By ordering the services of the application framework, which is owned and operated globally by the provider designated within the Master Subscription Agreement (hereinafter referred to as the “Provider”), the customer (“Customer”) unconditionally accepts the following Privacy Policy alongside the comprehensive, interconnected compliance matrix. In all other respects, the Terms of Sale, Terms of Service, Master Subscription Agreement (MSA), and the Data Processing Agreement (DPA) shall apply, whereby specific provisions in the present Privacy Policy shall govern the collection of platform telemetry, and the Data Processing Agreement (DPA) shall take absolute precedence regarding the processing of third-party personal data within hosted client databases.
The Provider reserves the right to change these privacy terms at any time. The amended policy shall come into force immediately upon publication. The Provider will make all necessary efforts to send the amended Privacy Policy to the Customer by e-mail or to draw the Customer's attention to the changes within the website control panel.
1. Categories of Information We Process
The vast majority of data within our ecosystem is directly provisioned by our users during account initialization or platform interaction. We categorize this data into the following distinct technical modules:
1.1 Account & Corporate Contact Data: When registering an account to download, evaluate, or subscribe to the relyd Framework, you voluntarily supply primary business identifiers. This typically includes your full name, corporate entity name, professional email address, telephone number, billing/physical delivery address, business sector, and encrypted access credentials.
1.2 Infrastructure & Browser Telemetry: When visiting our websites or accessing our online services, our nodes passively log operational metadata transmitted by your browser for statistical, security, and contractual tracking. This includes your Internet Protocol (IP) address, localized timestamp parameters, specific resources accessed, browser agent versions, hardware platforms, and the referring URL. Your browser may also store session-specific tokens via cookies to maintain secure authentication states.
1.3 Professional Application Data: When applying for a career position with the Provider, we collect primary contact profiles, curriculum vitae, and reference documentation. To mitigate structural application fraud within highly sensitive infrastructure engineering roles, we reserve the right to verify government identification or passport metrics strictly within legal boundaries.
1.4 Production Database Content (Client Assets): When deploying a client instance on the relyd Cloud Platform, any business information or personal data uploaded, integrated, or generated within your databases remains your sovereign property. This encompasses employee registries, customer matrices, messages, and custom workflows. As defined in our Data Processing Agreement (DPA), we act strictly as the Data Processor regarding these assets, and you retain absolute ownership and operational control.
1.5 Payment Card Security Stand: relyd does not capture, store, or parse raw credit card primary account numbers (PAN) or verification codes. All billing cycles rely entirely on trusted, Tier-1 PCI-DSS-compliant external payment processors for secure recurring transaction management.
2. Purpose and Operational Utilization of Data
We process personal information strictly to deliver a resilient, high-performance computing environment and to fulfill our contractual commitments:
2.1 Provision of Services: Account and contact profiles are utilized to manage subscriptions, execute accurate billing cycles, address helpdesk technical inquiries, and ensure seamless delivery of the relyd dashboard interface.
2.2 Platform Security & Countermeasures: Technical telemetry and server log diagnostics are anonymously analyzed to maintain infrastructure integrity, mitigate malicious intrusion attempts, prevent service abuse, and enforce our Acceptable Use Policy (AUP).
2.3 Corporate Marketing Communication: Contact profiles may be utilized to deliver platform updates, structural announcements, or professional marketing materials. Users maintain a permanent, absolute right to opt out of promotional communications at any time via an explicit "unsubscribe" mechanism.
2.4 Strategic Partner Engagement: If you express explicit interest in localized integration or deployment assistance, your primary corporate contact metrics may be routed to a certified relyd implementation partner within your respective geographic region to facilitate professional local services.
3. Data Retention Framework
To eliminate database bloat and strictly satisfy data minimization principles, information is retained only for the duration required to fulfill its operational or statutory purpose:
3.1 Active Subscription Telemetry: Structural account records and environment configurations remain active throughout the duration of your contractual relationship with the Provider.
3.2 Deactivated Client Environments: Upon formal cancellation or expiration of a cloud instance, the associated database layer is immediately deactivated and held in a secure state for a three-week (21-day) operational grace period. Upon the expiry of this window, the production database is permanently purged from our active systems.
3.3 Immutable Safety Backups: To protect infrastructure against catastrophic hardware degradation or malicious deletion events, data assets are mirrored onto secure, encrypted backup systems. Data within these immutable backups may persist for up to twelve (12) months until it is automatically overwritten via sequential retention loops.
3.4 Server & Security Logs: Standard network access logs and security incident telemetry are kept for a maximum duration of twelve (12) months, unless ongoing legal discovery or fraud investigations necessitate an extended preservation period.
3.5 Recruitment Portfolios: If an applicant is not selected, their profile may be retained for up to three (3) years to map against future personnel requirements, unless immediate erasure is requested.
4. Global Subprocessors & Structural Data Location
relyd relies on an elite network of audited, highly certified external infrastructure sub-providers to maintain our robust platform backbone.
4.1 Infrastructure Sovereignty: Customer databases are hosted within the specific geographic region selected by the client during account configuration (Americas, Europe, Asia & Pacific, Middle East, or Oceania).
4.2 Redundant Architecture: In addition to production nodes, the Provider maintains redundant backup copies distributed across independent, physically separated data centres to guarantee geographical resilience.
4.3 Subprocessor Standards: All engaged infrastructure subprocessors hold premier international data security credentials, including but not limited to ISO 27001, SOC 2 Type II, and PCI-DSS. A comprehensive directory of active infrastructure providers (such as OVHcloud, Microsoft Corporation and Google Cloud) is governed by individual Data Processing Agreements ensuring total compliance with data protection laws.
4.4 Centralized Global Infrastructure and Cross-Border Transfers: The Provider coordinates its global operations, platform telemetry analysis, and billing cycles through its centralized corporate framework in Switzerland. For localized technical support, regional infrastructure maintenance, and business operations, data may be accessed by or transferred to the Provider’s international affiliate operations:
a. relyd Inc., 28-07 Jackson Ave, New York, NY 11101, USA. (United States Affiliate)
b. relyd Limited, 3 Ballsbridge Park, Dublin, D04 C7H2, Ireland. (European Economic Area Affiliate)
Where personal data is transferred from Switzerland or the European Economic Area (EEA) to jurisdictions without an adequacy decision (such as the United States), the Provider enforces strict systemic safeguards, including the execution of standard contractual clauses (SCCs) approved by the competent supervisory authorities.
5. Rights of the Data Subject
In complete alignment with modern global privacy Frameworks - including the Swiss FADP, the European GDPR, the UK GDPR, and applicable United States federal and state privacy laws - you retain comprehensive statutory control over your personal data and information. Subject to applicable legal limitations, you have the right to:
5.1 Access and Portability: Request a transparent summary of the personal data we hold regarding your profile or download an automated, structured backup of your entire production database via your platform control panel.
5.2 Rectification: Update, modify, or correct your administrative billing information and user metrics directly within your account configuration portal.
5.3 Erasure ("Right to be Forgotten"): Request the permanent deletion of your account profiles, candidate records, or hosted databases, subject to legitimate statutory retentions required for corporate taxation, administration, and legal defense.
5.4 Restriction of Processing: Mandate the freezing or temporary suspension of your data processing operations during active legal disputes regarding data accuracy or processing legitimacy. To exercise any of these fundamental privacy rights, please submit a formal request to our dedicated data security team via electronic mail at: privacy@relyd.co.
6. Cookie & Localized Session Framework
relyd utilizes structural cookies and localized browser session tokens to deliver a smooth, frictionless authentication experience. These are categorized as follows:
Category of Cookie Purpose Active Tokens Session & Security Authenticates users, protects corporate user data, and ensures stable administrative file uploads. Disabling these cookies will break portal functionality. relyd_session_id, pulse_token Preferences Retains operational interface metrics such as your preferred language, deployment region, and active timezone. Your experience may be degraded if discarded, but the site will function. frontend_lang, relyd_tzAnalytics & Interaction Aggregates anonymous website audience traffic and path utilization via Google Analytics to optimize platform speed and interface layout. _ga, _gid
7. Corporate Governance, Representatives & Contact Protocols
The Provider reserves the right to update this Privacy Policy systematically to mirror infrastructure alterations, platform upgrades, or shifting statutory requirements. The "Last Updated" timestamp at the apex of this document indicates the effective date of all such modifications.
Pursuant to Article 27 of the European GDPR and the UK GDPR, the Provider has designated its regional infrastructure hub to act as its legal representative within the European Union for data protection inquiries:
EEA Data Protection Representative: relyd Limited, Attn: Data Privacy Desk, 3 Ballsbridge Park, Dublin, D04 C7H2, Ireland.
For comprehensive technical inquiries, data rights execution, or security mapping notifications, please contact our centralized data security desk directly at: privacy@relyd.co.