Legal & Compliance

Privacy Policy

Effective Date: April 20, 2026

This Privacy Policy ("Policy") explains how SentinelX by Uzumaru ("Company," "we," "us," or "our") collects, uses, discloses, and protects your information when you connect to our enterprise network infrastructure, utilize our network routing services, or access networks protected by our Deep Packet Inspection (DPI) and eXpress Data Path (XDP) engines. Please read this Policy carefully. Use of the SentinelX system strictly requires your informed, prior consent. By connecting to our infrastructure, you acknowledge and agree that your network traffic will be actively inspected, routed, and selectively logged in accordance with this Policy to ensure enterprise defense and operational integrity.

1. Definitions

For the purposes of this Privacy Policy:
"Clean Traffic" refers to network connections and data flows that conform to the current, dynamically authorized protocol topologies and geographic location configurations set by the network administrator, and which do not trigger any firewall restrictions, blacklists, or threat intelligence signatures.
"Connection Metadata" refers to non-payload network routing information, including but not limited to Source IP address, Destination IP address, port numbers, Server Name Indication (SNI), timestamp of the connection request, protocol classification (e.g., HTTP/S, SOCKS5, WireGuard), and the security verdict generated by our systems (e.g., ALLOW, DROP, AUDIT).
"Deep Packet Inspection" (DPI) refers to the methodology used by SentinelX to evaluate the structural integrity and protocol conformance of data packets traversing our network gateways, independently of the payload contents.
"Personal Data" or "Personally Identifiable Information" (PII) refers to any information relating to an identified or identifiable natural person. Under certain jurisdictions (such as GDPR and CCPA), an IP address is considered Personal Data.

2. Data Collection & Processing Methodology

We process network traffic data natively at the kernel level utilizing our eXpress Data Path (XDP) engine to ensure minimal latency while maintaining zero-trust security postures. We strictly distinguish between Connection Metadata and encrypted packet payloads. Importantly, we do not perform Transport Layer Security (TLS) interception, nor do we attempt to decrypt, unpack, or reconstruct encrypted packet payloads. We do not extract communications, passwords, user credentials, messages, emails, or equivalent semantic context from the traffic. Our logging mechanisms are strictly confined to observing the relationship between your Source IP, the requested destination (via Domain or SNI), and routing timestamps.

Depending on the traffic classification established by the network administrator through DPI/GeoIP configurations (which may dynamically include rules for Email/SMTP, SOCKS5, Encrypted Proxy/FET, WireGuard VPN, QUIC/HTTP3, and HTTP/HTTPS), data is segregated and handled as follows:

  • Clean Traffic (Zero-Logging Paradigm): Legitimate connections matching protocols actively permitted by the administrator are routed seamlessly. For this traffic, we do not inspect or store payload data. Packet flows are processed transiently in memory space and expunged from our buffers immediately upon routing completion.
  • Blocked Inbound Traffic: Packets originating from GeoIP regions restricted by the administrator, or protocols explicitly prohibited by the current custom DPI policy (such as unapproved Encrypted Proxies or unauthorized WireGuard endpoints), are dropped iteratively at the kernel boundary. We permanently log only the Connection Metadata (Source IP, Target Port, Timestamp, and Verdict Rule Code) to compile internal threat intelligence metrics.
  • Audited Outbound Traffic: Specific outbound traffic classifications designated as highly sensitive (e.g., interactions with unauthorized financial endpoints or corporate restricted social media platforms) are actively routed to a secondary outbound interface. This traffic's Connection Metadata is securely logged to fulfill compliance obligations, network usage auditing, and data exfiltration monitoring protocols.
  • Blacklist and Sinkholed Traffic: Deliberate attempts to access known malicious entities, dark web domains, or explicitly prohibited explicit content are sinkholed (i.e., diverted to a null route or localized block mechanism). Connection Metadata for these infractions is permanently appended to our secure Log Store for incident response operations.

3. Lawful Basis for Processing

In compliance with international data protection frameworks, including Article 6(1)(f) of the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), our lawful basis for collecting and processing your Connection Metadata is our Legitimate Interest. This encompasses, but is not limited to: safeguarding our corporate network infrastructure against cyber threats, monitoring for unauthorized data exfiltration, averting unauthorized access vectors, enforcing our Acceptable Use Policy, mitigating denial-of-service incursions, and ensuring holistic operational stability.

Where your explicit consent is mandated by local jurisdictional precedence, connecting to our network establishes your affirmative, demonstrable consent to such processing as a non-negotiable prerequisite of network access.

4. Data Retention, Localization, and Sovereignty

SentinelX implements strict data lifecycle management practices. Security logs—comprising sinkholed connections, audited metadata, and dropped inbound requests—are persisted in our encrypted Log Store for a standard retention lifecycle of ninety (90) calendar days. Following this interval, logs are systematically purged via cryptographic erasure procedures. Exceptions to this retention window are exclusively applied when extended preservation is mandated by validated subpoenas, court orders from competent jurisdictions, or active, ongoing cybersecurity forensic investigations originating from a verified network breach.

All stored metadata environments are secured using Advanced Encryption Standard (AES-256) encryption at rest, and all internal metric transmissions utilize strictly enforced TLS 1.3 transit encryption. Data processing happens locally or within the geographically proximate data center nodes managed by your direct organization, precluding unnecessary cross-border data transfers unless specifically architected by the network administrator.

5. Third-Party Sharing and Disclosures

We do not sell, rent, lease, or commercially distribute your network metadata to third parties for advertising or profiling purposes. Connection Metadata may only be disclosed under the following constrained scenarios:

  • Legal Imperative: To comply with compulsory legal obligations, lawful administrative requests, court orders, or robustly authorized governmental inquiries.
  • Enterprise Administrators: If you are utilizing SentinelX infrastructure commissioned by your employer or an IT administrator, the resulting logs are owned by and accessible to that commissioning entity.
  • Upstream Security Analysis: Aggregated, thoroughly anonymized signatures extracted from blocked payloads may be shared with threat intelligence consortiums; such signatures will not possess any linkages to your identifying PII or specific Source IP.

6. Data Subject Rights

Contingent upon your residency and the legal framework governing your jurisdiction (e.g., the EU GDPR, UK GDPR, California Consumer Privacy Act CCPA, or analogous privacy laws), you are afforded substantial rights concerning your Personal Data. You may possess the right to:

  • Right to Access / Portability: Demand disclosure of the specific categorizations of Connection Metadata we maintain concerning your IP address over the preceding retention period.
  • Right to Erasure (Right to be Forgotten): Submit a formalized request for the deletion of accumulated connection logs traversing your IP. (Note: Fulfillment of this request may be deferred if the logs are currently embargoed for legal holds or active threat analysis).
  • Right to Rectification: Assert corrections if you believe the metadata classifications linked to your identity are erroneous.
  • Right to Restriction of Processing: Mandate a cessation of processing relative to your network parameters; invoking this right will axiomatically necessitate the termination of your access to the SentinelX infrastructure.

To invoke any of these privileges, you are mandated to forward a verified request to the network administrative entity overseeing your infrastructure endpoint, or directly to our privacy compliance cadre at privacy@sentinalx.uzuma.ru. We endeavor to respond to authenticated requests within thirty (30) days.

7. Breach Notification and Incident Response

We maintain comprehensive incident response strategies. Should an unauthorized external breach compromise our Log Store repositories, leading to the demonstrable exfiltration of unencrypted, identifiable Connection Metadata, we commit to executing an emergency disclosure protocol. We will notify the registered enterprise stakeholders within seventy-two (72) hours of definitive incident verification, articulating the vectors of the breach, the scope of the disclosed data, and the immediate mitigatory actions undertaken by our security incident orchestration team.

8. Amendments to the Privacy Policy

SentinelX invariably reserves the right to amend, iteratively refine, or wholly reconstruct this Privacy Policy to mirror technological evolution within our DPI capabilities, alterations in regulatory strictures, or enhancements to our architectural framework. Substantive modifications influencing the scope of data logging will be promulgated via formal documentation releases or directly communicated to your network administrator prior to enforcement. Continued utilization of the SentinelX routing infrastructure effectively constitutes your binding acceptance of such revisions.

9. Contact Information

For any sophisticated inquiries regarding our cryptographic methodologies, compliance frameworks, or specific processing stipulations articulated within this document, please communicate with our Global Compliance Division:

SentinelX by Uzumaru
ATTN: Legal & Privacy Department
Email: compliance@sentinalx.uzuma.ru