EBA-AI™ · Moran-Smith Royal Family Trust · Updated August 25, 2026
This policy is evidence-conservative: it describes application behavior without claiming unverified certifications, encryption specifications, provider practices, fixed retention periods, or jurisdiction-specific rights that have not been established.
This notice describes privacy practices for the EBA-AI™ application as presently configured. The Platform may process account/profile information, professional contact details, projects, deals, rights records, contracts, submissions, negotiations, revenue/participation records, documents, access requests, audit events, AI prompts/outputs, and ordinary authentication/security/usage telemetry supplied by the hosting/runtime environment. Do not enter information you are not authorized to provide.
Data may be processed to authenticate users; enforce role-based access; operate business-affairs workflows; maintain records and audit history; generate requested AI decision-support outputs; handle access/commercial inquiries; send operational communications; troubleshoot and secure the service; and satisfy authorized legal, contractual, records-governance, or compliance obligations. A technical workflow does not itself establish a legal basis, consent, or regulatory conclusion for every jurisdiction.
When an authorized user invokes an AI feature, the information included in that governed request may be transmitted to the configured model/integration provider to produce the requested output. Hosting, authentication, email, file storage, analytics/security, and other activated providers may also process information necessary to deliver their services. EBA-AI™ does not represent that a provider is connected, certified, compliant, or contractually approved unless that status is separately verified. Provider retention, training, subprocessors, regions, and security terms are governed by the applicable provider/account configuration and agreements.
The application implements role-based route and data access, service-controlled consequential workflows, evidence gates, append-only audit records, and governed AI boundaries. Transport, storage, encryption, backup, recovery, vulnerability management, penetration testing, certifications, and infrastructure controls depend on the deployed Base44/provider environment and must be verified independently before they are represented as contractual or compliance facts. No system can guarantee absolute security.
Information may be disclosed to service providers necessary to operate authorized Platform functions; professional advisers or counterparties when authorized for a business-affairs process; regulators, courts, or other recipients when legally required; or other recipients with appropriate authority. The Platform itself does not provide an advertising-data-sale workflow. This statement does not replace review of provider contracts, cookies, telemetry, or applicable privacy-law definitions.
Retention is record-specific and may depend on account status, operational need, executed agreements, authorized records policy, legal holds, disputes, audit requirements, financial obligations, and applicable law. This notice does not invent a universal 30-day, 3-year, 7-year, or other fixed retention period. Deletion or export requests may be subject to identity verification, technical capability, legal holds, and lawful retention exceptions.
Depending on applicable law and the circumstances, a person may have rights or request mechanisms involving access, correction, deletion, restriction, objection, or portability. Those rights are not identical in every jurisdiction and may have exceptions. Privacy requests should be directed to the authorized privacy contact designated by the Trust. The Platform does not promise a specific statutory response deadline through this notice.
Authentication/session technologies and provider-required browser storage may be used to operate the Platform. Additional telemetry or analytics may depend on the deployed provider configuration. This notice does not make an unverified claim that every deployment contains, or does not contain, a particular cookie or tracker.
EBA-AI™ is designed for professional business-affairs workflows. Users should not create accounts or submit records unless they have authority and satisfy applicable age/capacity requirements. If information was submitted without authority, contact the designated administrator or privacy contact for review.
This notice may be updated as the Platform, provider configuration, or governing obligations change. Where an executed agreement, data-processing agreement, privacy addendum, applicable law, or authorized Trust policy controls a subject, that controlling source prevails over a conflicting general description here. Last Updated: August 25, 2026.
© 2026 EBA-AI™ · Moran-Smith Royal Family Trust