PROTOCOL: DATA_SAFETY // CLEARANCE: PUBLIC

    Data Safety

    Privacy and protection are architecture decisions, not afterthoughts. Here is how we handle your data at every stage.

    ENCRYPTIONCONSENTDELETIONRESIDENCYCOMPLIANCE

    TRANSPARENCY

    You see what we collect and why.

    Every data point collected is documented, purpose-tagged, and visible in your organization dashboard. No hidden telemetry or silent trackers.

    MINIMIZATION

    Collect only what is necessary.

    We follow data minimization by design. Fields are scoped to functional necessity with automatic expiry on ephemeral signals.

    ENCRYPTION

    AES-256 at rest, TLS 1.3 in transit.

    All stored data is encrypted with AES-256-GCM. All network communication uses TLS 1.3 with certificate pinning on critical endpoints.

    DELETION RIGHTS

    Full erasure on request.

    Data subject deletion requests are processed within 72 hours. Cascading deletion ensures no orphaned records across related tables.

    CONSENT MANAGEMENT

    Purpose-bound consent controls.

    Granular consent categories map to specific processing purposes. Consent state is versioned and auditable for regulatory reporting.

    JURISDICTION CONTROL

    Data stays where you choose.

    Select your data residency region at onboarding. Cross-border transfers only occur with explicit configuration and SCCs in place.

    Data Lifecycle

    Collection
    Consent Check
    Processing
    Retention
    Deletion

    Compliance Frameworks

    GDPRCCPALGPDPDPASOC 2 controls alignedISO 27001 practices aligned

    For a full copy of our data processing agreement or to submit a data subject request, contact our privacy team.

    CONTACT PRIVACY TEAM