Privacy Policy

Last updated August 2026 — reflects production architecture as of that date

This policy describes the personal information collected and processed by Natacha Essim / SoftHire Systems LLC when you use natachaessim.com, submit an inquiry, sign a client agreement, or receive AI Workforce services. It reflects the actual systems in production as of August 2026.

This policy does not claim GDPR compliance certification, SOC 2 certification, HIPAA compliance, or any other formal certification. It is a plain-language description of actual data practices.

Attorney review note: This policy was drafted without legal counsel. Clients subject to specific regulatory regimes (healthcare, financial services, education, etc.) should seek independent legal advice before sharing sensitive data in the course of an engagement.

What We Collect

When you submit an inquiry

The connect form at natachaessim.com/connect collects the following, which you provide directly:

  • Full name and email address
  • Organization name (optional)
  • Service interest, business description, and the problem you're trying to solve
  • Team size, timeline, and budget range
  • How you found this site (optional referral field)
  • Prior experience with systems work (optional, non-AI-Workforce inquiries)

For AI Workforce inquiries, the form also collects:

  • Current workflow handling, frequency, and existing systems
  • Operator of interest, process scope, and escalation preferences
  • AI readiness audit results and scoring (generated during the intake flow)
  • Entry source (how the inquiry was initiated)

When you sign a client agreement

The agreement signing flow at natachaessim.com/sign/[agreement-slug] collects:

  • Your typed name (as an electronic signature)
  • Your signature image, drawn in the browser and stored as a base64-encoded PNG
  • Your IP address and browser user-agent string, captured at the moment of signing for legal audit-trail purposes
  • The date and time of signing

The agreement itself — including its terms, service description, project fee, and effective date — is stored in association with your record.

When you make a payment

Consulting deposit payments are processed through Stripe. When a payment link is sent, your name and email address are passed to Stripe's checkout interface. Payment card details are entered directly into Stripe's secure form and are never transmitted to or stored on this site's servers. We receive confirmation of payment from Stripe's webhook system; we do not receive or store card numbers, CVVs, or full account details.

As an AI Workforce client

If you engage AI Workforce services, the following may be stored in the client management system:

  • Your organization name, contact names, and contact roles
  • Your operator deployment configuration (which operators are active, their current status)
  • Deployment activity logs (events generated by or about active operators)
  • Workflow information shared during onboarding or scoping
  • Operator output records (drafts, summaries, classifications, or other outputs generated by active operators), where retained for operational review and quality tracking

Technical and session data

  • Session cookie (cs_session): when you use the countersign flow, a short-lived, cryptographically signed HttpOnly cookie is set in your browser. It expires within 30 minutes and is scoped to a single agreement. It is not a tracking cookie and is not used for advertising.
  • Netlify access logs: as with any web host, Netlify may log basic access data including IP addresses and request metadata at the infrastructure level. This is outside direct control and governed by Netlify's own data practices.

This site does not use advertising trackers, third-party analytics pixels, or behavioral profiling tools.

How It's Used

  • Responding to inquiries: inquiry data is reviewed personally to assess fit and respond
  • Managing client engagements: name, email, and project details are used to draft agreements, send signing links, and manage payment schedules
  • Agreement execution: signature data (typed name, signature image, IP address, user-agent string, and timestamp) is stored to create an auditable electronic signature record for each party
  • Sending transactional emails: confirmation of inquiry receipt, agreement signing notifications, fully-executed agreement notices, and transactional notifications related to purchases made through this site
  • AI Workforce service delivery: client and deployment records are used to manage active AI Workforce engagements, track operator status, and communicate deployment updates
  • Internal records: inquiry and agreement records are retained for business record-keeping and to manage ongoing or past client relationships

Information is not used for advertising, sold to third parties, or shared with data brokers.

AI Workforce Data

The AI Workforce service involves deploying AI operators to assist with client workflows. The information you share during AI Workforce intake — including your workflow descriptions, process details, and business context — may be used to configure and operate those operators.

The AI operators themselves are built on third-party AI models and infrastructure. When an operator is active, it may process information you provide during interactions with it. The specific model provider(s) involved in any given deployment depend on the operator configuration and will be disclosed at the time of deployment scoping, to the extent they are known.

At the time this policy was last updated, no client-provided data is sent to third-party AI model APIs by this site's backend directly. AI processing occurs within operator systems that are configured and run separately. Client data is not used to train AI models by Natacha Essim / SoftHire Systems LLC. Whether model providers use interaction data for training depends on those providers' own terms and policies, which vary.

Note for AI Workforce clients: Before sharing sensitive, confidential, regulated, or proprietary information with an AI operator, review the AI Use & AI Workforce Disclosure. The service is designed for operational automation — not for processing regulated personal data, medical information, or financial records without additional safeguards.

Service Providers

The following third-party services receive personal data in the course of operating this site. Each processes data according to its own privacy policy and agreements.

Confirmed service providers

Supabase Database and file storage. Inquiry records, client agreement data, signature data, AI Workforce client and deployment records, and agreement PDFs are stored in Supabase-hosted infrastructure (PostgreSQL database and object storage). Supabase is hosted on AWS infrastructure in the United States. Supabase Privacy Policy
Resend Transactional email delivery. Used to send inquiry confirmations, agreement signing notifications, and fully-executed agreement notices. Recipient email addresses and email content (including name, organization, and service details) pass through Resend's infrastructure. Resend Privacy Policy
Stripe Payment processing. Handles all card data for consulting deposit payments. Client name and email are passed to Stripe's checkout interface; card details are handled exclusively by Stripe and are never stored here. Stripe Privacy Policy
Netlify Web hosting, serverless function execution, and blob storage for executed agreement PDFs. Netlify processes request data as part of serving this site. Netlify Privacy Policy
Cloudflare The Command Center (the internal operations interface) runs on Cloudflare Workers infrastructure. Cloudflare handles request routing for that interface and may log access-level data. Cloudflare Privacy Policy

No other third-party services are knowingly used to process personal data as of August 2026.

Data Retention

The following retention approach is applied:

  • Inquiry records (active clients): inquiries that result in a signed engagement are retained as part of the client record for as long as that relationship exists and thereafter.
  • Inquiry records (non-client): inquiries that do not result in a signed engagement are retained for a defined period that has not yet been formally established. These records may be deleted upon written request. See attorney review note below.
  • Client agreement records: retained indefinitely. Executed agreements constitute legal records and are kept for the duration of and after a business relationship.
  • Signature data: retained as part of the agreement record for the same period as the agreement itself. Signature images are stored in private Supabase Storage.
  • Executed agreement PDFs: retained for as long as reasonably necessary to maintain the legal and business record of the executed agreement and satisfy applicable legal, contractual, accounting, and dispute-resolution requirements. Stored in Netlify Blobs and Supabase Storage (private bucket).
  • Payment records: Stripe retains its own transaction records per its own policies. Internal payment and accounting records are retained for as long as reasonably necessary to satisfy applicable tax, accounting, legal, dispute-resolution, and business-record requirements, subject to applicable retention periods.
  • AI Workforce deployment records: retained while the client relationship is active. A formal retention period for post-engagement records has not been established; records are currently retained until a deletion request is received.
  • Session cookies: the cs_session cookie expires within 30 minutes and is not persisted to a database.

If you'd like your data reviewed or removed, send a written request to the contact address below. Deletion requests will be handled within 30 days where technically feasible and not in conflict with legal retention obligations.

Note: Executed agreement records may not be deletable in full where they constitute a legal contract between parties. In that case, you will be informed of what can and cannot be removed and why.

Attorney review note: SoftHire Systems LLC has not yet established a formal category-by-category data retention schedule. Specific retention periods — particularly for non-client inquiry records and post-engagement AI Workforce data — should be defined with legal counsel before GDPR, CCPA/CPRA, or other regulatory compliance is assessed.

Security Measures

The following security measures are in place as of August 2026:

  • Agreement PDFs and signature images are stored in private (non-public) Supabase Storage buckets; access is via time-limited signed URLs
  • The countersign flow uses HMAC-signed, short-lived session tokens delivered via HttpOnly cookies rather than reusable credentials in URLs
  • API authentication uses secret key validation for admin-accessible endpoints
  • All data is transmitted over HTTPS
  • Database access uses row-level service keys; client-facing endpoints do not expose database credentials

No security system is infallible. This description is accurate at the time of writing and is not a guarantee against breach. In the event of a data breach that affects your personal information, you will be notified as soon as reasonably practicable.

International Data Transfers

This site is operated from the United States. The service providers listed above — Supabase, Resend, Stripe, Netlify, and Cloudflare — are U.S.-based companies and process data on infrastructure primarily located in the United States.

If you are located in the European Economic Area, United Kingdom, or another jurisdiction with data transfer restrictions, your personal data will be transferred to the United States in the course of using this site and its services. The legal basis for such transfers, and the adequacy mechanisms applicable, depend on the service provider and may change as legal frameworks evolve.

Attorney review note: International transfer compliance (SCCs, adequacy decisions, UK IDTA) was not assessed by legal counsel. EEA/UK-based clients should seek independent advice regarding transfer mechanisms before sharing personal data.

Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data held about you
  • Correction: request that inaccurate or incomplete information be corrected
  • Deletion: request that your personal data be deleted, subject to legal retention requirements
  • Restriction: request that processing of your data be limited while a dispute is resolved
  • Objection: object to processing based on legitimate interests
  • Portability: request a machine-readable copy of data you've provided (where technically feasible)
  • Withdraw consent: where processing is based on consent, withdraw it at any time without affecting lawfulness of prior processing

All requests are handled personally. There is no automated portal — contact the email address below and the request will be addressed within 30 days.

California Residents

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

  • The right to know what personal information is collected, used, disclosed, or sold
  • The right to delete personal information (subject to exceptions)
  • The right to opt out of the sale or sharing of personal information
  • The right to non-discrimination for exercising these rights

We do not sell or share personal information with third parties for advertising or cross-context behavioral advertising purposes.

To exercise your California privacy rights, contact the email address below. Requests will be verified and responded to within 45 days.

Attorney review note: CCPA/CPRA compliance was not formally assessed. California residents with specific compliance concerns should seek independent legal advice.

Contact

For any questions about this policy, to exercise data rights, or to request deletion of your information:

natacha@natachaessim.com

Subject line: Privacy Request

All requests are reviewed personally. Response time is within 30 days for standard requests.