Privacy Policy
Effective Date: August 30, 2026 • Version 2.4 (Enterprise Production)
1. Data Controller & Scope
Aldra Labs Inc. (“Aldra Labs”, “we”, “us”, or “our”) provides autonomous execution infrastructure, deterministic software runtimes, and market intelligence services to enterprise organizations. This Privacy Policy governs our processing of personal data collected through our web portals, developer interfaces, and deployment architecture briefs.
For inquiries regarding data privacy or to exercise statutory rights under the General Data Protection Regulation (GDPR), UK GDPR, or California Consumer Privacy Act (CCPA), contact our Data Protection Officer at:
2. Categories of Data & Lawful Bases for Processing (GDPR Art. 6)
We process personal data only when an established lawful basis exists:
| Data Category | Purpose | GDPR Lawful Basis |
|---|---|---|
| Architecture Briefs (Company, Work Email, Cloud Topology) | Evaluating infrastructure topology, calculating SLA guarantees, provisioning sandbox enclaves. | Art. 6(1)(b) Contractual necessity / Art. 6(1)(f) Legitimate interest |
| Intelligence Newsletter Email | Delivering subscribed global technology dispatches and analysis. | Art. 6(1)(a) Explicit Consent |
| Salted Pseudonymized IP Hashes | Rate limiting, volumetric abuse prevention, terminal session isolation. Raw IP is never stored. | Art. 6(1)(f) Legitimate interest (Network Security) |
3. Data Retention & Erasure Schedule
In accordance with data minimization principles, Aldra Labs enforces automated retention policies:
- Telemetry Snapshots: Aggregated latency and throughput metrics are automatically pruned after 30 days.
- Terminal Simulator Sessions: Interactive CLI execution logs are purged after 14 days.
- Unsubscribed Newsletter Records: Fully erased from database clusters within 90 days of unsubscribe confirmation.
- SOC-2 Immutable Audit Logs: Cryptographically timestamped administrative status transitions are retained for 365 days to fulfill statutory compliance audits.
4. Data Subject Rights (GDPR & CCPA)
You possess statutory rights regarding your personal data:
Request a machine-readable export of all records associated with your work email.
Request total deletion of your deployment brief or subscriber records at any time.
Single-click unsubscription via tokenized link in every dispatch.
We never sell, broker, or monetize enterprise user data to third-party ad networks.
5. Security Controls & Encryption
All data in transit is protected using TLS 1.3 encryption with strict HSTS preloading. Data at rest is secured within isolated SQLite write-ahead-log (WAL) stores with strict file system access controls. Administrative authentication endpoints employ constant-time cryptographic comparisons (crypto.timingSafeEqual) to prevent side-channel timing attacks.