Legal
Privacy Policy
Plain-English summary: Enclawed LLC does not process your personal data within our own systems. The product is a self-deployable software framework; the runtime never sends data to us. We collect the absolute minimum information needed to do business with you, and we do not retain any personally identifying data anywhere for any reason other than what the law requires or what is strictly necessary to fulfill the contract we have with you. The moment a contractual or legal obligation no longer requires us to hold a particular record, that record is deleted or anonymised. We do not sell, rent, or share data with third parties for marketing. No cookies, no third-party analytics, no machine-learning training on your data.
1. Who we are, what we do, what we do NOT do
Enclawed LLC (“Enclawed”, “we”, “us”) is a California limited liability company. We sell enclawed-enclaved subscriptions — the closed-source production build of the framework — under individually negotiated business agreements, as described in our Terms of Service. The companion enclawed-oss open-source code is MIT-licensed, free, and unsupported (no sale, no support, only the security-disclosure inbox).
Enclawed LLC does not process personal data of your end-users. The framework runs entirely on your infrastructure. Your customers’ data, your application logs, your audit trail, and your accreditor journal all stay on your systems. We have no telemetry endpoint, no analytics back-channel, no “phone-home” from the runtime. If our software ever touches your customers’ data, it does so on a machine you control, and that processing is yours, not ours.
Enclawed retains no personally identifying data of any kind beyond what either (a) the law positively requires us to retain (for example: invoices and supporting transaction records for the period required by US Internal Revenue Code § 6001 and California Revenue and Taxation Code § 19133, or by analogous tax authorities in your jurisdiction), or (b) is strictly necessary to fulfill the contractual obligations we have with you under our Terms of Service or signed order form for as long as that obligation remains live. Once neither rationale applies, the record is deleted or irreversibly anonymised on the next periodic data-retention review. We do not retain personal data “just in case”, for future marketing, for product analytics, or for any speculative purpose.
The narrow set of personal data Enclawed LLC does see is limited to what you choose to share with us directly: the email you send to a sales / support / security address, the contact details you put in an order form or Master Services Agreement, or what our Merchant of Record (Paddle) hands us as part of a paid subscription receipt.
Privacy questions: privacy@enclawed.com.
2. What we actually receive
The personal data Enclawed LLC actually receives, limited to direct interactions with us:
- Email correspondence. If you write to a sales, support, billing, security, legal, or privacy address, we receive your email address, any other contact details you choose to include, and the content of the message. Hosted with our email provider; not used for marketing.
- Subscription billing receipts from our Merchant of Record. All paid
enclawed-enclavedsubscriptions are sold under an individually negotiated order form or MSA and billed through Paddle.com Market Limited (“Paddle”), our Merchant of Record. Paddle is the controller of your payment data and the seller of record for tax purposes; we receive only a billing receipt containing your name, email address, billing country, the subscription you contracted for, the transaction amount, and any taxes Paddle collected. We do not see your full card number, your bank details, or any payment-processor account password. Paddle’s own privacy policy at paddle.com/legal/privacy governs the data Paddle collects from you when you are invoiced. The free MIT-licensedenclawed-osscode is not sold and generates no billing data. - Order-form / MSA details. When you sign an order form or Master Services Agreement, we collect the contact details, billing address, and authorised-signatory information stated in that agreement. Payment for those contracts flows through Paddle on the schedule the agreement sets.
- Support-ticket contents (paid subscribers only). If you submit a support ticket, anything you include in it (configurations, logs, code snippets, deployment details) is processed for the purpose of providing the support and held only for as long as the ticket-handling provider retains it. Where Vendor-Delivered Support requires Enclawed personnel to access your data on your systems, your responsibility under section 7.5 of the Terms of Service is to provide the paperwork (BAA, DPA, NDA, SCC) that prevents the engagement from breaking your own certification.
- Server logs at our static-site host. The host serving enclawed.com records standard web-server logs (IP address, user agent, request URL, timestamp). Those logs live with the host, not on Enclawed’s own systems. Retention is ninety (90) days or as the host’s policy dictates, whichever is shorter.
We do not collect: cookies for tracking, third-party analytics fingerprints, behavioural-advertising identifiers, biometric data, or sensitive categories of personal data (race, religion, health, sexual orientation, political opinion, trade-union membership, genetic data) unless you voluntarily include such data in a support ticket or contract document.
3. How we use what we receive
The narrow set of personal data Enclawed receives is used to:
- Respond to your email, support ticket, or vulnerability disclosure;
- Provide and bill the Subscription you have purchased (our payment processor handles the payment-card processing; we handle the contract);
- Send transactional emails (subscription confirmations, security advisories to active subscribers, renewal reminders, billing notices);
- Comply with legal obligations (tax, accounting, court orders, valid law-enforcement requests);
- Investigate suspected fraud, abuse, or violations of our Terms of Service.
We do not use any personal data for advertising, profiling, automated decision-making with legal effect, or training of machine-learning models.
4. Legal basis (GDPR / UK GDPR readers)
To the extent Enclawed processes any personal data of readers in the European Economic Area, United Kingdom, or Switzerland (limited to the categories enumerated in section 2), the legal bases are:
- Contract performance (Article 6(1)(b) GDPR): to provide the Subscription you have purchased.
- Legitimate interests (Article 6(1)(f) GDPR): to respond to inbound email, secure our systems, prevent abuse, and pursue legal claims.
- Legal obligation (Article 6(1)(c) GDPR): to comply with tax, accounting, and other regulatory requirements.
- Consent (Article 6(1)(a) GDPR): where we ask for it explicitly — for example, by your acceptance of the Terms of Service when you sign your order form or MSA, which records your agreement to the cancellation and refund terms in section 4 of the Terms.
enclawed-enclavedsubscriptions are business-to-business and sold only under a signed agreement; should any signatory nonetheless qualify as a Consumer under Directive 2011/83/EU or an equivalent statute, their mandatory consumer-protection rights are honoured by default per the Refund Policy.
For data subjects whose personal data is processed by Enclawed’s customers using our framework, the customer is the controller and Enclawed is not a processor — we never receive that data and do not process it.
5. Who we share it with
We share personal data only with the following categories of recipient, and only to the extent necessary:
- Merchant of Record. All paid subscriptions across every tier are processed by Paddle.com Market Limited, our Merchant of Record. Paddle is the controller for the payment data it collects from you and the seller of record for tax purposes; its own privacy policy at paddle.com/legal/privacy governs that data.
- Banking and accounting. Funds settled to Enclawed LLC by Paddle land in our business bank account; our accountants and tax advisors process the resulting invoices and financial records under standard professional confidentiality.
- Legal counsel. When necessary to investigate a legal matter or respond to a claim, we may share data with our legal counsel under attorney-client privilege.
- Government and law enforcement. Where required by a valid subpoena, court order, or other legal process binding on us.
- Successors. If Enclawed LLC is acquired or merges with another entity, personal data may transfer to the successor under terms consistent with this Privacy Policy.
We do not: sell personal data; rent personal data; share personal data with marketing networks, data brokers, or advertising platforms; use third-party tracking pixels.
6. International transfers
Enclawed LLC is based in California, United States. Personal data collected from Customers outside the United States is transferred to and processed in the United States. For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Addendum. A copy of the relevant SCCs is available on request to privacy@enclawed.com.
7. Data retention — minimum necessary, no longer
We retain personal data strictly for the shorter of (a) the period legally required, or (b) the period necessary to fulfill the live contractual obligation. The defaults below give the maximum each category will be retained; in practice records are purged on the first review cycle after the rationale lapses.
- Subscription billing records: retained for the period required by US Internal Revenue Code § 6001 (currently four years from the date of the return or the date the tax was paid, whichever is later, US Treas. Reg. § 31.6001-1(e)(2)) and California Revenue and Taxation Code § 19133, then deleted. For Customers in jurisdictions with longer mandatory retention (for example, Germany’s ten-year record-keeping under HGB § 257), the local requirement governs.
- Support tickets: retained only while the Subscription is active plus ninety (90) days after closure to allow follow-up; after that, the ticket is deleted or, where useful for product improvement, irreversibly anonymised by stripping all identifiers.
- Server logs: retained for ninety (90) days as required for security and abuse-prevention purposes, then deleted by the host.
- Contact-form / cold-inbound emails: retained while the conversation is live plus one (1) year of inactivity, then deleted unless a Subscription contract has been formed.
- Vulnerability disclosures: the technical content is retained indefinitely for security-research continuity; the reporter’s contact details are stripped on request once the disclosure is complete and the credit (if requested) has been published.
We do not retain personal data “just in case,” for future marketing, for product analytics, or for any purpose beyond the two rationales in section 1 (legal requirement; contractual necessity). Where retention is required only by law, we hold the absolute minimum subset of records the law requires, not the broader business context.
8. Your rights
Depending on your jurisdiction, you may have some or all of the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure (“right to be forgotten”): request deletion, subject to our legal retention obligations.
- Restriction: request that we limit processing under certain circumstances.
- Portability: receive your data in a structured, commonly-used format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent.
- Complaint: lodge a complaint with your local data-protection authority (in the EU/EEA), the Information Commissioner’s Office (UK), or the appropriate state Attorney General (US).
California Consumer Privacy Act (CCPA / CPRA) rights. California residents have the rights to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under CCPA / CPRA. To exercise any other right, email privacy@enclawed.com.
To exercise any of the above rights, email privacy@enclawed.com with a clear description of the request. We will respond within thirty (30) days, or such shorter period as the law requires.
9. Cookies and tracking
This website does not set cookies on your browser and does not use third-party analytics or tracking pixels. The only third-party content loaded on this site is Google Fonts (for typography), which is requested without setting cookies. No personalised advertising or behavioural tracking takes place.
10. Children
The Subscription services are intended for business use by individuals aged eighteen (18) or older. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@enclawed.com and we will delete it.
11. Security
We protect personal data with administrative, technical, and physical safeguards proportionate to the sensitivity of the data and the size of our operation. This includes: encrypted transit (HTTPS); least-privilege access to support tickets; no sharing of customer data outside the parties named in section 5; periodic security review of our own infrastructure. No system is perfectly secure; if you believe your data has been compromised, contact security@enclawed.com immediately.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be announced at enclawed.com/privacy.html at least thirty (30) days before they take effect. Where we have your email on file, we will notify you of material changes by email.
13. Contact
Enclawed LLC
A California limited liability company
Privacy: privacy@enclawed.com
Legal: legal@enclawed.com
Security: security@enclawed.com