Data Governance

Privacy Policy

REF: PRIV-2025-11EFFECTIVE: NOV 01, 2025APPLICABILITY: GLOBAL

SCOPE: This policy outlines the data processing protocols of Blankline Research ("We", "Our") regarding the Dropstone platform. We treat data privacy as an architectural constraint, minimizing collection to the absolute requirements of system function.

Section 01

Information Collection Schema

We collect information under strict categorization protocols. The following schema defines the data classes processed by our systems:

Data Class
Fields Captured
Processing Purpose
Account Data
Email, Hash(Password), Name, Org ID
Authentication & Billing
Input Telemetry
Prompts, Context Windows, API Logs
Service Delivery & Safety
Device Fingerprint
IP Address, User Agent, Timezone
Security & Fraud Prevention
Billing Records
Transaction ID, Last4, Billing Address
Statutory Requirement
Section 02

Usage Protocols

We process the collected data solely for the following purposes:

  • Service Provisioning: Authenticating access to the Dropstone IDE and processing inference requests via our API.
  • Safety Alignment: Monitoring interaction traces to detect and prevent safety violations (e.g., generation of malware or non-consensual content).
  • Model Improvement (Optional): By default, we do not train our foundational models on data from Enterprise or Team tier workspaces. Free tier interaction data may be used for RLHF tuning unless opted out.
Section 03

Data Retention (TTL)

We enforce strict Time-To-Live (TTL) policies on all data classes. Once the retention period expires, data is cryptographically erased from our primary and backup clusters.

Session Logs
30 DaysTrigger: Creation
Account Metadata
IndefiniteTrigger: Active Status
Deleted Accounts
90 DaysTrigger: Deletion Request
Financial Records
7 YearsTrigger: Transaction Date
Section 05

Security Architecture

We implement defense-in-depth strategies to protect data at rest and in transit.

Encryption StandardsAll data is encrypted using AES-256 at rest and TLS 1.3 in transit. Key management is handled via hardware security modules (HSM).
IsolationEnterprise customer data is logically isolated in separate tenants. Code execution occurs in ephemeral, sandboxed microVMs.
Section 07

International Transfer

Blankline Research is headquartered in India. By using our Services, you acknowledge that your information will be transferred to, stored, and processed in India and other jurisdictions where our cloud infrastructure (AWS/GCP) operates.

For users in the EEA/UK, we rely on Standard Contractual Clauses (SCCs) to validate the transfer of personal data to non-adequate jurisdictions.

Section 08

Contact & DPO

To exercise your rights (access, rectification, erasure) or to raise a privacy concern, contact our Data Protection Officer.

Mailing Address
Blankline Research
Attn: Data Protection Officer
Chennai, Tamil Nadu, India