This policy describes the personal information collected and processed by Natacha Essim / SoftHire Systems LLC when you use natachaessim.com, submit an inquiry, sign a client agreement, or receive AI Workforce services. It reflects the actual systems in production as of August 2026.
This policy does not claim GDPR compliance certification, SOC 2 certification, HIPAA compliance, or any other formal certification. It is a plain-language description of actual data practices.
Attorney review note: This policy was drafted without legal counsel. Clients subject to specific regulatory regimes (healthcare, financial services, education, etc.) should seek independent legal advice before sharing sensitive data in the course of an engagement.
What We Collect
When you submit an inquiry
The connect form at natachaessim.com/connect collects the following, which you provide directly:
- Full name and email address
- Organization name (optional)
- Service interest, business description, and the problem you're trying to solve
- Team size, timeline, and budget range
- How you found this site (optional referral field)
- Prior experience with systems work (optional, non-AI-Workforce inquiries)
For AI Workforce inquiries, the form also collects:
- Current workflow handling, frequency, and existing systems
- Operator of interest, process scope, and escalation preferences
- AI readiness audit results and scoring (generated during the intake flow)
- Entry source (how the inquiry was initiated)
When you sign a client agreement
The agreement signing flow at natachaessim.com/sign/[agreement-slug] collects:
- Your typed name (as an electronic signature)
- Your signature image, drawn in the browser and stored as a base64-encoded PNG
- Your IP address and browser user-agent string, captured at the moment of signing for legal audit-trail purposes
- The date and time of signing
The agreement itself — including its terms, service description, project fee, and effective date — is stored in association with your record.
When you make a payment
Consulting deposit payments are processed through Stripe. When a payment link is sent, your name and email address are passed to Stripe's checkout interface. Payment card details are entered directly into Stripe's secure form and are never transmitted to or stored on this site's servers. We receive confirmation of payment from Stripe's webhook system; we do not receive or store card numbers, CVVs, or full account details.
As an AI Workforce client
If you engage AI Workforce services, the following may be stored in the client management system:
- Your organization name, contact names, and contact roles
- Your operator deployment configuration (which operators are active, their current status)
- Deployment activity logs (events generated by or about active operators)
- Workflow information shared during onboarding or scoping
- Operator output records (drafts, summaries, classifications, or other outputs generated by active operators), where retained for operational review and quality tracking
Technical and session data
- Session cookie (cs_session): when you use the countersign flow, a short-lived, cryptographically signed HttpOnly cookie is set in your browser. It expires within 30 minutes and is scoped to a single agreement. It is not a tracking cookie and is not used for advertising.
- Netlify access logs: as with any web host, Netlify may log basic access data including IP addresses and request metadata at the infrastructure level. This is outside direct control and governed by Netlify's own data practices.
This site does not use advertising trackers, third-party analytics pixels, or behavioral profiling tools.
How It's Used
- Responding to inquiries: inquiry data is reviewed personally to assess fit and respond
- Managing client engagements: name, email, and project details are used to draft agreements, send signing links, and manage payment schedules
- Agreement execution: signature data (typed name, signature image, IP address, user-agent string, and timestamp) is stored to create an auditable electronic signature record for each party
- Sending transactional emails: confirmation of inquiry receipt, agreement signing notifications, fully-executed agreement notices, and transactional notifications related to purchases made through this site
- AI Workforce service delivery: client and deployment records are used to manage active AI Workforce engagements, track operator status, and communicate deployment updates
- Internal records: inquiry and agreement records are retained for business record-keeping and to manage ongoing or past client relationships
Information is not used for advertising, sold to third parties, or shared with data brokers.
AI Workforce Data
The AI Workforce service involves deploying AI operators to assist with client workflows. The information you share during AI Workforce intake — including your workflow descriptions, process details, and business context — may be used to configure and operate those operators.
The AI operators themselves are built on third-party AI models and infrastructure. When an operator is active, it may process information you provide during interactions with it. The specific model provider(s) involved in any given deployment depend on the operator configuration and will be disclosed at the time of deployment scoping, to the extent they are known.
At the time this policy was last updated, no client-provided data is sent to third-party AI model APIs by this site's backend directly. AI processing occurs within operator systems that are configured and run separately. Client data is not used to train AI models by Natacha Essim / SoftHire Systems LLC. Whether model providers use interaction data for training depends on those providers' own terms and policies, which vary.
Note for AI Workforce clients: Before sharing sensitive, confidential, regulated, or proprietary information with an AI operator, review the AI Use & AI Workforce Disclosure. The service is designed for operational automation — not for processing regulated personal data, medical information, or financial records without additional safeguards.
Legal Basis for Processing
For individuals in the European Economic Area or United Kingdom, the following legal bases apply to the main processing activities:
- Contract performance: processing your name, contact details, agreement content, and signature data to execute and deliver services you've requested
- Legitimate interests: retaining inquiry records for business purposes and following up on active engagements, where this does not override your interests
- Legal obligation: retaining payment-related records for accounting and tax purposes, as required by applicable law
Attorney review note: This legal basis analysis was not reviewed by a qualified data protection practitioner. EEA/UK clients with specific compliance requirements should seek independent legal advice.
Service Providers
The following third-party services receive personal data in the course of operating this site. Each processes data according to its own privacy policy and agreements.
Confirmed service providers
No other third-party services are knowingly used to process personal data as of August 2026.
Data Retention
The following retention approach is applied:
- Inquiry records (active clients): inquiries that result in a signed engagement are retained as part of the client record for as long as that relationship exists and thereafter.
- Inquiry records (non-client): inquiries that do not result in a signed engagement are retained for a defined period that has not yet been formally established. These records may be deleted upon written request. See attorney review note below.
- Client agreement records: retained indefinitely. Executed agreements constitute legal records and are kept for the duration of and after a business relationship.
- Signature data: retained as part of the agreement record for the same period as the agreement itself. Signature images are stored in private Supabase Storage.
- Executed agreement PDFs: retained for as long as reasonably necessary to maintain the legal and business record of the executed agreement and satisfy applicable legal, contractual, accounting, and dispute-resolution requirements. Stored in Netlify Blobs and Supabase Storage (private bucket).
- Payment records: Stripe retains its own transaction records per its own policies. Internal payment and accounting records are retained for as long as reasonably necessary to satisfy applicable tax, accounting, legal, dispute-resolution, and business-record requirements, subject to applicable retention periods.
- AI Workforce deployment records: retained while the client relationship is active. A formal retention period for post-engagement records has not been established; records are currently retained until a deletion request is received.
- Session cookies: the cs_session cookie expires within 30 minutes and is not persisted to a database.
If you'd like your data reviewed or removed, send a written request to the contact address below. Deletion requests will be handled within 30 days where technically feasible and not in conflict with legal retention obligations.
Note: Executed agreement records may not be deletable in full where they constitute a legal contract between parties. In that case, you will be informed of what can and cannot be removed and why.
Attorney review note: SoftHire Systems LLC has not yet established a formal category-by-category data retention schedule. Specific retention periods — particularly for non-client inquiry records and post-engagement AI Workforce data — should be defined with legal counsel before GDPR, CCPA/CPRA, or other regulatory compliance is assessed.
Security Measures
The following security measures are in place as of August 2026:
- Agreement PDFs and signature images are stored in private (non-public) Supabase Storage buckets; access is via time-limited signed URLs
- The countersign flow uses HMAC-signed, short-lived session tokens delivered via HttpOnly cookies rather than reusable credentials in URLs
- API authentication uses secret key validation for admin-accessible endpoints
- All data is transmitted over HTTPS
- Database access uses row-level service keys; client-facing endpoints do not expose database credentials
No security system is infallible. This description is accurate at the time of writing and is not a guarantee against breach. In the event of a data breach that affects your personal information, you will be notified as soon as reasonably practicable.
International Data Transfers
This site is operated from the United States. The service providers listed above — Supabase, Resend, Stripe, Netlify, and Cloudflare — are U.S.-based companies and process data on infrastructure primarily located in the United States.
If you are located in the European Economic Area, United Kingdom, or another jurisdiction with data transfer restrictions, your personal data will be transferred to the United States in the course of using this site and its services. The legal basis for such transfers, and the adequacy mechanisms applicable, depend on the service provider and may change as legal frameworks evolve.
Attorney review note: International transfer compliance (SCCs, adequacy decisions, UK IDTA) was not assessed by legal counsel. EEA/UK-based clients should seek independent advice regarding transfer mechanisms before sharing personal data.
Your Rights
Depending on where you are located, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data held about you
- Correction: request that inaccurate or incomplete information be corrected
- Deletion: request that your personal data be deleted, subject to legal retention requirements
- Restriction: request that processing of your data be limited while a dispute is resolved
- Objection: object to processing based on legitimate interests
- Portability: request a machine-readable copy of data you've provided (where technically feasible)
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting lawfulness of prior processing
All requests are handled personally. There is no automated portal — contact the email address below and the request will be addressed within 30 days.
California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:
- The right to know what personal information is collected, used, disclosed, or sold
- The right to delete personal information (subject to exceptions)
- The right to opt out of the sale or sharing of personal information
- The right to non-discrimination for exercising these rights
We do not sell or share personal information with third parties for advertising or cross-context behavioral advertising purposes.
To exercise your California privacy rights, contact the email address below. Requests will be verified and responded to within 45 days.
Attorney review note: CCPA/CPRA compliance was not formally assessed. California residents with specific compliance concerns should seek independent legal advice.
Contact
For any questions about this policy, to exercise data rights, or to request deletion of your information:
Subject line: Privacy Request
All requests are reviewed personally. Response time is within 30 days for standard requests.