PRIME 88
DATA_GOVERNANCE // 02 REVISED: JULY 2026

Privacy Policy

Data minimization and telemetry privacy architecture across our edge infrastructure.

1. Data Minimization Philosophy

Prime 88 operates under a strict data minimization architecture. We do not sell user data, track behavior across third-party networks, or capture unneeded telemetry. Data processed through our client workspaces and API endpoints is limited strictly to what is required for system authorization, security boundary enforcement, and edge routing.

2. Information Collected

Session & Auth Tokens: Cryptographic tokens, hardware passkey verifications, and OAuth credentials required to maintain secure workspace states.

Edge Network Logs: Anonymized IP addresses, request headers, user-agent signatures, and response latencies used for DDoS protection and CIDR rate-limiting.

Account Credentials: Email addresses and domain identities explicitly provided during workspace provisioning or support dispatch.

3. How We Use Information

We use the information we collect to: provide, maintain, and improve the Service; communicate with you regarding your account, security notices, and service updates; monitor and analyze usage trends to improve performance and reliability; detect, prevent, and respond to abuse, fraud, unauthorized access, and security incidents; and comply with legal obligations.

4. Information Sharing

We do not sell your personal information. We may share information with service providers who perform functions on our behalf (hosting, security, analytics), with affiliates under common control, when required by law, or in connection with a merger or acquisition. All third-party providers are contractually bound to handle your information consistent with this policy.

5. Infrastructure & Edge Processing

All network payloads are routed through encrypted edge nodes running on Cloudflare's global network. Storage layer data is encrypted at rest using AES-256 and restricted to isolated databases with strict zero-trust access controls.

6. Data Retention

We retain your information only as long as necessary. Usage analytics are retained for 14 months. Authentication logs are retained for 90 days. Workspace data is retained for the duration of the tenant agreement plus 30 days, after which it is securely purged.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data. California residents have rights under CCPA. EEA/UK residents have rights under GDPR. All data subject requests are acknowledged within 72 hours and addressed within 30 days.

8. Cookies

We use essential cookies for session management, authentication, and security. We do not use third-party tracking or advertising cookies. See our Cookie Policy for details.

9. Contact

For data rights requests or privacy compliance inquiries:

[email protected]