Effective
Privacy Policy
- Effective date
- Last updated
1. Introduction
This Privacy Policy explains how Tigunny LLC ("Tigunny," "we," "our," or "us"), a Texas limited liability company, handles information for the Conflux website, portal, and separately authorized controlled pilots (the "Services"). Our contact information appears in Section 12.
The public marketing site is static. A separate portal supports Microsoft Entra sign-in, approved identity linking, exact-tenant memberships, and governed workflow and evidence records. Real customer participation and each additional capability require their own authorization. Planned AI execution, broader integrations, billing, and marketplace features are not described here as current processing.
This notice describes information handling; it does not itself grant permission to collect customer data or enable a service. A participating organization must establish the approved purpose, handling instructions, and any required agreement before its data is processed.
2. Information We Collect
- Website requests and communications: ordinary request metadata such as IP address, browser information, requested resources, and timing may be processed by hosting and delivery services. If you email us, we receive the information you choose to send.
- Portal identity and access: Microsoft supplies validated identity information, including a stable provider identifier and available display information. Conflux records canonical identity links, tenant memberships, roles, access requests, and access decisions. Conflux does not collect or store your Microsoft password.
- Workflow and evidence: approved participants may provide organization and workspace details, process descriptions, decisions, corrections, approvals, and evidence references within an authorized workflow. The exact content depends on the approved scope.
- Device and capture administration: an authorized Edge node uses device identifiers, public keys, trust status, signed requests, and bounded operational metadata. Private device keys are not ordinary workflow content.
- Process observation: the demonstrated Edge workflow collects bounded application-only metadata and produces a human-reviewed minimized process map. It excludes screenshots, window titles, URLs, page content, browser history, keystrokes, clipboard contents, and raw workstation evidence uploads. Real-customer capture requires separate authorization.
- Signature workflows: the demonstrated DocuSign integration uses fictitious Demo exercises. Signer routing information is handled transiently for an explicitly requested envelope; Conflux retains minimized identifiers, state, and evidence hashes. Production DocuSign and real-customer signing remain gated.
The marketing-site code does not set cookies or use advertising or behavioral-analytics tools. Google Fonts requests disclose ordinary network request information to Google, such as IP address, browser information, requested resources, and a referring page when supplied. Blocking those requests leaves fallback fonts available.
The authenticated portal uses functional session and request-security cookies, including cookies needed for the Microsoft sign-in round trip and protection against forged requests. Provider sites may use their own cookies under their notices. Blocking necessary cookies can prevent sign-in or protected actions.
3. How We Use Information
- Deliver the website, respond to inquiries, and operate approved portal and pilot workflows.
- Authenticate sessions, resolve explicitly approved identity links and tenant permissions, and manage access requests, invitations, and revocation.
- Preserve workflow decisions, approvals, minimized evidence, and operational audit records.
- Monitor service health, investigate failures or suspected abuse, protect the Services, and perform approved recovery.
- Meet applicable legal obligations and the documented commitments for an authorized service.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use customer data to train foundation models. Permission to process one task does not automatically permit reuse in model training, persistent memory, or evaluation datasets.
4. AI Processing and External Providers
General AI execution and external-model routing remain planned capabilities. This policy does not identify a currently enabled inference provider or promise that most processing runs locally.
Before AI processing is introduced, its data boundary, provider or local model, purpose, retention, and permitted actions must be approved under the AI Usage Policy. The required routing order is deterministic processing, then an eligible local model, then an explicitly approved external model; failure or timeout is not permission to expand data sharing.
Customer data may be sent to an external model only under an approved configuration and terms consistent with the no-foundation-model-training commitment. Provider selection, storage location, and data retention must be reviewed for the specific service before activation.
5. Service Providers and Other Disclosures
Providers receive information only for the service they deliver. The current documented service dependencies and the separately gated signature integration are:
| Provider | Purpose | Information and availability |
|---|---|---|
| Microsoft | Azure hosting, storage, security, and operational monitoring; Entra identity; Microsoft 365 communications | Website and portal request data, approved stored records, identity information, service logs, and communications as applicable. |
| Google Fonts on the public website | Ordinary network request metadata when font resources are requested; this is not Google sign-in or an AI integration. | |
| DocuSign | Explicitly requested signature workflow | Fictitious Demo exercise data only at the demonstrated stage. Production processing needs separate Go-Live, custody, runtime, and participant approval. |
This list does not assert that every provider has the same legal role or receives every data category. Identity-provider and direct website-resource processing may also be governed by the provider’s own notices. Before real participant processing, the applicable provider roles, locations, contractual terms, and approved data categories must be confirmed.
We may disclose information to authorized recipients acting within the approved service scope, where required by law, or as necessary to protect rights and investigate abuse. Any new provider or materially expanded processing must be reviewed and disclosed before it is used.
6. Data Security
- Portal access uses Microsoft Entra authentication, explicitly approved identity links, and server-managed roles for the exact tenant. An email claim or an MSP relationship does not independently authorize tenant access.
- The documented Azure deployment uses encrypted public connections, managed identities, private access to data dependencies, and tenant row-level security. Local development uses synthetic fixtures and is not production authentication.
- Governed workflows preserve append-only decisions and audit evidence. Secret and signing-key handling uses dedicated custody boundaries; secrets must not be entered into prompts or ordinary evidence records.
- The Edge capture workflow checks approved device, source, authority, duration, and budgets. It requires human review before minimized process-map promotion.
These measures reduce risk but do not guarantee error-free or uninterrupted security. Suspected incidents should be reported to the designated pilot contact or info@tigunny.com. Applicable notification obligations and agreed incident procedures govern the response.
7. Retention and Deletion
Before customer processing begins, the approved service or pilot must specify retention periods, evidence access, deletion procedures, and any applicable legal hold. Operational logs, workflow records, signature evidence, and backups may have different justified retention requirements.
Deletion requests are reviewed against those instructions, applicable obligations, and the need to preserve required evidence. We do not promise automatic deletion from all systems within 30 days or immediate removal from backups. Service termination does not by itself erase immutable audit records.
This revised notice does not retroactively reduce a retention or deletion commitment made for previously collected information. Any applicable existing agreement or prior commitment must be addressed before a different handling rule is applied. Contact us to request access, correction, or deletion.
8. Privacy Requests
Depending on applicable law and your circumstances, you may have rights to access, correct, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent where processing relies on consent; or complain to a competent authority. Applicable exceptions and verification requirements may affect a request.
Contact info@tigunny.com with your request and the service concerned. Do not send passwords, private keys, or unnecessary sensitive information. We will verify the requester’s authority and coordinate with the relevant organization when it controls the requested records. We will handle requests and any applicable appeal or complaint rights under the law that applies.
9. Processing Locations
Tigunny is based in the United States, and the documented Conflux Azure deployment uses United States resources. This does not establish that every provider operation is confined to one region.
Before accepting processing with international transfer requirements, the relevant locations, provider terms, and any required transfer mechanism must be established for that service. This notice does not claim that Standard Contractual Clauses, a UK addendum, or a transfer assessment have already been executed for every participant.
10. Children’s Privacy
The Services are not directed to, and we do not knowingly collect personal information from, children under the age of eighteen (18). The Services are not intended for individuals subject to the U.S. Children’s Online Privacy Protection Act (COPPA). If you believe a child under 18 has provided us with personal information, contact info@tigunny.com and we will take steps to delete the information.
11. Changes to This Policy
We will version material changes and identify the effective date of an approved release. Where notice, consent, or an updated agreement is required before changed processing, we will obtain it. Publishing a revised notice does not by itself authorize a new use of information already collected.
12. Contact
Questions, requests, or complaints about this Privacy Policy or our data-handling practices may be sent to:
Email: info@tigunny.comMailing address: Tigunny LLC, 10601 Clarence Dr, Frisco, TX 75033, United States