Trust Center
The AI Change Loop platform handles transformation program data for enterprise clients. This page documents what data we collect, how it is used, how it is protected, and what rights clients have over it.
Client data is not sold
Data commercialization
Not used to train public AI models
AI training use
PHI not accepted
Sensitive data
Deletion targeted within 30 days
Data retention rights
Core Data Commitments
Client data is not sold or licensed to third parties
Program records, diagnostic results, SICI scores, instrument outputs, and client-identifiable data are never sold, rented, licensed, or shared with third parties for commercial purposes. This applies to all data submitted through the EAD, the client portal, or any platform instrument.
Client data is not used to train public AI models
Diagnostic responses, program records, and instrument outputs are not used as training data for any public AI model, language model, or machine learning system operated by AI Change Loop or any third party.
PHI is not accepted on the platform
The AI Change Loop platform is not designed to receive, store, or process protected health information as defined under HIPAA. If a client engagement requires PHI handling, a separate data processing agreement must be executed before submission.
Deletion requests are targeted for completion within 30 days
Clients may request deletion of their program record and associated diagnostic data. Deletion is targeted within 30 days, subject to legal, financial, security, and operational retention requirements that may require longer retention periods.
Program data is isolated per client
Each client program record is maintained in a logically isolated data environment. Diagnostic outputs, SICI scores, instrument results, and portal records from one program are not accessible to or visible by any other client.
AI Change Loop does not access client program data without authorization
Client portal data and instrument outputs are accessed only for the purpose of delivering the contracted platform service. Raheel Malik accesses client program data only in the context of a contracted framework engagement where that access is explicitly authorized.
Benchmark data is anonymized and aggregated before any use
Where diagnostic data contributes to the platform benchmark dataset, it is anonymized and aggregated. No individual program data point is identifiable in benchmark outputs. Client consent is obtained at EAD intake before any diagnostic data contributes to the benchmark dataset.
Security review and DPA available upon request
Enterprise clients and consulting firms may request a security review document and a Data Processing Agreement before platform registration. Contact raheel@aichangeloop.com to initiate the review process.
Questions About Data Governance
If your organization requires a Data Processing Agreement, security review documentation, or a pre-registration compliance review before engaging with the AI Change Loop platform, contact us directly. We respond to all enterprise data governance inquiries within one business day.
Data Processing Agreement
A DPA is available for enterprise clients and consulting firms that require contractual data processing terms before platform engagement. Request via email.
Security Review Document
A security review document covering platform architecture, data isolation methodology, access controls, and retention policy is available upon request for enterprise diligence purposes.