Privacy Policy & Data Protection
Last updated: June 9, 2026
1. Overview
Adneura Labs ("we," "our," or "us") provides custom software development services that may involve processing sensitive business data, including personally identifiable information (PII). We are committed to protecting your privacy and handling your data with the highest standards of security and compliance.
This Privacy Policy explains how we collect, use, store, and protect your information, including client data processed through our development services.
2. Information We Collect
2.1 Business Contact Information
When you inquire about or engage our services, we collect:
- Name, email address, phone number
- Company name and business information
- Payment and billing information
- Communication preferences
2.2 Client Data Processed Through Development Services
In the course of providing development services, we may process various types of client business data, which may include:
- Application Data: Data necessary for developing and testing your applications
- Personally Identifiable Information (PII): Customer names, addresses, email addresses, phone numbers
- Business Data: Transaction information, user data, operational metrics
- API Keys & Credentials: Third-party service credentials needed for integrations
- Healthcare Information: For healthcare clients, we may process protected health information (PHI) as defined by HIPAA
3. Data Privacy & Protection Measures
3.1 Client Data Handling
Before processing any client data containing PII or sensitive business information:
- We establish a written client agreement that explicitly authorizes data processing
- We assess the regulatory requirements applicable to your business (GDPR, CCPA, HIPAA, etc.)
- We implement appropriate technical and organizational safeguards based on data sensitivity
- We configure our systems to comply with applicable data protection regulations
3.2 Third-Party Services Usage
Our development services may leverage third-party services including AI/ML APIs, cloud infrastructure, and other development tools. When client data is processed through these services:
- We only share data with third-party services when explicitly authorized by the client agreement
- We review and comply with third-party data privacy policies
- We use appropriate configurations to protect client data
- We ensure third-party providers maintain appropriate security certifications (SOC 2, ISO 27001, etc.)
- Data transmission to third-party services is encrypted using industry-standard protocols
3.3 Data Security
We implement comprehensive security measures to protect your data:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
- Access controls and authentication mechanisms to limit data access
- Regular security audits and vulnerability assessments
- Secure development practices and code reviews
- Incident response procedures for data breaches
- Regular backups and disaster recovery procedures
4. Regulatory Compliance
4.1 GDPR (General Data Protection Regulation)
For clients subject to GDPR (European Union data protection law):
- We act as a data processor on behalf of the client (data controller)
- We execute Data Processing Agreements (DPAs) as required
- We assist with data subject requests (access, rectification, erasure, portability)
- We maintain records of processing activities
- We report data breaches within 72 hours as required
4.2 CCPA (California Consumer Privacy Act)
For clients subject to CCPA:
- We act as a service provider and do not sell personal information
- We assist with consumer rights requests (know, delete, opt-out)
- We maintain records to demonstrate compliance
- We provide notices regarding categories of personal information processed
4.3 HIPAA (Health Insurance Portability and Accountability Act)
For healthcare clients (dental practices, clinics, medical offices) processing Protected Health Information (PHI):
- We execute Business Associate Agreements (BAAs) before processing any PHI
- We implement HIPAA Security Rule safeguards (administrative, physical, technical)
- We maintain compliance with HIPAA Privacy Rule requirements
- We ensure subcontractors (including AI API providers) have appropriate BAAs in place
- We provide breach notification as required by HIPAA Breach Notification Rule
- We maintain audit logs and access controls for PHI
Important: Healthcare clients must explicitly request HIPAA-compliant services and execute a BAA before we process any PHI. Standard automation services are not HIPAA-compliant by default.
5. How We Use Your Information
We use collected information solely for the following purposes:
- Providing and improving our development services
- Building, testing, and deploying software applications
- Communicating with you about your service
- Billing and payment processing
- Technical support and troubleshooting
- Compliance with legal obligations
We do not:
- Sell or rent your data to third parties
- Use client data for marketing or advertising purposes
- Allow third parties to use your data for their own purposes without authorization
- Share client data except as required by law or authorized by the client
6. Data Retention & Deletion
We retain client data only as long as necessary to provide services or as required by law:
- Active Projects: Data is retained for the duration of the development project
- Completed Projects: Data may be retained for up to 90 days for support purposes, unless otherwise specified in the client agreement
- Legal Retention: Billing and tax records retained as required by law (typically 7 years)
- Deletion Requests: Clients may request data deletion at any time; we will comply within 30 days unless legally required to retain
Upon project completion or service termination, we securely delete or return all client data as specified in the client agreement.
7. Client Rights & Control
You have the following rights regarding your data:
- Access: Request copies of data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Request data in a structured, machine-readable format
- Restriction: Request limitation of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdrawal: Withdraw consent for data processing at any time
To exercise these rights, contact us at support@adneura.ca
8. Data Breach Notification
In the unlikely event of a data breach affecting your information:
- We will notify affected clients within 72 hours of discovery
- We will provide details about the nature and scope of the breach
- We will describe steps taken to mitigate harm and prevent future breaches
- We will comply with all applicable breach notification laws
- For HIPAA clients, we will follow HIPAA Breach Notification Rule procedures
9. International Data Transfers
If your data is transferred outside your jurisdiction:
- We use Standard Contractual Clauses (SCCs) or equivalent mechanisms for GDPR compliance
- We ensure adequate safeguards are in place for cross-border transfers
- We notify clients of data transfer locations when required
10. Third-Party Services & Subprocessors
We may engage the following categories of third-party service providers:
- AI/ML Services: Third-party AI and machine learning APIs for intelligent features
- Cloud Infrastructure: Hosting and storage providers (cloud platforms)
- Payment Processors: For billing and payment processing
- Communication Tools: Email and messaging services
All subprocessors are contractually required to maintain appropriate data protection standards and comply with applicable regulations.
11. Cookies & Analytics
Our website uses minimal cookies and analytics:
- Essential cookies for website functionality
- Analytics cookies (with consent) to understand site usage
- No advertising or tracking cookies
You can control cookie preferences through your browser settings.
12. Children's Privacy
Our services are intended for businesses and are not directed to individuals under 18. We do not knowingly collect personal information from children.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify clients of material changes via email or through our service. Continued use after changes constitutes acceptance of the updated policy.
14. Contact Information
For privacy questions, data requests, or to report concerns:
Privacy & Data Protection Inquiries:
support@adneura.ca
HIPAA/Healthcare Inquiries:
Email support@adneura.ca with "HIPAA Inquiry" in the subject line
Adneura Labs operates under the laws of Ontario, Canada.
Disclaimer: This Privacy Policy provides general information about our data practices. Specific client engagements may be subject to additional terms in client agreements, Data Processing Agreements (DPAs), or Business Associate Agreements (BAAs). In case of conflict, the specific agreement terms control.