[{"data":1,"prerenderedAt":2378},["ShallowReactive",2],{"legal-privacy":3},{"id":4,"title":5,"body":6,"description":2364,"extension":2365,"meta":2366,"navigation":2373,"path":2374,"seo":2375,"stem":2376,"__hash__":2377},"content\u002Flegal\u002Fprivacy.md","CueCrux Privacy Notice",{"type":7,"value":8,"toc":2310},"minimark",[9,13,17,20,25,37,40,43,87,90,124,138,145,149,165,185,201,213,225,237,253,265,268,272,278,299,320,335,356,367,378,389,400,415,435,450,456,459,463,480,500,518,540,556,573,590,607,609,614,621,648,651,655,672,674,678,735,737,741,785,787,791,847,849,853,917,919,923,976,978,982,1040,1042,1046,1090,1092,1106,1110,1132,1147,1149,1163,1188,1202,1216,1230,1243,1260,1276,1278,1282,1292,1329,1342,1344,1351,1355,1374,1381,1383,1387,1436,1438,1442,1477,1479,1483,1540,1542,1546,1586,1588,1592,1629,1631,1635,1680,1682,1695,1699,1725,1741,1767,1782,1786,1815,1818,1820,1824,1842,1846,1884,1888,1891,1912,1923,1927,1953,1963,1965,1972,1976,1983,1986,2024,2028,2054,2058,2090,2092,2096,2111,2115,2157,2164,2166,2170,2173,2206,2210,2237,2239,2243,2255,2259,2294,2298],[10,11,5],"h1",{"id":12},"cuecrux-privacy-notice",[14,15,16],"p",{},"Last updated: 25 February 2026",[14,18,19],{},"This notice describes how CueCrux collects, processes, stores, and protects personal data. It explains how users, contributors, and organisations can exercise their rights, how data is handled within the CueCrux service, and how the underlying architecture ensures lawful, fair, and transparent processing by design.",[21,22,24],"h2",{"id":23},"_1-purpose-of-this-notice","1. Purpose of this Notice",[14,26,27,28,32,33,36],{},"CueCrux is built on the principle of ",[29,30,31],"strong",{},"verifiable knowledge",", not personal profiling.",[34,35],"br",{},"\nCueCrux exists to create trust in private knowledge operations, not to exploit user data. However, certain personal data must be processed to deliver, secure, and improve the service; for example, when you onboard, use Usage Unit-metered features, submit a support request, or manage organisational roles within CueCrux.",[14,38,39],{},"Where you purchase a subscription or other paid feature, payments are processed by Paddle (our Merchant of Record). Paddle collects and processes payment details. CueCrux receives limited transaction metadata (for example, the plan purchased, payment status, and renewal dates) to provision CueCrux access and provide customer support.",[14,41,42],{},"This Privacy Notice explains in clear terms:",[44,45,46,53,59,65],"ol",{},[47,48,49,52],"li",{},[29,50,51],{},"What personal data we collect and why",": including account details, organisational information, and operational metadata necessary for authentication, billing, and compliance.",[47,54,55,58],{},[29,56,57],{},"How we store, protect, and minimise that data",": through encryption, compartmentalisation, and strict retention schedules.",[47,60,61,64],{},[29,62,63],{},"How you can exercise your privacy rights",": such as access, correction, deletion, and objection under data protection law.",[47,66,67,70,71,74,75,78,79,82,83,86],{},[29,68,69],{},"How CueCrux enforces compliance through technology",": including the ",[29,72,73],{},"provenance ledger",", automated ",[29,76,77],{},"retention controls",", ",[29,80,81],{},"Vault-based key management",", and a ",[29,84,85],{},"privacy-by-design"," architecture verified by independent audits (WatchCrux).",[14,88,89],{},"CueCrux’s privacy framework aligns with the leading data protection and privacy laws governing our operations:",[91,92,93,102,107],"ul",{},[47,94,95,98,99],{},[29,96,97],{},"UK GDPR"," and the ",[29,100,101],{},"Data Protection Act 2018 (DPA 2018)",[47,103,104],{},[29,105,106],{},"EU General Data Protection Regulation (EU GDPR)",[47,108,109,112,113,116,117,120,121],{},[29,110,111],{},"US Federal and State privacy frameworks",", including the ",[29,114,115],{},"California Consumer Privacy Act (CCPA)"," and emerging equivalents such as the ",[29,118,119],{},"Virginia Consumer Data Protection Act (VCDPA)"," and ",[29,122,123],{},"Colorado Privacy Act (CPA)",[14,125,126,127,78,130,133,134,137],{},"We continuously monitor updates to these laws, relevant ICO, EDPB, and FTC guidance, and recognised security frameworks (such as ",[29,128,129],{},"ISO 27001",[29,131,132],{},"SOC 2",", and ",[29,135,136],{},"NIST 800-53",") to maintain compliance and best practice.",[14,139,140,141,144],{},"This document is therefore intended for ",[29,142,143],{},"users, partners, auditors, and regulators"," reviewing the CueCrux platform’s privacy, legal, and technical posture under UK, EU, and US data protection standards.",[21,146,148],{"id":147},"_2-core-principles","2. Core Principles",[14,150,151,152,78,154,157,158,161,162,164],{},"CueCrux adheres to internationally recognised privacy and data protection principles derived from the ",[29,153,97],{},[29,155,156],{},"EU GDPR",", and relevant ",[29,159,160],{},"US privacy laws"," (including CCPA, VCDPA, and CPA).",[34,163],{},"\nThese principles form the foundation for how we design, operate, and audit all CueCrux services.",[14,166,167,170,172,173,176,177,180,181,184],{},[29,168,169],{},"Lawfulness & Fairness",[34,171],{},"\nAll processing of personal data has a lawful basis typically ",[29,174,175],{},"contractual necessity"," (for account management and service delivery), ",[29,178,179],{},"legitimate interests"," (for security, analytics, and fraud prevention), or ",[29,182,183],{},"explicit consent"," (for communications or optional features). Processing is conducted transparently and proportionately, with clear user notice and the right to withdraw consent at any time.",[14,186,187,190,192,193,196,197,200],{},[29,188,189],{},"Purpose Limitation",[34,191],{},"\nData is collected and used only for the specific, legitimate purposes disclosed at the time of collection such as authentication, usage analytics, billing, or support. We ",[29,194,195],{},"never repurpose or sell"," data for advertising, profiling, or third-party marketing. Any new processing purpose triggers an internal ",[29,198,199],{},"Data Protection Impact Assessment (DPIA)"," before implementation.",[14,202,203,206,208,209,212],{},[29,204,205],{},"Data Minimisation",[34,207],{},"\nWe collect only the ",[29,210,211],{},"minimum data necessary"," to provide and secure the service. Engine responses and AI-generated content exclude personal data unless it has been deliberately included by the user. Identifiers, telemetry, and logs are pseudonymised wherever possible, and personal identifiers are hashed or redacted before storage.",[14,214,215,218,220,221,224],{},[29,216,217],{},"Accuracy & Freshness",[34,219],{},"\nUsers can update or correct their information at any time. Metadata such as timestamps, receipts, and provenance entries are ",[29,222,223],{},"versioned"," to maintain historical accuracy while supporting traceability and compliance reporting.",[14,226,227,230,232,233,236],{},[29,228,229],{},"Storage Limitation",[34,231],{},"\nRetention periods are ",[29,234,235],{},"time-boxed by data type"," for example, support tickets (18 months), logs (12 months), and backups (30-90 days). WatchCrux audits verify adherence to these schedules. When data expires, it is securely deleted or anonymised, and the deletion is logged.",[14,238,239,242,244,245,248,249,252],{},[29,240,241],{},"Integrity & Confidentiality",[34,243],{},"\nData is protected by ",[29,246,247],{},"encryption in transit and at rest"," using industry-standard protocols (TLS 1.3 and AES-256). Secrets and signing keys are stored in ",[29,250,251],{},"Vault Transit",", not on disk. Append-only ledgers ensure provenance records cannot be altered, preserving evidential integrity for audits and dispute resolution.",[14,254,255,258,260,261,264],{},[29,256,257],{},"Accountability",[34,259],{},"\nEvery data flow, system, and purpose is documented in the ",[29,262,263],{},"Register of Processing Activities (ROPA)"," maintained in OpsCrux. This enables end-to-end visibility, aligns with ICO and EDPB guidance, and ensures that data controllers, processors, and subprocessors can demonstrate compliance on demand.",[14,266,267],{},"Together, these principles ensure that CueCrux’s processing of data is lawful, transparent, and technically enforced not merely policy-based.",[21,269,271],{"id":270},"_3-data-categories-processed","3. Data Categories Processed",[14,273,274,275,277],{},"CueCrux processes a limited set of personal and operational data required to deliver its services, ensure platform security, and maintain verifiable integrity.",[34,276],{},"\nWe deliberately avoid collecting sensitive categories of personal data (e.g., health, race, religion, political opinions) unless strictly necessary for a specific contractual purpose and with explicit consent.",[14,279,280,283,285,286,288,289,78,292,133,295,298],{},[29,281,282],{},"Account Data",[34,284],{},"\nExample Fields: name, email address, hashed password (Argon2id), organisation membership, verification status",[34,287],{},"\nPurpose: Used for ",[29,290,291],{},"authentication",[29,293,294],{},"role-based access control",[29,296,297],{},"session management",". Account credentials are securely hashed and never stored in plain text. Email addresses are used solely for account recovery, notifications, or security alerts.",[14,300,301,304,306,307,309,310,78,313,133,316,319],{},[29,302,303],{},"Usage Metadata",[34,305],{},"\nExample Fields: query IDs, timestamps, mode (light \u002F verified \u002F audit), feature flags, performance logs",[34,308],{},"\nPurpose: Enables ",[29,311,312],{},"service analytics",[29,314,315],{},"reliability monitoring",[29,317,318],{},"service-level objective (SLO)"," reporting. Metadata is pseudonymised and used to improve response quality and system efficiency never for profiling or marketing.",[14,321,322,325,327,328,330,331,334],{},[29,323,324],{},"Support Data",[34,326],{},"\nExample Fields: ticket body, attachments, sender address, support channel identifiers",[34,329],{},"\nPurpose: Managed by ",[29,332,333],{},"SupportCrux"," for ticket triage and resolution. Attachments and message bodies are stored only as long as required to resolve the case, subject to the retention policy. Sensitive content is automatically redacted or flagged for limited access.",[14,336,337,340,342,343,345,346,78,349,133,352,355],{},[29,338,339],{},"Organisation Data",[34,341],{},"\nExample Fields: team name, member roles, plan tier, entitlements, usage limits",[34,344],{},"\nPurpose: Facilitates ",[29,347,348],{},"workspace management",[29,350,351],{},"billing",[29,353,354],{},"role-based permissions",". Organisation administrators can review or delete member data through their admin interface.",[14,357,358,361,363,364,366],{},[29,359,360],{},"Usage Units Data",[34,362],{},"\nExample Fields: usage unit balance, usage debits\u002Fspend events, escrow balance, reputation tier signals",[34,365],{},"\nPurpose: Used to operate usage-metered features (e.g., proofing, monitoring votes), prevent abuse, and provide account continuity. Usage Units are internal service measures with no cash value and are not stored-value products.",[14,368,369,372,374,375,377],{},[29,370,371],{},"Agent Profile & Feedback Data",[34,373],{},"\nExample Fields: display name, domain tags, profile visibility, feature request votes, survey responses",[34,376],{},"\nPurpose: Used to provide optional profile\u002Fresidency features and to collect structured product feedback (in aggregate) without impacting retrieval or evidence.",[14,379,380,383,385,386,388],{},[29,381,382],{},"Seat & Invitation Data",[34,384],{},"\nExample Fields: invited email, role, invitation status, audit timestamps",[34,387],{},"\nPurpose: Used to administer multi-seat workspaces, enforce role-based access control, and maintain an auditable record of workspace changes.",[14,390,391,394,396,397,399],{},[29,392,393],{},"Transaction and Billing Data",[34,395],{},"\nExample Fields: transaction IDs, purchase history, subscription status, invoicing details, tax\u002FVAT IDs (where applicable)",[34,398],{},"\nPurpose: Used to manage purchases, subscriptions, receipts and refunds. Payments are processed by Paddle (our Merchant of Record). CueCrux receives limited transaction metadata needed to provision and support your subscription; Paddle processes payment card details under its own privacy terms.",[14,401,402,405,407,408,410,411,414],{},[29,403,404],{},"Receipts & Provenance Data",[34,406],{},"\nExample Fields: cryptographic hashes (BLAKE3), timestamps, citation sources, verification signatures",[34,409],{},"\nPurpose: Core to CueCrux’s ",[29,412,413],{},"proof and auditability framework",". These records demonstrate that data has not been tampered with and ensure compliance with integrity and trust policies. Receipts are append-only and immutable.",[14,416,417,420,422,423,288,425,78,428,133,431,434],{},[29,418,419],{},"System Telemetry",[34,421],{},"\nExample Fields: latency, error rates, cost metrics, model token usage, queue depth",[34,424],{},[29,426,427],{},"reliability",[29,429,430],{},"budget control",[29,432,433],{},"FinOps reporting",". Contains no personal content; identifiers are anonymised at the point of collection.",[14,436,437,440,442,443,445,446,449],{},[29,438,439],{},"Cookies \u002F Session IDs",[34,441],{},"\nExample Fields: secure httpOnly refresh tokens, short-lived session identifiers",[34,444],{},"\nPurpose: Support ",[29,447,448],{},"user session continuity"," and authentication without storing personal information in browser-accessible form. No third-party or tracking cookies are used.",[14,451,452,455],{},[29,453,454],{},"CueCrux does not use personal data for marketing, advertising, profiling, or automated decision-making"," beyond essential operational functions such as rate limiting, security analysis, or fraud prevention.",[457,458],"hr",{},[21,460,462],{"id":461},"_4-lawful-basis-roles","4. Lawful Basis & Roles",[14,464,465,466,469,470,120,473,476,477,479],{},"CueCrux operates within a ",[29,467,468],{},"multi-role data governance model",", acting as both ",[29,471,472],{},"data controller",[29,474,475],{},"data processor"," depending on the context of processing.",[34,478],{},"\nThese distinctions ensure compliance with UK GDPR, EU GDPR, and major US privacy frameworks (e.g., CCPA \u002F VCDPA \u002F CPA) while maintaining transparency for enterprise customers and end users.",[14,481,482,485,487,488,491,493,494,497,499],{},[29,483,484],{},"Account Registration",[34,486],{},"\nLawful Basis: ",[29,489,490],{},"Contractual necessity",[34,492],{},"\nController \u002F Processor Role: ",[29,495,496],{},"Controller",[34,498],{},"\nExplanation: Personal data is required to create and maintain user accounts. Processing enables access, authentication, and security notifications. Without this data, the service cannot be provided.",[14,501,502,505,487,507,509,493,511,514,515,517],{},[29,503,504],{},"Purchases, payments and refunds",[34,506],{},[29,508,490],{},[34,510],{},[29,512,513],{},"Independent Controllers"," (CueCrux and Paddle)",[34,516],{},"\nExplanation: Where you purchase a subscription or paid feature, Paddle processes the transaction as Merchant of Record and CueCrux receives subscription metadata required to provision access and provide support. Paddle processes payment details under its own privacy terms.",[14,519,520,523,487,525,528,493,530,533,534,536,537,539],{},[29,521,522],{},"Query Processing",[34,524],{},[29,526,527],{},"Contract \u002F Legitimate Interest",[34,529],{},[29,531,532],{},"Processor"," (on behalf of the organisation)",[34,535],{},"\nExplanation: Queries, including artefacts and evidence sets, are processed under the organisation’s control. CueCrux acts as a ",[29,538,475],{},", handling information on their behalf in accordance with documented contracts and data processing agreements (DPAs).",[14,541,542,545,487,547,549,493,551,553,555],{},[29,543,544],{},"Support Tickets",[34,546],{},[29,548,527],{},[34,550],{},[29,552,496],{},[34,554],{},"\nExplanation: Support data (e.g., ticket content) is processed by CueCrux to diagnose and resolve issues. Limited operational analytics (e.g., resolution times, categories) may be derived without exposing message content.",[14,557,558,561,487,563,566,493,568,570,572],{},[29,559,560],{},"Telemetry & SLO Metrics",[34,562],{},[29,564,565],{},"Legitimate Interest",[34,567],{},[29,569,496],{},[34,571],{},"\nExplanation: Anonymous telemetry and performance metrics are collected to maintain service quality, detect abuse, and meet operational SLOs. No personal identifiers are retained.",[14,574,575,578,487,580,583,493,585,587,589],{},[29,576,577],{},"Usage Units Participation",[34,579],{},[29,581,582],{},"Consent \u002F Contract",[34,584],{},[29,586,496],{},[34,588],{},"\nExplanation: Data related to participation (e.g., user balance, contribution records) is processed with explicit consent and contract acceptance. These records are pseudonymous and verifiable through signed receipts, not personal financial data.",[14,591,592,595,487,597,600,493,602,604,606],{},[29,593,594],{},"Audit & Provenance Storage",[34,596],{},[29,598,599],{},"Legal Obligation \u002F Security Integrity",[34,601],{},[29,603,496],{},[34,605],{},"\nExplanation: Provenance and receipt data are required for audit and compliance with integrity laws and certification standards (e.g., SOC 2, ISO 27001). Records are immutable and retained for evidentiary purposes.",[457,608],{},[610,611,613],"h3",{"id":612},"cross-border-transfers","Cross-Border Transfers",[14,615,616,617,620],{},"Where data leaves the ",[29,618,619],{},"UK or EEA",", CueCrux ensures lawful and secure transfer using one or more of the following safeguards:",[44,622,623,632,638],{},[47,624,625,98,628,631],{},[29,626,627],{},"Standard Contractual Clauses (SCCs)",[29,629,630],{},"UK International Data Transfer Addendum"," for any transfers to non-adequate jurisdictions.",[47,633,634,637],{},[29,635,636],{},"Encryption in transit and at rest"," for all data, with keys held in UK\u002FEU regions.",[47,639,640,643,644,647],{},[29,641,642],{},"Data localisation and federated proof mechanisms"," for enterprise tenants (via ",[29,645,646],{},"Private Stack","), allowing verification without exposing personal or proprietary data beyond their jurisdiction.",[14,649,650],{},"CueCrux regularly reviews its subprocessors and publishes a transparency report detailing all data locations and legal bases for transfer.",[21,652,654],{"id":653},"_5-privacy-by-design-technical-enforcement","5. Privacy by Design & Technical Enforcement",[14,656,657,658,661,662,664,665,667,668,671],{},"CueCrux applies ",[29,659,660],{},"privacy by design and by default"," across every architectural layer of the platform.",[34,663],{},"\nEach service implements specific technical safeguards that collectively ensure lawful, secure, and transparent processing.",[34,666],{},"\nThese safeguards are auditable, measurable, and independently verified through automated checks and periodic reviews by ",[29,669,670],{},"WatchCrux",".",[457,673],{},[610,675,677],{"id":676},"webcrux-front-end-backend-for-frontend","WebCrux (Front-end & Backend-for-Frontend)",[91,679,680,686],{},[47,681,682,685],{},[29,683,684],{},"Role:"," Manages user-facing authentication, session security, and API request mediation between users and the Engine.",[47,687,688,691],{},[29,689,690],{},"Key Safeguards:",[91,692,693,704,710,720,732],{},[47,694,695,696,699,700,703],{},"Uses ",[29,697,698],{},"short-lived JWTs (RS256)"," and rotating ",[29,701,702],{},"httpOnly, Secure, SameSite=Strict"," cookies for session control.",[47,705,706,709],{},[29,707,708],{},"Engine credentials are never exposed to browsers",": all requests route through the WebCrux BFF, which signs and proxies requests on the user’s behalf.",[47,711,712,713,120,716,719],{},"Strict ",[29,714,715],{},"Cross-Origin Resource Sharing (CORS)",[29,717,718],{},"Content Security Policy (CSP)"," headers prevent unauthorised data access.",[47,721,722,723,726,727,731],{},"The ",[29,724,725],{},"JWKS endpoint"," (",[728,729,730],"code",{},"\u002F.well-known\u002Fjwks.json",") provides public key material for verification, supporting transparent validation of all access tokens.",[47,733,734],{},"All authentication events are logged, versioned, and auditable within OpsCrux under the ROPA registry.",[457,736],{},[610,738,740],{"id":739},"engine-knowledge-provenance-layer","Engine (Knowledge & Provenance Layer)",[91,742,743,748],{},[47,744,745,747],{},[29,746,684],{}," Core compute and evidence system; processes factual data, not personal data.",[47,749,750,752],{},[29,751,690],{},[91,753,754,761,764,775,782],{},[47,755,756,757,760],{},"Stores only ",[29,758,759],{},"evidence metadata",": such as URLs, canonical domains, timestamps, and content hashes (BLAKE3).",[47,762,763],{},"Excludes personal or user-generated identifiers unless explicitly submitted in a query.",[47,765,766,767,770,771,774],{},"Implements ",[29,768,769],{},"append-only provenance ledgers"," with ",[29,772,773],{},"ed25519 digital signatures",", ensuring each record’s authenticity and immutability.",[47,776,777,778,781],{},"Supports ",[29,779,780],{},"QUORUM (MiSES)"," (Quorum of Unified Observations and Referenced Underlying Material) for verifiable transparency without revealing sensitive inputs; QUORUM selects MiSES (Minimal Evidence Sets) per claim where evidence is required.",[47,783,784],{},"Retention and replay are enforced via WatchCrux audits; records are cryptographically linked and non-modifiable.",[457,786],{},[610,788,790],{"id":789},"factorycrux-ingestion-data-sourcing","FactoryCrux (Ingestion & Data Sourcing)",[91,792,793,798],{},[47,794,795,797],{},[29,796,684],{}," Policy-aware ingestion service that transforms public data into verified artefacts.",[47,799,800,802],{},[29,801,690],{},[91,803,804,814,821,827,837,844],{},[47,805,806,807,78,810,813],{},"Fully honours ",[29,808,809],{},"robots.txt",[29,811,812],{},"X-Robots-Tag",", and explicit licence headers when fetching or parsing content.",[47,815,816,817,820],{},"Offers a ",[29,818,819],{},"metadata-only mode"," for sources with uncertain or restrictive licences to avoid processing or storing personal data.",[47,822,766,823,826],{},[29,824,825],{},"anti-PII scanning"," (based on the ATAM framework) to redact or flag sensitive information automatically.",[47,828,829,830,78,833,836],{},"Retains artefacts under clear jurisdictional and licence tags (",[728,831,832],{},"license_id",[728,834,835],{},"jurisdiction",") to enforce downstream compliance.",[47,838,839,840,843],{},"Ingested data is subject to ",[29,841,842],{},"deduplication via BLAKE3 hashes",", reducing redundant or repeated storage of similar content.",[47,845,846],{},"Access to ingestion jobs and results is authenticated via WebCrux’s BFF and audited by WatchCrux.",[457,848],{},[610,850,852],{"id":851},"watchcrux-independent-audit-operator","WatchCrux (Independent Audit Operator)",[91,854,855,860],{},[47,856,857,859],{},[29,858,684],{}," Acts as an independent, read-only observer that continuously validates system health, metrics, and privacy posture.",[47,861,862,864],{},[29,863,690],{},[91,865,866,879,886,897,904],{},[47,867,868,869,78,872,133,875,878],{},"Polls ",[728,870,871],{},"\u002Fhealthz",[728,873,874],{},"\u002Freadyz",[728,876,877],{},"\u002Fmetrics"," across all services every 15 seconds; logs compliance outcomes.",[47,880,881,882,885],{},"Executes ",[29,883,884],{},"deterministic audits"," of data retention, backup success, and security configurations.",[47,887,888,889,896],{},"Maintains its own ",[29,890,891,892,895],{},"Postgres schema (",[728,893,894],{},"watchcrux",")"," for audit logs, ensuring separation of duties and evidence integrity.",[47,898,899,900,903],{},"Publishes ",[29,901,902],{},"PASS\u002FWARN\u002FFAIL"," findings to OpsCrux dashboards, enabling transparent privacy oversight.",[47,905,906,907,78,910,133,913,916],{},"Verifies ",[29,908,909],{},"Vault key rotation",[29,911,912],{},"JWKS overlap",[29,914,915],{},"data deletion completeness"," as part of each audit cycle.",[457,918],{},[610,920,922],{"id":921},"infracrux-infrastructure-security-plane","InfraCrux (Infrastructure & Security Plane)",[91,924,925,930],{},[47,926,927,929],{},[29,928,684],{}," Provides the secure, monitored foundation for all services compute, networking, and storage.",[47,931,932,934],{},[29,933,690],{},[91,935,936,946,953,959,966,969],{},[47,937,938,939,120,942,945],{},"Enforces ",[29,940,941],{},"TLS 1.3 encryption in transit",[29,943,944],{},"AES-256 encryption at rest"," across all databases and object stores.",[47,947,948,949,952],{},"Centralises secrets management through ",[29,950,951],{},"HashiCorp Vault Transit",", ensuring keys never reside on disk.",[47,954,766,955,958],{},[29,956,957],{},"Point-in-Time Recovery (PITR)"," for Postgres and nightly snapshot verification for ClickHouse.",[47,960,961,962,965],{},"Conducts ",[29,963,964],{},"monthly restore drills"," to ensure recoverability and RTO \u003C 30 minutes.",[47,967,968],{},"Maintains immutable logs and metrics through Prometheus and Grafana, forming part of WatchCrux’s validation loop.",[47,970,971,972,975],{},"Operates under strict ",[29,973,974],{},"network segmentation",", separating internal systems (Engine, DBs) from public endpoints.",[457,977],{},[610,979,981],{"id":980},"sdkcrux-developer-integration-layer","SDKCrux (Developer Integration Layer)",[91,983,984,989],{},[47,985,986,988],{},[29,987,684],{}," Provides standardised data contracts, safe type definitions, and client libraries for developers.",[47,990,991,993],{},[29,992,690],{},[91,994,995,1002,1008,1020,1027],{},[47,996,997,998,1001],{},"All SDK data transfer objects (",[29,999,1000],{},"DTOs",") exclude raw credentials or sensitive tokens.",[47,1003,938,1004,1007],{},[29,1005,1006],{},"Zod-based schema validation"," for every API payload to prevent malformed or unsafe inputs.",[47,1009,695,1010,726,1013,78,1016,1019],{},[29,1011,1012],{},"secure header injection",[728,1014,1015],{},"X-WebCrux-User",[728,1017,1018],{},"X-WebCrux-Org",") in server contexts only, preventing exposure to browsers.",[47,1021,1022,1023,1026],{},"Includes built-in ",[29,1024,1025],{},"cryptographic verification utilities"," for receipts, ensuring any consumer can verify provenance without trusting CueCrux blindly.",[47,1028,1029,1030,78,1033,1036,1037,1039],{},"Version compatibility (",[728,1031,1032],{},"sdkVersion",[728,1034,1035],{},"compat.requires",") is reported in ",[728,1038,871],{}," endpoints for transparency and auditability.",[457,1041],{},[610,1043,1045],{"id":1044},"atam-auth-trust-anti-manipulation-framework","ATAM (Auth, Trust & Anti-Manipulation Framework)",[91,1047,1048,1053],{},[47,1049,1050,1052],{},[29,1051,684],{}," Detects, mitigates, and flags bias, misinformation, or malicious manipulation attempts across ingestion and retrieval.",[47,1054,1055,1057],{},[29,1056,690],{},[91,1058,1059,1066,1073,1080,1083],{},[47,1060,1061,1062,1065],{},"Scans artefacts and retrieved data for ",[29,1063,1064],{},"personally identifiable information (PII)",", prompt-injection attempts, and other anomalies.",[47,1067,1068,1069,1072],{},"Identifies ",[29,1070,1071],{},"retracted or predatory sources",", labelling them clearly without suppressing content promoting transparency over censorship.",[47,1074,1075,1076,1079],{},"Applies ",[29,1077,1078],{},"reputation weighting and contradiction scoring"," to maintain trust without subjective moderation.",[47,1081,1082],{},"Annotates flagged content with contextual badges (e.g., “retracted source”, “weak quote”) displayed within WebCrux and OpsCrux UIs.",[47,1084,1085,1086,1089],{},"All detections are ",[29,1087,1088],{},"recorded in WatchCrux audit logs",", ensuring visibility for legal and compliance reviews.",[457,1091],{},[14,1093,1094,1095,1098,1099,1101,1102,1105],{},"By enforcing these layered controls, CueCrux ensures privacy is not just a policy but a ",[29,1096,1097],{},"built-in feature"," of its architecture.",[34,1100],{},"\nEach subsystem contributes to a holistic model of ",[29,1103,1104],{},"defensible privacy",", enabling compliance with UK, EU, and US laws while maintaining the verifiability that defines CueCrux.",[21,1107,1109],{"id":1108},"_6-data-retention-deletion","6. Data Retention & Deletion",[14,1111,1112,1113,1115,1116,78,1119,133,1122,1125,1126,1129,1130,671],{},"CueCrux maintains strict, verifiable retention policies to ensure personal and operational data are only kept for as long as necessary.",[34,1114],{},"\nEvery dataset has a ",[29,1117,1118],{},"defined retention period",[29,1120,1121],{},"documented deletion method",[29,1123,1124],{},"automated audit trail"," managed through ",[29,1127,1128],{},"OpsCrux"," and verified by ",[29,1131,670],{},[14,1133,1134,1135,1138,1139,1142,1143,1146],{},"All deletions manual or automated are ",[29,1136,1137],{},"recorded as immutable audit events"," and form part of CueCrux’s demonstrable compliance under ",[29,1140,1141],{},"UK GDPR Article 5(1)(e)"," (storage limitation) and ",[29,1144,1145],{},"DPA 2018 Schedule 1"," (security and retention).",[457,1148],{},[14,1150,1151,1154,1156,1157,1160,1162],{},[29,1152,1153],{},"User Accounts",[34,1155],{},"\nDefault Retention: Until voluntary closure or ",[29,1158,1159],{},"inactivity exceeding 24 months",[34,1161],{},"\nDeletion Method: Securely erases login credentials, session data, and organisation memberships. Keys and tokens are invalidated in Vault; related logs are anonymised. A closure confirmation and deletion receipt are issued to the account holder.",[14,1164,1165,1167,1169,1170,1173,1174,1176,1177,1180,1181,78,1184,1187],{},[29,1166,544],{},[34,1168],{},"\nDefault Retention: ",[29,1171,1172],{},"18 months"," from resolution",[34,1175],{},"\nDeletion Method: ",[29,1178,1179],{},"Cascade deletion"," across ",[728,1182,1183],{},"support_tickets",[728,1185,1186],{},"support_messages",", and attachments tables. WatchCrux verifies purge completion and flags any residual rows for follow-up.",[14,1189,1190,1193,1169,1195,1198,1199,1201],{},[29,1191,1192],{},"Workspace Invitations",[34,1194],{},[29,1196,1197],{},"90 days"," from acceptance\u002Fexpiry\u002Frevocation",[34,1200],{},"\nDeletion Method: Invitation tokens expire quickly; invitation records retained briefly for security auditing, then deleted or anonymised.",[14,1203,1204,1207,1169,1209,1212,1213,1215],{},[29,1205,1206],{},"Feedback & Survey Responses",[34,1208],{},[29,1210,1211],{},"24 months"," (or until deletion request, where applicable)",[34,1214],{},"\nDeletion Method: Stored in constrained form; older records are aggregated\u002Fanonymised for trend analysis. Individual-level responses can be deleted or de-identified where feasible.",[14,1217,1218,1221,1169,1223,1226,1227,1229],{},[29,1219,1220],{},"Receipts & Provenance Records",[34,1222],{},[29,1224,1225],{},"Permanent"," (append-only, tamper-evident)",[34,1228],{},"\nDeletion Method: Not deleted. These records form part of CueCrux’s verifiable integrity framework. They are cryptographically signed (BLAKE3 + ed25519) and stored as immutable ledger entries. Deletion would undermine legal and evidential trust obligations; instead, access is restricted where required.",[14,1231,1232,1235,1169,1237,1240,1242],{},[29,1233,1234],{},"Logs \u002F Telemetry",[34,1236],{},[29,1238,1239],{},"12 months",[34,1241],{},"\nDeletion Method: Automatically pruned from ClickHouse according to partitioned retention policies. Summarised aggregates (non-personal, statistical data) are retained for trend and performance analysis. WatchCrux validates pruning success in each audit cycle.",[14,1244,1245,1248,1169,1250,1253,1254,1256,1257,1259],{},[29,1246,1247],{},"Backups",[34,1249],{},[29,1251,1252],{},"30-90 days",", depending on dataset and region",[34,1255],{},"\nDeletion Method: Overwritten as part of ",[29,1258,957],{}," schedules. Monthly restore drills verify recoverability and ensure expired snapshots cannot be restored. Backups remain encrypted with keys rotated via Vault Transit.",[14,1261,1262,1265,1169,1267,1270,1176,1272,1275],{},[29,1263,1264],{},"PII-Flagged Artefacts",[34,1266],{},[29,1268,1269],{},"≤ 6 months",[34,1271],{},[29,1273,1274],{},"FactoryCrux"," automatically redacts, masks, or purges artefacts identified as containing personal data. Redaction logs and proof-of-purge receipts are stored for accountability. Audit confirmation is required before closure.",[457,1277],{},[610,1279,1281],{"id":1280},"deletion-requests-dsar-workflow","Deletion Requests (DSAR Workflow)",[14,1283,1284,1285,120,1288,1291],{},"CueCrux honours all ",[29,1286,1287],{},"Data Subject Access Requests (DSARs)",[29,1289,1290],{},"erasure requests"," in line with UK GDPR Articles 15-17.",[91,1293,1294,1304,1311,1318],{},[47,1295,1296,1297,671],{},"Requests can be made through the in-app privacy portal or by emailing ",[29,1298,1299],{},[1300,1301,1303],"a",{"href":1302},"mailto:privacy@cuecrux.com","privacy@cuecrux.com",[47,1305,1306,1307,1310],{},"Each request is ",[29,1308,1309],{},"triaged by OpsCrux"," and assigned a unique reference ID.",[47,1312,1313,1314,1317],{},"Where data resides in operational systems, deletion tasks are executed within ",[29,1315,1316],{},"30 calendar days"," and verified by WatchCrux.",[47,1319,1320,1321,1324,1325,1328],{},"Completed requests generate a ",[29,1322,1323],{},"deletion confirmation receipt"," and are logged in the ",[29,1326,1327],{},"OpsCrux DSAR ledger"," for compliance reporting.",[14,1330,1331,1332,1335,1336,671,1339,1341],{},"Certain datasets such as cryptographically signed receipts, provenance ledgers, and legal audit artefacts may be exempt from full deletion due to ",[29,1333,1334],{},"legal obligations"," or ",[29,1337,1338],{},"public interest archiving",[34,1340],{},"\nIn such cases, access is restricted, anonymisation is applied where feasible, and the data subject is informed of the limitation.",[457,1343],{},[14,1345,1346,1347,1350],{},"CueCrux’s data lifecycle management is ",[29,1348,1349],{},"proactive and auditable",": combining automation, encryption, and oversight to ensure that no personal data outlives its lawful purpose.",[21,1352,1354],{"id":1353},"_7-security-controls","7. Security Controls",[14,1356,1357,1358,78,1360,133,1363,1366,1367,1369,1370,1373],{},"CueCrux’s security model is engineered to meet and exceed international standards including ",[29,1359,129],{},[29,1361,1362],{},"SOC 2 Type II",[29,1364,1365],{},"UK NCSC Cyber Essentials Plus"," principles.",[34,1368],{},"\nSecurity is not treated as an afterthought or compliance checkbox, but as a ",[29,1371,1372],{},"verifiable and measurable discipline"," built into the platform’s architecture, operations, and culture.",[14,1375,1376,1377,1380],{},"Every service, from the Engine to WebCrux and InfraCrux, follows a ",[29,1378,1379],{},"defence-in-depth"," model: secrets are centrally managed, traffic is encrypted, access is tightly controlled, and all actions are logged in an immutable ledger.",[457,1382],{},[610,1384,1386],{"id":1385},"vault-transit-signing","Vault Transit Signing",[91,1388,1389,1395],{},[47,1390,1391,1394],{},[29,1392,1393],{},"Purpose:"," To ensure that cryptographic operations never expose private key material.",[47,1396,1397,1400],{},[29,1398,1399],{},"Implementation:",[91,1401,1402,1408,1419,1426,1429],{},[47,1403,1404,1405,671],{},"All signing operations (JWTs, provenance receipts, API tokens) are performed via ",[29,1406,1407],{},"HashiCorp Vault Transit Engine",[47,1409,1410,1411,1414,1415,1418],{},"JWTs use ",[29,1412,1413],{},"RSA-2048"," keys; provenance receipts use ",[29,1416,1417],{},"ed25519"," signatures.",[47,1420,1421,1422,1425],{},"Private keys ",[29,1423,1424],{},"never reside on disk",": Vault signs transactions in memory and returns the signed payload only.",[47,1427,1428],{},"Each signing event is auditable via Vault logs and WatchCrux, which verifies key rotation and signing integrity.",[47,1430,1431,1432,1435],{},"Vault keys rotate on a ",[29,1433,1434],{},"90-day cadence",", and overlapping versions are supported to prevent downtime during renewal.",[457,1437],{},[610,1439,1441],{"id":1440},"end-to-end-encryption","End-to-End Encryption",[91,1443,1444,1449],{},[47,1445,1446,1448],{},[29,1447,1393],{}," To protect data confidentiality and authenticity in transit and at rest.",[47,1450,1451,1453],{},[29,1452,1399],{},[91,1454,1455,1462,1471,1474],{},[47,1456,1457,1458,1461],{},"All communication between services is secured with ",[29,1459,1460],{},"TLS 1.3"," using strong cipher suites and perfect forward secrecy (PFS).",[47,1463,1464,1465,770,1468,671],{},"All databases (Postgres, ClickHouse, and backup archives) are ",[29,1466,1467],{},"encrypted at rest",[29,1469,1470],{},"AES-256-GCM",[47,1472,1473],{},"Certificates are managed through InfraCrux’s automated ACME or internal CA pipeline, with monitoring for expiry.",[47,1475,1476],{},"WatchCrux audits confirm the validity of TLS endpoints and encryption policies weekly.",[457,1478],{},[610,1480,1482],{"id":1481},"access-controls-privilege-management","Access Controls & Privilege Management",[91,1484,1485,1497],{},[47,1486,1487,1489,1490,120,1493,1496],{},[29,1488,1393],{}," To enforce ",[29,1491,1492],{},"least privilege",[29,1494,1495],{},"separation of duties"," across all services and personnel.",[47,1498,1499,1501],{},[29,1500,1399],{},[91,1502,1503,1520,1523,1529,1535],{},[47,1504,1505,1506,1509,1510,78,1514,133,1517,671],{},"Role-Based Access Control (",[29,1507,1508],{},"RBAC",") is applied per organisation, defining roles such as ",[1511,1512,1513],"em",{},"owner",[1511,1515,1516],{},"admin",[1511,1518,1519],{},"member",[47,1521,1522],{},"OpsCrux enforces privilege levels and logs every administrative or configuration change.",[47,1524,1525,1528],{},[29,1526,1527],{},"API keys and service accounts"," are scoped to the minimum required permissions; they cannot escalate privileges.",[47,1530,1531,1534],{},[29,1532,1533],{},"Multi-factor authentication (MFA)"," and device validation are mandatory for administrative accounts.",[47,1536,1537,1539],{},[29,1538,670],{}," monitors access patterns and alerts on anomalies, failed logins, or privilege escalations.",[457,1541],{},[610,1543,1545],{"id":1544},"backups-disaster-recovery","Backups & Disaster Recovery",[91,1547,1548,1553],{},[47,1549,1550,1552],{},[29,1551,1393],{}," To ensure business continuity and protect against data loss or corruption.",[47,1554,1555,1557],{},[29,1556,1399],{},[91,1558,1559,1568,1574,1580,1583],{},[47,1560,1561,1563,1564,1567],{},[29,1562,957],{}," is available for Postgres databases, ensuring recovery to within ",[29,1565,1566],{},"30 minutes"," of any event.",[47,1569,1570,1573],{},[29,1571,1572],{},"Nightly backup verification"," checks snapshot integrity for Postgres, ClickHouse, and Vault.",[47,1575,1576,1579],{},[29,1577,1578],{},"Monthly restore drills"," simulate full environment recovery to validate runbooks and RTO\u002FRPO compliance.",[47,1581,1582],{},"Backup data remains encrypted at rest, versioned, and geographically redundant where applicable.",[47,1584,1585],{},"Results of restore drills are published in OpsCrux and validated by WatchCrux for audit purposes.",[457,1587],{},[610,1589,1591],{"id":1590},"audit-trails-accountability","Audit Trails & Accountability",[91,1593,1594,1599],{},[47,1595,1596,1598],{},[29,1597,1393],{}," To maintain full traceability and non-repudiation of privileged or sensitive actions.",[47,1600,1601,1603],{},[29,1602,1399],{},[91,1604,1605,1612,1617,1623],{},[47,1606,1607,1608,1611],{},"Every administrative, system, or user action that affects configuration, access, or data retention generates a ",[29,1609,1610],{},"signed ledger entry"," in OpsCrux.",[47,1613,1614,1616],{},[29,1615,670],{}," independently ingests and verifies these ledger entries, ensuring audit evidence cannot be altered or deleted.",[47,1618,1619,1620,671],{},"Audit data includes ",[29,1621,1622],{},"timestamp, actor, reason, affected resource, and digital signature",[47,1624,1625,1626,1366],{},"Ledger immutability ensures compliance with ISO 27001 Annex A.12 and SOC 2’s ",[1511,1627,1628],{},"Security & Integrity",[457,1630],{},[610,1632,1634],{"id":1633},"data-integrity-provenance-assurance","Data Integrity & Provenance Assurance",[91,1636,1637,1642],{},[47,1638,1639,1641],{},[29,1640,1393],{}," To ensure that evidence and records remain verifiable, tamper-evident, and immutable throughout their lifecycle.",[47,1643,1644,1646],{},[29,1645,1399],{},[91,1647,1648,1654,1664,1667],{},[47,1649,722,1650,1653],{},[29,1651,1652],{},"Provenance Ledger"," enforces append-only semantics once written, no record can be modified or deleted.",[47,1655,1656,1657,120,1660,1663],{},"Each entry is ",[29,1658,1659],{},"hashed using BLAKE3",[29,1661,1662],{},"signed with ed25519",", producing verifiable cryptographic receipts.",[47,1665,1666],{},"Any attempted modification or rollback produces a signature mismatch, instantly flagged by WatchCrux.",[47,1668,1669,1670,78,1673,133,1676,1679],{},"OpsCrux dashboards surface integrity metrics, including ",[29,1671,1672],{},"provenance OK rate",[29,1674,1675],{},"ledger gap alerts",[29,1677,1678],{},"contradiction rate"," trends.",[457,1681],{},[14,1683,1684,1685,78,1688,133,1691,1694],{},"CueCrux’s layered security approach provides ",[29,1686,1687],{},"cryptographic assurance",[29,1689,1690],{},"operational transparency",[29,1692,1693],{},"auditable accountability"," at every stage aligning legal, technical, and ethical standards into a single unified trust framework.",[21,1696,1698],{"id":1697},"_8-cookies-tracking","8. Cookies & Tracking",[14,1700,1701,1702,1705,1706,1708,1709,1712,1713,1715,1716,78,1718,133,1721,1724],{},"CueCrux adopts a ",[29,1703,1704],{},"privacy-first cookie policy",", using only cookies essential to the operation and security of the platform.",[34,1707],{},"\nWe do ",[29,1710,1711],{},"not"," deploy advertising trackers, third-party analytics, fingerprinting tools, or behavioural profiling technologies.",[34,1714],{},"\nAll cookies are scoped to CueCrux-owned domains and comply with the ",[29,1717,97],{},[29,1719,1720],{},"EU ePrivacy Directive",[29,1722,1723],{},"US state privacy laws"," such as the CCPA.",[14,1726,1727,1732,1734,1735,1738,1740],{},[29,1728,1729],{},[728,1730,1731],{},"cc_refresh",[34,1733],{},"\nType: ",[29,1736,1737],{},"Secure, httpOnly",[34,1739],{},"\nPurpose: Maintains authenticated sessions without exposing tokens to the browser or client-side scripts. This cookie cannot be accessed via JavaScript and expires automatically after a short duration or on logout.",[14,1742,1743,1748,1734,1750,1753,1755,1756,78,1759,1762,1763,1766],{},[29,1744,1745],{},[728,1746,1747],{},"cc_mode",[34,1749],{},[29,1751,1752],{},"Preference",[34,1754],{},"\nPurpose: Stores the user’s last selected trust mode (",[728,1757,1758],{},"light",[728,1760,1761],{},"verified",", or ",[728,1764,1765],{},"audit",") to improve usability without retaining personal identifiers. The preference is local to the device and never transmitted externally.",[14,1768,1769,1774,1734,1776,1779,1781],{},[29,1770,1771],{},[728,1772,1773],{},"cc_consent",[34,1775],{},[29,1777,1778],{},"Consent",[34,1780],{},"\nPurpose: Records a user’s cookie consent choice in line with GDPR and ePrivacy regulations. It ensures that optional or non-essential cookies (if introduced in the future) are never set without prior consent.",[610,1783,1785],{"id":1784},"operational-safeguards","Operational Safeguards",[91,1787,1788,1798,1805,1812],{},[47,1789,1790,1791,120,1794,1797],{},"Cookies are set using the ",[29,1792,1793],{},"Secure",[29,1795,1796],{},"SameSite=Strict"," attributes to prevent cross-site attacks.",[47,1799,1800,1801,1804],{},"Session cookies are ",[29,1802,1803],{},"rotated periodically"," and invalidated upon logout or account inactivity.",[47,1806,1807,1808,1811],{},"All cookie policies are transparently listed in the in-app ",[29,1809,1810],{},"Privacy Settings"," page and are subject to user review at any time.",[47,1813,1814],{},"No data collected via cookies is shared with external parties or analytics providers.",[14,1816,1817],{},"CueCrux believes that functionality should never come at the expense of privacy our session design eliminates tracking dependencies while maintaining full compliance across UK, EU, and US regulatory frameworks.",[457,1819],{},[21,1821,1823],{"id":1822},"_9-user-rights","9. User Rights",[14,1825,1826,1827,1830,1831,78,1833,78,1835,1838,1839,1841],{},"CueCrux respects and enables all ",[29,1828,1829],{},"data subject rights"," defined under the ",[29,1832,97],{},[29,1834,156],{},[29,1836,1837],{},"CCPA",", and comparable privacy frameworks.",[34,1840],{},"\nWe provide users and organisational administrators with clear mechanisms to access, manage, and control their data at any time.",[610,1843,1845],{"id":1844},"your-rights","Your Rights",[91,1847,1848,1854,1860,1866,1872,1878],{},[47,1849,1850,1853],{},[29,1851,1852],{},"Access",": You can request a copy of the personal data CueCrux holds about you, including account, organisational, and support records.",[47,1855,1856,1859],{},[29,1857,1858],{},"Rectification",": You can correct inaccurate or incomplete information directly through your account settings or by contacting support.",[47,1861,1862,1865],{},[29,1863,1864],{},"Erasure (“Right to be Forgotten”)",": You may request deletion of your personal data where it is no longer required for lawful processing, subject to legal and evidentiary obligations (e.g., provenance ledgers cannot be deleted but can be restricted).",[47,1867,1868,1871],{},[29,1869,1870],{},"Restriction \u002F Objection",": You may restrict or object to specific processing activities, such as non-essential analytics or optional product updates.",[47,1873,1874,1877],{},[29,1875,1876],{},"Data Portability",": You can export your account data in a structured, machine-readable format (JSON or CSV) for transfer to another provider.",[47,1879,1880,1883],{},[29,1881,1882],{},"Withdrawal of Consent",": You can withdraw consent for optional data uses (e.g., newsletters or beta participation) at any time without affecting your access to the core service.",[610,1885,1887],{"id":1886},"how-to-exercise-your-rights","How to Exercise Your Rights",[14,1889,1890],{},"You can submit a request in one of the following ways:",[44,1892,1893,1903],{},[47,1894,1895,1898,1899],{},[29,1896,1897],{},"By email:"," ",[1300,1900,1902],{"href":1901},"mailto:support@cuecrux.com","support@cuecrux.com",[47,1904,1905,1908,1909],{},[29,1906,1907],{},"Through the in-app privacy portal:"," Accessible from ",[1511,1910,1911],{},"Settings → Privacy → Manage My Data",[14,1913,1914,1915,1918,1919,1922],{},"All requests are handled by CueCrux’s ",[29,1916,1917],{},"Data Protection Team"," and logged in the ",[29,1920,1921],{},"OpsCrux DSAR workflow",", which tracks each request from submission to resolution.",[610,1924,1926],{"id":1925},"response-times-verification","Response Times & Verification",[91,1928,1929,1939,1947],{},[47,1930,1931,1934,1935,1938],{},[29,1932,1933],{},"Acknowledgement:"," Within ",[29,1936,1937],{},"5 working days"," of receipt.",[47,1940,1941,1934,1944,1946],{},[29,1942,1943],{},"Completion:",[29,1945,1316],{},", extendable by an additional 30 days for complex cases (per Article 12(3) UK GDPR).",[47,1948,1949,1952],{},[29,1950,1951],{},"Verification:"," Identity verification is required to prevent unauthorised access to personal data.",[14,1954,1955,1956,1959,1960,1962],{},"All DSAR actions are ",[29,1957,1958],{},"audited by WatchCrux"," and preserved as immutable entries for regulatory accountability.",[34,1961],{},"\nUsers receive written confirmation when a request has been fulfilled, declined (with reason), or partially restricted under a lawful exemption.",[457,1964],{},[14,1966,1967,1968,1971],{},"CueCrux’s privacy governance ensures that every user retains ",[29,1969,1970],{},"full ownership and oversight of their data",", supported by traceable, compliant, and verifiable privacy operations across the entire platform.",[21,1973,1975],{"id":1974},"_10-independent-oversight-auditing","10. Independent Oversight & Auditing",[14,1977,1978,1979,1982],{},"CueCrux operates under a ",[29,1980,1981],{},"multi-layered governance model"," designed to provide independent, continuous, and verifiable oversight of all privacy, integrity, and compliance functions.",[610,1984,1985],{"id":851},"WatchCrux - Independent Audit Operator",[91,1987,1988,1993],{},[47,1989,1990,1992],{},[29,1991,684],{}," WatchCrux functions as an autonomous, read-only service responsible for verifying data integrity, retention adherence, and key management across all CueCrux systems.",[47,1994,1995,1998],{},[29,1996,1997],{},"Operation:",[91,1999,2000,2008,2015,2021],{},[47,2001,2002,2003,78,2005,2007],{},"Continuously polls ",[728,2004,871],{},[728,2006,877],{},", and retention endpoints for anomalies.",[47,2009,2010,2011,2014],{},"Executes automated ",[29,2012,2013],{},"PASS \u002F WARN \u002F FAIL"," audits covering deletion completeness, backup freshness, and encryption status.",[47,2016,906,2017,2020],{},[29,2018,2019],{},"Vault Transit key rotation",", ensuring all cryptographic material is current and overlapping rotations are honoured.",[47,2022,2023],{},"Produces immutable artefacts containing hash-verified audit results.",[610,2025,2027],{"id":2026},"opscrux-compliance-visibility-layer","OpsCrux - Compliance & Visibility Layer",[91,2029,2030,2051],{},[47,2031,2032,2033,2036,2037],{},"OpsCrux dashboards display key ",[29,2034,2035],{},"Privacy & Security KPIs",", including:\n",[91,2038,2039,2042,2045,2048],{},[47,2040,2041],{},"DSAR completion times and volumes.",[47,2043,2044],{},"Retention and deletion policy adherence.",[47,2046,2047],{},"Audit lag (time between scheduled and completed reviews).",[47,2049,2050],{},"Provenance integrity rate and ledger consistency checks.",[47,2052,2053],{},"Service owners receive automated alerts for out-of-policy findings, with remediation tracked in OpsCrux’s incident and change calendar modules.",[610,2055,2057],{"id":2056},"legal-security-governance","Legal & Security Governance",[91,2059,2060,2072,2083],{},[47,2061,722,2062,120,2065,2068,2069,671],{},[29,2063,2064],{},"Legal",[29,2066,2067],{},"Security"," teams jointly perform ",[29,2070,2071],{},"quarterly compliance reviews",[47,2073,2074,2075,2078,2079,2082],{},"Results are summarised in CueCrux’s ",[29,2076,2077],{},"Transparency Report",", published to the ",[728,2080,2081],{},"\u002Fdocs\u002Fpolicies\u002F"," directory and mirrored in the Transparency Portal within WebCrux.",[47,2084,2085,2086,2089],{},"Any material findings (e.g., delayed deletions, rotation gaps, DSAR non-compliance) trigger immediate alerting via OpsCrux, with ",[29,2087,2088],{},"WatchCrux verification logs"," providing independent corroboration.",[457,2091],{},[21,2093,2095],{"id":2094},"_11-international-transfers","11. International Transfers",[14,2097,2098,2099,78,2101,133,2104,2107,2108,2110],{},"CueCrux recognises its obligations under the ",[29,2100,97],{},[29,2102,2103],{},"EU GDPR Chapter V",[29,2105,2106],{},"US state transfer frameworks"," governing data movements outside their originating jurisdiction.",[34,2109],{},"\nCross-border transfers are designed to preserve both privacy and verifiability.",[610,2112,2114],{"id":2113},"key-safeguards","Key Safeguards",[44,2116,2117,2127,2133,2142,2151],{},[47,2118,2119,2122,2123,2126],{},[29,2120,2121],{},"Data Localisation by Default",": Primary hosting occurs within ",[29,2124,2125],{},"UK and EU data centres"," with redundancy in privacy-adequate regions only.",[47,2128,2129,2132],{},[29,2130,2131],{},"Standard Contractual Clauses (SCCs) & UK Addendum",": Implemented for subprocessors located outside the UK\u002FEEA, ensuring equivalent protection under international transfer rules.",[47,2134,2135,2138,2139],{},[29,2136,2137],{},"Encryption & Transport Security",": All data transferred between regions is encrypted in transit (TLS 1.3) and at rest (AES-256). ",[29,2140,2141],{},"Plaintext exports are strictly prohibited.",[47,2143,2144,2147,2148,2150],{},[29,2145,2146],{},"Federated Proof Model",": Enterprise tenants using ",[29,2149,646],{}," can verify proofs via federated hashing without exporting raw or personal data outside their jurisdiction.",[47,2152,2153,2156],{},[29,2154,2155],{},"Continuous Monitoring",": WatchCrux validates regional routing, data flow compliance, and transfer logs, ensuring adherence to contractual and regulatory controls.",[14,2158,2159,2160,2163],{},"CueCrux maintains an ",[29,2161,2162],{},"up-to-date list of subprocessors and hosting regions"," in its Transparency Page, accessible through OpsCrux and the public documentation repository.",[457,2165],{},[21,2167,2169],{"id":2168},"_12-contact-dispute-resolution","12. Contact & Dispute Resolution",[14,2171,2172],{},"CueCrux is committed to transparency, fairness, and full cooperation with regulators in all privacy matters.",[91,2174,2175,2184,2191,2197],{},[47,2176,2177,2180,2181],{},[29,2178,2179],{},"Data Controller",": ",[29,2182,2183],{},"CueCrux Limited",[47,2185,2186,2180,2189],{},[29,2187,2188],{},"Email (Data Protection Office)",[1300,2190,1303],{"href":1302},[47,2192,2193,2196],{},[29,2194,2195],{},"Address",": Registered office address available on Companies House for CueCrux Limited.",[47,2198,2199,2202,2203,2205],{},[29,2200,2201],{},"Data Protection Officer (DPO)",": For DPO enquiries, contact ",[1300,2204,1303],{"href":1302}," and we will route your request.",[610,2207,2209],{"id":2208},"how-to-raise-concerns","How to Raise Concerns",[91,2211,2212,2215,2226],{},[47,2213,2214],{},"Users may raise concerns or file complaints directly with CueCrux’s data protection contact via email or through the in-app privacy portal.",[47,2216,2217,2218,2221,2222,2225],{},"If unsatisfied with CueCrux’s response, individuals may escalate to the ",[29,2219,2220],{},"Information Commissioner’s Office (ICO, UK)"," or their ",[29,2223,2224],{},"local data protection authority"," in the EU\u002FEEA or other applicable jurisdictions.",[47,2227,2228,2229,2232,2233,2236],{},"CueCrux will ",[29,2230,2231],{},"cooperate fully with all regulatory inquiries",", provide evidence of compliance upon request, and publish anonymised summaries of investigation outcomes on its ",[29,2234,2235],{},"Transparency Page"," within WebCrux.",[457,2238],{},[21,2240,2242],{"id":2241},"_13-future-updates","13. Future Updates",[14,2244,2245,2246,78,2249,133,2252,671],{},"CueCrux’s privacy commitments evolve in step with ",[29,2247,2248],{},"legal requirements",[29,2250,2251],{},"technological developments",[29,2253,2254],{},"user expectations",[610,2256,2258],{"id":2257},"policy-versioning-notifications","Policy Versioning & Notifications",[91,2260,2261,2291],{},[47,2262,2263,2264],{},"All material changes to this Privacy Notice or related subprocessors are:\n",[91,2265,2266,2275,2281],{},[47,2267,2268,2271,2272,2274],{},[29,2269,2270],{},"Versioned"," and archived in the ",[728,2273,2081],{}," repository.",[47,2276,2277,2280],{},[29,2278,2279],{},"Changelog entries"," are automatically propagated to OpsCrux dashboards.",[47,2282,2283,2286,2287,2290],{},[29,2284,2285],{},"Users are notified"," at least ",[29,2288,2289],{},"14 days in advance"," of substantive updates (e.g., new subprocessors, new categories of data use, or jurisdictional changes).",[47,2292,2293],{},"Minor clarifications or formatting adjustments may be released without advance notice but will still appear in the policy version history.",[610,2295,2297],{"id":2296},"governance-review-cycle","Governance & Review Cycle",[91,2299,2300,2307],{},[47,2301,2302,2303,2306],{},"The Privacy Notice is reviewed at least ",[29,2304,2305],{},"annually",", or sooner following legal or architectural changes.",[47,2308,2309],{},"Legal, Security, and OpsCrux teams jointly certify each version through the governance workflow logged in WatchCrux.",{"title":2311,"searchDepth":2312,"depth":2312,"links":2313},"",2,[2314,2315,2316,2317,2321,2330,2333,2341,2344,2349,2354,2357,2360],{"id":23,"depth":2312,"text":24},{"id":147,"depth":2312,"text":148},{"id":270,"depth":2312,"text":271},{"id":461,"depth":2312,"text":462,"children":2318},[2319],{"id":612,"depth":2320,"text":613},3,{"id":653,"depth":2312,"text":654,"children":2322},[2323,2324,2325,2326,2327,2328,2329],{"id":676,"depth":2320,"text":677},{"id":739,"depth":2320,"text":740},{"id":789,"depth":2320,"text":790},{"id":851,"depth":2320,"text":852},{"id":921,"depth":2320,"text":922},{"id":980,"depth":2320,"text":981},{"id":1044,"depth":2320,"text":1045},{"id":1108,"depth":2312,"text":1109,"children":2331},[2332],{"id":1280,"depth":2320,"text":1281},{"id":1353,"depth":2312,"text":1354,"children":2334},[2335,2336,2337,2338,2339,2340],{"id":1385,"depth":2320,"text":1386},{"id":1440,"depth":2320,"text":1441},{"id":1481,"depth":2320,"text":1482},{"id":1544,"depth":2320,"text":1545},{"id":1590,"depth":2320,"text":1591},{"id":1633,"depth":2320,"text":1634},{"id":1697,"depth":2312,"text":1698,"children":2342},[2343],{"id":1784,"depth":2320,"text":1785},{"id":1822,"depth":2312,"text":1823,"children":2345},[2346,2347,2348],{"id":1844,"depth":2320,"text":1845},{"id":1886,"depth":2320,"text":1887},{"id":1925,"depth":2320,"text":1926},{"id":1974,"depth":2312,"text":1975,"children":2350},[2351,2352,2353],{"id":851,"depth":2320,"text":1985},{"id":2026,"depth":2320,"text":2027},{"id":2056,"depth":2320,"text":2057},{"id":2094,"depth":2312,"text":2095,"children":2355},[2356],{"id":2113,"depth":2320,"text":2114},{"id":2168,"depth":2312,"text":2169,"children":2358},[2359],{"id":2208,"depth":2320,"text":2209},{"id":2241,"depth":2312,"text":2242,"children":2361},[2362,2363],{"id":2257,"depth":2320,"text":2258},{"id":2296,"depth":2320,"text":2297},"How CueCrux collects, uses, and protects personal data.","md",{"version":2367,"lastUpdated":2368,"owners":2369,"source":2371,"order":2372},2026.02,"2026-02-25",[2370],"contact@cuecrux.com","cuecrux\u002Fmaster-plan",98,true,"\u002Flegal\u002Fprivacy",{"title":5,"description":2364},"legal\u002Fprivacy","BzgRXjDGJxjjV5XvYZmNyVl-EyR-GDzPHI8xNqyoEUw",1785371922000]