Privacy • Minimal data footprint

Privacy Policy

Debsync Trust Portal is designed for a minimal data footprint. We store CRM-level information only (email/name/company/role, deal status) and audit-lite events (authentication, status changes, downloads). Upload is OFF — we do not accept or store client obligation/ledger datasets.

Data we collect
  • • Account & user info: email, name, company, role (CRM-level).
  • • Deal status for access gating (e.g., status ≥ PACK_GRANTED).
  • • Audit-lite events: auth events, status updates, downloads (timestamped).
  • • Limited technical metadata: IP and user-agent (for security/audit).
Data we do NOT collect (hard boundary)
  • • No client obligation/ledger datasets.
  • • No file uploads and no “paste your ledger” flows.
  • • No payment card data in the portal (if payments are used, they are handled by a payment provider).
Purpose & retention
  • • Purpose: enable licensing workflow access and maintain access transparency.
  • • Retention: minimal; audit-lite events kept as needed for operational traceability.
  • • Access control: magic link authentication; status-based gating for downloads.
Note: this page is a placeholder. Final privacy language should be reviewed by legal counsel before production launch.
Contact
Questions about privacy: info@debsync.com