COMPLIANCE: ACTIVEEFF_DATE: 2026-01-01
[PROTOCOL_08: LEGAL REPOSITORY]

Privacy Policy &
Data Sovereignty Governance

We architect web platforms on absolute zero-surveillance and zero-bloat principles. Here is our legally binding declaration regarding telemetry collection, tracking immunity, client IP containment, and continuous verification under GDPR, CCPA/CPRA, and Swiss FADP.

GDPR ART. 13/14 COMPLIANTCCPA / CPRA EXEMPT FROM SALESWISS FADP ACCREDITEDSOC 2 TYPE II STACK
LIVE TELEMETRY AUDITZERO_DOM_POLLUTION
3RD-PARTY TRACKERS:0 (BLOCKED)
SESSION REPLAY:NONE INJECTED
CANVAS FINGERPRINTING:DISABLED
RETENTION AT EDGE:< 24 HOURS (EPHEMERAL)
CODE ENCRYPTION:AES-256-GCM + FIDO2
SECURITY HEALTH SCORE100 / 100 NOMINAL
// PILLARS

Core Privacy Tenets

01 // TRACKING IMMUNITY

Zero Third-Party Trackers

Our websites do not invoke Meta Pixel, TikTok Pixel, Google Ads Tag, or surveillance-based audience network scripts. Clean DOM, zero unauthorized telemetry broadcast.

DOM AUDIT: PASSED
02 // TRANSIENT EDGE

Ephemeral Processing

Serverless edge compute workers aggregate request metrics strictly in memory. IP addresses are salted and permanently scrubbed from routing logs within a strict 24-hour cycle.

RETENTION: 24H FLUSH
03 // HARDWARE ENCLAVES

Full IP & Repo Isolation

Client code repositories, architectural diagrams, and staging servers operate in siloed virtual perimeter networks protected by mutual TLS and physical hardware YubiKeys.

ISOLATION: ZERO-TRUST
04 // ZERO LOCK-IN

Absolute Portability

You maintain unencumbered ownership of design systems, telemetry schema, and assets. Upon written request, all staging artifacts are securely wiped via DoD 5220.22-M sanitization.

PORTABILITY: NATIVE JSON/GIT
ARTICLE 01 // LEGAL SCOPEREF: PARAGRAPH 14.2

01. Scope & Purpose of Data Processing

ThemeImpact (“the Agency”, “we”, “us”, or “our”) provides high-performance web engineering, design systems, and digital infrastructure advisory. This Governance Framework delineates our processing of personal data obtained via our corporate web interfaces (themeimpact.com), project estimation calculators, encrypted contact channels, and staging infrastructure.

We do not collect personal identification records indiscriminately. Processing is restricted entirely to:

  • Direct Architectural Inquiries: Processing corporate email, engineering requirements, and timeline parameters explicitly submitted by prospective enterprise partners.
  • Performance & DDoS Security: Inspecting anonymized network request packets to prevent automated abuse, Layer 7 volumetric attacks, and API injection vulnerabilities.
  • Client Contractual Execution: Maintaining cryptographically audited access logs for production deployments, CI/CD pipeline triggers, and design review boards.
ARTICLE 02 // USER INTAKEREF: DATA_CAPTURE_SCHEMA

02. Information Collected via Interactive Terminals

When interacting with our contact terminals, architectural survey boards, or performance audit calculators, the only fields stored are those deliberately transmitted by your user agent:

TELEMETRY FIELDLEGAL BASIS (GDPR)RETENTION LIFESPAN
corporate_emailArt. 6(1)(b) Contract Pre-negotiation180 Days (or immediate purge)
client_domainArt. 6(1)(f) Legitimate InterestActive Engagement Scope
budget_tech_specArt. 6(1)(b) Proposal PreparationDuration of Architectural SOW

We do not purchase enrichment databases (e.g., Clearbit, ZoomInfo, Apollo) to perform covert profile building on visitors who simply read our engineering case studies.

ARTICLE 03 // INFRASTRUCTUREREF: CLOUDFLARE_EDGE_POPS

03. Edge Infrastructure & Server Log Telemetry

ThemeImpact is served globally over a distributed serverless edge topology powered by Cloudflare Workers and enterprise edge gateways. When your browser requests resources:

> INCOMING PACKET METRICS CAPTURED AT POP:
- Anonymized Client IPv4/IPv6 (Last 16 bits truncated)
- TLS Cipher Negotiation Version (TLS 1.3 / ECH Handshake)
- HTTP Request Method, Status Code, & Microsecond Latency
- Generalized ASN Country Code (City-level coordinates discarded)

These diagnostic logs are held in memory-volatile logstreams strictly for automatic threat filtering and bot neutralization. They are purged every 24 hours and are never merged with personal identifiers.

ARTICLE 04 // STORAGE DIRECTIVEREF: ZERO_COOKIE_HEADER

04. Cookie Policy & Local Storage Usage

ZERO TRACKING COOKIE DECLARATION

We do not set non-essential cookies. You will never encounter an obstructive cookie consent banner because no cross-site surveillance cookies exist on our domains.

We employ purely essential HTML5 localStorage or sessionStorage keys strictly on your machine to save:

  • theme_state: Persisting your system preference for dark mode interfaces.
  • estimator_draft: Temporarily preserving entered project scope choices locally on your browser without cloud-side synchronization.
ARTICLE 05 // CONFIDENTIALITYREF: NDA_FORTRESS_V3

05. Client Repository & Intellectual Property Protection

For contracted enterprise partners, client source code, design libraries, and proprietary algorithmic architectures are governed by bilateral, high-enforcement Non-Disclosure Agreements (NDAs).

// AIR-GAPPED ENVIRONMENT

Staging domains run under private zero-trust access tunnels requiring WebAuthn/FIDO2 hardware security keys. Public crawler bots are hard-blocked via automated gateway resets.

// ZERO AI TRAINING LEAKAGE

Client source code, custom typography, and copywriting are explicitly forbidden from public LLM/AI training pools. All partner repositories are flagged with strict no-scraping heuristics.

ARTICLE 06 // USER SOVEREIGNTYREF: GDPR_CH_III

06. Data Subject Rights (GDPR / CCPA / CPRA)

Regardless of geographic origin, we extend GDPR-tier sovereign protections to all users globally. You maintain unambiguous command over your digital imprint:

RIGHT TO ACCESS & EXPORT

Receive an immediate, machine-readable JSON bundle containing every record, communication log, and metadata parameter associated with your contact profile.

RIGHT TO IMMEDIATE ERASURE (“FORGET”)

Issue a one-click purge order. Our systems execute a hard cryptographic erase across all warm and cold data stores within 72 business hours.

RIGHT TO RECTIFICATION

Update organizational designations, billing contacts, or deployment endpoints without administrative resistance.

NO AUTOMATED PROFILING

You are never subject to algorithmic credit evaluations, discriminatory behavioral scoring, or AI pricing models.

ARTICLE 07 // TRANSIT PROTOCOLSREF: SCHREMS_II_SAFEGUARDS

07. International Data Transfers

ThemeImpact operates globally with core engineering hubs in Hanoi, Vietnam, and regional nodes across Frankfurt, Zurich, and Singapore. Data transfers are bound by the European Commission’s Standard Contractual Clauses (SCCs) (Module 1 and Module 2) supplemented by technical controls:

  • End-to-end cryptographic transit security via TLS 1.3 with Perfect Forward Secrecy (PFS).
  • At-rest encryption governed strictly by client-retained keys (BYOK) for enterprise-tier staging instances.
  • Full certification alignment under the EU-U.S. Data Privacy Framework (DPF).
ARTICLE 08 // INFRASTRUCTURE PARTNERSREF: SUB_PROCESSOR_LIST

08. Sub-processors & Infrastructure Partners

We mandate that all third-party cloud infrastructure vendors hold verifiable SOC 2 Type II, ISO/IEC 27001, and CSA STAR security accreditations. Our contracted sub-processors are limited to:

CLOUDFLARE, INC.Global CDN, Edge Compute, WAF Security
USA / GLOBAL EDGE
AMAZON WEB SERVICES (AWS)Encrypted Cold Storage & Backup Vaults
EU (FRANKFURT)
VERCEL INC.Next.js Edge Deployment Runtime
GLOBAL EDGE
SUPABASE PTE. LTD.Isolated PostgreSQL Instances with RLS
EU (IRELAND)
DATA PROTECTION OFFICER // DIRECT APPOINTMENT

Sovereignty & Legal Terminal

For security vulnerability disclosures, statutory data subject access requests (DSAR), or bilateral NDA execution requests, engage directly with our legal and cryptographic officers.

LEGAL COUNSEL:legal@themeimpact.com
RESPONSE SLA:< 24 BUSINESS HOURS
PGP SECURITY FINGERPRINT
4A9F 88C1 B2D9 7E3D EF24 9011 C73B 229A E8F1 00C4
INSTANT DSAR TELEMETRY INTAKE

Exercise Your Sovereign Rights

Submit your verified email below to execute an immediate data inspection or initiate a full cryptographic wipe of your interactive submissions.

AUTOMATED PRIVACY DISPATCHSECURE AES-GCM STREAM