Privacy and terms readiness

Production privacy notices and service terms are not approved.

The development preview is not an offer of production service and must not receive real identities, customer data, credentials, payment instructions, or approval decisions. This readiness notice is not a privacy policy, terms of service, DPA, SLA, or legal advice.

Technical privacy work

The repository defines data classification, narrow exports, retention/legal-hold/deletion primitives, diagnostic redaction, low-cardinality analytics, destination/token digests, and secret-safe logging. Authoritative processing purposes, controller/processor roles, retention schedule, subprocessors, rights intake, transfers/residency, cookies, backups, and deletion SLA remain undecided.

Terms work

Entity, eligibility, acceptable use, service/support commitments, warranty/liability, security responsibilities, IP, payment/tax/refund behavior, suspension/termination, data return/deletion, governing law, notices, and change control require Product and Legal approval.

Before a pilot

Approve the product/data boundary, privacy and security architecture, pilot agreement/DPA, retention/export/deletion behavior, subprocessors, support/disclosure contacts, incident notice, customer acceptance criteria, and named go-live authority.

See release readiness →