SE
StackExpert Infrastructure Engineering
DATA PROTECTION & PRIVACY

Privacy Policy & Data Governance.

StackExpert operates an engineering services platform for mission-critical infrastructure. We hold ourselves to uncompromising standards of technical transparency, data minimization, and zero-trust credential isolation.

Last Updated: October 2026 • Version 1.1 • Operator: StackExpert Systems Architecture
01

Scope & Data Minimization Principles

This Privacy Policy describes how StackExpert collects, stores, protects, and handles information across our public website, Client Portal, and administrative platforms. Our foundational engineering rule is data minimization: we never collect extraneous behavioral tracking data, sell customer information to third parties, or run third-party advertising networks.

Engineering Practice Boundary: We execute systems engineering directly on your cloud or bare-metal instances. We do not ingest, re-host, or process your end-user application databases onto StackExpert servers.
02

Information We Collect & Process

We collect only the technical, contractual, and account information required to provide professional systems engineering and client management services:

Contact & Inquiry Data

When submitting pre-sales inquiries, we collect your name, business email, company name, primary engineering need, operating environment summary (AWS, GCP, Hetzner, Bare-Metal), and message details.

Account & Auth Credentials

Full name, corporate email address, organization name, cryptographic password hash (Argon2id/bcrypt), and encrypted TOTP two-factor authentication secrets.

Diagnostic Files & Logs

Configuration snippets, log dumps, error stack traces, and architectural diagrams uploaded via tickets or project milestones. All files are automatically scanned by ClamAV for malware upon ingestion.

Session & Security Telemetry

IP address, browser user-agent, session identifiers, device timestamps, and immutable audit logs of privileged security and vault access actions.

03

Credential Vaulting & Cryptographic Destruction

Client infrastructure credentials (such as temporary SSH access, database staging credentials, or root passwords) receive special protective handling under our zero-trust vault architecture:

Multi-Layer Envelope Encryption
Secrets are encrypted using authenticated ciphers (AES-256-GCM) with unique per-credential encryption keys derived using cryptographic salt and master keys. Plaintext secrets are never written to application logs, disk swap, or persistent storage unencrypted.
Strict Auditing & Access Controls
Credential reveal actions require high-privilege staff roles, are strictly isolated by client organization context, and generate an immutable, tamper-evident audit log recording the actor, timestamp, and IP address.
Cryptographic Destruction Guarantee
Upon milestone sign-off, incident stabilization, or client request, the specific data encryption material associated with the secret is deleted and zeroed in memory, rendering the stored ciphertext mathematically and permanently irrecoverable. We do not claim physical drive overwriting on multi-tenant cloud storage; our guarantee rests on proven cryptographic key destruction.
04

Uploaded Documents, Diagnostics & Malware Scanning

Files uploaded to tickets, service requests, or project workspaces are protected through isolated storage mechanisms:

  • Automated Ingestion Scanning: All files are passed through a dedicated ClamAV daemon prior to being made available in the portal. Suspicious files are instantly quarantined.
  • Non-Executable Storage: Uploaded evidence is stored in private, non-web-accessible directories with execution permissions stripped.
  • Role-Based Access: Documents marked as internal engineering notes are completely hidden from client views, while client evidence is accessible only to members of that specific organization.
05

Third-Party Infrastructure & Subprocessors

StackExpert relies on select, industry-standard infrastructure providers to operate resilient platform services:

Provider Function Data Handled & Security Controls
Cloudflare WAF, DDoS mitigation, DNS, Turnstile bot verification IP address and ephemeral network telemetry. Turnstile operates without third-party tracking cookies or personal fingerprinting.
Payment Processors (Stripe & PayPal) Payment processing & settlement PCI-DSS compliant payment processing. StackExpert never handles, transmits, or stores full card numbers (PANs) or security codes (CVVs). For corporate wire transfers, manual settlements are processed via standard corporate banking rails without storing client banking credentials.
Amazon Web Services (AWS) Core platform compute, object storage, and backups SOC 2 / ISO 27001 compliant cloud infrastructure. Encrypted at rest (AES-256) and in transit (TLS 1.3).
Transactional Email (SMTP/API) Ticket updates, invoice notifications, security alerts Recipient email and notification subject. Passwords and raw credential secrets are stripped prior to email dispatch.
06

Data Retention & Deletion Schedule

We maintain structured retention schedules to balance engineering context with strict privacy requirements:

Vault Secrets
Cryptographically destroyed within 48 hours of project sign-off or immediately upon client request in the portal.
Diagnostic Logs & Evidence
Retained for 90 days following milestone completion for warranty review, then automatically scheduled for deletion.
Invoices & Legal Records
Retained for statutory tax and accounting periods (typically 7 years) in compliance with corporate financial regulations.
07

Your Rights & Privacy Desk

Under applicable data protection frameworks (including GDPR, CCPA, and statutory regulations), you have full authority over your personal information:

✓ Right to Access: Request a complete export of your user data, tickets, and technical reports.
✓ Right to Rectification: Update or correct inaccurate organization, billing, or contact records.
✓ Right to Erasure: Request permanent removal of your account, organization history, and associated diagnostic files.
✓ Right to Revoke: Terminate active sessions and revoke authorized devices instantly in Account Security settings.
Data Protection Officer / Security Desk
Submit Privacy Inquiry →