Privacy Policy
Effective 2026-08-23. SPP2 Platform is a product of Desvy Protocol ("Desvy," "we," "us"). This is a general starting-point draft; it has not been reviewed by outside counsel and should be treated as provisional until it has.
1. What we collect
Account information (name, email, organization), authentication data (password hashes only -- never plaintext, PBKDF2-HMAC-SHA256 with 600,000 iterations), usage and audit logs, evidence and propositions you submit for verification, billing information (processed by our payment provider -- we do not store full card numbers), and contact-form submissions.
2. How we use it
To provide and operate the Service; to authenticate you and enforce authorization boundaries; to detect abuse and enforce rate limits; to communicate with you about your account or support requests; and to comply with legal obligations.
3. What we don't do
We do not sell your personal data. We do not use the content of your evidence/propositions to train models. Platform staff do not have standing access to your organization's confidential evidence -- access requires an explicit, reason-logged, audited break-glass procedure limited to security/audit-tier staff.
4. Data retention
Account and evidence data is retained for the retention period configured on your organization (editable in Settings), or until you delete your account. Audit logs and receipts are retained as immutable records for integrity/compliance purposes even after other data is deleted.
5. Data sharing
We share data with service providers strictly as needed to operate the Service (e.g. our payment processor for billing, our hosting infrastructure). We do not share your evidence content with any third party for their own purposes.
6. Security
Sessions are server-side and hash-only in storage. All traffic is encrypted in transit (TLS). We maintain audit logging, rate limiting, and tenant-isolation controls described in our security documentation.
7. Your rights
You may access, correct, export, or request deletion of your account data by contacting us. Organization owners can export their audit log directly from the product.
8. Governing law
This Privacy Policy and our handling of personal information are governed by the laws of the Province of Ontario and applicable federal Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are located outside Canada, your information may be transferred to and processed in Canada.
9. Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated effective date.
10. Contact
Privacy questions: admin@3enet.ca or use our contact form.