Legal & Compliance

Corporate Governance &
Privacy Policy.

Privacy & Data ProtectionSix Tenet LLC (WY #2026-001987259)Effective: May 25, 2026Last Updated: September 3, 2026

How Six Tenet LLC collects, encrypts, processes, and safeguards client data, source code, and telemetry across all engineering engagements.

Executive Summary & Key Governance Takeaways

Zero-training guarantee: We NEVER train public AI models on your proprietary source code or client datasets.
Full GDPR, UK GDPR, and California CCPA/CPRA compliance with complete data subject request protocols.
Enterprise-grade encryption: AES-256 for databases at rest and TLS 1.3 for all data in transit.
Transparent third-party subprocessor disclosure with strict Data Processing Agreements.
01

Introduction & Data Controller Identification

Core Scope

This Privacy Policy ("Privacy Policy" or "Policy") sets forth the comprehensive data protection, privacy, and processing practices of Six Tenet LLC, a Wyoming limited liability company registered under Wyoming Secretary of State Filing ID: 2026-001987259, with its principal registered office located at 30 N Gould St Ste N, Sheridan, WY 82801, USA ("Six Tenet", "Company", "we", "us", or "our").

Six Tenet operates as a high-performance software engineering, technology consulting, and growth systems firm, providing bespoke software development, operational automation architectures, and enterprise cloud systems via https://sixtenet.com (the "Platform" or "Site") and through executed Master Services Agreements, Statements of Work (SOW), and custom client engagements (collectively, the "Services").

We recognize that data integrity, technical transparency, and client privacy are paramount. This Policy applies to all individuals, clients, prospective clients, platform users, and authorized representatives who access our Site, interact with our services, or communicate with our engineering and business operations teams.

Designated Data Controller:

Under the European Union General Data Protection Regulation (EU GDPR), United Kingdom General Data Protection Regulation (UK GDPR), and applicable United States state privacy frameworks (including the California Consumer Privacy Act as amended by the CPRA), Six Tenet LLC serves as the primary Data Controller for personal information collected through our corporate website and customer management infrastructure.

02

Categories of Information We Collect

Data Inventory

In the course of operating our digital infrastructure, scoping technical engagements, and executing software engineering services, we collect and process several categories of information:

1. Direct Personal & Commercial Identifiers

Information provided voluntarily when submitting discovery questionnaires, booking architectural consultations, requesting technical audits, or executing contracts. This includes: full name, business email address, direct phone number, corporate entity affiliation, professional title, billing address, and authorized signatory credentials.

2. Technical Infrastructure & Telemetry Data

Information automatically collected upon visiting our website or utilizing client portals: Internet Protocol (IP) addresses, approximate geographic location (city/country level derived from IP), browser specifications and user-agent string, operating system telemetry, referring/exit URLs, interaction timestamps, page latency metrics, and navigational clickstream logs.

3. Client Engineering Artifacts & Credentials

During custom development, API integration, and cloud architecture deployments, clients may provide sandbox credentials, API keys, database connection schemas, webhooks, or sample datasets. All such information is strictly governed by contractual confidentiality obligations and stored within isolated, encrypted credential vaults.

4. Transactional & Accounting Data

Records of fees billed, milestone payment dates, invoice identifiers, wire reference numbers, and payment confirmation tokens. Note: We do not store raw credit card numbers or banking passwords on our local servers; all card and merchant processing is handled via certified PCI-DSS Level 1 third-party payment gateways (e.g., Stripe).

03

AI & Automation Engineering Data Safeguards

Zero-Training Guarantee

As a specialized engineering firm that develops artificial intelligence pipelines, predictive scoring models, and autonomous workflow automations, Six Tenet adheres to strict data segregation and model integrity principles:

Strict Non-Training Guarantee for Client Data

Six Tenet LLC will NEVER utilize proprietary client source code, confidential business data, database records, or customer information to train, fine-tune, or calibrate public third-party foundation models (including but not limited to public OpenAI, Anthropic, or Meta models) without explicit, affirmative written authorization from the client.

  • Enterprise inference workloads are routed through dedicated API tiers featuring Zero Data Retention (ZDR) agreements.
  • Data processed in automation nodes (such as n8n, LangChain, or custom microservices) is transient and purged immediately upon execution completion unless persistent storage is expressly contracted.
  • All automated workflows are secured using ephemeral, least-privilege service tokens and end-to-end payload encryption.
04

Lawful Bases for Data Processing (GDPR & Global Standards)

Legal Justification

Under European data protection laws (EU GDPR Art. 6 / UK GDPR), we process personal data only when a recognized lawful basis applies:

1. Performance of Contract

Processing necessary to execute and fulfill our contractual commitments under Master Services Agreements, custom software scopes, onboarding, and milestone deliverable validation.

2. Legitimate Business Interests

Processing required to maintain network security, prevent distributed denial of service (DDoS) attacks, detect fraud, monitor web performance, and improve our engineering systems.

3. Legal & Statutory Compliance

Processing necessary to satisfy state and federal corporate reporting (e.g., Wyoming LLC compliance, IRS accounting records, Corporate Transparency Act compliance, and anti-fraud mandates).

4. Freely Given Consent

Where you have provided express consent, such as opting in to receive technical whitepapers, architectural blueprints, or subscribing to our engineering newsletter.

05

Purposes of Data Processing

Operations

We process collected information exclusively for legitimate, defined commercial and technical purposes:

  • Engineering & Platform Delivery: Provisioning custom software architectures, deploying API endpoints, configuring database schemas, and validating system logic.
  • Client Communications & Project Management: Communicating sprint progress, staging environment reviews, milestone sign-offs, and technical troubleshooting tickets.
  • Billing & Invoicing: Generating commercial invoices, managing payment schedules, reconciling transactions, and maintaining statutory accounting records.
  • Platform Security & Threat Mitigation: Monitoring server health, detecting malicious injection attacks, filtering automated spam bots, and enforcing rate limiting.
  • Analytics & Continuous Improvement: Analyzing aggregated behavioral patterns to optimize page speed, interface responsiveness, and user experience.
06

Cookies, Analytics & Tracking Technologies

Telemetry

Our website utilizes standard session cookies, persistent cookies, and lightweight tracking scripts to optimize performance and gather aggregate analytics:

Strictly Necessary Cookies:

Essential for platform navigation, security tokens, and theme preference persistence. These cannot be disabled in our systems.

Performance & Analytics Telemetry:

We utilize privacy-conscious telemetry tools (such as Google Tag Manager, Vercel Web Analytics, and Speed Insights) to evaluate server response times, core web vitals, and navigational flows. IP addresses are anonymized where feasible.

Browser Controls & GPC: You may configure your browser to reject cookies or alert you when cookies are sent. We recognize and honor affirmative Global Privacy Control (GPC) signals broadcast by supported web browsers.

07

Third-Party Subprocessors & Service Providers

Subprocessors

Six Tenet engages vetted third-party vendors and cloud infrastructure providers to support platform operations. All subprocessors are bound by stringent Data Processing Agreements (DPAs) and confidentiality covenants:

SubprocessorRole / FunctionLocationSafeguards
Vercel Inc.Edge Hosting & Serverless ComputeUnited States / Global CDNSOC 2 Type II, ISO 27001, SCCs
Supabase, Inc.Managed PostgreSQL DatabaseUnited StatesAES-256 Encryption at Rest, DPA
Stripe, Inc.Payment Processing & Merchant BillingUnited StatesPCI-DSS Level 1 Certified
Google Cloud / GTMTag Management & DiagnosticsUnited States / EUISO 27001, Data Privacy Framework
08

Cross-Border & International Data Transfers

Cross-Border

Six Tenet LLC is headquartered in Wyoming, United States. When you access our Platform or engage our Services from the European Economic Area (EEA), United Kingdom, Switzerland, Canada, or Latin America, your personal data will be transferred to and processed within the United States.

To guarantee lawful cross-border data flows, we implement appropriate contractual safeguards, including standard contractual clauses ("Standard Contractual Clauses" or "SCCs") approved by the European Commission, along with the UK International Data Transfer Addendum, supplemented by technical encryption and organizational access limits.

09

Data Retention & Archival Schedules

Retention

We retain personal information only for as long as necessary to satisfy the purposes for which it was collected, comply with legal obligations, and resolve commercial disputes:

  • Client Engagement & Project Files: Retained for the active duration of the contract plus three (3) years post-termination for warranty and support continuity, after which source code repositories are archived or transferred.
  • Financial, Billing & Tax Records: Retained for seven (7) years in accordance with United States Internal Revenue Service (IRS) and Wyoming statutory accounting mandates.
  • General Inquiries & Lead Data: Retained for up to twenty-four (24) months from the last documented interaction, or purged immediately upon verified opt-out request.
  • Server Access Logs: Automatically rotated and purged after ninety (90) days, unless retained for active cybersecurity investigation.
10

Security Architecture & Cryptographic Safeguards

Infosec

Six Tenet maintains rigorous technical, administrative, and physical controls designed to protect personal information against unauthorized access, destruction, loss, or alteration:

Cryptographic Encryption

All web traffic is enforced over Transport Layer Security (TLS 1.3). Datastores utilize AES-256 encryption at rest.

Role-Based Access (RBAC)

Access to production environments and client credentials is strictly restricted to authorized engineers on a least-privilege basis.

Multi-Factor Authentication (MFA)

Mandatory hardware or TOTP multi-factor authentication across all internal administrative tools, repositories, and cloud consoles.

Vulnerability Management

Continuous automated dependency scanning, static code analysis, and periodic penetration testing audits.

11

Your Legal Rights & Choices

GDPR & CCPA

Depending on your jurisdiction of residence (e.g., EEA, UK, California, Virginia, Colorado, Utah, Connecticut), you possess specific statutory rights regarding your personal information:

  • Right of Access / Right to Know: The right to request confirmation of whether we process your data and receive a portable copy of personal information held.
  • Right to Rectification: The right to request correction of inaccurate, outdated, or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): The right to request permanent deletion of your personal data, subject to statutory retention exceptions (e.g., tax records).
  • Right to Restrict & Object: The right to limit processing or object to processing conducted under legitimate interests.
  • California CCPA/CPRA Notice: We do NOT sell personal information and have not sold personal information in the preceding 12 months. We do NOT share personal information for cross-context behavioral advertising without affirmative consent. You have the right to non-discrimination for exercising privacy rights.

Exercising Your Rights: To submit a verifiable data subject request, email our compliance desk at privacy@sixtenet.com. We verify your identity prior to fulfilling requests and respond within forty-five (45) days (or thirty (30) days for GDPR inquiries).

12

Children's Privacy (COPPA Compliance)

Minors

Six Tenet provides business-to-business (B2B) enterprise engineering and technology consulting services. Our Platform and Services are not directed to individuals under the age of 18 (or under 13 for COPPA purposes).

We do not knowingly collect, maintain, or solicit personal data from children. If we discover that personal information of a minor has been collected inadvertently, we will take immediate measures to permanently purge such data from our systems.

13

Policy Amendments & Notification Protocols

Updates

We reserve the right to modify this Privacy Policy periodically to reflect technological evolutions, operational refinements, or statutory updates.

When material changes occur, we will update the "Last Updated" date at the top of this document. For significant modifications impacting active client engagements, we will provide advance notification via electronic mail or prominent portal announcement. Continued use of our Platform or Services following posted modifications constitutes acknowledgment and acceptance of the revised terms.

14

Contact Information & Compliance Desk

Contact

For questions, legal notices, or to exercise your statutory privacy rights, please direct formal correspondence to:

Six Tenet LLC — Legal & Privacy Compliance Office

Entity Registration: Wyoming Secretary of State ID: 2026-001987259

Registered Address: 30 N Gould St Ste N, Sheridan, WY 82801, USA

Direct Privacy Inquiries: privacy@sixtenet.com

General Legal Counsel: legal@sixtenet.com

Corporate Operations: info@sixtenet.com

Have questions regarding this policy?

Our compliance desk is available to assist enterprise clients with bespoke Master Services Agreements (MSAs) and Data Processing Agreements (DPAs).

Contact Legal