LEGAL & DATA GOVERNANCE

PRIVACY POLICY

COMPREHENSIVE GLOBAL DATA PROTECTION & PRIVACY CHARTER • LAST REVISED: AUGUST 2026

1. INTRODUCTION & SCOPE OF POLICY

Code Minerals ("we," "our," "us," or the "Agency") operates as a premier full-stack software development agency, SaaS engineering studio, AI integration partner, and digital design firm accessible via https://www.codeminerals.com and its affiliated APIs, client portals, and communications channels. This Privacy Policy governs the collection, processing, storage, disclosure, and protection of personal data and business technical data obtained from visitors, prospective clients, active software clients, and platform users ("User," "you," or "your"). By interacting with our website, submitting project intake forms, executing Statements of Work (SOWs), or utilizing our digital infrastructure, you consent to the data practices described herein.

2. CATEGORIES OF INFORMATION WE COLLECT

We collect information across three distinct categories to evaluate project requirements, deliver custom software applications, and maintain technical infrastructure: A. Voluntarily Provided Personal & Commercial Data: • Contact Identifiers: Full name, professional title, corporate email address, business telephone number, and physical office location. • Inquiry & Project Briefs: Business model documentation, feature requirements, budget allocations, technical specifications, and uploaded assets. • Financial & Billing Data: Invoicing addresses, tax identification numbers, and transactional logs processed via secure third-party payment gateways (we do not store raw credit card numbers). B. Automated Technical & Telemetry Data: • System Logs: IP addresses, browser engine types, operating system versions, referral URLs, time zone configurations, and language preferences. • Interaction Metrics: Clickstream pathways, time spent per service module, viewport dimensions, and interface interaction telemetry. C. Client Technical Assets & Credential Vaulting: • During active software engineering engagements, clients may provide access keys, repository credentials, cloud deployment tokens (AWS/Vercel/Docker), and API secrets. All such credentials are stored in zero-trust encrypted secret vaults and used exclusively for authorized project scope execution.

3. LEGAL BASES FOR DATA PROCESSING (GDPR & CCPA COMPLIANCE)

Under applicable global data protection frameworks—including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and international privacy statutes—Code Minerals processes personal data under the following lawful bases: • Performance of a Contract: Processing necessary to execute project intake agreements, deliver custom web/mobile software, fulfill Statements of Work, and provide technical support. • Legitimate Business Interests: Processing necessary for vulnerability monitoring, preventing unauthorized access, improving software performance, conducting business analytics, and defending against fraud. • Legal Obligations: Retention of financial ledgers, tax compliance records, and response to valid law enforcement subpoenas or court orders. • Explicit Consent: Where you have granted explicit consent for direct technical newsletters or optional marketing communications, which may be revoked at any time.

4. PURPOSE & UTILIZATION OF COLLECTED DATA

Collected information is utilized strictly for professional software engineering and corporate business operations: 1. Project Architecture & Proposal Generation: Evaluating technical feasibility, estimating sprint timelines, and modeling custom software proposals. 2. End-to-End Service Delivery: Building, testing, and deploying Next.js web applications, SaaS multi-tenant platforms, custom AI/LLM pipelines, and native mobile apps. 3. System Diagnostics & Security Auditing: Monitoring server stability, detecting DDoS attacks, patching vulnerability vectors, and maintaining sub-second application responsiveness. 4. Client Account Management: Issuing milestone invoices, delivering progress reports, facilitating code repository transfers, and providing SLA support.

5. COOKIES, ANALYTICS & TRACKING MECHANISMS

Code Minerals utilizes minimal, privacy-first session cookies and local storage tokens to enhance platform usability: • Essential Cookies: Necessary for security authentication, CSRF token validation, and administrative session management. • Performance & Telemetry Cookies: Anonymous analytics to monitor server request loads, static page hydration speeds, and navigation paths. • Opt-Out Control: You can modify your browser settings to reject non-essential cookies. However, disabling essential cookies may impact functional client portal authentication.

6. THIRD-PARTY DISCLOSURE & SERVICE PROCESSORS

Code Minerals DOES NOT sell, lease, trade, or rent personal data, project briefs, or proprietary client source code to third-party advertisers or data brokers under any circumstances. We disclose necessary data strictly to vetted sub-processors essential for service operations: • Cloud Infrastructure Providers: Amazon Web Services (AWS), Vercel Inc., Cloudflare, and MongoDB Atlas (encrypted database clusters). • Communication Infrastructure: Transactional email gateways (Nodemailer / SendGrid) for inquiry confirmation. • Legal & Regulatory Mandates: When required by law, legal process, or court order to protect intellectual property, prevent imminent fraud, or defend legal claims.

7. DATA RETENTION & PURGING SCHEDULES

We retain personal and project data only for as long as required to fulfill the purposes for which it was collected: • Prospective Client Briefs: Retained for up to 24 months from inquiry submission, after which non-converting briefs are automatically archived or purged. • Active Project & Financial Records: Retained for 7 years post-contract completion to satisfy statutory tax, accounting, and audit mandates. • Client Access Credentials & API Secrets: Immediately revoked and purged from secure vaults within 30 business days following formal project sign-off and code handover, unless an ongoing maintenance retainer is active.

8. CROSS-BORDER DATA TRANSFERS & INTERNATIONAL SAFEGUARDS

Code Minerals operates globally. Personal data and project technical assets may be processed on servers located outside your jurisdiction. When data transfers occur across international borders, we enforce strict protection standards: • End-to-End Encryption: TLS 1.3 encryption for data in transit and AES-256 encryption for data at rest. • Standard Contractual Clauses (SCCs): Incorporation of EU-approved Standard Contractual Clauses for transfers outside the European Economic Area (EEA).

9. YOUR PRIVACY RIGHTS (GDPR / CCPA RIGHTS)

Depending on your regional jurisdiction, you possess specific statutory privacy rights: • Right of Access: Request a copy of all personal data held by Code Minerals concerning you. • Right to Rectification: Request correction of inaccurate or incomplete personal records. • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where legal retention obligations no longer apply. • Right to Data Portability: Request transfer of your personal data in a structured, machine-readable JSON format. • Right to Object & Restrict Processing: Object to data processing based on legitimate interests or revoke marketing consent. To exercise any of these rights, submit a written request to hello@codeminerals.com. We respond to all verified privacy requests within 30 business calendar days.

10. SECURITY INFRASTRUCTURE & DISASTER RECOVERY

Code Minerals enforces enterprise-grade physical, technical, and managerial security controls: • Encryption Standards: All sensitive database fields, API credentials, and client uploads are encrypted using military-grade AES-256 algorithms. • Access Control & Isolation: Strict Role-Based Access Control (RBAC) and mandatory Multi-Factor Authentication (MFA) across all administrative tools. • Incident Response: In the event of a confirmed data security breach affecting your records, Code Minerals will notify affected parties and supervisory regulatory bodies within 72 hours of verification.

11. PROTECTION OF MINORS

Code Minerals provides enterprise B2B software engineering services and does not knowingly solicit or collect personal information from individuals under the age of 18. If we learn that we have inadvertently collected data from a minor without verified parental consent, we will take immediate steps to delete such data from our records.

12. POLICY AMENDMENTS & CONTACT OFFICERS

Code Minerals reserves the right to amend or update this Privacy Policy periodically to reflect technological advancements, legal revisions, or organizational shifts. Amendments become effective immediately upon posting to this URL. For privacy enquiries, statutory rights requests, or data protection questions: • Data Privacy Desk: Code Minerals • Direct Email: hello@codeminerals.com • Official Domain: https://www.codeminerals.com