International Data Protection Framework

Privacy Policy & Data Governance

TripleW Digital operates as an international software engineering studio. This policy outlines how we collect, process, safeguard, and transfer enterprise and personal data under EU GDPR, UK GDPR, California CCPA/CPRA, and UAE Federal Decree-Law No. 45/2021.

Effective: January 1, 2026•Last Revised: March 2026•Version: 2.4.0 (Multi-Jurisdiction Enterprise)
EU & UK GDPR (Art. 13/14)
California CCPA / CPRA
UAE Federal Decree-Law 45/2021
Morocco CNDP Law 09-08

1. Data Controller & Legal Entity Information

The data controller responsible for the processing of personal data collected through triplew.digital and during commercial software engineering engagements is:

Legal Operator: TripleW SARL / TripleW Digital International Operations
Headquarters: Agadir Innovation Center / Casablanca Financial Axis, Morocco
Registered Entity: Registered pursuant to Commercial Code Regulations & CNDP Declaration
Data Protection Office (DPO): legal@triplew.digital
Lead Systems Architect: omar@triplew.digital
Direct Technical Dispatch: contact@triplew.digital

For clients operating within the European Economic Area (EEA), the United Kingdom, or the Dubai International Financial Centre (DIFC), contractual data processing is governed by Standard Contractual Clauses (SCCs) and specific Data Processing Agreements (DPAs) incorporated into each client Master Services Agreement (MSA).

2. Scope & Lawful Bases for Processing (EU & UK GDPR)

In accordance with Article 6 of the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, we only process personal information where a valid legal ground exists:

  • Contractual Necessity (Art. 6(1)(b)): Processing necessary to prepare engineering proposals, execute 1-Week Architecture Sprints, draft sprint statements of work (SOW), and deliver production software code.
  • Legitimate Interests (Art. 6(1)(f)): Securing our web platform against distributed denial-of-service (DDoS) attacks, preventing fraudulent intake spam, measuring server infrastructure performance, and improving our technical developer documentation.
  • Legal Obligation (Art. 6(1)(c)): Compliance with corporate accounting, export control, anti-money laundering (AML), and cross-border invoicing requirements in Morocco, the EU, UK, and UAE.
  • Explicit Consent (Art. 6(1)(a)): Voluntarily opted-in subscriptions to our engineering research publications and optional performance telemetry cookies.

3. Categories of Personal Data Collected

A. Technical Intake & Consultation Data

When you request a Sprint, cost calculation, or consultation: Full name, business email address, company name, target technology stack, monthly engineering budget range, project specifications, and architectural requirements.

B. System & Telemetry Data (Server Logs)

IP address (pseudonymized / truncated to protect user privacy), HTTP request headers, browser type and engine version, operating system, referrer URL, pages visited, and edge execution timing (TTFB, Core Web Vitals) collected via Cloudflare edge logs for security and performance benchmarking.

C. Client Codebase & Repository Access (Under Contract)

For active software engineering clients: GitHub / GitLab team handles, SSH public keys, staging environment credentials. All client code access is governed by strict isolated workstations and non-disclosure covenants.

4. California Consumer Privacy Act (CCPA / CPRA) Notice

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA), California residents are entitled to specific disclosures regarding the collection and sale of personal information:

TripleW Digital does NOT sell, rent, monetize, or trade your personal information. We do NOT share personal information for cross-context behavioral advertising.

In the preceding twelve (12) months, TripleW Digital has collected identifiers (name, business email, IP address) solely for B2B contract performance and infrastructure security.

California consumers have the right to request deletion, rectification, disclosure of categories collected, and the right to non-discrimination for exercising their statutory rights. To exercise rights under CCPA/CPRA, email legal@triplew.digital with subject line "CCPA Request".

5. UAE Federal Decree-Law No. 45/2021 & DIFC Data Protection

For our partners and enterprise clients located in the United Arab Emirates (Dubai, Abu Dhabi, Sharjah) and the Dubai International Financial Centre (DIFC):

  • Cross-Border Transfer Safeguards: Personal data transferred outside the UAE is handled under equivalent protection mechanisms mandated by the UAE Data Office and Article 22 of Federal Decree-Law No. 45/2021.
  • Right to Cease Processing: UAE data subjects possess the unconditional right to object to and demand cessation of marketing communications, profiling, or automated decision-making.
  • Data Minimization: Commercial project specifications and fintech client telemetry are retained only for the duration required to satisfy mutual contract deliverables and banking compliance audits.

6. Your International Statutory Privacy Rights

Regardless of your geographical jurisdiction, TripleW Digital extends comprehensive data control rights:

Right of Access (Art. 15 GDPR):Receive confirmation of whether personal data is processed, copies of your data, and transfer details.
Right to Rectification (Art. 16 GDPR):Require the immediate correction of inaccurate or incomplete corporate or personal details.
Right to Erasure / "To Be Forgotten" (Art. 17):Demand complete erasure of your data when retention is no longer necessary for contract or tax compliance.
Right to Data Portability (Art. 20):Obtain your data in a structured, commonly used, machine-readable JSON format.
Right to Restriction of Processing (Art. 18):Restrict active processing during verification of accuracy or ongoing legal disputes.
Right to Lodge a Regulatory Complaint:You may lodge a complaint with your local supervisory authority (e.g., CNIL in France, ICO in the UK, BfDI in Germany, CNDP in Morocco, or the UAE Data Office).

7. Infrastructure Security & Cryptographic Standards

TripleW Digital applies rigorous defense-in-depth technical and organizational measures (TOMs) as mandated by Article 32 of GDPR:

  • Transport Layer Security: All data in transit is encrypted using modern TLS 1.3 with strict HTTP Strict Transport Security (HSTS) and Perfect Forward Secrecy.
  • Encryption at Rest: Database records, encrypted API tokens, and backup snapshots utilize AES-256 GCM encryption.
  • Edge Isolation: Web traffic is filtered via Cloudflare Enterprise Web Application Firewalls (WAF) with real-time DDoS mitigation.
  • Principle of Least Privilege: Source code repositories and client database tokens require hardware-backed FIDO2 multi-factor authentication (MFA).

8. Data Protection Officer Contact

To submit a Subject Access Request (SAR), exercise CCPA/CPRA rights, or request a signed Data Processing Agreement (DPA) with EU Standard Contractual Clauses for your organization, contact our legal counsel:

Enterprise Legal Inquiries:legal@triplew.digital
General Engineering Intake:contact@triplew.digital