Privacy Policy
Last Updated: September 2026
At BlueGrid Core Solutions ("we," "our," or "us"), we are uncompromisingly committed to protecting the privacy, security, and integrity of our clients' data. This Privacy Policy outlines our expansive approach to how we collect, use, process, and safeguard your personal and enterprise information when you interact with our website, our Enterprise Command Center portal, and our five specialized technology branches (collectively referred to as the "Services"). By utilizing our Services, you consent to the data practices meticulously detailed in this comprehensive policy.
1. Comprehensive Information Collection
We collect information that identifies, relates to, describes, or could reasonably be linked to you or your organization ("Personal Data"). Because we operate at the enterprise level, the data we collect spans multiple vectors of interaction:
- Contact & Identity Information: Name, business email address, corporate physical address, job title, company name, phone numbers, and emergency contact details for NOC escalations.
- Authentication & Security Credentials: Passwords (stored exclusively via salted bcrypt hashes), Multi-Factor Authentication (MFA) TOTP secrets, and secure OAuth tokens from third-party identity providers (e.g., Google Workspace).
- Billing & Financial Information: Company billing address, VAT/Tax identification numbers, authorized signatory details, and purchase order history. (Note: We use secure third-party gateways for payment processing; we do not store raw credit card numbers).
- Technical & Usage Data (Telemetry): IP addresses, browser types, User Agents (captured via our Audit Logs), and specific actions taken within the portal required for internal security audits and compliance.
- Enterprise Branch Data: Any infrastructure configurations, support tickets, project data, and meeting schedules generated while utilizing BlueGrid Digitals, Connect, Security, AI, and Managed services.
2. Strategic Utilization of Your Information
Data is the lifeblood of modern technology, but we respect its boundaries. We use your data strictly for legitimate business purposes and operational excellence, including but not limited to:
- Provision of Core Services: To seamlessly set up, operate, and maintain your cloud resources, projects, and active tickets within the Command Center.
- Proactive Security & Authentication: To definitively verify your identity utilizing JWT session tokens, enforce mandatory Multi-Factor Authentication (MFA) via TOTP, and protect against malicious activity.
- Billing & Contract Administration: To generate Subscription Invoices, track our strict 3-day billing cycles, calculate late penalty compounding fees, and manage Service Credits and Referrals.
- Newsletter Broadcasting: If subscribed, to send you enterprise security alerts, infrastructure updates, and articles (facilitated securely via the Resend email API).
- Advanced Support & Incident Response: To address critical helpdesk tickets and perform root-cause analysis on system outages.
3. Strict Data Sharing and Disclosure Protocols
BlueGrid Core Solutions adheres to a strict anti-monetization stance regarding your data. We do not, and will never, sell your Personal Data to data brokers or advertising networks. We share your data exclusively under the following carefully controlled circumstances:
- Vetted Infrastructure Providers: We share absolutely necessary data with trusted tier-1 infrastructure vendors—specifically, Neon Serverless Postgres (hosted on AWS us-west-2) for our core databases, and Resend for transactional/newsletter email delivery. These providers act strictly as Data Processors bound by uncompromising DPAs.
- Legal Compliance & Subpoenas: We may disclose information if legally compelled by a valid court order, regulation, or subpoena, or to protect the safety of BlueGrid Core Solutions. We enforce a policy of notifying you prior to compliance with legal requests whenever legally permissible.
- Corporate Restructuring: In the event of a merger, acquisition, or asset sale, your enterprise data may be transferred to the acquiring entity subject to standard confidentiality agreements.
4. Uncompromising Data Security & Retention Policies
Military-Grade Security Posture: We implement enterprise-grade technical measures to protect your data. Authentication is handled via highly secure JSON Web Tokens (JWT) stored in HttpOnly, SameSite=Lax cookies, preventing XSS extraction. Passwords are never stored in plaintext (using bcrypt), and MFA is aggressively supported utilizing standard otplib algorithms. All database communication with our Neon Postgres clusters is encrypted in transit via SSL/TLS.
Data Retention & Destruction: We retain your Personal Data, Audit Logs, and enterprise telemetry only for as long as functionally necessary. Upon termination (including automated termination resulting from consecutive unaddressed late payment penalties), all associated data is securely purged across our active databases.
5. Automated Decision-Making and Profiling
To maintain the integrity of our infrastructure, BlueGrid employs specific automated decision-making processes regarding account billing. Our system dynamically tracks invoices on a strict 3-day cycle. If an invoice remains unpaid, the system automatically applies a 5% compounding penalty. After three consecutive penalties (12 days total past due) and a final 24-hour notice, the system will automatically terminate access and purge infrastructure. You maintain the right to contest these automated decisions by submitting a priority support ticket before the final termination window closes.
6. Strict Zero-Tracking Cookie Policy
Unlike many enterprise platforms, we deploy a strict "Portal-Only" cookie policy. We categorically do NOT use third-party advertising cookies (such as Facebook Pixel or Google Ads). The cookies deployed by our portal (e.g., `accessToken`, `refreshToken`) are exclusively HttpOnly, first-party cookies utilized solely for cryptographic session management, security auditing, and user authentication.
7. Your Global Privacy Rights
Depending on your geopolitical jurisdiction (including compliance with the GDPR in Europe and POPIA in South Africa), you possess fundamental rights regarding your Personal Data. You have the absolute right to access, correct, port, delete, or restrict the processing of your Personal Data. You can independently manage your profile information, MFA settings, and Newsletter subscriptions directly within the BlueGrid Enterprise Command Center. For comprehensive data deletion requests (the "Right to be Forgotten"), please contact our support team.
8. Cross-Border Data Transfers and Data Sovereignty
As a global enterprise technology provider headquartered in Johannesburg, South Africa, your data may be transferred to, stored, and processed in high-security data center facilities operated by our strategic infrastructure partners, notably AWS (us-west-2 region) supporting our Neon Serverless Postgres architecture. We guarantee that any international transfers are governed by robust, legally binding safeguards, ensuring your data enjoys equivalent protections regardless of its geographic location.
9. Data Breach Notification Timeline (POPIA / GDPR)
In the highly unlikely event of a critical security failure resulting in the unauthorized exposure of your Personal Data, BlueGrid maintains a stringent incident response protocol. We guarantee that your Organization’s designated Super Client and the relevant regulatory authorities (such as the Information Regulator in South Africa) will be formally notified within seventy-two (72) hours of breach verification, complete with a detailed technical post-mortem and mitigation roadmap.
10. Protection of Children's Privacy (COPPA)
The BlueGrid Enterprise Command Center and our associated B2B technology branches are designed explicitly for corporate entities and adult professionals. We do not intentionally or knowingly collect Personal Data from individuals under the age of eighteen (18). If we become aware that we have inadvertently collected data from a minor, we will immediately execute protocols to purge that data from our infrastructure.
11. Continuous Evolution of this Policy
Technology and regulatory landscapes evolve rapidly. Accordingly, we reserve the right to update this Privacy Policy periodically to reflect enhancements in our security practices or changes in international regulatory requirements. Continued use of our Services following such modifications constitutes your formal acceptance of the revised policy.
12. Dedicated Data Protection Contact
Transparency is our baseline. If you harbor any questions, concerns, or technical requests regarding this Privacy Policy, our data handling architecture, or our compliance posture, please escalate your inquiry to our dedicated Data Protection Officer (DPO) at privacy@bluegridcoresolutions.co.za. Alternatively, active clients may submit a secure, high-priority support ticket directly through the portal for immediate resolution.