Global Privacy Policy
Active Regional Privacy Notice: United States (CCPA / CPRA & US Federal Trade Commission (FTC) Guidelines)
We process personal telemetry and diagnostic intake strictly in compliance with CCPA / CPRA & US Federal Trade Commission (FTC) Guidelines. Clank Dynamics operates on a strict zero-data-broker policy: we never sell, license, monetize, or share your proprietary code, emails, or personal information with advertisers.
Zero-Broker Policy
We never sell, rent, or trade founder emails, company details, or project codebases to third-party brokers.
Encrypted Ingestion
All diagnostic telemetry and repos are protected with AES-256 encryption at rest and TLS 1.3 in transit.
Right to Erasure
Full compliance with GDPR Art. 17 & CCPA deletion requests. Submit an erasure request with a single email.
1. Scope & International Compliance
This Global Privacy Policy outlines how CLANK DYNAMICS SERVICES (“Clank Dynamics”, “we”, “us”, or “our”) collects, protects, utilizes, and discloses personal information obtained through our website (clankdynamics.com), diagnostic triage funnels (/schedule), and custom engineering projects.
This policy is structured to adhere simultaneously to statutory international data protection frameworks, including the European Union GDPR (Regulation EU 2016/679), the UK GDPR & Data Protection Act 2018, the California Consumer Privacy Act (CCPA/CPRA), the Nigeria Data Protection Act (NDPA 2023), and Canada's PIPEDA.
2. Categories of Information We Collect
A. Pre-Flight Diagnostic Telemetry (Voluntarily Provided)
Collected during the diagnostic interview at /schedule:
- Contact Identity: Full name, work email address, company or project name.
- Technical Environment: Target tech stack, prototyping platform (Cursor, Bolt, Lovable, v0), team size.
- Triage Telemetry: Primary technical blocker (database recursion, store rejection, build hanging), urgency level, GitHub repository link, and diagnostic error logs.
B. Edge Network & Telemetry Data (Automatically Collected)
Collected via Cloudflare Edge to optimize performance and prevent malicious DDoS traffic:
- Country of origin (derived from IP via Cloudflare
cf-ipcountry) for currency and legal adaptation. - Browser type, operating system user agent, and request timestamps.
- Essential session cookies (
NEXT_CURRENCY,NEXT_JURISDICTION) storing user preferences.
C. Commercial Billing & Payment Data
All payment transactions are processed through PCI-DSS Level 1 compliant gateways (Paystack Inc.). Clank Dynamics never stores, views, or has access to full credit card numbers, CVVs, or bank account PINs. We receive only a confirmation transaction reference and settlement verification.
3. How We Use Collected Data
- Pre-Call Diagnostic Briefing: To analyze your repository, reproduce reported errors, and ensure senior engineers arrive at discovery calls with actionable solutions.
- Live Calendar Sync: To schedule discovery calls on Cal.com and deliver Google Meet calendar invites to your email address.
- Service Delivery: To execute contracted engineering milestones, security audits, and code signing pipelines.
- Security & Fraud Prevention: To detect malicious bots, unauthorized penetration attempts, and safeguard infrastructure.
4. Sub-Processor Registry
Clank Dynamics partners strictly with enterprise-grade cloud service providers bound by Data Processing Addenda (DPAs) and Standard Contractual Clauses (SCCs):
| Partner Entity | Role & Function | Data Center Location | Compliance Standard |
|---|---|---|---|
| Cloudflare, Inc. | Edge CDN, DDoS Defense, DNS & Geolocation | Global Anycast Network | SOC 2 Type II, ISO 27001 |
| Supabase, Inc. | Encrypted PostgreSQL Database for Pre-Flight Intake (discovery_leads) | AWS US / EU (Encrypted at rest) | SOC 2 Type II, HIPAA, GDPR |
| Paystack Payments Ltd | Payment Processing & Milestone Invoicing | West Africa & Global Secure Rails | PCI-DSS Level 1, NDPA, ISO 27001 |
| Cal.com, Inc. | Consultation Scheduling & Video Routing | US / EU Tier-4 Cloud | SOC 2, GDPR Compliant |
5. Regional Statutory Privacy Rights
5.1 European Union (GDPR) & United Kingdom (UK GDPR)
Under Articles 15–22 of the GDPR and the UK Data Protection Act 2018, individuals in the EEA and UK possess the following statutory rights:
- Right of Access (Art. 15): Request a complete copy of personal records held by Clank Dynamics.
- Right to Erasure / “Be Forgotten” (Art. 17): Request the immediate deletion of your pre-flight lead records and diagnostic notes from our database.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete contact information.
- Right to Data Portability (Art. 20): Receive your technical diagnostic dossier in a structured JSON format.
5.2 California & US Residents (CCPA / CPRA)
Under the California Consumer Privacy Act and California Privacy Rights Act:
- Do Not Sell or Share My Personal Information: We do not sell personal data for monetary or other valuable consideration.
- Right to Know & Delete: Request disclosure of categories of personal information collected and request deletion without discrimination.
5.3 Nigerian Residents (NDPA 2023)
In accordance with the Nigeria Data Protection Act 2023, data subjects possess the right to object to data processing, request erasure of un-contracted pre-flight telemetry, and file complaints with the Nigeria Data Protection Commission (NDPC).
5.4 Canadian Residents (PIPEDA & CASL)
Canadian individuals have the right to access and challenge the accuracy of personal information held by Clank Dynamics. In compliance with CASL, commercial electronic messages are sent only with express consent.
6. Retention Schedule & Data Erasure
- Pre-Flight Inbound Leads: Retained for twelve (12) months in
public.discovery_leadsfor project tracking and diagnostic history, after which un-converted records are purged. - Client Repositories & Analysis Environments: Staging clones and audit logs created during an active sprint are permanently shredded within fourteen (14) business days of final project sign-off.
- Tax & Financial Invoicing: Kept for seven (7) years to satisfy statutory tax compliance requirements (FIRS, IRS, HMRC).
7. How to Submit an Erasure or Privacy Request
To exercise your Right to Erasure (“Be Forgotten”), request a copy of your diagnostic data, or submit an inquiry to our Data Protection Team:
Recipient: Data Protection Officer / Legal Operations
Entity: CLANK DYNAMICS SERVICES
Email: contact@clankdynamics.com
Subject Format: “Privacy Request: [Your Company / Reference Code]”
Response SLA: All statutory data requests are acknowledged and fulfilled within 30 days without charge.