Privacy should be understandable without requiring someone to decode a legal document.
This Privacy Policy explains how Idrok Industries handles information when you visit our public website, contact us, submit an application, create or use an account, or interact with products and services operated by Idrok Industries, including Tensor OS where this policy is presented or incorporated.
Our approach is based on a simple principle: collect information for a defined purpose, limit access to it, protect it appropriately, and avoid using it in ways that people would not reasonably expect.
We do not believe privacy should be treated as a paragraph hidden at the bottom of a website. As our systems become more capable, the responsibility to define how information moves through those systems becomes more important.
This policy describes our current practices. As Idrok Industries and Tensor develop, we may publish additional product-specific notices where a more specialized explanation is appropriate.
1. Who this policy applies to
This Privacy Policy applies to information processed by Idrok Industries through:
- idrokindustries.com;
- public pages operated by Idrok Industries;
- contact and recruiting interactions;
- account registration and authentication;
- Tensor OS where this Privacy Policy is linked or incorporated;
- communications you send to us;
- product feedback and support requests;
- operational systems used to provide, protect, maintain, and improve our services.
Some Idrok Industries products, enterprise deployments, APIs, integrations, research systems, or future services may have additional privacy terms.
Where a product-specific privacy notice conflicts with this general Privacy Policy, the more specific notice will normally apply to that product.
2. Information you provide to us
The information we receive depends on how you interact with Idrok Industries.
Account information
When you create or use an account, we may receive information such as:
- your name;
- email address;
- profile image;
- account identifier;
- authentication information provided by an identity provider;
- workspace or organization membership;
- account preferences;
- settings associated with your account.
Where sign-in is provided through an external identity provider, we receive only the information made available to us through the authentication process and permitted by the relevant configuration.
We do not need or intend to receive your password for an external identity provider.
Information you provide to Tensor
When you use Tensor OS, you may provide information including:
- conversations and prompts;
- instructions given to AI employees;
- employee names, roles, descriptions, and operating instructions;
- knowledge supplied to an AI employee;
- documents or files you choose to upload;
- workflow information;
- integration configuration;
- approval decisions;
- task information;
- feedback;
- settings;
- other content intentionally submitted to the service.
The precise information processed depends on the capabilities you choose to use.
Tensor is designed around the idea that context should be available only where it is useful for the work being performed. We therefore aim to associate product information with the appropriate user, workspace, organization, employee, task, or integration rather than treating all information as one shared pool.
Integration information
If you connect Tensor to an external service, we may process information necessary to establish and operate that connection.
Depending on the integration, this may include:
- integration identifiers;
- account identifiers;
- configuration information;
- authorization information;
- access credentials or tokens;
- webhook information;
- messages or events delivered through the integration;
- records of actions performed through the integration.
We aim to separate sensitive credentials from ordinary conversational and knowledge content and to expose them only to the parts of the system that require them.
Connecting an integration does not mean that every AI employee automatically receives unrestricted access to that service. Access can depend on the configuration, permissions, product capabilities, and controls associated with the integration.
Applications and recruiting
If you apply to work with Idrok Industries, participate in a recruiting conversation, or otherwise express interest in joining us, you may provide:
- your name;
- contact information;
- education information;
- employment or project history;
- résumé or CV;
- portfolio or personal website links;
- GitHub or other professional profiles;
- answers to application questions;
- availability;
- work authorization or location information where relevant;
- other information you decide to include.
Please do not submit highly sensitive personal information that is not necessary for the application process.
We use recruiting information to evaluate applications, communicate with applicants, organize interviews, understand potential fit, and operate our recruiting process.
Submission of an application does not guarantee that we will respond, interview, or make an offer.
Communications
If you email us, report a problem, request support, provide feedback, or otherwise contact Idrok Industries, we may receive the contents of your communication together with relevant contact and account information.
3. Information generated when you use our services
Some information is generated automatically as part of operating a website or software platform.
This can include:
- IP address;
- browser type;
- operating system;
- device type;
- requested pages or endpoints;
- timestamps;
- authentication events;
- session information;
- error information;
- security events;
- API activity;
- integration events;
- feature usage;
- request metadata;
- system performance information;
- audit and activity records.
This information helps us deliver requests, investigate failures, maintain reliability, prevent abuse, protect accounts, and understand whether systems are functioning as expected.
Not every category above is necessarily collected in every interaction.
4. Public website analytics and advertising
The Idrok Industries public website is not designed around advertising surveillance.
We do not sell personal information to advertisers.
We do not operate the website for the purpose of building advertising profiles about visitors.
We do not intentionally use the public website to create third-party advertising audiences based on a visitor's activity.
The infrastructure used to deliver and protect the website may nevertheless process ordinary technical information required for web requests, security, routing, abuse prevention, and service reliability.
If we introduce analytics or other measurement systems in the future, we will review the privacy implications and update this policy where appropriate.
5. How we use information
We process information for purposes connected to operating Idrok Industries and providing our services.
These purposes may include:
Providing the service
We use information to:
- authenticate users;
- maintain accounts;
- provide workspaces;
- store user settings;
- operate Tensor;
- maintain conversations;
- create and manage AI employees;
- provide knowledge to configured employees;
- operate integrations;
- process user instructions;
- provide requested functionality;
- return responses;
- synchronize account and product state.
Operating AI functionality
Tensor may use AI models supplied by Idrok Industries or external model providers.
When an AI capability requires model inference, relevant portions of a request may be sent to the model system selected or configured for that operation.
The information sent should be limited to what is reasonably required for the requested task, but users should understand that information included in prompts, files, knowledge, conversations, tool results, or workflow context may need to be processed by an AI model in order to provide the requested functionality.
Different providers may have their own terms and privacy practices.
Where we introduce additional model choices, controls, or provider-specific configurations, we intend to explain those options in relevant product documentation.
Maintaining safety and control
We may use operational information to:
- enforce permissions;
- verify account ownership;
- maintain workspace boundaries;
- route requests to the correct organization;
- identify unauthorized access attempts;
- detect suspicious behavior;
- apply approval requirements;
- investigate misuse;
- protect credentials;
- understand execution history;
- maintain audit records;
- enforce product policies.
These controls are particularly important in Tensor because an AI employee may be capable of interacting with external systems.
Intelligence alone should not determine authority.
Tensor is being designed so that permissions, tools, organizational boundaries, approval requirements, and execution rules exist outside the model itself.
Improving reliability and product quality
We may analyze product behavior, errors, feedback, and technical performance to:
- fix defects;
- improve reliability;
- improve interfaces;
- understand failure modes;
- improve system architecture;
- evaluate safety controls;
- understand which capabilities are useful;
- develop new functionality.
When practical, we prefer operational or aggregated information that does not require unnecessary exposure of user content.
Communicating with you
We may use contact information to send:
- account-related communications;
- security notices;
- service information;
- responses to support requests;
- recruiting communications;
- important product updates;
- information you specifically requested.
Legal and security purposes
We may process information when reasonably necessary to:
- comply with applicable law;
- respond to lawful legal process;
- protect users;
- protect Idrok Industries;
- investigate fraud or abuse;
- enforce agreements;
- establish, exercise, or defend legal claims;
- respond to security incidents.
6. AI models and your information
Tensor is an operating system for AI employees. AI processing is therefore a core part of certain Tensor workflows.
An important distinction is that the AI model is not intended to be the authority layer of Tensor.
A model may reason about a task, generate content, suggest an action, or request the use of a tool. Whether it is permitted to perform an action should be determined by controls outside the model, including the user's configuration, workspace boundaries, permissions, policies, and approval requirements.
Depending on the configuration of Tensor, information necessary to complete a request may be processed by third-party model providers.
We aim to avoid sending unrelated account data or credentials to models merely because a model is participating in a workflow.
Credentials and other sensitive integration secrets should be handled separately from ordinary prompt context wherever the architecture allows it.
Users should still avoid entering information into an AI workflow unless they are comfortable having that information processed as necessary to complete the requested task.
7. AI training
We believe users should be able to distinguish between information being processed to provide a service and information being used to train future models.
Idrok Industries does not intend to silently turn private customer workspaces, confidential business information, or private user conversations into a general-purpose training dataset.
If we introduce a program that uses customer content for model training beyond what is necessary to provide the requested service, we intend to provide appropriate disclosure and controls before that use occurs.
This statement does not prevent us from using feedback, evaluations, de-identified information, security data, or operational information where appropriate to improve our systems.
External model providers may operate under their own data-use policies depending on the service and agreement through which they are accessed.
8. How we share information
We do not sell personal information.
We may share information in limited circumstances necessary to operate Idrok Industries.
Service providers
We may use infrastructure, hosting, authentication, database, communications, AI, security, storage, monitoring, and other technology providers.
Those providers may process information to perform services for us.
We aim to provide each service only with the information reasonably necessary for its role.
AI providers
Where an external AI model is used to perform a Tensor request, relevant request information may be processed by that provider.
The information shared depends on the selected model, task, integration, and requested capability.
Connected services
When you instruct Tensor to interact with an external service, information may be transmitted to or received from that service as necessary to perform the requested operation.
The external service's own privacy practices apply to its processing.
Organization administrators
Where Tensor supports shared workspaces or organizations, authorized organization administrators may be able to access information associated with that organization according to the product's permissions and functionality.
Legal and safety requirements
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with law or legal process;
- investigate fraud or abuse;
- protect against security threats;
- protect the rights or safety of users, Idrok Industries, or others;
- enforce applicable agreements.
Business changes
If Idrok Industries is involved in a financing, reorganization, merger, acquisition, asset transfer, or similar corporate transaction, information may be reviewed or transferred as part of that process subject to appropriate confidentiality and legal requirements.
9. Data separation inside Tensor
Tensor is designed around organizational and user boundaries.
A core architectural objective is that one user's or organization's information should not simply become available to another because both use the same underlying platform.
Depending on the product capability, data may be associated with:
- a specific account;
- a personal workspace;
- an organization;
- an AI employee;
- a conversation;
- a knowledge source;
- a task;
- an integration;
- an approval;
- an execution event.
These boundaries help reduce accidental information mixing and give the system a clearer understanding of which context belongs to which operation.
No software system should be described as impossible to compromise, and this Privacy Policy does not make such a claim.
Our security approach is described in greater detail on the Idrok Industries Security page.
10. Credentials and sensitive integration information
Connected services may require sensitive information such as API credentials, access tokens, bot tokens, or secrets.
We treat this category differently from ordinary product content.
Our design objective is to:
- restrict access to credentials;
- avoid exposing credentials unnecessarily to users, models, logs, or interfaces;
- keep secrets separate from ordinary knowledge content;
- use credentials only for the integration or function for which they were provided;
- remove or invalidate stored access when an integration is disconnected where technically applicable.
Users remain responsible for granting appropriate permissions to connected services and for revoking credentials if they believe those credentials have been compromised.
11. Human approvals and activity records
Certain Tensor actions may be configured to require human approval.
Information related to approvals can include:
- the proposed action;
- the requesting AI employee;
- relevant context;
- the approving user;
- the decision;
- timestamps;
- execution status.
Tensor may also maintain activity or audit information so that users can understand important actions performed within their workspace.
These records support accountability, debugging, security investigation, and product operation.
They should not be understood as a guarantee that every possible internal operation will always be recorded.
12. Data retention
We do not believe information should be retained forever merely because storage is inexpensive.
Different categories of information may need different retention periods.
We may retain information for as long as reasonably necessary to:
- provide an active account or service;
- maintain requested product state;
- preserve required operational records;
- secure the platform;
- investigate abuse;
- resolve disputes;
- comply with legal obligations;
- maintain necessary backups;
- support legitimate business operations.
When information is no longer reasonably needed, we may delete, aggregate, or de-identify it.
Deletion from active systems may not instantly remove every copy from temporary caches, system backups, security records, or disaster-recovery systems. Those copies may remain for a limited period until they are overwritten or expire according to the relevant system.
Recruiting information may be retained for the duration of the hiring process and for a reasonable period afterward where necessary for recruiting administration, legal compliance, or future opportunities where appropriate.
13. Account deletion and information requests
Where supported, users may be able to delete information directly through product controls.
You may also contact us to request information about personal data you have provided to Idrok Industries.
Depending on applicable law and the nature of the request, you may have rights to request:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection to certain processing;
- withdrawal of consent where processing relies on consent.
These rights vary by jurisdiction and are not absolute.
We may need to verify your identity before processing a request.
We may retain information where required by law, necessary for security, necessary to prevent fraud or abuse, or otherwise permitted under applicable law.
Privacy-related requests may be sent to:
As Idrok Industries develops, we may establish a dedicated privacy channel and update this page accordingly.
14. International processing
Idrok Industries, our infrastructure providers, AI providers, and other service providers may operate in different countries.
As a result, information may be processed or stored outside the country in which you are located.
Different countries may have different privacy and data-protection laws.
Where required, we will take steps appropriate to the relevant service and legal requirements governing international processing.
15. Security
We use technical and organizational measures intended to protect information against unauthorized access, loss, alteration, misuse, or disclosure.
Security is an ongoing engineering process rather than a permanent state.
Our approach includes principles such as:
- account authentication;
- workspace and organization boundaries;
- authorization checks;
- scoped permissions;
- controlled integration access;
- protection of sensitive credentials;
- human approval mechanisms;
- activity visibility;
- auditability;
- defensive system design.
No internet service can guarantee absolute security.
Users should also protect their accounts, connected systems, credentials, and devices.
More information is available on our Security & Trust page.
16. Children and younger users
Idrok Industries products are primarily designed for professional, technical, organizational, and business use.
We do not intentionally design our services for the purpose of collecting personal information from young children.
Where local law requires parental or guardian authorization for a person to use a service or enter into an agreement, that authorization must be obtained.
If we learn that information has been collected in circumstances that require removal under applicable law, we will take appropriate steps.
17. Third-party websites and services
Idrok Industries may link to external websites or allow users to connect external services.
We do not control the privacy practices of independent third parties.
A link from Idrok Industries does not mean that the external service operates under this Privacy Policy.
You should review the terms and privacy practices of external services before providing them with information or connecting them to Tensor.
18. Changes to this policy
Our products will evolve.
Our privacy documentation should evolve with them.
When we make material changes to this Privacy Policy, we will update this page and revise the "Last updated" date.
Where a change materially affects active users and additional notice is appropriate, we may provide notice through the product, account communications, or another reasonable channel.
We do not want this policy to describe an imaginary future system. It should remain an accurate explanation of how Idrok Industries actually operates.
19. Contact
Questions about this Privacy Policy, personal information, or privacy practices can be sent to:
Idrok Industries https://idrokindustries.com
Privacy is part of system design. As intelligence becomes more capable, keeping data ownership, access, authority, and purpose understandable becomes more important—not less.
