Privacy Policy & Data Governance
TripleW Digital operates as an international software engineering studio. This policy outlines how we collect, process, safeguard, and transfer enterprise and personal data under EU GDPR, UK GDPR, California CCPA/CPRA, and UAE Federal Decree-Law No. 45/2021.
1. Data Controller & Legal Entity Information
The data controller responsible for the processing of personal data collected through triplew.digital and during commercial software engineering engagements is:
For clients operating within the European Economic Area (EEA), the United Kingdom, or the Dubai International Financial Centre (DIFC), contractual data processing is governed by Standard Contractual Clauses (SCCs) and specific Data Processing Agreements (DPAs) incorporated into each client Master Services Agreement (MSA).
2. Scope & Lawful Bases for Processing (EU & UK GDPR)
In accordance with Article 6 of the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018, we only process personal information where a valid legal ground exists:
- Contractual Necessity (Art. 6(1)(b)): Processing necessary to prepare engineering proposals, execute 1-Week Architecture Sprints, draft sprint statements of work (SOW), and deliver production software code.
- Legitimate Interests (Art. 6(1)(f)): Securing our web platform against distributed denial-of-service (DDoS) attacks, preventing fraudulent intake spam, measuring server infrastructure performance, and improving our technical developer documentation.
- Legal Obligation (Art. 6(1)(c)): Compliance with corporate accounting, export control, anti-money laundering (AML), and cross-border invoicing requirements in Morocco, the EU, UK, and UAE.
- Explicit Consent (Art. 6(1)(a)): Voluntarily opted-in subscriptions to our engineering research publications and optional performance telemetry cookies.
3. Categories of Personal Data Collected
A. Technical Intake & Consultation Data
When you request a Sprint, cost calculation, or consultation: Full name, business email address, company name, target technology stack, monthly engineering budget range, project specifications, and architectural requirements.
B. System & Telemetry Data (Server Logs)
IP address (pseudonymized / truncated to protect user privacy), HTTP request headers, browser type and engine version, operating system, referrer URL, pages visited, and edge execution timing (TTFB, Core Web Vitals) collected via Cloudflare edge logs for security and performance benchmarking.
C. Client Codebase & Repository Access (Under Contract)
For active software engineering clients: GitHub / GitLab team handles, SSH public keys, staging environment credentials. All client code access is governed by strict isolated workstations and non-disclosure covenants.
4. California Consumer Privacy Act (CCPA / CPRA) Notice
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA), California residents are entitled to specific disclosures regarding the collection and sale of personal information:
In the preceding twelve (12) months, TripleW Digital has collected identifiers (name, business email, IP address) solely for B2B contract performance and infrastructure security.
California consumers have the right to request deletion, rectification, disclosure of categories collected, and the right to non-discrimination for exercising their statutory rights. To exercise rights under CCPA/CPRA, email legal@triplew.digital with subject line "CCPA Request".
5. UAE Federal Decree-Law No. 45/2021 & DIFC Data Protection
For our partners and enterprise clients located in the United Arab Emirates (Dubai, Abu Dhabi, Sharjah) and the Dubai International Financial Centre (DIFC):
- Cross-Border Transfer Safeguards: Personal data transferred outside the UAE is handled under equivalent protection mechanisms mandated by the UAE Data Office and Article 22 of Federal Decree-Law No. 45/2021.
- Right to Cease Processing: UAE data subjects possess the unconditional right to object to and demand cessation of marketing communications, profiling, or automated decision-making.
- Data Minimization: Commercial project specifications and fintech client telemetry are retained only for the duration required to satisfy mutual contract deliverables and banking compliance audits.
6. Your International Statutory Privacy Rights
Regardless of your geographical jurisdiction, TripleW Digital extends comprehensive data control rights:
7. Infrastructure Security & Cryptographic Standards
TripleW Digital applies rigorous defense-in-depth technical and organizational measures (TOMs) as mandated by Article 32 of GDPR:
- Transport Layer Security: All data in transit is encrypted using modern TLS 1.3 with strict HTTP Strict Transport Security (HSTS) and Perfect Forward Secrecy.
- Encryption at Rest: Database records, encrypted API tokens, and backup snapshots utilize AES-256 GCM encryption.
- Edge Isolation: Web traffic is filtered via Cloudflare Enterprise Web Application Firewalls (WAF) with real-time DDoS mitigation.
- Principle of Least Privilege: Source code repositories and client database tokens require hardware-backed FIDO2 multi-factor authentication (MFA).
8. Data Protection Officer Contact
To submit a Subject Access Request (SAR), exercise CCPA/CPRA rights, or request a signed Data Processing Agreement (DPA) with EU Standard Contractual Clauses for your organization, contact our legal counsel: