Ohu Logo OHU
COMPLIANCE & LEGAL

Privacy Policy

Effective Date: August 25, 2026  |  Version: 2.1.0  |  Data Controller: Sluxia Inc.

This Privacy Policy outlines how Sluxia Inc. ("Sluxia", "Ohu", "we", "us", or "our") collects, uses, processes, stores, and protects personal data and technical metadata when developers, organizations, and automated agents interact with the Ohu Web Intelligence Platform, REST APIs (`/ohu/api/v1/*`), and Remote Model Context Protocol (MCP) Server (`/ohu/mcp`).

1. Identity of the Data Controller

For the purposes of the European Union General Data Protection Regulation (EU GDPR 2016/679), the UK Data Protection Act, and applicable international data privacy frameworks, the designated Data Controller is:

Sluxia Inc. / Ohu Platform Division
Data Protection & Legal Compliance Department
Email Contact: ohusupport@sluxia.com
Security Officer Contact: security@sluxia.com

2. Categories of Data Collected & Processed

We collect and process personal and technical data strictly necessary to provide reliable, secure API services:

  • Developer Account Data: Email address, cryptographically hashed passwords (using 12-round `bcrypt`), subscription tier status, and billing customer identifiers.
  • API Credentials: API keys generated via the Developer Console. Secret keys are displayed once upon creation and stored in our database strictly as SHA-256 one-way cryptographic hashes.
  • HTTP Audit & Telemetry Logs: Timestamp, request method, request URI path, HTTP response status code, execution duration in milliseconds, IP address, and API key ID (for monthly quota metering and rate-limit enforcement).
  • Subscription Billing Data: Payment details, credit card metadata, and transaction records are processed directly by our PCI-DSS Level 1 certified payment processor (Stripe Inc.). We do not store raw credit card numbers.

3. Transient In-Memory Scraping Data Policy

Zero Long-Term Target Content Storage: When an API request or MCP tool call executes target web crawling, PDF conversion, RAG chunking, synthetic dataset generation, or security auditing (`ohu_crawl`, `ohu_clean_article`, `ohu_pdf_to_markdown`, `ohu_rag_chunk`, `ohu_synthetic_dataset`):

  • The target web content is fetched and processed ephemerally in volatile RAM memory.
  • Once the structured Markdown, JSON payload, or vector chunk response is returned to the client, the target HTML/DOM contents are immediately discarded from memory.
  • We do NOT retain, index, log, store, or sell target website content fetched on behalf of developers.

4. Legal Bases for Processing (EU GDPR)

Under EU GDPR Article 6, we process data based on the following legal grounds:

  • Contract Performance (Article 6(1)(b)): Account management, API request execution, key authentication, and subscription billing services.
  • Legitimate Interests (Article 6(1)(f)): Platform security, rate-limit enforcement, denial-of-service mitigation, brute-force detection, and system performance optimization.
  • Legal Obligation (Article 6(1)(c)): Compliance with tax laws, legal audits, and statutory financial reporting.

5. Third-Party Subprocessors & Infrastructure

We engage vetted third-party subprocessors adhering to stringent security and privacy standards:

Subprocessor Role / Purpose Data Center Location
Stripe Inc. Subscription Payment Processing & Billing Portal United States / Global EU Edge
Cloudflare Inc. Edge Network Protection, SSL/TLS Termination & WAF Global Distributed Edge Nodes

6. International Data Transfers

Personal data collected within the European Economic Area (EEA) or UK may be transferred to and processed in global data centers. All international transfers are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent adequacy decisions.

7. Data Subject Rights (EU GDPR & UK)

EEA and UK residents possess statutory data privacy rights:

  • Right of Access & Portability: Request copies of your personal account data and request logs in structured JSON format.
  • Right to Rectification: Request correction of inaccurate account credentials.
  • Right to Erasure ("Right to be Forgotten"): Request immediate account deletion and key invalidation by emailing ohusupport@sluxia.com.
  • Right to Restrict or Object: Object to processing based on legitimate interests.

8. US State Privacy Disclosures (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and related US state privacy statutes:

  • No Sale or Sharing of Personal Data: Ohu does NOT sell or share developer personal data, API request logs, or target web scraping data to third parties or data brokers.
  • Right to Deletion & Opt-Out: You have the right to request deletion of your personal account data without discrimination. Submit CCPA requests to ohusupport@sluxia.com.

9. Data Retention & Deletion Schedule

We retain data only as long as necessary for account fulfillment and legal obligations:

  • Developer Account Data: Retained for the duration of the active account lifecycle. Deleted within 30 days of explicit account termination request.
  • HTTP Access Logs: Automatically purged from active database tables on a rolling 30-day schedule.
  • Target Web Content: Purged immediately upon HTTP response transmission (0 seconds).

10. Contacting Privacy & Legal Compliance

For privacy inquiries, GDPR data requests, or compliance documentation:

Email: ohusupport@sluxia.com
Security Desk: security@sluxia.com
Official Web Portal: https://sluxia.com/ohu