1. Sovereign Data Doctrine
INNOSPHIRE operates under the strict doctrine of Absolute Brand Confidentiality. As an autonomous creative intelligence partner handling sensitive enterprise marketing strategies and pre-launch campaigns, we treat all client data as protected trade secrets.
2. Zero AI Training Covenant
Under no circumstances does INNOSPHIRE permit:
- Client brand imagery, product photographs, 3D models, or creative briefs to be incorporated into training sets for public models (e.g. OpenAI, Midjourney, Stability AI);
- Customer contact lists, campaign conversion rates, or lead dossiers to be sold, monetized, or cross-referenced across third-party ad networks;
- Storage of unmasked corporate client intelligence in public vector indices.
3. Brand Asset Sandboxing & Security
During active Creative Sprints ($1,499) and Campaign Blitzes ($3,499), client materials are uploaded to encrypted, access-restricted project sandboxes. Neural rendering pipelines (gmax-video, gmax-image) process source imagery in transient GPU memory buffers that automatically wipe temporary frames upon completion of export rendering.
4. Data We Collect & Legitimate Purpose
We process only information required for agency operations and delivery:
- Brand Briefing & Intake: Company name, brand URL, target audience demographics, campaign brief, and authorized contact email.
- Creative Deliverables: Rendered video files, audio tracks, and campaign dossiers stored temporarily for client download.
- Infrastructure Telemetry: Minimal server logs (IP address, user agent, timestamp) retained for 14 days solely for network security and DDoS mitigation.
5. Payment Processing & Financial Security
All creative retainer fees are processed through Stripe, Inc., utilizing PCI-DSS Level 1 certified infrastructure. INNOSPHIRE does not capture, process, or store credit card numbers, CVVs, or sensitive payment credentials on its servers.
6. European GDPR & Swiss nFADP Rights
Clients and European data subjects possess complete rights under Regulation (EU) 2016/679:
- Right to Access: Obtain a complete copy of all stored briefs and project metadata;
- Right to Rectification: Update campaign contacts or brand credentials;
- Right to Erasure ("Right to be Forgotten"): Demand instantaneous wiping of all source assets and brand dossiers upon project wrap-up;
- Right to Data Portability: Receive campaign analytics and master renders in universal open formats.
7. Retention & Secure Asset Purge
Raw client input files are automatically purged 30 calendar days following client sign-off on final deliverables, unless an extended enterprise asset escrow retainer is explicitly contracted. Invoices and statutory accounting records are retained in encrypted cold vaults for mandatory legal periods (5-7 years).
8. Data Protection Officer & Privacy Desk
To execute an asset purge, request a compliance audit, or sign a bilateral enterprise NDA: