How Vovance Inc. handles information across Rumbe AI — designed for organizations that may process PII or PHI, with multi-tenant isolation, encryption, and AI integrity controls.
This document is a template and should be reviewed by qualified legal counsel before publication, especially if Rumbe AI is used in healthcare, insurance, financial services, or other regulated industries.
Rumbe AI is a product of Vovance Inc. and is owned, provided, operated, and commercially administered by Vovance Inc.
For customer deployments, Rumbe AI may operate as a technology service provider, processor, subprocessor, or business associate, depending on the contractual relationship and the nature of the data processed.
This Policy does not replace the privacy policy of a Rumbe AI customer. If you interact with a Rumbe AI-powered assistant on a customer’s website, that customer remains responsible for its own privacy notices and lawful basis for processing user data.
Depending on the customer’s use case, Rumbe AI may process PII or PHI including name, email, phone, account identifiers, support context, and healthcare-related information for regulated deployments. Where PHI is processed, additional contractual protections may apply, including a BAA where required.
Customers may upload or authorize access to help center articles, FAQs, policies, product documentation, internal playbooks, ticket history (where enabled), and other approved sources for retrieval-augmented generation. Rumbe AI is designed to answer from approved sources and maintain source-anchored responses.
We do not use customer content, PII, or PHI to train public AI models unless explicitly agreed in writing and legally permitted.
User identities, agent identities, and organization-level personal details are treated as high-sensitivity data and isolated with elevated controls.
Where email lookup is required, Rumbe AI may use HMAC-based blinded indices so the system can match users by email without storing or exposing plain-text email in searchable indexes.
Rumbe AI supports erasure workflows through soft-delete patterns such as deletedAt across PII-heavy tables, enabling scrubbing and applicable deletion requests.
Rumbe AI may maintain AI transaction logs containing SHA-256 hashes of AI request payloads, creating an integrity record without duplicating sensitive content unnecessarily.
Where required by law or contract, Vovance Inc. may enter into a BAA with covered entities or business associates using Rumbe AI for PHI-related workflows.
Customer data is isolated using organization-level identifiers, and one organization is not permitted to access another organization’s data.
API keys and integration secrets are not stored in plain text. Secrets may be encrypted using AES-256-GCM with unique initialization vectors and authentication tags.
Application-level secrets encryption is managed using a dedicated secrets encryption key that is separate from primary database credentials.
Rumbe AI may support BYOL/BYOK for providers such as OpenAI, Groq, Gemini, Twilio, Stripe, SMTP providers, and other integrations, allowing customers to control provider relationships and applicable data terms.
Rumbe AI may connect to AI, communication, payment, analytics, email, database, hosting, and other infrastructure providers as needed. Depending on configuration, providers may include OpenAI, Groq, Gemini, Twilio, Stripe, SMTP/email providers, vector retrieval systems, and hosting / monitoring providers. See the Subprocessors page for the current disclosure framework.
Rumbe AI may use JWT-based authentication, secure session management, and session secret rotation capabilities.
Access may be limited by role, organization, permissions, and product area, including customer administrator, agent, operator, and system-level access.
Rumbe AI uses strict schema validation across API boundaries to reduce injection risks and unsafe data processing.
Embeddable chat widgets may use a dual-key system (public key + server-side secret key hash) and domain whitelisting to prevent unauthorized embedding.
Rumbe AI websites and deployed interfaces may use cookies, local storage, session identifiers, and similar technologies to keep users signed in, secure sessions, remember preferences, measure performance, detect abuse, and support analytics. Customers embedding Rumbe AI widgets are responsible for disclosing cookie or tracking behavior in their own privacy notices where required.
We retain information only as long as reasonably necessary to provide the service, maintain security and audit trails, support customers, comply with legal obligations, and resolve disputes. Periods vary by contract, plan, configuration, and whether the data includes PII or PHI. Customers may request deletion or export of applicable data subject to legal, security, and contractual limitations.
We do not sell PII or PHI.
End users should avoid submitting unnecessary sensitive personal information unless the customer deployment clearly requests it and provides appropriate notice. AI-generated responses may be helpful but should not be treated as professional, medical, legal, financial, tax, insurance, or emergency advice unless verified through authorized human channels.
Information may be processed in the United States or other countries where Rumbe AI, Vovance Inc., customers, providers, subprocessors, or infrastructure partners operate. Where required, we use appropriate contractual and technical safeguards for cross-border processing.
If you are an end user of a Rumbe AI-powered assistant operated by one of our customers, please contact that customer first. We may need to coordinate with the customer because they may be the controller of your data.
Rumbe AI is not intended for use by children under the age required by applicable law. Customers must not knowingly configure Rumbe AI to collect information from children unless legally permitted and properly authorized.
We use technical, organizational, and administrative safeguards to protect information. However, no system can be guaranteed to be completely secure. Customers and users are responsible for maintaining secure credentials, managing access, and using the platform responsibly.
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date and may provide additional notice where required.
Vovance Inc. / Rumbe AI · 1338 Eastbrooke Trace, Marietta, GA 30066, USA · Website: https://rumbe.ai
We do not sell PII or PHI.
We do not use customer content, PII, or PHI to train public AI models unless explicitly agreed in writing and legally permitted.
Customer and organization data is isolated using organization-level identifiers, and one organization is not permitted to access another organization’s data.
Secrets may be encrypted using AES-256-GCM with unique initialization vectors and authentication tags, using a dedicated secrets encryption key separate from primary database credentials.
Depending on location, users may have rights to access, correct, delete, restrict, port their data, or withdraw consent — typically coordinated with the customer that controls the deployment.
Vovance Inc. can discuss Rumbe AI’s contracts, controls, deployment assumptions, and commercial options for your use case.