These Sensitive Data Terms define the strict contractual limitations, prohibitions, and unique regulatory boundaries governing the processing of highly classified, specialized, or high-liability data categories within the relyd infrastructure network. These terms supplement the General Terms of Sale and apply to all customer database deployments.
1. Classification of Restricted and Prohibited Data Types
The standard multi-tenant, cloud-hosted infrastructure nodes provided by relyd are engineered, calibrated, and optimized for corporate ERP execution, supply chain management, operational telemetry, and conventional transactional business workflows. Except where explicitly authorized in writing via a bespoke, single-tenant Enterprise Addendum executed by our operations team, the Customer is strictly prohibited from storing, hosting, or processing the following data classes within the platform:
1.1 Protected Health and Medical Information: Data falling under specialized medical privacy frameworks, including patient records, clinical diagnostic logs, healthcare insurance parameters, or any information governed by international medical data retention laws.
1.2 Biometric and Genetic Identifiers: Raw biometric telemetry intended for unique automated human identification, including fingerprint data, facial recognition vectors, retina scans, or genetic sequencing profiles.
1.3 High-Risk National Identification Assets: Plain-text, unencrypted files or data fields containing highly restricted national identifiers, including social security numbers, tax identification keys, passports, or national identity cards, unless handled inside specialized, isolated file containers.
1.4 Special Categories of Personal Data: Data detailing a human subject’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union memberships, or data concerning an individual’s sex life or sexual orientation.
2. Payment Card Industry (PCI-DSS) Operational Boundaries
2.1 Tokenization Mandate: While the relyd platform enforces Grade A TLS/HTTPS encryption and advanced PBKDF2+SHA512 credential salting, standard database instances are not certified for the raw storage of unmasked credit card Primary Account Numbers (PAN), CVV/CVC codes, or magnetic stripe metadata.
2.2 Gateway Integration: All financial collection processes, checkout forms, and payment processing configurations executed within the Customer's database must utilize compliant, tokenized, external third-party API gateway architectures (such as Stripe, Adyen, or PayPal). Under no circumstances shall raw cardholder data be written directly into standard transactional database tables.
3. Allocation of Liability and Indemnification
Should the Customer breach the conditions set forth in Section 1 and Section 2 of these terms by uploading or processing unauthorized sensitive data profiles without a dedicated Single-Tenant Isolated Enterprise Environment, the following structural legal mechanisms shall apply immediately:
3.1 Sole Financial Responsibility: The Customer assumes absolute, exclusive legal and financial liability for any regulatory non-compliance fines, statutory breach penalties, data protection litigation costs, or forensic auditing expenses originating from the unauthorized data presence.
3.2 Complete Corporate Indemnification: The Customer shall fully indemnify, defend, and hold entirely harmless relyd, its executive board, and its underlying tier-one infrastructure sub-providers against any third-party claims, administrative actions, or regulatory investigations resulting from the breach.
3.3 Disapplication of the Liability Ceiling: The fifty percent (50%) aggregate liability cap defined in the Terms of Sale or Master Subscription Agreement shall be rendered completely inapplicable to any claims, damages, or breaches arising out of or related to the Customer's explicit violation of these Sensitive Data Terms. The Customer's financial liability to the Provider in such an event shall be completely uncapped.