ℵ₀ CANTOR LABS
Company Products Developer Docs Changelog
PRIVACY & DATA GOVERNANCE — CDX-PRIVACY-2026-V1

Global Privacy Policy

Cantor Labs commitments to international data privacy, GDPR compliance, and Zero Data Retention.

Last Updated: September 7, 2026 | Effective Date: September 7, 2026
🛡️ Zero Data Retention (ZDR) Architectural Guarantee:
CDX A2A Slimmer middleware operates 100% locally in-memory within your computing environment. Company never transmits, collects, or stores customer conversation payloads, prompt texts, or AI tool parameters on external servers. External transmission is strictly 0.0%.

Section 1. Information We Collect

Company collects minimal personal data solely for account management, authentication, billing, and developer support:

  • Account Credentials: Login email address, salted cryptographic password hash (Argon2 / PBKDF2).
  • Billing Details (Paid Tiers): Cardholder name, corporate entity name, billing email, and encrypted customer tokens (actual cardholder primary account numbers are handled strictly by PCI-DSS Level 1 certified processors like Stripe, Inc. and are never stored on Company servers).
  • Technical & Audit Logs: Console login IP address, browser user-agent, and authentication timestamps retained solely for account security audit trails.

Section 2. Purpose of Processing

  • To provide, maintain, and authenticate developer portal and console access.
  • To manage API keys, license tokens, and cluster quota enforcement.
  • To process commercial subscription billings and statutory tax invoicing.
  • To dispatch critical security advisories, bug fixes, and protocol updates.

Section 3. Retention & Deletion of Personal Data

1. Account personal data is promptly deleted upon account termination, except where statutory retention obligations apply.
2. In accordance with commercial, tax, and telecommunication laws, transaction records are safely archived for five (5) years, and console security access logs are retained for three (3) months before permanent cryptographic purging.

Section 4. Third-Party Subprocessors & Cross-Border Transfers

1. Company does not sell, lease, or monetize personal data.
2. For international credit card billing, Company engages Stripe, Inc. (USA / Ireland) as an authorized PCI-DSS certified payment subprocessor. Transfer is secured via TLS 1.3 and standard contractual clauses (SCCs). Customers may opt out of international card billing by utilizing domestic electronic tax invoices or corporate bank wire transfer.

Section 5. Data Subject Rights (GDPR & CCPA/CPRA)

Users in the European Union, United Kingdom, California, and other jurisdictions have the statutory right to:

  • Access & Portability: Request a machine-readable copy of their account personal data.
  • Rectification: Correct inaccurate account credentials.
  • Erasure (Right to be Forgotten): Request the permanent deletion of their account data.
  • Restriction & Objection: Object to processing of personal data.

Requests may be submitted directly to privacy@cdxengine.com and will be fulfilled within thirty (30) days without charge.

Section 6. Data Protection Officer (DPO) & Inquiries

[Data Protection Officer]
• Officer: Oh-dong-kyu, Representative
• Entity: Cantor Labs
• Address: Teheran-ro, Gangnam-gu, Seoul, Republic of Korea
• Contact: privacy@cdxengine.com / support@cdxengine.com
ℵ₀ CANTOR LABS © 2026 Cantor Labs Inc. All rights reserved.
99.99% Operational
· Terms · Privacy