// DATA_PRIVACY • ZERO_TRUST_SECURITY

Privacy & Data Telemetry Policy

Effective Date: August 15, 2026 • Security Architecture Standard: ISO-27001 / GDPR

1. Zero-Trust Data Isolation

Zenova Devs enforces strict client environment data isolation. Customer databases, application telemetry, and API keys are stored in encrypted environments protected by AES-256 GCM encryption at rest and TLS 1.3 transport security in transit.

2. Telemetry & Privacy Analytics

Our internal telemetry system (`lib/analytics.ts`) tracks aggregated operational performance metrics (P99 query latency, build success rates, HTTP status logs) without harvesting personally identifiable information (PII). We do not utilize third-party ad tracking scripts.

3. API Key & Credential Vaulting

Client API credentials, database strings, and third-party tokens provided for development or deployment are stored in environment vaults with restricted RBAC access granted only to assigned lead engineers.

4. Data Retention & Erasure

Upon engagement completion, clients may request complete zero-footprint data erasure of staging databases and temporary engineering artifacts. Backup retention schedules automatically purge non-active records after 30 days.

// INITIALIZE_ENGAGEMENT

Ready to architect the system behind your next growth phase?

Schedule a technical discovery session with our engineering leads to audit your current architecture and outline an execution roadmap.