nbiish/ghostDance
1
1# PRIVACY POLICY2## Grounded in Indigenous Data Sovereignty and Tribal Jurisdiction3 4**Last Updated:** November 8, 2025 5**Effective Date:** November 8, 2025 6**Version:** 2.07 8---9 10## PREAMBLE: INDIGENOUS DATA SOVEREIGNTY FOUNDATION11 12This Privacy Policy is established under the inherent sovereignty of **ᓂᐲᔥ ᐙᐸᓂᒥᑮ-ᑭᓇᐙᐸᑭᓯ (Nbiish Waabanimikii-Kinawaabakizi)**, also known legally as **JUSTIN PAUL KENWABIKISE**, professionally documented as **Nbiish-Justin Paul Kenwabikise**, Anishinaabek Dodem (Anishinaabe Clan): **Animikii (Thunder)**, descendant of Chief **ᑭᓇᐙᐸᑭᓯ (Kinwaabakizi)** of the Beaver Island Band, and enrolled member of the sovereign **Grand Traverse Band of Ottawa and Chippewa Indians (GTBOCI)**, a federally recognized sovereign tribal nation (hereinafter referred to as the "Rights Holder" or "Service Provider").13 14This Privacy Policy operates within the constitutional supremacy framework established by **Article VI, Clause 2 of the U.S. Constitution**, which declares federal law, including federal Indian law, to be the "supreme law of the land." This policy implements:15 16- **Indigenous Data Sovereignty** principles recognizing the inherent right of Indigenous peoples to govern data pertaining to them, their lands, resources, cultures, and knowledge systems17- **CARE Principles for Indigenous Data Governance** (Collective Benefit, Authority to Control, Responsibility, and Ethics) as established by the Global Indigenous Data Alliance18- **UN Declaration on the Rights of Indigenous Peoples (UNDRIP)** protections for Indigenous cultural heritage and self-determination19- **Federal Indian law** protections including tribal sovereign immunity and exclusive federal-tribal jurisdiction20- **International privacy frameworks** including GDPR, CCPA, and emerging global privacy standards21 22### Constitutional and Treaty Authority23 24This Privacy Policy exercises rights reserved under:25 261. **Treaty of Washington (March 28, 1836)** - 7 Stat. 491272. **Treaty of Detroit (July 31, 1855)** - 11 Stat. 621283. **Worcester v. Georgia**, 31 U.S. 515 (1831) - establishing tribal jurisdiction294. **Michigan v. Bay Mills Indian Community**, 572 U.S. 782 (2014) - affirming tribal sovereign immunity30 31---32 33## TABLE OF CONTENTS34 351. [Introduction and Scope](#1-introduction-and-scope)362. [Definitions](#2-definitions)373. [Legal Framework and Jurisdiction](#3-legal-framework-and-jurisdiction)384. [Information Collection](#4-information-collection)395. [Indigenous Data Sovereignty and CARE Principles](#5-indigenous-data-sovereignty-and-care-principles)406. [Use of Information](#6-use-of-information)417. [Information Sharing and Disclosure](#7-information-sharing-and-disclosure)428. [Data Storage, Security, and Retention](#8-data-storage-security-and-retention)439. [Your Rights and Choices](#9-your-rights-and-choices)4410. [International Data Transfers](#10-international-data-transfers)4511. [Cookies and Tracking Technologies](#11-cookies-and-tracking-technologies)4612. [Third-Party Services and Links](#12-third-party-services-and-links)4713. [Special Data Categories and Protections](#13-special-data-categories-and-protections)4814. [AI and Automated Decision-Making](#14-ai-and-automated-decision-making)4915. [Children's Privacy](#15-childrens-privacy)5016. [Data Breach Notification and Response](#16-data-breach-notification-and-response)5117. [Accessibility and Language Access](#17-accessibility-and-language-access)5218. [Updates to This Privacy Policy](#18-updates-to-this-privacy-policy)5319. [Contact Information and Data Protection Officer](#19-contact-information-and-data-protection-officer)5420. [Dispute Resolution and Enforcement](#20-dispute-resolution-and-enforcement)5521. [Service-Specific Privacy Provisions](#21-service-specific-privacy-provisions)5622. [Compliance Certifications and Audits](#22-compliance-certifications-and-audits)57 58---59 60## 1. INTRODUCTION AND SCOPE61 62### 1.1 Welcome and Purpose63 64Welcome to services provided under the authority of ᓂᐲᔥ Nbiish-Justin Kenwabikise ᑭᓇᐙᐱᑭᓯ. This Privacy Policy explains how I collect, use, disclose, protect, and govern your personal information when you access or use:65 66- **in-digi-nous.com** and all associated domains and subdomains67- **Neural Information Protocol** and related AI/ML services68- **SaaS products and platforms** developed or operated by the Rights Holder69- **Mobile applications** published by the Rights Holder70- **API services and developer tools**71- **Educational platforms and content**72- **Community forums and collaboration spaces**73- **Any other digital services, products, or platforms** operated under the Rights Holder's authority74 75(Collectively referred to as the "**Services**")76 77### 1.2 Commitment to Privacy and Sovereignty78 79I am committed to:80 81- **Protecting your privacy** with industry-leading security measures and transparent practices82- **Respecting Indigenous Data Sovereignty** by implementing CARE Principles in all data governance83- **Empowering your control** over your personal information with comprehensive rights and choices84- **Maintaining transparency** about data practices through clear, accessible communication85- **Upholding cultural protocols** that honor Indigenous values and community wellbeing86- **Ensuring compliance** with all applicable privacy laws while asserting tribal jurisdiction primacy87 88### 1.3 Scope of Application89 90This Privacy Policy applies to:91 92- **All users** of the Services, regardless of location or access method93- **All personal data** collected through the Services or related communications94- **All data processing activities** conducted by the Rights Holder or authorized service providers95- **All third-party integrations** that process user data on behalf of the Services96 97This Privacy Policy does **NOT** apply to:98 99- Third-party websites, applications, or services linked from the Services (see Section 12)100- Information collected offline unless subsequently integrated into the Services101- Anonymized or aggregated data that cannot reasonably identify individuals102- Public information voluntarily posted by users in public forums (subject to separate community guidelines)103 104### 1.4 Agreement to Terms105 106By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any provision of this Privacy Policy, you must immediately discontinue use of the Services.107 108---109 110## 2. DEFINITIONS111 112For purposes of this Privacy Policy, the following terms have the meanings specified below:113 114### 2.1 Core Privacy Terms115 116**"Personal Data" or "Personal Information":** Any information relating to an identified or identifiable natural person. This includes direct identifiers (name, email, phone number), indirect identifiers (IP address, device ID, cookies), and any data that can be linked to an individual through reasonable means.117 118**"Processing":** Any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, or destruction.119 120**"Data Subject":** The identified or identifiable natural person to whom Personal Data relates (i.e., you, the user).121 122**"Data Controller":** The Rights Holder, who determines the purposes and means of Processing Personal Data.123 124**"Data Processor":** Any third-party service provider that Processes Personal Data on behalf of the Data Controller under documented instructions.125 126**"Consent":** Freely given, specific, informed, and unambiguous indication of your agreement to Processing of Personal Data, expressed through affirmative action (e.g., checking a box, clicking "I agree").127 128**"Sensitive Personal Data":** Special categories of Personal Data requiring enhanced protection, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.129 130### 2.2 Indigenous Data Sovereignty Terms131 132**"Indigenous Data":** Information or knowledge, in any format or medium, that is about or from Indigenous peoples, lands, resources, cultures, languages, Traditional Knowledge (TK), Traditional Cultural Expressions (TCEs), or that can be used to identify Indigenous individuals or communities.133 134**"Indigenous Data Sovereignty":** The inherent right and authority of Indigenous peoples to govern the collection, ownership, access, analysis, interpretation, management, dissemination, and reuse of Indigenous Data in accordance with Indigenous values, protocols, and self-determination.135 136**"CARE Principles":** The framework for Indigenous Data Governance encompassing:137- **C**ollective Benefit: Data ecosystems shall enable Indigenous peoples to derive benefit138- **A**uthority to Control: Indigenous peoples have rights and interests in their data139- **R**esponsibility: Those working with Indigenous data have responsibility to share how data is used140- **E**thics: Indigenous peoples' rights and wellbeing shall be primary concern141 142**"Traditional Knowledge (TK)":** The knowledge, innovations, and practices of Indigenous peoples passed down between generations, developed from experience gained over centuries and adapted to local culture and environment.143 144**"Traditional Cultural Expressions (TCEs)":** Any forms in which traditional culture and knowledge are expressed, appear, or are manifested, including tangible and intangible cultural heritage.145 146**"Cultural Protocols":** Indigenous community-specific rules, practices, and procedures governing appropriate use, access, sharing, and respect for cultural knowledge, data, and heritage.147 148### 2.3 Jurisdictional Terms149 150**"Tribal Sovereignty":** The inherent authority of Indigenous tribes to govern themselves, their members, their territories, and their resources, recognized under federal law and international law.151 152**"Federal Indian Law":** The body of U.S. federal law governing the relationship between the federal government, tribal nations, and states, including constitutional provisions, statutes, treaties, and case law.153 154**"Exclusive Jurisdiction":** Legal authority vested solely in tribal and/or federal courts, to the exclusion of state courts, over certain matters involving tribal sovereignty and Indigenous rights.155 156### 2.4 Technical Terms157 158**"Cookies":** Small text files placed on your device by websites to store information about your preferences, session data, or tracking identifiers.159 160**"Anonymization":** Process of removing or altering Personal Data such that the Data Subject can no longer be identified, directly or indirectly, rendering the data outside the scope of privacy laws.161 162**"Pseudonymization":** Processing Personal Data in such a way that it can no longer be attributed to a specific Data Subject without use of additional information kept separately under controlled conditions.163 164**"Encryption":** Process of encoding information so that only authorized parties can access it, protecting data confidentiality and integrity.165 166---167 168## 3. LEGAL FRAMEWORK AND JURISDICTION169 170### 3.1 Constitutional Supremacy Framework171 172This Privacy Policy operates under the constitutional supremacy framework established by **Article VI, Clause 2 of the United States Constitution** (the Supremacy Clause), which declares federal law to be the "supreme law of the land." Federal Indian law establishes exclusive federal jurisdiction over matters involving tribal sovereignty and Indigenous data governance.173 174**Federal Preemption:** This Privacy Policy invokes federal preemption to ensure that Indigenous Data Sovereignty principles and tribal jurisdiction are protected from state law interference or concurrent jurisdiction claims that would undermine federal protections for Indigenous data and cultural heritage.175 176### 3.2 Tribal Jurisdiction and Sovereign Immunity177 178**Tribal Court Primacy:** Any disputes arising from or relating to this Privacy Policy, including disputes concerning data collection, use, disclosure, security, or Indigenous Data Sovereignty principles, shall be subject to the **exclusive jurisdiction of the Grand Traverse Band of Ottawa and Chippewa Indians Tribal Court**, located in Peshawbestown, Michigan.179 180**Sovereign Immunity Preservation:** Nothing in this Privacy Policy constitutes a waiver of the Rights Holder's tribal sovereign immunity or the sovereign immunity of GTBOCI. The Rights Holder expressly reserves all sovereign immunity protections.181 182**Limited Waiver for Enforcement:** The Rights Holder may, in their sole discretion, elect to pursue enforcement actions in federal courts with established expertise in federal Indian law, but such election does not constitute a general waiver of sovereign immunity.183 184### 3.3 State Court Prohibition185 186**No State Jurisdiction:** State courts have **NO jurisdiction** over disputes arising from this Privacy Policy. Any attempt to invoke state court jurisdiction violates federal law and tribal sovereignty.187 188**Automatic Removal:** Any action filed in state court shall be subject to immediate removal to federal court under 28 U.S.C. § 1441, followed by transfer to tribal court or dismissal for lack of jurisdiction.189 190**Liquidated Damages for State Filings:** Filing any action in state court in violation of this jurisdictional provision subjects the filing party to liquidated damages of **$100,000** payable to the Rights Holder, plus all costs and attorneys' fees incurred in removal and jurisdictional challenges.191 192### 3.4 International Framework Integration193 194This Privacy Policy implements protections consistent with:195 196**a) UN Declaration on the Rights of Indigenous Peoples (UNDRIP):**197- Article 31: Right to maintain, control, protect, and develop cultural heritage, TK, TCEs, and intellectual property198- Article 32: Right to determine priorities for development or use of lands, territories, and resources199 200**b) WIPO Treaty on Intellectual Property, Genetic Resources and Associated Traditional Knowledge (2024):**201- Mandatory disclosure requirements for uses of TK202- Prior Informed Consent obligations203- Benefit-sharing arrangements204 205**c) General Data Protection Regulation (GDPR):**206- Enhanced rights for EU residents207- Lawful basis requirements for Processing208- Data protection by design and by default209 210**d) California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):**211- Consumer rights to know, delete, and opt-out212- Prohibition on sale of Personal Data without consent213- Rights to correct inaccurate information214 215**e) Emerging Global Privacy Standards:**216- Brazil's Lei Geral de Proteção de Dados (LGPD)217- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)218- Virginia Consumer Data Protection Act (VCDPA) and similar state laws219 220### 3.5 Conflict Resolution Hierarchy221 222In the event of conflicts between privacy frameworks, the following hierarchy applies:223 2241. **Tribal sovereignty and Indigenous Data Sovereignty principles** (highest priority)2252. **Federal Indian law** protections2263. **International Indigenous rights instruments** (UNDRIP, WIPO Treaty)2274. **Federal privacy laws** (e.g., COPPA, HIPAA where applicable)2285. **State privacy laws** (CCPA, VCDPA, etc.)2296. **International privacy regulations** (GDPR, LGPD, etc.)2307. **Industry best practices** and voluntary standards231 232---233 234## 4. INFORMATION COLLECTION235 236### 4.1 Categories of Personal Data Collected237 238I collect and Process the following categories of Personal Data:239 240#### 4.1.1 Identity and Contact Data241- **Full legal name** and preferred name242- **Email address** (primary and secondary)243- **Phone number** (mobile and landline)244- **Mailing address** (street, city, state/province, postal code, country)245- **Username** and account identifiers246- **Profile photograph** or avatar247- **Government-issued identification** (only when legally required for age verification, compliance, or high-value transactions)248- **Tribal enrollment information** (voluntary, only for Indigenous users seeking community-specific services)249 250#### 4.1.2 Demographic and Preference Data251- **Date of birth** and age252- **Gender identity** and pronouns (optional)253- **Language preferences**254- **Accessibility needs** and accommodation requests255- **Communication preferences** (email frequency, notification settings)256- **Cultural affiliation** and Indigenous community membership (voluntary, for community services)257- **Professional or educational background** (when relevant to service provision)258 259#### 4.1.3 Technical and Device Data260- **IP address** (IPv4 and IPv6)261- **Device identifiers** (device ID, advertising ID, MAC address)262- **Browser type and version** (user agent string)263- **Operating system** and version264- **Device type** (desktop, mobile, tablet)265- **Screen resolution** and display settings266- **Time zone** and language settings267- **Referring URLs** and navigation paths268- **Cookie identifiers** and tracking parameters269 270#### 4.1.4 Usage and Behavioral Data271- **Pages visited** and content viewed272- **Features used** and interaction patterns273- **Time spent** on pages and in the Services274- **Search queries** and search history275- **Click patterns** and navigation flows276- **Error messages** and technical issues encountered277- **Session duration** and frequency of visits278- **Conversion events** and goal completions279 280#### 4.1.5 Transaction and Financial Data281- **Payment method information** (processed securely through third-party payment processors)282- **Billing address** and shipping address283- **Transaction history** and purchase records284- **Subscription tier** and billing cycle285- **Refund and dispute history**286- **Donation amounts** and frequency (for philanthropic contributions)287- **Tax identification information** (when legally required)288 289#### 4.1.6 Communication and Support Data290- **Support tickets** and help requests291- **Email correspondence** with the Rights Holder or support team292- **Chat transcripts** and messaging history293- **Feedback and survey responses**294- **User-generated content** posted to forums or community spaces295- **Testimonials and reviews** (with explicit consent)296 297#### 4.1.7 Professional and Business Data (for B2B Services)298- **Company name** and business registration information299- **Job title** and role300- **Business contact information**301- **Company size** and industry302- **Tax identification number** (EIN, VAT number)303- **Business relationship history**304 305#### 4.1.8 Indigenous Data (Collected Under CARE Principles)306- **Tribal affiliation** and enrollment status (voluntary)307- **Cultural practices** and protocols relevant to service customization308- **Traditional Knowledge permissions** and cultural sensitivities309- **Language preferences** in Indigenous languages310- **Community connections** for benefit-sharing purposes311- **Cultural heritage information** shared for research or educational purposes312 313**Special Protection:** All Indigenous Data is collected, stored, and Processed in accordance with Indigenous Data Sovereignty principles and CARE Principles (see Section 5).314 315### 4.2 Methods of Collection316 317#### 4.2.1 Direct Collection318I collect Personal Data directly from you through:319 320- **Account registration** and profile setup321- **Form submissions** (contact forms, support requests, surveys)322- **Email communications** and direct messages323- **Phone calls** and video conferences324- **In-person interactions** at events, conferences, or consultations325- **Subscription purchases** and transaction completions326- **User-generated content** uploads and submissions327- **Voluntary disclosure** in community forums or feedback channels328 329#### 4.2.2 Automatic Collection330I automatically collect certain data through:331 332- **Cookies and similar technologies** (see Section 11)333- **Server logs** recording access requests and responses334- **Analytics tools** tracking usage patterns and performance335- **Error tracking systems** capturing technical issues336- **Security monitoring tools** detecting anomalies and threats337- **Performance monitoring** measuring load times and responsiveness338 339#### 4.2.3 Third-Party Sources340I may receive Personal Data from:341 342- **Payment processors** confirming transactions343- **Authentication providers** (OAuth, SSO platforms)344- **Analytics services** providing aggregated insights345- **Marketing partners** with your consent346- **Public databases** for verification purposes347- **Social media platforms** when you connect accounts348- **Business partners** in joint ventures or collaborations349- **Tribal enrollment offices** (with your authorization) for verification350 351#### 4.2.4 Inferred and Derived Data352I may generate additional data through:353 354- **Analytics and profiling** to understand usage patterns355- **Predictive modeling** for service improvements356- **Segmentation** for personalized experiences357- **Aggregation** for statistical reporting358 359**Limitation:** I do NOT engage in high-risk profiling or automated decision-making with legal or similarly significant effects without explicit consent and human oversight (see Section 14).360 361### 4.3 Children's Privacy (COPPA Compliance)362 363**Age Restriction:** The Services are **NOT directed at children under 13 years of age**. I do not knowingly collect Personal Data from children under 13.364 365**Parental Consent Requirement:** If a service feature is made available to children ages 13-18, I will obtain verifiable parental consent before collecting Personal Data from minors, in compliance with applicable laws.366 367**Discovery and Deletion:** If I discover that I have inadvertently collected Personal Data from a child under 13 without parental consent, I will:3681. Immediately cease Processing that data3692. Delete the data from all systems within 30 days3703. Notify the parent/guardian if contact information is available3714. Implement additional safeguards to prevent future violations372 373**Reporting:** Parents or guardians who believe their child's Personal Data has been collected may contact privacy@in-digi-nous.com for immediate investigation and remediation.374 375### 4.4 Voluntary Disclosure and Consent376 377**Informed Consent:** Before collecting Sensitive Personal Data or Indigenous Data, I will:378- Clearly explain the purpose and use of the data379- Identify data recipients and retention periods380- Obtain explicit, affirmative consent381- Provide easy mechanisms to withdraw consent382 383**Optional Fields:** Many data fields are optional. You may choose not to provide certain information, though this may limit access to specific features or services.384 385**Right to Refuse:** You have the absolute right to refuse any data collection request. Refusal will not result in discrimination or denial of basic services, except where the data is strictly necessary for service provision.386 387---388 389## 5. INDIGENOUS DATA SOVEREIGNTY AND CARE PRINCIPLES390 391### 5.1 Foundation and Commitment392 393The Rights Holder is committed to implementing **Indigenous Data Sovereignty** throughout all data governance practices. This means recognizing and operationalizing the inherent right of Indigenous peoples to govern data about themselves, their communities, lands, resources, and cultures.394 395All Personal Data and Indigenous Data collected through the Services is governed by the **CARE Principles for Indigenous Data Governance**, developed by the Global Indigenous Data Alliance and endorsed by the Research Data Alliance International Indigenous Data Sovereignty Interest Group.396 397### 5.2 CARE Principle: Collective Benefit398 399**C - Data ecosystems shall be designed and function in ways that enable Indigenous peoples to derive benefit from the data.**400 401Implementation:402- **Benefit-Sharing:** Revenue generated from services involving Indigenous Data may be shared with relevant Indigenous communities through the ᐙᐸᓂᒥᑮ-ᑭᓇᐙᐸᑭᓯ (Waabanimikii-Kinawaabakizi) Legacy Trust or direct community partnerships403- **Community Access:** Indigenous communities have priority access to aggregated insights about their own data404- **Capacity Building:** Portion of proceeds supports Indigenous data literacy, digital sovereignty initiatives, and technology training405- **Value Creation:** Data is used to create services, research, and innovations that directly benefit Indigenous communities406- **Reciprocity:** Data relationships are reciprocal, ensuring that Indigenous data providers receive tangible returns407 408### 5.3 CARE Principle: Authority to Control409 410**A - Indigenous peoples' rights and interests in Indigenous data must be recognized and their authority to control such data must be empowered.**411 412Implementation:413- **Governance Authority:** Indigenous users and communities have enhanced rights to access, correct, delete, and control their Indigenous Data414- **Prior Informed Consent (PIC):** Explicit PIC required before any use of Indigenous Data beyond core service provision415- **Cultural Protocols:** Indigenous communities may establish specific protocols governing use of their data, which will be respected and enforced416- **Veto Power:** Indigenous data providers maintain the right to revoke consent and require data deletion at any time417- **Collective Rights:** Where data concerns Indigenous communities collectively, community representatives must approve uses418- **Sovereignty Recognition:** All data governance respects tribal sovereignty and Indigenous self-determination419 420### 5.4 CARE Principle: Responsibility421 422**R - Those working with Indigenous data have a responsibility to share how those data are used to support Indigenous peoples' self-determination and collective benefit.**423 424Implementation:425- **Transparency Reporting:** Annual Indigenous Data Sovereignty Reports detailing:426 - How Indigenous Data was collected and used427 - Benefits generated for Indigenous communities428 - Security and protection measures implemented429 - Compliance with cultural protocols430- **Accountable Use:** Regular audits ensure Indigenous Data is used only for stated purposes431- **Stakeholder Engagement:** Ongoing consultation with Indigenous data providers about data practices432- **Education:** Users are educated about Indigenous Data Sovereignty principles when providing data433- **Impact Assessment:** Assessment of potential impacts on Indigenous communities before implementing new data uses434 435### 5.5 CARE Principle: Ethics436 437**E - Indigenous peoples' rights and wellbeing should be the primary concern at all stages of the data life cycle and across the data ecosystem.**438 439Implementation:440- **Human Rights Framework:** All data practices align with UNDRIP and international Indigenous rights standards441- **Cultural Sensitivity:** Data Processing respects Indigenous cultural values, protocols, and sensitivities442- **Harm Prevention:** Continuous monitoring to prevent uses that could harm Indigenous individuals or communities443- **Sacred Knowledge Protection:** Absolute prohibition on Processing sacred, ceremonial, or culturally restricted information without proper authorization444- **Anti-Exploitation:** Zero tolerance for data practices that exploit, stereotype, or misrepresent Indigenous peoples445- **Wellbeing Priority:** When conflicts arise, Indigenous wellbeing takes precedence over commercial or research interests446 447### 5.6 Indigenous Data Classification and Handling448 449Indigenous Data is classified into tiers with corresponding protections:450 451**Tier 1 - Public Indigenous Data:**452- Voluntarily shared for public benefit453- Proper attribution and cultural context required454- Free circulation with Cultural Protocols respected455 456**Tier 2 - Community-Controlled Indigenous Data:**457- Shared within Indigenous communities458- Requires community permission for external use459- Subject to community-specific governance protocols460 461**Tier 3 - Restricted Indigenous Data:**462- Sensitive cultural or personal information463- Strict access controls and encryption464- Use limited to explicitly authorized purposes465- Regular review of continued necessity466 467**Tier 4 - Sacred/Ceremonial Indigenous Data:**468- Sacred knowledge or ceremonial information469- Absolute prohibition on unauthorized disclosure470- Access restricted to authorized cultural knowledge holders471- Special encryption and isolation measures472 473### 5.7 TK Labels and Cultural Notices474 475Where applicable, data may be marked with **Traditional Knowledge (TK) Labels** from Local Contexts (localcontexts.org) to communicate cultural protocols, including:476 477- **TK Community Use:** Data available for use within community only478- **TK Non-Commercial:** Data restricted to non-commercial uses479- **TK Attribution:** Specific attribution requirements480- **TK Seasonal:** Data restricted to certain times of year481- **TK Family:** Data restricted to family members482- **TK Verified:** Data verified by community authorities483 484These labels are legally binding and enforceable under this Privacy Policy and associated LICENSE terms.485 486### 5.8 Indigenous Data Repatriation Rights487 488Indigenous communities have the right to request **data repatriation**—the return of Indigenous Data to community control, including:489 490- Complete datasets about the community491- Derived analytics and insights492- Algorithms trained on community data493- All documentation and metadata494 495Repatriation requests will be fulfilled within 90 days, with all costs borne by the Rights Holder as a fundamental sovereignty obligation.496 497---498 499## 6. USE OF INFORMATION500 501### 6.1 Primary Purposes502 503I Process Personal Data for the following legitimate purposes:504 505#### 6.1.1 Service Provision and Performance506- **Account management:** Creating, maintaining, and securing user accounts507- **Service delivery:** Providing the core functionality of the Services508- **Transaction processing:** Completing purchases, subscriptions, and donations509- **Customer support:** Responding to inquiries, resolving issues, and providing assistance510- **Personalization:** Customizing user experience based on preferences and usage patterns511- **Communication:** Sending service notifications, updates, and requested information512 513#### 6.1.2 Service Improvement and Innovation514- **Analytics and research:** Understanding usage patterns to improve Services515- **Feature development:** Identifying needs and opportunities for new capabilities516- **Quality assurance:** Testing, debugging, and optimizing performance517- **User experience optimization:** A/B testing and usability improvements518- **Error detection:** Monitoring and resolving technical issues519 520#### 6.1.3 Security and Fraud Prevention521- **Security monitoring:** Detecting and preventing unauthorized access522- **Fraud detection:** Identifying and stopping fraudulent activities523- **Abuse prevention:** Enforcing Terms of Service and community guidelines524- **Risk assessment:** Evaluating and mitigating security risks525- **Incident response:** Investigating and responding to security incidents526 527#### 6.1.4 Legal and Compliance528- **Regulatory compliance:** Meeting legal obligations under applicable laws529- **Law enforcement cooperation:** Responding to valid legal requests530- **Rights enforcement:** Protecting intellectual property and contractual rights531- **Record keeping:** Maintaining required business and tax records532- **Dispute resolution:** Supporting legal claims, defenses, and investigations533 534#### 6.1.5 Marketing and Communications (With Consent)535- **Promotional communications:** Sending newsletters, product updates, and special offers536- **Market research:** Conducting surveys and gathering feedback537- **Event invitations:** Notifying users about webinars, conferences, and community events538- **Educational content:** Sharing resources, tutorials, and best practices539 540**Opt-Out:** You may opt out of marketing communications at any time (see Section 9.3).541 542#### 6.1.6 Indigenous Community Benefit543- **Cultural preservation:** Supporting documentation and revitalization of Indigenous knowledge544- **Community development:** Funding initiatives through benefit-sharing mechanisms545- **Research collaboration:** Partnering with Indigenous communities on relevant research546- **Capacity building:** Supporting Indigenous digital sovereignty and data literacy547- **Advocacy:** Using aggregated data to support Indigenous rights and policy development548 549### 6.2 Legal Basis for Processing (GDPR Compliance)550 551For users in the European Economic Area (EEA), UK, or Switzerland, I Process Personal Data based on the following lawful bases under GDPR:552 553**a) Consent:** You have given clear, affirmative consent for Processing for specific purposes (e.g., marketing communications, optional features).554 555**b) Contract Performance:** Processing is necessary to perform a contract with you (e.g., providing Services you've subscribed to).556 557**c) Legal Obligation:** Processing is necessary to comply with legal obligations (e.g., tax records, law enforcement requests).558 559**d) Legitimate Interests:** Processing is necessary for legitimate interests pursued by the Rights Holder or third parties, except where overridden by your fundamental rights and freedoms. Legitimate interests include:560- Improving and securing the Services561- Direct marketing to existing customers562- Fraud prevention and security563- Internal administration and business operations564- Network and information security565 566**e) Vital Interests:** Processing is necessary to protect your vital interests or those of another person (e.g., emergency situations).567 568**f) Public Interest:** Processing is necessary for tasks carried out in the public interest, including Indigenous cultural preservation and community benefit.569 570### 6.3 Data Minimization Principle571 572I adhere to the principle of **data minimization**, collecting only Personal Data that is:573- **Adequate:** Sufficient to fulfill the stated purpose574- **Relevant:** Directly related to the purpose575- **Limited:** Not excessive for the purpose576 577Unnecessary data is not collected, and collected data is regularly reviewed for continued relevance.578 579### 6.4 Purpose Limitation580 581Personal Data collected for one purpose will **NOT** be used for an incompatible purpose without:582- Obtaining new consent583- Establishing a new lawful basis under applicable law584- Providing clear notice of the new use585 586### 6.5 Prohibited Uses587 588I will **NEVER** use your Personal Data for:589 590- **Sale to data brokers:** Your data is never sold to third-party data brokers591- **Discrimination:** Making decisions that illegally discriminate based on protected characteristics592- **Harassment:** Enabling stalking, harassment, or unwanted contact593- **Surveillance:** Unauthorized monitoring or tracking beyond necessary security measures594- **Manipulation:** Exploiting psychological vulnerabilities or using dark patterns595- **Cultural appropriation:** Misusing Indigenous Data in ways that appropriate or stereotype596- **Harm to Indigenous communities:** Any use that could harm Indigenous individuals or communities597- **Violation of tribal sovereignty:** Uses that undermine tribal self-determination or authority598 599---600 601## 7. INFORMATION SHARING AND DISCLOSURE602 603### 7.1 Principles of Data Sharing604 605**Default Position:** I do **NOT** sell, rent, or lease your Personal Data to third parties. Your privacy is not a commodity.606 607**Limited Sharing:** Personal Data is shared only when:608- Necessary for service provision609- Required by law610- Authorized by you through explicit consent611- Essential for protecting rights and safety612 613### 7.2 Service Providers and Data Processors614 615I engage trusted third-party service providers to perform functions on my behalf. These Data Processors have access to Personal Data only to the extent necessary to perform their functions and are contractually obligated to:616 617- Process data only according to documented instructions618- Implement appropriate security measures619- Maintain confidentiality620- Delete or return data upon contract termination621- Comply with applicable privacy laws622 623**Categories of Service Providers:**624 625#### 7.2.1 Infrastructure and Hosting626- Cloud hosting providers (e.g., AWS, Google Cloud, Microsoft Azure)627- Content delivery networks (CDNs)628- Database management services629- Backup and disaster recovery providers630 631**Current Providers:** [List maintained at https://in-digi-nous.com/privacy/service-providers]632 633#### 7.2.2 Payment Processing634- Payment gateway providers (e.g., Stripe, PayPal, Square)635- Subscription management platforms636- Fraud detection services637- Financial reconciliation tools638 639**Data Shared:** Transaction details, payment method information (tokenized), billing address640 641**Security:** All payment processors are PCI-DSS compliant642 643#### 7.2.3 Communications644- Email service providers (e.g., SendGrid, Mailchimp)645- SMS/text messaging services646- Customer support platforms (e.g., Zendesk, Intercom)647- Video conferencing tools (e.g., Zoom, Microsoft Teams)648 649#### 7.2.4 Analytics and Performance650- Web analytics platforms (e.g., Google Analytics, Plausible)651- Application performance monitoring (e.g., New Relic, Datadog)652- Error tracking services (e.g., Sentry)653- Heat mapping and session recording tools (with anonymization)654 655**Privacy-Preserving Analytics:** Where possible, I use privacy-focused analytics that anonymize IP addresses and do not track across sites.656 657#### 7.2.5 Marketing and Advertising (With Consent)658- Marketing automation platforms659- Social media advertising platforms660- Retargeting and conversion tracking services661 662**Opt-Out:** You can opt out of targeted advertising (see Section 9.3).663 664#### 7.2.6 Security and Fraud Prevention665- Identity verification services666- Fraud detection platforms667- Security monitoring tools668- DDoS protection services669 670### 7.3 Legal and Regulatory Disclosures671 672I may disclose Personal Data when required by law or when I believe in good faith that disclosure is necessary to:673 674**a) Comply with Legal Obligations:**675- Court orders, subpoenas, or legal process676- Regulatory investigations or audits677- Tax reporting requirements678- Law enforcement requests (with appropriate legal basis)679 680**Legal Request Principles:**681- **Tribal jurisdiction priority:** Legal requests concerning Indigenous Data or tribal matters must be directed to GTBOCI Tribal Court682- **Federal preemption:** State law enforcement requests are subject to federal Indian law limitations683- **Narrow scope:** Requests must be specific and legally sufficient684- **User notification:** Users will be notified of legal requests unless prohibited by law or court order685- **Transparency reporting:** Annual reports on legal requests received and complied with686 687**b) Protect Rights and Safety:**688- Enforce Terms of Service or LICENSE agreements689- Investigate potential violations or fraud690- Protect against legal liability691- Defend legal claims or actions692- Prevent harm to individuals or public safety693 694**c) Tribal Sovereignty Protection:**695- Report violations to GTBOCI authorities696- Cooperate with tribal law enforcement697- Support tribal regulatory enforcement698- Comply with tribal court orders699 700### 7.4 Business Transfers701 702In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets:703 704**a) Successor Obligations:** Any acquiring entity must:705- Honor this Privacy Policy or provide 90 days notice of changes706- Maintain the same level of data protection707- Respect Indigenous Data Sovereignty principles708- Preserve CARE Principles implementation709- Obtain GTBOCI approval for transfers involving Indigenous Data710 711**b) User Notification:** You will be notified via email and prominent website notice at least 60 days before any ownership transfer.712 713**c) Opt-Out Right:** You may delete your account and request data deletion before the transfer completes.714 715**d) Tribal Sovereignty Preservation:** The acquiring entity must acknowledge and agree to tribal jurisdiction and sovereign immunity provisions.716 717### 7.5 Aggregate and Anonymized Data718 719I may share **aggregated, anonymized, or de-identified data** that cannot reasonably identify individuals:720 721- Industry benchmarks and trends722- Research publications and presentations723- Public reports on service usage724- Statistical analysis for policy advocacy725 726**Re-Identification Prohibition:** Recipients are contractually prohibited from attempting to re-identify individuals from anonymized data.727 728**Indigenous Data Protections:** Even when anonymized, Indigenous Data shared publicly includes:729- Cultural context and appropriate attribution730- Compliance with community protocols731- Benefit-sharing arrangements where applicable732 733### 7.6 No Sale of Personal Data734 735**Explicit Prohibition:** I do **NOT** sell Personal Data, as defined by CCPA and other privacy laws.736 737**Advertising Exception:** If targeted advertising is used (with your consent), advertising partners may receive limited identifiers (cookies, device IDs). This does NOT constitute a "sale" under most privacy laws, but you may opt out regardless (see Section 9.3).738 739### 7.7 International Transfers740 741Personal Data may be transferred to and processed in countries other than your country of residence. When transferring data internationally, I ensure adequate protection through:742 743- **Standard Contractual Clauses (SCCs):** EU-approved contract terms for GDPR compliance744- **Adequacy Decisions:** Relying on jurisdictions deemed adequate by relevant authorities745- **Binding Corporate Rules:** For intra-organizational transfers746- **Indigenous Data Sovereignty Preservation:** International transfers of Indigenous Data require additional community authorization747 748See Section 10 for detailed international transfer provisions.749 750### 7.8 Transparency and Accountability751 752**Data Sharing Registry:** I maintain an internal registry of all data sharing arrangements, reviewed quarterly for compliance and necessity.753 754**Annual Transparency Report:** Published annually, disclosing:755- Categories and volumes of data shared756- Legal requests received and complied with757- Security incidents and responses758- Indigenous Data Sovereignty compliance metrics759 760---761 762## 8. DATA STORAGE, SECURITY, AND RETENTION763 764### 8.1 Data Storage Locations765 766Personal Data is primarily stored in:767 768**a) United States:** Servers located in Michigan (tribal territory) and other U.S. locations, subject to U.S. federal law and tribal jurisdiction.769 770**b) Trusted Cloud Providers:** Infrastructure-as-a-Service (IaaS) providers with SOC 2 Type II certification, operating under strict data processing agreements.771 772**c) Backup Locations:** Encrypted backups stored in geographically distributed locations for disaster recovery.773 774**Data Residency Requests:** Users in certain jurisdictions may request data residency within specific regions where technically feasible.775 776### 8.2 Security Measures777 778I implement comprehensive security measures following industry best practices:779 780#### 8.2.1 Technical Security Controls781 782**Encryption:**783- **In Transit:** TLS 1.3 or higher for all data transmissions784- **At Rest:** AES-256 encryption for all stored Personal Data785- **End-to-End:** Available for sensitive communications where applicable786- **Key Management:** Hardware security modules (HSMs) and key rotation policies787 788**Access Controls:**789- Role-based access control (RBAC) limiting data access to authorized personnel790- Multi-factor authentication (MFA) required for administrative access791- Principle of least privilege enforced across all systems792- Regular access reviews and revocation of unnecessary permissions793 794**Network Security:**795- Firewalls and intrusion detection/prevention systems (IDS/IPS)796- DDoS protection and traffic filtering797- Network segmentation isolating sensitive data798- Virtual Private Networks (VPNs) for remote access799 800**Application Security:**801- Secure coding practices and code reviews802- Regular security testing and penetration testing803- Input validation and output encoding804- Protection against OWASP Top 10 vulnerabilities805- Security headers and Content Security Policy (CSP)806 807**Monitoring and Logging:**808- 24/7 security monitoring and alerting809- Comprehensive logging of access and activities810- Anomaly detection and behavioral analysis811- Security Information and Event Management (SIEM) integration812 813#### 8.2.2 Organizational Security Controls814 815**Personnel Security:**816- Background checks for personnel with data access817- Security awareness training for all staff818- Confidentiality and non-disclosure agreements819- Limited personnel with Personal Data access820 821**Vendor Management:**822- Due diligence and security assessments for all vendors823- Contractual security and privacy obligations824- Regular vendor audits and compliance verification825- Vendor risk ratings and monitoring826 827**Incident Response:**828- Documented incident response plan829- Incident response team with defined roles830- Regular incident response drills and simulations831- Post-incident analysis and improvement832 833**Business Continuity:**834- Disaster recovery plan tested annually835- Backup and restoration procedures836- Redundant systems and failover capabilities837- Recovery time objectives (RTO) and recovery point objectives (RPO)838 839#### 8.2.3 Enhanced Protections for Indigenous Data840 841**Cultural Security:**842- Cultural competency training for personnel handling Indigenous Data843- Restricted access based on cultural protocols844- Special handling procedures for sacred or sensitive information845- Community consultation for security measure design846 847**Sovereignty Protections:**848- Data isolation for Indigenous community data849- Tribal authority approval for access to restricted data850- Enhanced encryption for sacred knowledge851- Regular security audits with Indigenous oversight852 853### 8.3 Data Retention854 855**Retention Principles:**856- Data is retained only as long as necessary for stated purposes857- Retention periods are documented and enforced858- Data is securely deleted when no longer needed859- Regular reviews identify data eligible for deletion860 861**Retention Periods by Data Category:**862 863| Data Category | Retention Period | Rationale |864|---------------|------------------|-----------|865| Account Information | Duration of account + 30 days | Service provision, account recovery |866| Transaction Records | 7 years | Tax and legal compliance |867| Support Communications | 3 years after resolution | Quality assurance, dispute resolution |868| Usage Logs | 1 year | Security monitoring, service improvement |869| Marketing Communications | Until opt-out + 30 days | Communication preferences |870| Anonymous Analytics | Indefinite | No personal identification possible |871| Indigenous Data (Restricted) | Per community protocols | Respect for cultural governance |872 873**Early Deletion Requests:** You may request deletion before standard retention periods (see Section 9.2).874 875**Legal Hold:** Retention periods may be extended when data is subject to legal obligations, investigations, or litigation.876 877### 8.4 Secure Data Deletion878 879When Personal Data is deleted:880 881**Deletion Methods:**882- **Logical Deletion:** Immediate removal from production systems and user interfaces883- **Physical Deletion:** Secure overwriting or cryptographic erasure within 90 days884- **Backup Purging:** Removal from backups according to backup rotation schedules (typically within 180 days)885 886**Verification:**887- Deletion completion verification and documentation888- Audit logs of deletion activities889- Certification of deletion upon request890 891**Limitations:**892- Anonymized data may be retained indefinitely893- Aggregated statistical data without Personal Data may be retained894- Legal requirements may mandate retention despite deletion requests895 896### 8.5 Security Limitations and User Responsibilities897 898**No Absolute Security:** Despite robust measures, no system is 100% secure. I cannot guarantee absolute security of Personal Data.899 900**User Responsibilities:**901- Keep account credentials confidential and secure902- Use strong, unique passwords903- Enable multi-factor authentication when available904- Promptly report suspected security incidents905- Keep contact information current for security notifications906- Follow security best practices when accessing Services907 908**Shared Responsibility:** Security is a shared responsibility between the Rights Holder and users.909 910---911 912## 9. YOUR RIGHTS AND CHOICES913 914### 9.1 Universal Rights915 916Regardless of location, all users have the following rights:917 918#### 9.1.1 Right to Access919- **Request copies** of your Personal Data920- **Receive information** about how your data is Processed921- **Obtain details** about data sharing and recipients922- **Access in portable format** (machine-readable, commonly used format)923 924**How to Exercise:** Email privacy@in-digi-nous.com with subject line "Data Access Request"925 926**Response Time:** Within 30 days (may be extended to 60 days for complex requests with notice)927 928#### 9.1.2 Right to Rectification929- **Correct inaccurate** Personal Data930- **Complete incomplete** Personal Data931- **Update outdated** information932 933**How to Exercise:** Update via account settings or email privacy@in-digi-nous.com934 935**Response Time:** Immediate for account updates; within 30 days for verification-required updates936 937#### 9.1.3 Right to Deletion ("Right to be Forgotten")938- **Request deletion** of your Personal Data939- **Account closure** with full data removal940- **Exceptions apply** for legal obligations, dispute resolution, security, and fraud prevention941 942**How to Exercise:** Email privacy@in-digi-nous.com with subject line "Data Deletion Request"943 944**Response Time:** Within 30 days (data removal within 90 days)945 946**Limitations:**947- Legal or contractual retention requirements948- Ongoing disputes or investigations949- Security and fraud prevention needs950- Anonymized data (cannot identify you)951 952#### 9.1.4 Right to Object953- **Object to Processing** based on legitimate interests954- **Opt out of marketing** communications955- **Withdraw consent** for consent-based Processing956- **Restrict certain uses** of your data957 958**How to Exercise:** Email privacy@in-digi-nous.com or use unsubscribe links in communications959 960#### 9.1.5 Right to Data Portability961- **Receive your data** in structured, machine-readable format962- **Transfer data** to another service provider963- **Direct transmission** where technically feasible964 965**How to Exercise:** Email privacy@in-digi-nous.com with subject line "Data Portability Request"966 967**Format:** JSON, CSV, or other commonly used formats968 969#### 9.1.6 Right to Restrict Processing970- **Limit Processing** to storage only while disputes are resolved971- **Challenge accuracy** of data during verification972- **Object to deletion** but request restriction instead973 974**How to Exercise:** Email privacy@in-digi-nous.com with specific restriction request975 976#### 9.1.7 Rights Related to Automated Decision-Making977- **Not be subject** to solely automated decisions with significant effects978- **Request human review** of automated decisions979- **Receive explanation** of automated decision logic980- **Challenge and contest** automated decisions981 982(See Section 14 for detailed AI and automated decision-making provisions)983 984### 9.2 Enhanced Rights for Indigenous Data Subjects985 986Indigenous users and community members have additional rights:987 988#### 9.2.1 Cultural Authority Rights989- **Invoke cultural protocols** governing data use990- **Apply TK Labels** to your Indigenous Data991- **Request cultural review** of data uses992- **Designate community representatives** for collective data governance993 994#### 9.2.2 Sovereignty-Based Rights995- **Invoke tribal jurisdiction** for dispute resolution996- **Request tribal court** adjudication of rights997- **Assert sovereign immunity** protections998- **Demand compliance** with CARE Principles999 1000#### 9.2.3 Collective Rights1001- **Represent community interests** in data governance1002- **Request community consultation** for significant data uses1003- **Participate in benefit-sharing** decisions1004- **Access aggregated community data** (where authorized)1005 1006### 9.3 Jurisdiction-Specific Rights1007 1008#### 9.3.1 California Residents (CCPA/CPRA Rights)1009 1010**Right to Know:**1011- Categories of Personal Data collected1012- Categories of sources of Personal Data1013- Business or commercial purposes for collecting data1014- Categories of third parties with whom data is shared1015- Specific pieces of Personal Data collected1016 1017**Right to Delete:**1018- Request deletion of Personal Data (subject to exceptions)1019 1020**Right to Opt-Out:**1021- Opt out of "sale" or "sharing" of Personal Data (Note: I do not sell data)1022- Opt out of targeted advertising1023- Limit use of Sensitive Personal Data1024 1025**Right to Correct:**1026- Request correction of inaccurate Personal Data1027 1028**Right to Limit Use of Sensitive Personal Data:**1029- Restrict use of Sensitive Personal Data to necessary purposes1030 1031**Right to Non-Discrimination:**1032- Not be discriminated against for exercising privacy rights1033- No denial of service, different pricing, or degraded experience1034 1035**Authorized Agent:** You may designate an authorized agent to make requests on your behalf by providing written authorization.1036 1037**Verification:** Requests require identity verification to protect against fraudulent requests.1038 1039**How to Exercise:** Complete form at https://in-digi-nous.com/privacy/ccpa-request or email privacy@in-digi-nous.com1040 1041**Response Time:** Within 45 days (may extend to 90 days with notice)1042 1043#### 9.3.2 European Residents (GDPR Rights)1044 1045**Right of Access (Article 15):**1046- Obtain confirmation of Processing1047- Access Personal Data and supplementary information1048 1049**Right to Rectification (Article 16):**1050- Correct inaccurate Personal Data1051- Complete incomplete data1052 1053**Right to Erasure (Article 17):**1054- Request deletion under specific grounds:1055 - Data no longer necessary1056 - Consent withdrawn1057 - Unlawful Processing1058 - Legal obligation to delete1059 1060**Right to Restriction (Article 18):**1061- Restrict Processing while:1062 - Accuracy is contested1063 - Processing is unlawful but deletion not desired1064 - Data needed for legal claims1065 1066**Right to Data Portability (Article 20):**1067- Receive data in machine-readable format1068- Transmit to another controller1069 1070**Right to Object (Article 21):**1071- Object to Processing based on legitimate interests1072- Object to direct marketing (absolute right)1073- Object to profiling1074 1075**Rights Related to Automated Decision-Making (Article 22):**1076- Not subject to solely automated decisions1077- Human intervention and explanation rights1078 1079**Right to Withdraw Consent (Article 7):**1080- Withdraw consent at any time1081 1082**Right to Lodge Complaint:**1083- File complaint with supervisory authority in EU member state1084 1085**Supervisory Authority Contact:** [Your local Data Protection Authority - list available at https://edpb.europa.eu/about-edpb/board/members_en]1086 1087**How to Exercise:** Email privacy@in-digi-nous.com1088 1089**Response Time:** Within 1 month (may extend to 3 months for complex requests with notice)1090 1091#### 9.3.3 Other Jurisdictions1092 1093Residents of other jurisdictions may have additional rights under local laws, including:1094 1095- **Virginia (VCDPA)**1096- **Colorado (CPA)**1097- **Connecticut (CTDPA)**1098- **Utah (UCPA)**1099- **Brazil (LGPD)**1100- **Canada (PIPEDA)**1101- **Australia (Privacy Act)**1102- **Switzerland (Federal Data Protection Act)**1103- **UK (UK GDPR)**1104 1105Contact privacy@in-digi-nous.com to learn about rights specific to your jurisdiction.1106 1107### 9.4 Account Management1108 1109**Account Settings:**1110- Update Personal Data via account dashboard1111- Manage communication preferences1112- Control privacy settings1113- View data access and usage history1114 1115**Account Deletion:**1116- Delete account through account settings or by contacting privacy@in-digi-nous.com1117- Data deletion as described in Section 9.1.31118 1119### 9.5 Cookie and Tracking Preferences1120 1121**Cookie Management:**1122- Adjust cookie preferences through cookie consent banner1123- Manage browser settings to block or delete cookies1124- Use "Do Not Track" browser settings (honored where technically feasible)1125 1126**Opt-Out Tools:**1127- **Google Analytics:** [Google Analytics Opt-Out Browser Add-on](https://tools.google.com/dlpage/gaoptout)1128- **Advertising Opt-Outs:** [Digital Advertising Alliance](http://optout.aboutads.info/), [Network Advertising Initiative](http://optout.networkadvertising.org/)1129 1130(See Section 11 for detailed cookie information)1131 1132### 9.6 Marketing and Communications Opt-Out1133 1134**Email Marketing:**1135- Click "unsubscribe" link in any marketing email1136- Update preferences in account settings1137- Email privacy@in-digi-nous.com with subject "Unsubscribe"1138 1139**Transactional Emails:** Certain service-related emails (e.g., account security, transaction confirmations) cannot be opted out while account is active.1140 1141**SMS/Text:** Reply "STOP" to opt out of text messages1142 1143**Push Notifications:** Manage via device settings or app settings1144 1145### 9.7 Exercising Your Rights1146 1147**How to Make Requests:**1148 11491. **Email:** privacy@in-digi-nous.com1150 - Include clear subject line indicating request type1151 - Provide sufficient information for verification1152 11532. **Online Form:** https://in-digi-nous.com/privacy/rights-request1154 11553. **Mail:** 1156 ᓂᐲᔥ Nbiish-Justin Kenwabikise 1157 Privacy Rights Requests 1158 [Mailing address to be provided]1159 1160**Verification Process:**1161- Identity verification required to protect against fraudulent requests1162- May request additional information to verify identity1163- Authorized agents must provide written authorization1164 1165**No Fee:** Rights requests are generally processed free of charge.1166 1167**Excessive Requests:** Manifestly unfounded or excessive requests (especially repetitive requests) may incur reasonable administrative fees or be refused.1168 1169**Response Timeline:**1170- Acknowledgment within 10 days1171- Full response within 30-45 days (depending on jurisdiction)1172- Extension notifications provided when additional time needed1173 1174**Appeals:**1175- If request is denied, you may appeal by contacting privacy@in-digi-nous.com1176- Jurisdiction-specific appeal rights are honored (e.g., CCPA appeal process)1177 1178---1179 1180## 10. INTERNATIONAL DATA TRANSFERS1181 1182### 10.1 Cross-Border Data Transfers1183 1184Personal Data may be transferred to, stored in, and processed in countries other than your country of residence, including the United States. These countries may have data protection laws different from those in your jurisdiction.1185 1186### 10.2 Transfer Safeguards1187 1188When transferring Personal Data internationally, I implement appropriate safeguards to ensure adequate protection:1189 1190#### 10.2.1 Standard Contractual Clauses (SCCs)1191 1192- EU Commission-approved Standard Contractual Clauses for GDPR compliance1193- UK International Data Transfer Agreement (IDTA) for UK GDPR compliance1194- Swiss-approved transfer mechanisms for Swiss data subjects1195- Regular reviews and updates as regulations evolve1196 1197#### 10.2.2 Adequacy Decisions1198 1199- Relying on jurisdictions deemed to provide adequate protection by relevant authorities1200- Currently recognized adequacy decisions (subject to change):