Privacy Policy
Effective Date: August 17, 2026•Last Updated: August 17, 2026
BKX Labs ("Company," "we," "our") values the privacy and security of our clients, website visitors, and users. This Privacy Policy describes how we collect, process, store, and protect your information when you visit bkxlabs.com, utilize our online compliance assessment tools, or engage us for codebase rescue and auditing services.
01. Information We Collect
1.1 Information You Provide Directly
- Contact Information: Name, business email, company name, website URL, and details provided when submitting contact forms or booking discovery sessions.
- Audit & Technical Submissions: Codebase metadata, repository URLs, architectural descriptions, and technical specifications submitted for diagnostic analysis.
- Billing Information: Invoicing details, VAT/tax IDs, and billing addresses. (Credit card and wire processing are handled by PCI-DSS compliant third-party payment processors; we do not store raw card numbers).
1.2 Information Collected via Online Tools & Assessment Suites
- Our public tools (e.g., EU AI Act Classifier, Post-Quantum CBOM Evaluator, SOC 2 Readiness Checkers) operate primarily on client-side or ephemeral, stateless server-side processing.
- Technical payloads, text inputs, or architecture metadata submitted into our free public assessment tools are evaluated in-memory and are NOT logged, stored, or indexed in persistent databases.
1.3 Automated Analytical Information
- Standard server logs: IP addresses, browser types, operating systems, referring URLs, and timestamps.
- Cookies and performance telemetry: Minimal session cookies to ensure site functionality and anonymous aggregate traffic analytics.
02. Codebase Security & Client Data Processing Principles
When performing a Forensic Diagnostic Audit or Rescue Protocol, BKX Labs adheres to strict enterprise security standards:
2.1 Codebase Ingestion & Ephemeral Storage
- Code repositories are cloned strictly into isolated, encrypted development environments accessible only by assigned senior engineering personnel.
- Multi-Factor Authentication (MFA) and least-privilege role-based access control (RBAC) are strictly enforced across all repository access points.
2.2 Production Data Zero-Retention Policy
- BKX Labs does NOT extract, export, or store live production client database records containing consumer Personally Identifiable Information (PII) or Protected Health Information (PHI).
- Clients are instructed to provide synthetic, obfuscated, or sanitized database dumps for local and staging replication.
2.3 Post-Engagement Data Purging
- Within thirty (30) days following the conclusion of the 30-Day Defect Warranty period (or upon written request), BKX Labs securely deletes all local development clones, static analysis artifact caches, and staging credential tokens, retaining only formal contractual documentation and invoices for tax compliance.
03. How We Use Your Information
We process collected information solely for:
3.1 Operational Processing Purposes
- Delivering and executing Diagnostic Audits, Technical Health Reports, and SOW deliverables.
- Communication regarding project milestones, security notices, and administrative invoicing.
- Complying with legal, tax, and regulatory obligations.
- Preventing security incidents, unauthorized access, and malicious activity on our web platforms.
3.2 Commercial Non-Monetization Pledge
- We NEVER sell, rent, monetize, or trade client information, codebase analysis findings, or business contact details to third-party data brokers or marketing networks.
04. Third-Party Service Providers & Sub-Processors
We use vetted third-party service providers to support our operations under strict confidentiality and data protection agreements:
4.1 Infrastructure and Tooling Providers
- Cloud & Infrastructure Hosting: AWS / DigitalOcean / Vercel (encrypted data storage and compute).
- Project & Repository Management: GitHub / GitLab (version control and staging CI/CD pipelines).
- Communication & Project Tracking: Sentry (error tracking), Slack, and Google Workspace (encrypted enterprise email).
- Payment Processing: Stripe / Wire Banking (PCI-compliant billing).
05. International Data Transfers & Compliance (GDPR / UK GDPR / CCPA)
For users and clients in the European Economic Area (EEA), United Kingdom, or California:
5.1 Legal Basis and Data Rights
- Legal Basis for Processing: We process data under the performance of a contract (delivering requested audits/rescues), legitimate business interests (site security and communications), or explicit consent.
- Data Subject Rights: You have the right to access, rectify, port, or request the erasure of your personal data held by BKX Labs.
- Data Processing Addendum (DPA): Enterprise clients requiring Standard Contractual Clauses (SCCs) or a tailored DPA can request execution via [email protected].
06. Security Governance
BKX Labs implements industry-standard technical and organizational security controls:
6.1 Technical Safeguards
- End-to-end encryption in transit (TLS 1.3) and at rest (AES-256).
- Mandatory hardware/authenticator MFA on all corporate infrastructure.
- Zero-trust network access policies for engineering workstations.
07. Contact Information
7.1 Legal & Security Operations Desk
For inquiries regarding these legal terms, privacy practices, or data deletion requests, contact:
- Company: BKX Labs Legal & Security Operations
- Direct Email: [email protected]
- Official Website: https://bkxlabs.com/
