This policy describes how Leanear Enterprises LLC meets its obligations under applicable data protection law, including the GDPR (where applicable), the CCPA/CPRA, and other relevant U.S. and international privacy regulations.
✓ GDPR-aligned
✓ CCPA / CPRA
✓ Data minimization
✓ Encryption at rest & in transit
✓ Right to erasure
1. Introduction and Scope
Leanear Enterprises LLC ("we", "us", "our") is committed to protecting the personal data of everyone who uses the Däätum platform. This Data Protection Policy describes the technical, organizational, and legal measures we take to protect personal data, and it supplements our Privacy Policy.
This Policy applies to all personal data processed by Leanear Enterprises LLC in connection with the Platform, regardless of the format in which data is held.
2. Data Protection Principles
We process personal data in accordance with the following principles:
- Lawfulness, fairness, and transparency: We only process data on a valid legal basis and in a transparent manner.
- Purpose limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed in a way incompatible with those purposes.
- Data minimization: We collect only the minimum data necessary to provide the Platform's features.
- Accuracy: We take reasonable steps to keep personal data accurate and up to date.
- Storage limitation: Data is retained only for as long as necessary for the purpose for which it was collected.
- Integrity and confidentiality: We use appropriate technical and organizational measures to protect data against unauthorized access, loss, or destruction.
- Accountability: We are responsible for, and can demonstrate compliance with, these principles.
3. Categories of Personal Data Processed
- Identity data: Name, email address, profile photo.
- Professional data: Job title / role.
- Location data: Geographic coordinates voluntarily provided or captured with GPS permission.
- Communication data: Direct messages and media shared between users.
- Content data: Posts, comments, and event RSVPs.
- Technical data: IP addresses, browser type, session tokens, and log files.
- Security data: Hashed passwords and authentication logs.
We do not knowingly process special categories of sensitive personal data (e.g., health data, race, religious beliefs, biometric data).
4. Legal Bases for Processing
We rely on the following legal bases under applicable law:
- Contract: Processing necessary to perform the Platform services for registered users.
- Legitimate interests: Operating, securing, and improving the Platform; fraud prevention; analytics.
- Legal obligation: Compliance with applicable laws and responding to lawful requests from authorities.
- Consent: Location data capture via GPS (where we explicitly ask for browser permission).
5. Data Retention Schedule
- Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Posts and user content: Deleted within 30 days of account deletion, unless required by law.
- Direct messages: Retained while both participants' accounts are active; deleted within 30 days when either party deletes their account.
- Server logs (IP, access logs): Retained for up to 90 days for security and debugging purposes.
- Legal hold data: Retained as long as required by applicable legal obligation.
6. Technical Security Measures
- Passwords are hashed using bcrypt with a minimum cost factor of 10; plain-text passwords are never stored.
- All data is transmitted over encrypted HTTPS/TLS connections.
- Database credentials and API secrets are stored as environment variables, not in application code.
- Uploaded media files are stored server-side with randomized filenames to prevent enumeration.
- Access to production systems is restricted by role-based access controls.
- Regular dependency audits are performed to identify and patch known vulnerabilities.
7. Organizational Measures
- Access to personal data is restricted to personnel who need it to perform their job functions.
- Team members handling personal data receive guidance on data protection obligations.
- Third-party service providers are assessed for compliance and bound by data processing agreements.
- We conduct periodic reviews of our data processing activities.
8. Data Breach Response
In the event of a personal data breach, we will:
- Assess the breach within 24 hours of becoming aware of it.
- Where required by applicable law (e.g., GDPR Article 33), notify the relevant supervisory authority within 72 hours.
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Document the breach, its effects, and the remedial actions taken.
To report a suspected security issue, contact security@leanear.com.
9. Your Data Protection Rights
Under GDPR (EEA / UK users)
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure / "right to be forgotten" (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object to processing (Article 21)
- Right not to be subject to automated decision-making (Article 22)
Under CCPA / CPRA (California residents)
- Right to know what personal information is collected, used, shared, or sold.
- Right to delete personal information.
- Right to opt-out of the sale or sharing of personal information. (We do not sell personal information.)
- Right to non-discrimination for exercising CCPA rights.
- Right to correct inaccurate personal information.
- Right to limit use and disclosure of sensitive personal information.
To exercise any right, email privacy@leanear.com. We will respond within 30 days (or 45 days for CCPA requests with a single 45-day extension if needed).
10. International Data Transfers
Where we transfer personal data outside the European Economic Area or the United Kingdom, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms. Transfers to the United States are made in compliance with applicable data transfer frameworks.
11. Third-Party Data Processors
We use third-party service providers (data processors) for hosting infrastructure, email delivery, and analytics. All processors are subject to written data processing agreements that require them to maintain appropriate security, process data only on our instructions, and assist us in fulfilling data subject requests.
12. Cookies and Tracking Technologies
Däätum uses only session cookies required for login functionality. We do not set persistent tracking cookies, advertising cookies, or third-party analytics cookies at this time. You can configure your browser to refuse cookies, but doing so may prevent you from using the Platform.
13. Changes to This Policy
We review this Policy at least annually and following any significant changes to our data processing activities. We will notify you of material changes via email or in-app notice.
14. Contact and Supervisory Authority
Leanear Enterprises LLC — Data Protection
Email: privacy@leanear.com
If you are in the EEA or UK and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.