PALCYAI • PRIVATE FINANCIAL DISCOVERY
Privacy Notice
This notice explains how the PALCIDUSAI advisor experience is designed to collect, use, protect and route information. It is an implementation notice, not legal advice. Applicable legal requirements and final retention periods should be reviewed with qualified counsel.
Information we may collect
Depending on the workflow, this can include name, email, mobile number, preferred language, selected financial priorities, discovery answers, appointment details, consent records, communications, voice transcripts or summaries, documents intentionally submitted by the user, and technical/security information needed to operate and protect the service.
Why information is used
Information is used to deliver requested educational material, maintain a requested discovery workflow, arrange appointments, provide communications the user has requested or consented to, prepare advisor-facing summaries, operate security and audit controls, and improve reliability.
Consent
The public discovery flow uses a purpose-specific consent control before contact details are submitted. Consent may be withdrawn for future communications, subject to lawful record-keeping, security, contractual and regulatory obligations.
AI and third-party services
PALCIDUSAI may use infrastructure or service providers such as Cloudflare, Supabase, Resend, Vapi, n8n, Google services, calendar providers and messaging providers, as configured for the particular workflow. A provider may process information outside the user's province or country. The project uses server-side credentials and controlled integration boundaries rather than exposing privileged credentials in the browser.
Email, SMS, WhatsApp and voice
These channels are separate processing paths. A user should not submit highly sensitive information through an unsecured or inappropriate channel. Provider delivery, bounce, complaint, inbound and other events may be recorded for workflow integrity and audit purposes.
Security controls
The project uses TLS/HTTPS, server-side secret storage, least-privilege access, row-level security where configured, authenticated owner consoles, audit logging, input validation, rate limiting, idempotency, webhook signature verification, controlled external actions and an emergency-stop model.
Retention and deletion
Information is intended to be retained only as long as necessary for the stated purpose, security, auditability, contractual needs and applicable legal or regulatory obligations. Exact retention schedules are maintained in the project's operational configuration and may differ by record type. Requests for access, correction or deletion can be submitted using the contact below.
Your privacy requests
For a privacy, access, correction, consent-withdrawal or deletion request, contact patrickpalcidus@gmail.com. The requester may be asked to verify identity before information is disclosed or changed.
No absolute security guarantee
Web content can never be made impossible to copy or inspect by every technical means. PALCIDUSAI therefore treats client-side copy/inspection deterrence as a convenience control only; actual privacy protection is enforced through authentication, authorization, data minimization, backend controls, secrets management and auditability.
Related notices
Terms of Use · Cookie / Local Storage Notice · Data Rights · Security & Privacy Controls · Back to PALCIDUSAI