PRIVACY & DATA ETHICS
Humanity AI’d is built on deep respect for individual privacy — not as a compliance checkbox, but as a core operating principle. The power of AI must be exercised within clear ethical and legal boundaries, and this statement explains how we uphold that in practice.
Our role: processor, not owner
We act solely as a service provider to the authorized government agencies we serve — never as the owner or controller of the data we work with. Every dataset our technology interfaces with, including identity records, photographs, and biometric references, is sourced, owned, and governed by the authorized agency of the country in which we operate. We provide the intelligence layer on top of data that already lawfully exists within that agency’s systems; we do not introduce new data, and we do not become a party with independent rights to use, sell, or repurpose it.
What we do and do not do with data
We do not retain, export, or replicate citizen data within our own infrastructure beyond what is strictly necessary to perform the processing the agency has instructed. Where data is processed transiently — for example, in memory during an inference or matching operation — it is not persisted beyond that processing session, and any outputs (matches, scores, flags, or other derived results) remain solely within the customer’s environment and control. We do not build independent profiles or databases from the data we touch, and we do not use it to train models for other customers or purposes.
Biometric and identity data
We recognize that biometric data and identity records carry heightened sensitivity under most legal frameworks. Where our systems interface with this category of data, we apply additional safeguards: encryption in transit, strict access controls limited to what is necessary for the engagement, and processing that stays within the agency’s own environment wherever technically possible.
Jurisdiction and compliance
Privacy is not a one-size-fits-all standard applied uniformly across markets. We recognize the distinct legal frameworks, sovereignty, and data governance regulations of each country we operate in, and each engagement is structured to comply with the laws and policies of that specific jurisdiction — independently and with full accountability to the agency and to local law.
Security practices
We maintain technical and organizational safeguards appropriate to the sensitivity of the data our systems interact with, including encrypted data transmission, restricted access, and processing architectures designed to minimize data exposure outside the customer’s own systems.
In short
The data belongs to our customer. We bring the intelligence. What we never bring is the data itself.
Questions
For questions about this statement or our data practices, contact us at privacy@humanityaid.ai.
