1. Scope and roles

This notice applies to Hyfens websites, Cloud accounts, Customer Workspace, Platform Console interactions, support, and related managed services. The open-source software and a self-hosted deployment may process data under the operator’s own configuration and policies.

For direct account, website, security, and billing administration, the Hyfens operating entity identified in the approved legal record is the controller or business responsible for the relevant processing. For customer application, release, end-user, or organization data processed on the customer’s instructions, the customer may be the controller and Hyfens may act as a processor. The applicable agreement and Data Processing Addendum determine the relationship.

2. Information we process

We collect only information needed for the relevant service, security, legal, and support purpose. Depending on use, categories may include:

  • Account and contact information such as name, email address, organization membership, roles, authentication and verification state.
  • Organization and project information such as application, environment, release, patch, artifact, configuration, entitlement, and deployment metadata.
  • Runtime and delivery telemetry such as pseudonymous device or installation identifiers, platform/runtime version, patch sequence, delivery result, signature/digest references, timestamps, and trusted usage classifications.
  • Billing and commercial information such as plan, subscription, invoice, provider customer/payment references, tax or billing details supplied by the customer, promotion/redemption state, and refund-review evidence. Full card credentials are handled by the payment provider.
  • Security and operational data such as IP address, request identifiers, browser and operating-system information, logs, audit events, error and performance signals, rate-limit events, and abuse reports.
  • Support and communications such as messages, attachments, case metadata, preferences, and records of policy or service notices.

3. Sources

Information comes from you, your organization administrators, your devices and applications when they use the delivery protocol, authenticated service requests, payment and communications providers, security tools, and public or legally available sources. We do not treat a marketing claim or a customer-provided browser price as authoritative billing data.

4. Purposes and legal bases

We use information to create and secure accounts, verify identity, provide Cloud features, authorize organization actions, deliver and validate requested releases and patches, calculate and display usage, administer subscriptions, prevent fraud and abuse, investigate incidents, provide support, maintain auditability, improve reliability, comply with law, and communicate material service changes.

Depending on the context and applicable law, the basis may be performance of a contract, legitimate interests in operating and securing the service, consent where required, compliance with legal obligations, or protection of users and the service. The final legal owner must confirm the applicable jurisdiction-specific basis and notice language.

5. Customer data and end-user information

Customers decide what application and end-user data to submit. Hyfens is not intended to be a general-purpose end-user analytics or identity database. Customers must minimize personal data, provide required notices, obtain required permissions, and use the supported Cloud configuration and DPA for any personal data processed on their behalf.

Operational identifiers used to count or deduplicate delivery and installation events should be pseudonymous and limited to what is necessary for integrity, support, security, and the subscribed usage model. They are not a promise that the service collects no device information.

6. Sharing and service providers

We disclose information to service providers that host, secure, monitor, communicate, support, or process payments for Cloud, and when required by law, a valid legal process, a merger or acquisition, or to protect rights and safety. Providers receive the minimum role-appropriate information and are bound by contract or equivalent safeguards where required.

The public Subprocessors page identifies the currently approved provider categories and named providers when they are confirmed. Provider lists, processing locations, and contract status must be updated before a new provider is used for production customer data.

7. International transfers

Cloud providers or support personnel may process information in countries other than the customer’s country. The final notice and Data Processing Addendum must identify the applicable transfer mechanism, safeguards, and provider locations for each launch jurisdiction. We do not infer a legal transfer mechanism from a provider’s marketing page alone.

8. Retention, deletion, and backups

We retain information only as long as needed for the stated service, security, accounting, dispute, fraud-prevention, audit, backup, and legal purposes. The applicable retention schedule must be documented by the legal and operations owners; this notice does not invent a universal deletion period for every record type.

Account or organization deletion requests are handled through the supported account-deletion flow and may be staged when ownership, billing, security, audit, or backup retention requires it. Deletion or anonymization from active systems does not necessarily remove immutable audit evidence or time-limited backups immediately.

9. Rights and requests

Subject to applicable law and the customer’s organization role, a person may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. We may need to verify identity, coordinate with an organization controller, retain limited information, or refuse a request where law permits or requires it.

Use the supported account-deletion flow for account requests and contact support@hyfens.com for privacy questions or rights requests. The final legal record must add the responsible entity, privacy contact, response deadlines, appeal route, and regulator information required for each launch jurisdiction.

10. Security

Hyfens uses scoped authentication and authorization, tenant boundaries, protected secrets, encrypted transport where supported, signed artifact verification, rate limiting, audit records, and least-privilege operational access appropriate to the service. No internet service can guarantee absolute security, and customers remain responsible for account credentials, application code, and their own devices.

The Security page describes the product security boundary, limitations, incident communication approach, and responsible-disclosure route. We will notify affected customers of a qualifying incident as required by law and the applicable agreement.

11. Cookies and similar technologies

The current frontend uses essential technical storage and preferences such as theme selection, authentication/session state, security protections, and service operation. The Cookies Policy describes the current categories. If non-essential analytics, advertising, or similar tracking is introduced, the notice, consent controls, and provider list must be updated before it is enabled where consent is required.

12. Children and changes

Cloud is intended for organizations and professional developers, not for children to use independently. Do not submit a child’s information unless the responsible organization has the required authority and legal basis.

We may update this notice to reflect service, provider, legal, or security changes. The published version and effective date identify the notice in force. Material changes will be communicated through an appropriate service channel where required.

13. Contact and review status

For privacy questions or rights requests, contact support@hyfens.com and include enough context for us to route the request without sending passwords, access tokens, verification links, or private keys.

This page is a structured implementation draft and is not final legal advice. The operating entity, controller/processor allocation, transfer safeguards, retention schedule, provider list, jurisdictional rights, and effective version require legal and privacy-owner approval before final publication.

Back to legal and policy index