Data Governance & Compliance

Privacy Policy

Effective Date: August 30, 2026 • Version 2.4 (Enterprise Production)

1. Data Controller & Scope

Aldra Labs Inc. (“Aldra Labs”, “we”, “us”, or “our”) provides autonomous execution infrastructure, deterministic software runtimes, and market intelligence services to enterprise organizations. This Privacy Policy governs our processing of personal data collected through our web portals, developer interfaces, and deployment architecture briefs.

For inquiries regarding data privacy or to exercise statutory rights under the General Data Protection Regulation (GDPR), UK GDPR, or California Consumer Privacy Act (CCPA), contact our Data Protection Officer at:

Aldra Labs Data Governance Office
Security & Attestation: security@aldralabs.com

2. Categories of Data & Lawful Bases for Processing (GDPR Art. 6)

We process personal data only when an established lawful basis exists:

Data CategoryPurposeGDPR Lawful Basis
Architecture Briefs (Company, Work Email, Cloud Topology)Evaluating infrastructure topology, calculating SLA guarantees, provisioning sandbox enclaves.Art. 6(1)(b) Contractual necessity / Art. 6(1)(f) Legitimate interest
Intelligence Newsletter EmailDelivering subscribed global technology dispatches and analysis.Art. 6(1)(a) Explicit Consent
Salted Pseudonymized IP HashesRate limiting, volumetric abuse prevention, terminal session isolation. Raw IP is never stored.Art. 6(1)(f) Legitimate interest (Network Security)

3. Data Retention & Erasure Schedule

In accordance with data minimization principles, Aldra Labs enforces automated retention policies:

  • Telemetry Snapshots: Aggregated latency and throughput metrics are automatically pruned after 30 days.
  • Terminal Simulator Sessions: Interactive CLI execution logs are purged after 14 days.
  • Unsubscribed Newsletter Records: Fully erased from database clusters within 90 days of unsubscribe confirmation.
  • SOC-2 Immutable Audit Logs: Cryptographically timestamped administrative status transitions are retained for 365 days to fulfill statutory compliance audits.

4. Data Subject Rights (GDPR & CCPA)

You possess statutory rights regarding your personal data:

Right to Access (Art. 15)

Request a machine-readable export of all records associated with your work email.

Right to Erasure (Art. 17)

Request total deletion of your deployment brief or subscriber records at any time.

Right to Opt-Out

Single-click unsubscription via tokenized link in every dispatch.

Right to Non-Discrimination

We never sell, broker, or monetize enterprise user data to third-party ad networks.

5. Security Controls & Encryption

All data in transit is protected using TLS 1.3 encryption with strict HSTS preloading. Data at rest is secured within isolated SQLite write-ahead-log (WAL) stores with strict file system access controls. Administrative authentication endpoints employ constant-time cryptographic comparisons (crypto.timingSafeEqual) to prevent side-channel timing attacks.