Privacy Policy
Last Updated: 17 May 2026
1. Data Controller
JuLenny Ltd is the data controller responsible for your personal data as described in this Privacy Policy. This policy applies to all users of the JuLenny FHE Platform, including primary contacts, administrators, data stewards, and members. It explains what personal data we collect, why we collect it, how we use it, and what rights you have.
2. Encrypted Data: What We Cannot See
IMPORTANT DISTINCTION: The encrypted datasets you upload to the platform are not personal data from our perspective. We cannot access, read, or derive any information from your ciphertexts. We do not possess the private keys required to decrypt them. This section of the policy applies only to account-level personal data that we can actually access.
All data uploaded for FHE computation must be encrypted client-side using your own cryptographic keys before it reaches our infrastructure. Our compute instances perform mathematical operations on ciphertexts only. We are technically incapable of determining whether the underlying plaintext contains personal data, trade secrets, or random noise.
3. Personal Data We Collect
We collect the following categories of personal data:
3.1 Account Information
- Full name
- Email address (work)
- Phone number (optional)
- Company name, registration number, and VAT ID
- Billing address
- Role within the company (primary contact, admin, data steward, member)
3.2 Authentication Data
- Authentication tokens and session identifiers (managed by Google Cloud Identity / Firebase Auth)
- Sign-in method (Google SSO or email/password)
- Two-factor authentication enrollment status
3.3 Billing and Transaction Data
- Credit purchase history and amounts
- Execution cost records
- Stripe customer and payment method identifiers (we do not store full card numbers)
3.4 Usage and Log Data
- IP addresses
- Browser type and version
- Pages visited and actions taken within the platform
- Timestamps of access and API calls
- Error logs related to your account activity
3.5 Communication Data
- Messages submitted through our contact form
- Support queries and correspondence
4. Legal Basis for Processing
Under GDPR Article 6, we process your personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): Processing your account information, billing data, and usage data is necessary to provide the Service you have registered for.
- Legitimate interest (Art. 6(1)(f)): Processing log data and IP addresses for platform security, fraud prevention, and service stability. Our legitimate interest does not override your fundamental rights given the limited and non-sensitive nature of this data.
- Legal obligation (Art. 6(1)(c)): Retaining billing records and transaction data as required by Cyprus tax law and EU anti-money laundering regulations.
- Consent (Art. 6(1)(a)): Setting analytics cookies, subscribing to our newsletter, or any other processing where we explicitly ask for your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
5. How We Use Your Data
We use your personal data for the following purposes:
- Creating and managing your account
- Authenticating access to the platform
- Processing credit purchases and issuing invoices
- Executing and tracking FHE computations on your behalf
- Sending transactional emails (account verification, deletion codes, execution notifications)
- Responding to support queries submitted via our contact form
- Detecting and preventing fraud, abuse, and unauthorized access
- Ensuring compliance with export control and sanctions requirements
- Improving platform performance and reliability through aggregated, anonymized analytics
We do not sell your personal data. We do not use your data for profiling or automated decision-making that produces legal effects.
6. Data Retention
We retain personal data only as long as necessary for the purposes described above:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion |
| Authentication tokens | Session duration or until sign-out |
| Billing and transaction records | 7 years (Cyprus tax law requirement) |
| Access logs and IP addresses | 90 days |
| Analytics data | 14 months (anonymized) |
| Contact form submissions | 12 months after resolution |
| Encrypted datasets and executions | Immediately upon account/company deletion |
7. Third-Party Processors
We share personal data with a limited number of third-party service providers, each bound by a Data Processing Agreement (DPA) where required. Our main providers include Google Cloud Platform, which hosts our infrastructure, and Stripe, which processes payments. We also rely on established providers for services such as invoicing, transactional email, bot protection, and customer relationship management. In every case we share only the minimum personal data the provider needs to perform its service.
We do not share your personal data with any other third parties for marketing, advertising, or data brokerage purposes. A current list of sub-processors is available on request.
8. International Data Transfers
Our primary infrastructure is hosted on Google Cloud Platform within the European Union (region: europe-west4, Netherlands). Your encrypted datasets and account data are stored and processed within the EU.
Some of our third-party processors may process data in the United States. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:
- EU-US Data Privacy Framework adequacy decision (where the processor is certified)
- Standard Contractual Clauses (SCCs) approved by the European Commission
9. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights. To exercise any of these, submit a request via our contact form.
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Correct inaccurate or incomplete personal data. You can update most account information directly from your profile settings.
- Right to erasure (Art. 17): Request deletion of your personal data. The primary contact can delete the entire company account from Company Settings, triggering a cascading purge of all associated data. Other members can delete their individual account from their Account page.
- Right to restriction (Art. 18): Request that we restrict processing of your data in certain circumstances (e.g., while we verify accuracy).
- Right to data portability (Art. 20): Receive your personal data in a structured, machine-readable format (JSON). Available via the platform dashboard for account and billing data.
- Right to object (Art. 21): Object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent (e.g., analytics cookies), you may withdraw at any time without affecting prior processing.
- Right to lodge a complaint: You have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus or your local supervisory authority.
We will respond to data subject requests within 30 days. In complex cases, this may be extended by an additional 60 days, in which case we will notify you of the extension and the reasons.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256 via Google Cloud)
- Role-based access controls within the platform
- Firebase App Check and reCAPTCHA for request validation
- API key authentication with SHA-256 hashed storage
- Audit logging of administrative actions
- Regular review of access permissions and security configurations
No system is perfectly secure. While we take reasonable precautions, we cannot guarantee absolute security of data transmitted over the internet or stored on our systems.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay via the email address associated with your account. We will also notify the Office of the Commissioner for Personal Data Protection of Cyprus within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
12. Children
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will delete it promptly.
13. Cookies
Our use of cookies is described in detail in our separate Cookie Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last Updated" date at the top of this page. It is your responsibility to review this policy periodically. Your continued use of the Service after a revision constitutes acceptance of the updated policy.
15. Contact
For privacy-related queries or to exercise your data subject rights, please submit a request via our contact form.