Legal & Compliance

Privacy Policy

Last Updated: July 28, 2026 | Version 2.4

1. Overview & Data Controller Identification

This Privacy Policy ("Policy") sets forth the explicit protocols, data collection mechanics, storage infrastructure, and user rights governed by GLAD Studio ("Company", "We", "Us", or "Our") in connection with your access to and use of gladstudio.net (the "Site"), our product engineering services, proprietary client portals, API endpoints, and associated digital products (collectively, the "Services").

GLAD Studio operates as both a Data Controller and Data Processor under applicable global data protection legislation, including but not limited to the General Data Protection Regulation (EU 2016/679) ("GDPR"), the California Consumer Privacy Act ("CCPA/CPRA"), the UK Data Protection Act 2018, and the Digital Personal Data Protection Act ("DPDP").

2. Categories of Information Collected

We collect information through direct submission, automated system telemetry, and integrated third-party analytical pipelines. The specific categories of data processed include:

  • Identity & Contact Telemetry: Full names, business email addresses, telephone numbers, organizational affiliations, job titles, and preferred communication channels provided via discovery forms, scheduling calendars, or inquiry interfaces.
  • Project & Technical Artifacts: Product specifications, architecture blueprints, database schemas, repository keys, API credentials, wireframes, brand assets, and proprietary code bases shared during client engagements.
  • Artificial Intelligence & Model Interaction Logs: Prompts, contextual embeddings, model evaluation logs, and structured inputs submitted to AI workflow features integrated into our platform or client custom solutions.
  • Automated System & Diagnostic Data: Internet Protocol (IP) addresses, browser fingerprinting metrics, device OS profiles, HTTP headers, referrer URIs, session duration, clickstream pathways, and time-stamped interaction metrics.
  • Billing & Transactional Metadata: Invoice records, transaction identifiers, payment gateway tokens, tax identification metrics, and payment milestone logs (handled securely via PCI-DSS compliant third-party gateways).

3. Legal Basis for Processing

We process personal and client data under the following established legal grounds:

  • Contractual Necessity: Processing required to execute non-disclosure agreements, project proposals, master service agreements, and software delivery milestones.
  • Legitimate Interests: Processing necessary to secure infrastructure, optimize platform latency, prevent fraud, run internal diagnostic checks, and maintain service availability.
  • Legal Compliance: Processing mandated by statutory audit obligations, tax laws, court orders, or law enforcement inquiries.
  • Explicit Consent: Where you have provided unambiguous affirmative consent for marketing communications or optional analytics tracking.

4. How We Use Collected Information

We explicitly enforce strict data minimization principles. Your data is used strictly for:

  • Architecting, prototyping, building, testing, and deploying custom MVP software, web applications, mobile apps, and business automations.
  • Provisioning client staging environments, secure repository access, and automated CI/CD pipeline notifications.
  • Monitoring system performance, resolving runtime exceptions, and preventing security breaches or DDoS vectors.
  • Conducting direct project communications, sprint check-ins, milestone sign-offs, and technical support.
  • Complying with legal obligations, tax filings, and anti-fraud protocols.

Strict AI Exclusion Notice: We DO NOT sell, lease, or use client proprietary source code, internal data assets, or confidential project briefs to train public third-party LLMs or foundational AI models.

5. Third-Party Sub-processors & Service Providers

To maintain infrastructure reliability, GLAD Studio engages vetted third-party sub-processors subject to strict Data Processing Agreements (DPAs) and confidentiality obligations:

Cloud Infrastructure & Hosting

Amazon Web Services (AWS), Vercel Inc., Cloudflare Inc., Supabase Inc.

AI & Machine Learning APIs

OpenAI LLC (API Zero-Data Retention), Anthropic PBC, HuggingFace Inc.

Communication & Scheduling

Cal.com Inc., Resend Inc., Slack Technologies / Salesforce.

Payment Gateways

Stripe Inc., Razorpay Software Pvt. Ltd.

6. Cross-Border Data Transfers

As a global digital product studio serving international clients, information collected by GLAD Studio may be stored, processed, or transferred across servers located in the United States, European Union, and India. All cross-border data transfers are executed under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent data protection safeguards regardless of physical server location.

7. Data Retention & Automatic Destruction Schedules

We retain personal data and project telemetry only for the period necessary to fulfill contractual obligations and statutory compliance requirements.

  • Active Client Project Repositories & Credentials: Retained during active development and 90 days post-delivery to assist with warranty support, after which staging access is revoked and local build caches are securely wiped.
  • Financial & Invoice Records: Retained for 7 years to satisfy statutory tax and financial audit mandates.
  • Contact Inquiries & Analytics Logs: Retained for 24 months from last interaction unless erasure is requested.

8. Security Architecture & Encryption Standards

GLAD Studio enforces defense-in-depth cybersecurity measures:

  • Encryption in Transit: TLS 1.3 protocol enforcement with HSTS headers across all public endpoints and API interfaces.
  • Encryption at Rest: AES-256 encryption applied to static database storage, environment variables, and encrypted key vaults.
  • Access Controls: Strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), and zero-trust administrative policies.
  • Code Vulnerability Audits: Automated static application security testing (SAST) integrated into internal build pipelines.

9. Cookie & Tracking Policy

Our Site uses essential cookies, functional cookies, and privacy-focused telemetry to maintain active user sessions, remember theme preferences, and analyze aggregate traffic patterns.

Upon your first visit, a cookie consent interface allows you to select preferences or opt out of non-essential analytical cookies. You may also clear or block cookies directly via your browser settings at any time.

10. Client Confidentiality & Intellectual Property

GLAD Studio acknowledges that during client engagements, proprietary trade secrets, unreleased software logic, and strategic assets may be shared. All such assets are protected under signed Non-Disclosure Agreements (NDAs) and strict internal compartmentalization controls. Client source code and intellectual property remain 100% owned by the client upon milestone payment settlement.

11. Your Data Protection Rights

Depending on your jurisdiction, you possess the following statutory rights regarding your personal information:

  • Right of Access & Data Portability: Request a structured, machine-readable copy of your personal data held by us.
  • Right to Rectification: Request correction of inaccurate or incomplete personal metrics.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal records, subject to statutory tax or legal exceptions.
  • Right to Restrict or Object to Processing: Limit or object to automated profiling or marketing communications.

To exercise any of these rights, submit a formal request to contact@gladstudio.net. We process verified privacy requests within 30 calendar days.

12. Breach Notification Protocols (72-Hour SLA)

In the event of a confirmed cybersecurity incident impacting personal or client data, GLAD Studio will notify affected data controllers and regulatory authorities within 72 hours of incident confirmation, accompanied by an actionable remediation report detailing scope and containment measures.

13. Children's Privacy Prohibition

GLAD Studio's services are tailored strictly for enterprise clients, founders, and individuals aged 18 and older. We do not knowingly collect or solicit personal data from children under the age of 16. If we become aware of accidental collection, records are purged immediately.

14. Amendments to this Policy

We reserve the right to modify this Policy periodically to reflect technological shifts, statutory updates, or service expansions. The updated version will be posted with a revised "Last Updated" timestamp at the top of this page.

15. Contact Information & Legal Inquiries

For any privacy inquiries, Data Protection Officer (DPO) requests, or legal notices, contact our compliance team:

GLAD Studio Legal & Compliance

Email: contact@gladstudio.net

General Contact: hello@gladstudio.net

Website: https://gladstudio.net