1. Introduction & Scope
SoftSolex ("Company", "we", "us") operates as a premier Enterprise AI, Cloud, Data Center Infrastructure, and Managed IT Consultancy. Our global infrastructure spans nodes across the United States (Texas), United Kingdom (London), European Union (Vienna, Helsinki), and the Middle East (Riyadh, Dubai).
This Privacy Policy strictly governs the data architecture and processing pipelines associated with your interaction on softsolex.com and our related digital ecosystems. We enforce a Zero-Trust data model, meaning we only ingest data that is absolutely necessary to fulfill technical scoping and service level agreements (SLAs).
2. Information Collection Architecture
As a B2B technical consultancy, our data ingestion is fundamentally minimal. We do not run consumer-grade ad trackers. Data is collected through explicit enterprise engagement mechanisms.
Explicitly Provided Data
- Identity Vectors: Full Name, Organization / Company Entity Name.
- Communication Vectors: Corporate Email Address, Direct Phone / WhatsApp Dispatch numbers.
- Operational Vectors: Selected Target Delivery Nodes, Primary Domain inquiries (e.g., AI Automation vs Cloud Engineering), and any architectural RFPs or payload descriptions submitted via our Unified Contact Portal.
Automated Edge Telemetry (Usage Data)
- Network Diagnostics: IP Addresses (temporarily logged at the edge for DDoS mitigation via our WAF), TLS handshake protocols, and User-Agent strings.
- Interaction Telemetry: Anonymized metrics detailing which architectural whitepapers or capability specifications are accessed, enabling us to optimize CDN routing and content caching.
- Cookies: We deploy strictly necessary session cookies required for fundamental routing, CSRF protection, and load balancer affinity. We do not deploy third-party retargeting cookies.
3. Data Processing & Utilization
Data ingested into the SoftSolex network is routed securely to the appropriate regional node for processing. We process this data under the legal basis of legitimate business interest and contract necessity:
- Service Fulfillment: To rapidly dispatch technical scoping teams, architecture reviews, and engineering responses within our 24-hour SLA.
- Continuous Improvement: To analyze edge telemetry in order to scale our microservices, optimize database indexing, and improve the latency of our digital properties.
- Security Auditing: To autonomously detect and neutralize anomalous traffic patterns, ensuring compliance with SOC2 Type II operating principles.
4. Cryptography & Security Controls
SoftSolex engineers systems for high-security environments, and we apply those same standards to our internal data handling.
In Transit: All data transmitted to our endpoints is secured via strict TLS 1.3 encryption protocols, preventing man-in-the-middle (MITM) interception.
At Rest: Operational databases are encrypted using AES-256 block-level encryption. Access is governed by Identity-Aware Proxies (IAP) and mandatory multi-factor authentication (MFA) for all SoftSolex personnel.
Data Isolation: Client inquiry data is strictly partitioned and inaccessible from public-facing edge compute environments.
5. Third-Party Edge & Telemetry Integration
We maintain strict vendor lock-down policies. We do not sell, broker, or monetize your corporate data. We share necessary diagnostic data solely with infrastructure sub-processors essential for our uptime:
- Cloudflare: Utilized for Edge caching, DNS routing, and global WAF/DDoS protection.
- Enterprise Email Relays: Utilized exclusively for dispatching secure transactional communications to our engineering desks.
6. Global Compliance (GDPR, UK GDPR & CCPA/CPRA)
Operating globally requires strict adherence to sovereign data regulations. Depending on your origin node, you retain absolute sovereign rights over your data.
European Union & United Kingdom (GDPR / UK GDPR)
If you are accessing our site from within the EEA or UK, you are granted specific rights under the General Data Protection Regulation:
- Right to Access: Request full extraction of your identity records held by us.
- Right to Erasure: Request immediate cryptographic destruction of your records (Right to be Forgotten).
- Right to Rectification: Request modification of inaccurate datasets.
- Right to Restrict Processing: Request suspension of data processing while a dispute is resolved.
United States / California (CCPA/CPRA)
For enterprise partners in California, we comply with the CCPA/CPRA. SoftSolex definitively does not sell or share personal information for cross-context behavioral advertising. You possess the right to non-discrimination for exercising your privacy rights.
7. Data Retention Cycles
We enforce automated lifecycle management on our operational databases. Technical inquiries that do not convert into active Statements of Work (SOWs) or active Master Service Agreements (MSAs) are subjected to automated purging protocols after 24 months of inactivity, retaining only cryptographic hashes necessary for compliance and suppression lists.
8. Contact the Data Protection Officer (DPO)
For GDPR data subject access requests, CCPA inquiries, or any security concerns regarding our operational telemetry, please contact our global Data Protection Officer:
Email: mail@softsolex.com
Engineering & Support Desk (Texas Node): +1 (321) 999-1388