Privacy Policy & Data Processing Addendum (DPA)
Effective Date: September 7, 2026 · Jurisdiction: Vienna, Austria (European Union)
Executive Summary: Lamis Network provides B2B entity risk scoring and egress routing. Our services are designed for GDPR-aligned workflows. We adhere to strict data minimization principles: IP telemetry received for scoring is evaluated in real time, and web server logs are retained for 14 days under standard log rotation policies before permanent deletion.
1. Scope & Applicability
This Privacy Policy and Data Processing Addendum ("Policy") governs the collection, processing, and protection of technical data by Lamis Network (operated by Einzelunternehmen Grechanyi, commercially trading as Grecciani Labs, Vienna, Austria, who acts as the Data Controller) when providing Fraud Score API, Egress Proxy Routing, and Threat Intelligence services to business clients ("Customers").
2. Roles of Parties (GDPR Article 28)
In the context of the European General Data Protection Regulation (GDPR):
- Customer as Data Controller: The Customer determines the lawful basis (such as legitimate interest under Art. 6(1)(f) GDPR for fraud prevention) for evaluating end-user telemetry.
- Lamis Network as Data Processor: Lamis Network processes technical indicators (IP addresses, user agents, headers) strictly on documented customer instructions to compute risk scores and route egress traffic.
3. Categories of Data Processed
We process the following technical categories:
- Telemetry Indicators: IPv4/IPv6 addresses submitted to
/v1/score for fraud analysis.
- Derived Risk Signals: Autonomous ASN classification, VPN/proxy indicators, and geographical country-level mapping.
- Account & Billing Data: Corporate contact email, EU VAT identification number, and Stripe transaction references.
4. Data Minimization & Retention Schedule
We apply automated retention lifecycles to all telemetry:
- In-Memory Evaluation: IP scoring lookups against local databases occur in high-performance local-first execution (p50: 1.4ms) without writing payload bodies to persistent storage.
- 7-Day Reconciliation Period: High-level request counts and IP hashes are retained for up to 7 calendar days to resolve quota disputes and mitigate denial-of-service attempts.
- Server Connection Logs: Client IP addresses connecting to our web infrastructure are recorded in standard web server logs (Nginx) for network security and DDoS mitigation, rotated daily, and permanently deleted after 14 days under standard log rotation policies.
- Operational Threat Cache & Persistence Lifecycle: IP risk scores expire via automated time-to-live policies (1 hour default for IP risk scores, up to 7 days for deep triage verdicts) from the active in-memory keyspace. For container crash recovery, Redis maintains an append-only journal (AOF) and snapshot files on a dedicated volume. Under our operational retention procedure, residual journal entries are compacted daily via automated AOF rewriting (
BGREWRITEAOF), and disaster recovery snapshots are rotated and permanently purged after a maximum retention period of 7 calendar days. No permanent user dossiers or historical observable archives are compiled.
5. Technical and Organizational Measures (TOMs)
Lamis Network implements state-of-the-art security controls:
- Enforced TLS 1.3 encryption across all public API endpoints and administrative dashboards.
- Isolated Redis caching clusters accessible strictly via internal container networking.
- Zero active scanning or intrusive port probing against third-party customer infrastructure.
6. Sub-Processors & Data Transfers
Infrastructure nodes are hosted within European data center facilities (including Austria and Germany). Third-party sub-processors are strictly limited to vetted enterprise partners operating under compliant Data Processing Addenda:
- Hetzner Online GmbH (Germany, EU) — Dedicated server infrastructure, container runtimes, and core network egress.
- Stripe Payments Europe, Ltd. (Ireland, EU) — PCI-DSS Level 1 payment gateway and Merchant of Record transaction processing.
- Brevo SAS (France, EU) — Transactional email dispatch for credential delivery and account notices.
- RunPod Inc. (USA / EU) — Dedicated private GPU compute pods for Level-2 AI Triage under strict confidentiality addenda with zero data retention for model training.
7. Data Retention Policy
Our operational data storage adheres strictly to minimization principles:
- Queried Target IP Addresses: Evaluated in-memory and cached in Redis with automated 1-hour TTL expiration for active score keys. Persistence journals and recovery snapshots on disk are strictly capped at a 7-day maximum retention lifecycle with daily AOF compaction, ensuring telemetry is never compiled into persistent user-tracking dossiers or profiling databases.
- Web Server Ingress Logs: Server connection logs are retained for 14 days for infrastructure security and rate limiting, then permanently deleted via daily logrotate.
- Transient Cache Records: Active Redis cache entries expire automatically via TTL (1 hour default for IP risk scores, 7 days for deep triage). Persistence journals (AOF) and disaster recovery snapshots on storage volumes are permanently purged after a maximum 7-day retention lifecycle.
- Customer Billing & Account Records: Retained for the duration of the commercial agreement and statutory fiscal record-keeping periods under Austrian commercial law.
8. Inquiries & DPA Requests
Enterprise clients requiring an executed bespoke Data Processing Agreement (DPA) or standard contractual clauses may submit an inquiry through our compliance desk:
Email: [email protected] · Support Bot: @lamis_post_bot