewed with qualified counsel.

Privacy by design: PALCIDUSAI asks for only information needed for the requested workflow, requires purpose-specific consent before lead capture, keeps privileged actions behind authenticated controls, and keeps provider secrets out of browser code and public repositories.

Information we may collect

Depending on the workflow, this can include name, email, mobile number, preferred language, selected financial priorities, discovery answers, appointment details, consent records, communications, voice transcripts or summaries, documents intentionally submitted by the user, and technical/security information needed to operate and protect the service.

Why information is used

Information is used to deliver requested educational material, maintain a requested discovery workflow, arrange appointments, provide communications the user has requested or consented to, prepare advisor-facing summaries, operate security and audit controls, and improve reliability.

Consent

The public discovery flow uses a purpose-specific consent control before contact details are submitted. Consent may be withdrawn for future communications, subject to lawful record-keeping, security, contractual and regulatory obligations.

AI and third-party services

PALCIDUSAI may use infrastructure or service providers such as Cloudflare, Supabase, Resend, Vapi, n8n, Google services, calendar providers and messaging providers, as configured for the particular workflow. A provider may process information outside the user's province or country. The project uses server-side credentials and controlled integration boundaries rather than exposing privileged credentials in the browser.

Email, SMS, WhatsApp and voice

These channels are separate processing paths. A user should not submit highly sensitive information through an unsecured or inappropriate channel. Provider delivery, bounce, complaint, inbound and other events may be recorded for workflow integrity and audit purposes.

Security controls

The project uses TLS/HTTPS, server-side secret storage, least-privilege access, row-level security where configured, authenticated owner consoles, audit logging, input validation, rate limiting, idempotency, webhook signature verification, controlled external actions and an emergency-stop model.

Retention and deletion

Information is intended to be retained only as long as necessary for the stated purpose, security, auditability, contractual needs and applicable legal or regulatory obligations. Exact retention schedules are maintained in the project's operational configuration and may differ by record type. Requests for access, correction or deletion can be submitted using the contact below.

Your privacy requests

For a privacy, access, correction, consent-withdrawal or deletion request, contact patrickpalcidus@gmail.com. The requester may be asked to verify identity before information is disclosed or changed.

No absolute security guarantee

Web content can never be made impossible to copy or inspect by every technical means. PALCIDUSAI therefore treats client-side copy/inspection deterrence as a convenience control only; actual privacy protection is enforced through authentication, authorization, data minimization, backend controls, secrets management and auditability.

Related notices

Terms of Use · Cookie / Local Storage Notice · Data Rights · Security & Privacy Controls · Back to PALCIDUSAI