Effective Date: February 1, 2026
1. Data Minimalism & Sovereignty
GridBase operates on a strict Data Minimalism principle, ingesting only the specific technical telemetry and model outputs required to perform assessments.
- 1.1 Zero-Retention of Sensitive Data: All test data, assessment results, and sensitive technical telemetry are destroyed upon final delivery. GridBase does not retain proprietary client data post-engagement.
- 1.2 Identity Anonymization: GridBase prioritizes business-only identifiers and does not require personal data of individual employees beyond what is necessary for billing.
2. Encryption & Async Protocol
- AES-256 Standards: GridBase employs industry-standard AES-256 encryption for all data handling and communication.
- Encrypted Async Protocol: All high-stakes data exchange is conducted via secure, encrypted asynchronous channels.
3. Data Residency & Retention
- Operational Records: Only the minimal operational records required to administer the engagement are retained, and are purged within 30 days of final delivery.
- Storage Sovereignty: GridBase utilizes localized, encrypted nodes to keep data within the required jurisdiction during the audit window.
4. Individual Rights (GDPR / CCPA)
Authorized client representatives have the following rights:
- Access & Rectification: The right to access or update professional data held by GridBase.
- Erasure: The right to request immediate deletion of data prior to the standard 30-day purge cycle.
- Inquiries: Contact briefing@gridbase.tech.
GridBase is an independent technical entity. All rights reserved.