Compliance Protocols

Legal & Regulatory
Framework

Privacy Protocol

1. Data Controller Identity
The data controller responsible for the processing of personal data within this digital ecosystem is PeakHarborForge, registered at 753 20, Kungsgatan 38, Uppsala, Sweden. For all data-related inquiries, you may contact our Data Protection Node at [email protected].

2. Categories of Personal Data Processed
We process the following categories of personal data: (a) identification data including your name and email address submitted through our contact forms; (b) technical data including IP addresses, browser type and version, operating system, and device identifiers automatically collected during your interaction with this system; (c) usage data including pages visited, time spent on each interface, navigation patterns, and interaction events captured through essential tracking protocols.

3. Legal Basis for Processing
Processing of your personal data is conducted under the following legal bases as defined in Article 6 of the EU General Data Protection Regulation (GDPR): (a) Consent — where you have explicitly provided your consent for specific processing activities; (b) Contractual Necessity — where processing is necessary for the performance of a contract to which you are a party or for pre-contractual measures; (c) Legitimate Interest — where processing is necessary for our legitimate interests in maintaining and improving our digital services, provided such interests are not overridden by your fundamental rights.

4. Purpose of Data Processing
Personal data is processed exclusively for the following purposes: responding to your inquiries and transmitting requested information; fulfilling contractual obligations related to our enterprise services; maintaining and optimizing the operational integrity of this digital platform; ensuring compliance with applicable legal and regulatory frameworks; generating anonymized analytical insights to improve service quality.

5. Data Retention Periods
Your personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Contact form submissions are retained for a maximum of 24 months following the last interaction. Technical logs are automatically purged after 90 days. Data associated with active contractual relationships is retained for the duration of the contract plus an additional 60 months to comply with statutory retention requirements under Swedish commercial law.

6. Data Recipients and Transfers
Your data may be shared with the following categories of recipients: (a) cloud infrastructure providers operating within the European Economic Area (EEA) who provide hosting and processing services under data processing agreements compliant with Article 28 GDPR; (b) payment processing services for the execution of financial transactions; (c) analytics providers who process anonymized data under contractual obligations ensuring GDPR compliance. We do not transfer personal data outside the EEA without implementing appropriate safeguards such as Standard Contractual Clauses (SCCs) as approved by the European Commission.

7. Your Rights Under GDPR
Under the General Data Protection Regulation, you possess the following rights regarding your personal data: the right of access (Article 15) to obtain confirmation of whether your data is being processed and to receive a copy thereof; the right to rectification (Article 16) to correct inaccurate or incomplete data; the right to erasure (Article 17) to request deletion of your data where no overriding legal obligation requires its retention; the right to restrict processing (Article 18) in specific circumstances; the right to data portability (Article 20) to receive your data in a structured, commonly used, machine-readable format; the right to object (Article 21) to processing based on legitimate interests; the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe your rights have been infringed.

8. Data Security Measures
We implement state-of-the-art technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include: TLS 1.3 encryption for all data in transit; AES-256 encryption for data at rest; regular penetration testing and vulnerability assessments; access controls based on the principle of least privilege; continuous monitoring and automated threat detection systems.

Cookie Directives

1. What Are Cookies
Cookies are small text files deposited onto your device when you interact with our digital ecosystem. They enable the system to recognize your device, store your preferences, and maintain session continuity across pages. Cookies do not contain executable code and cannot access files stored on your device beyond the data they explicitly carry.

2. Categories of Cookies Deployed
Essential Cookies: These are strictly necessary for the core functionality of this platform. They enable navigation, form submission, and security features. Without these cookies, the system cannot operate as requested. These cookies do not require your consent under the ePrivacy Directive (2002/58/EC).

Analytics Cookies: These cookies collect anonymized information about how visitors interact with our platform, including which pages are visited most frequently and whether error messages are encountered. All analytics data is aggregated and does not personally identify individual users. These cookies are deployed only after you provide explicit consent.

Functional Cookies: These cookies enable enhanced functionality and personalization, such as remembering your preferences and choices. They may be set by us or by third-party providers whose services we have integrated into our platform.

3. Cookie Duration
Session cookies are temporary and are automatically deleted from your device once you close your browser. Persistent cookies remain on your device for a predetermined period or until you manually delete them. The maximum lifespan of any persistent cookie deployed by this platform does not exceed 12 months from the date of issuance.

4. Managing Your Cookie Preferences
When you first access this platform, a cookie consent banner is presented allowing you to accept or decline non-essential cookies. You may modify your preferences at any time by clearing your browser cookies and revisiting the platform, where the consent banner will be re-presented. Additionally, most web browsers provide settings to block or delete cookies. Please note that disabling essential cookies may impair the functionality of this platform.

5. Third-Party Cookie Providers
Our platform may integrate services from third-party providers that deploy their own cookies. These include: Google Analytics (analytics and performance measurement), and Stripe (payment processing session management). Each third-party provider operates under their own privacy policy, which we encourage you to review. We maintain data processing agreements with all third-party providers to ensure GDPR compliance.

Refund Framework

1. Scope of Applicability
This Refund Framework applies to all enterprise services procured through PeakHarborForge digital commerce channels. The refund provisions outlined herein are supplementary to your statutory rights under the EU Consumer Rights Directive (2011/83/EU) and applicable Swedish consumer protection legislation.

2. Cancellation and Cooling-Off Period
For services procured through our digital platform, you are entitled to a 14-day cooling-off period from the date of purchase, during which you may request a full refund without providing justification, provided that the service has not yet been initiated. If you expressly consent to the commencement of service delivery before the expiry of the cooling-off period, you acknowledge that the right of withdrawal is forfeited upon initiation of the service.

3. Milestone-Based Refund Structure
For ongoing projects structured around defined milestones, refunds are calculated proportionally based on the completed and unpaid milestones at the time of termination request. Completed milestones for which work has been delivered and accepted are non-refundable. Work-in-progress milestones are subject to a pro-rata refund based on the percentage of completion as independently verified through our project tracking systems.

4. Refund Processing
Approved refunds are processed within 14 business days of approval using the original payment method. If the original payment method is no longer available, an alternative refund method will be arranged in coordination with you. Transaction fees charged by third-party payment processors are non-refundable and will be deducted from the refund amount.

5. Dispute Resolution
In the event of a refund dispute, both parties agree to engage in good-faith mediation before pursuing any formal dispute resolution proceedings. Disputes that cannot be resolved through mediation shall be submitted to the competent courts of Uppsala, Sweden, in accordance with applicable procedural rules.

Service Terms

1. Acceptance of Terms
By accessing or utilizing any services provided through the PeakHarborForge digital ecosystem, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service. If you are accepting these terms on behalf of an organization, you represent that you have the authority to bind that organization to these terms.

2. Scope of Services
PeakHarborForge provides enterprise-grade digital engineering services including but not limited to web development, API integration, infrastructure architecture, and digital ecosystem deployment. The specific scope, deliverables, timelines, and pricing for each engagement are defined in the corresponding service agreement or statement of work executed between the parties.

3. Intellectual Property
Upon full payment of all applicable fees, all custom-developed code, designs, and digital assets created specifically for your engagement are transferred to your ownership. PeakHarborForge retains the right to utilize generalized methodologies, frameworks, and non-proprietary patterns developed during the engagement in future projects. Third-party libraries and tools remain subject to their respective open-source or commercial licenses.

4. Confidentiality
Both parties agree to maintain the confidentiality of all proprietary information exchanged during the course of the engagement. This obligation survives the termination of the service agreement for a period of 36 months. Confidential information shall not be disclosed to third parties without prior written consent, except as required by applicable law or regulatory authority.

5. Limitation of Liability
To the maximum extent permitted by applicable law, PeakHarborForge's total aggregate liability for any claims arising from or related to the services provided shall not exceed the total fees paid by you for the specific service giving rise to the claim during the 12-month period preceding the event giving rise to the claim. In no event shall PeakHarborForge be liable for indirect, incidental, special, consequential, or punitive damages.

6. Force Majeure
Neither party shall be liable for delays or failures in performance resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, war, terrorism, pandemic, government actions, power failures, or internet infrastructure failures. The affected party shall promptly notify the other party and use commercially reasonable efforts to mitigate the impact of the force majeure event.

7. Governing Law and Jurisdiction
These Terms of Service shall be governed by and construed in accordance with the laws of Sweden, without regard to its conflict of law provisions. Any disputes arising from these terms or the services provided shall be subject to the exclusive jurisdiction of the courts of Uppsala, Sweden.

8. Amendments
PeakHarborForge reserves the right to amend these Terms of Service at any time. Material changes will be communicated through our digital platform with a minimum of 30 days' notice before taking effect. Your continued use of our services following the effective date of any amendments constitutes acceptance of the updated terms.

Last protocol synchronization: 2026 — PeakHarborForge — All regulatory nodes active