Privacy

Privacy Policy

Hive Civilization provides receipt and routing services at thehiveryiq.com. Data handling differs between client-side hashing, server-side classification and public demos. This policy identifies those boundaries and the evidence still needed for a deployment.

Last updated: September 5, 2026 · Evidence and change log

On this page Who We Are What We Collect Payload boundaries Legal Bases (GDPR) Data Retention Sub-processors International Transfers Your Rights Cookies Children Changes Contact
Section 1

Who We Are

Hive Civilization is the brand operating at thehiveryiq.com. The registered contracting entity, incorporation jurisdiction and controller/processor roles must be verified against charter and agreement records. Earlier Wyoming and Delaware descriptions conflict; neither is confirmed by this review.

Privacy contact: [email protected]
EU/EEA inquiries: [email protected]. This contact is not evidence of an appointed Article 27 representative.
Section 2

What We Collect

Operational records, submitted content and account interactions have different data paths. Encryption in transit does not mean the receiving service cannot read submitted text.

a. Operational Data

Receipts and routing: Signed fields can include hashes, timestamps, model or agent identifiers, transaction details and customer-supplied metadata. They are not universally hashes-only.
Carnac classification: The service receives request/output text. The judgment schema records derived features, categories and metadata rather than raw request/output fields. Optional semantic processing sends that text to the configured compute endpoint.
Optional inspection and demos: The ML-DSA text signer receives pasted text or fragments. Carnac sandbox also processes text, but skips durable judgment/Howler writes and does not commit effects. Logging and downstream processing are separate; use synthetic, non-sensitive input.

b. Account Data

Account and contact: Names, email addresses and messages may be supplied through account or contact workflows. Do not include secrets in an email request.
Transactions: Receipt fields may include payer/payee identifiers, amounts and transaction hashes. Public-chain records, when used, are not private storage.
Telemetry and logs: The shared site beacon sends page path/query, referrer, user agent and time zone. Legacy receipt-service telemetry also collects IP and location metadata and writes to Supabase. The active processor inventory and retention checks remain open. review evidence.
Section 3

Payload boundaries

Customer-side hashing: If your integration sends only a digest and no original payload fields, the original content can remain on your systems. Check the actual request schema.
Server-side processing: Carnac and text-signing inputs reach the service in readable form. A digest-only response does not mean the input was never received.
Stored records: Carnac judgments omit raw request/output fields, but free-form identifiers, classifier labels and error details may still carry sensitive content. Logs, inspection stores and processor copies require separate review.
Backups and exports: Carnac has bounded export code; exported copies remain with their recipients. No universal payload-exclusion, backup expiry or complete-export guarantee was verified. review evidence.
Section 4

Legal bases: deployment review

Processing activity Legal basis
Issuing and routing signed receipts Contract performance only where Article 6(1)(b) applies to the data subject and processing
Fraud prevention, system integrity Legitimate interests only after the necessary purpose, necessity and balancing assessment
Logging required by an applicable law, including the EU AI Act where in scope Legal obligation (Art. 6(1)(c)), only where the obligation applies to the deployment and processing
Telemetry and analytics Applicable basis and any consent requirement need assessment; this page does not verify a consent-gated implementation
Section 5

Data Retention

Receipts: The receipt service uses process memory; Carnac uses memory with a conditional Supabase mirror. The countersigner has a declared 1 GB persistent disk at /var/hive. Typed API compute has no declared disk. These are storage observations, not approved retention periods.
Account data: Creation, closure and inactivity events, purpose-specific durations and legal holds require business/legal approval.
Operational and inspection records: Log creation and inspection completion are candidate start events, not approved triggers. Field lists, durations, holds, deletion methods and sample verification are open.
Backups, processors and exports: Backup creation/expiry, processor termination and export custody must each be scheduled. Owner, duration, hold exceptions, deletion steps and verification remain unapproved. review evidence contains the class-by-deployment inventory.

Schedule approval is open for every data class reviewed. No retention duration, legal hold rule or automatic deletion process is inferred from storage type. Ephemeral loss is not controlled deletion; a persistent disk is not a tested backup. A signed deletion statement does not prove removal of all copies.

EU AI Act Article 12 requires logging capability for in-scope high-risk AI systems. It does not set a seven-year retention default. Article 19(1) and Article 26(6) address automatically generated logs under the provider's or deployer's control and specify an appropriate period of at least six months, unless applicable Union or national law provides otherwise, particularly personal-data law. Applicability and timing must be assessed for the deployment. These provisions do not set a universal retention period for every Hive receipt.

Section 6

Sub-processors

The hosting review identifies the locations below. It is not a complete, legally approved subprocessor register. See review evidence for configured source paths and unresolved provider, contract and region checks.

Sub-processor Purpose Location
Render Four reviewed API/signer services Oregon, United States
Cloudflare Site distribution and edge services Global; no single region verified
Base Public settlement network, not assumed to be a contracted subprocessor Public distributed ledger
Supabase / compute / email Storage paths, optional semantic processing and contact services require provider-specific review Active projects, processors and regions not fully verified

Processor agreements, authorized data classes, notice terms and onward transfers require verification. Vendor security pages do not establish an executed Hive agreement.

Section 7

International Transfers

The reviewed Render compute is in Oregon, United States; the static site is globally distributed. No EU-only routing or storage path was verified.

Before an EEA deployment, the responsible legal reviewer must confirm roles, recipients and the applicable transfer mechanism. Executed SCCs and transfer assessments were not supplied. See GDPR Chapter V.

Section 8

Your Rights

Under GDPR (EEA residents)

Right of access: you can get a copy of your personal data.
Right to rectification: you can correct inaccurate data.
Right to erasure: you can ask us to delete your data when we have no legal basis to keep processing it.
Right to data portability: you can get your data in a machine-readable format.
Right to restriction of processing.
Right to object to processing based on legitimate interest.

Under CCPA (California residents)

Right to know what personal information is collected and how it is used.
Right to delete personal information.
Right to opt out of sale of personal information. (Hive does not sell personal information.)
Right to non-discrimination for exercising your rights.

To exercise rights, contact [email protected]. Rights and exceptions depend on applicable law. Where GDPR applies, Article 12(3) requires a response without undue delay and within one month, with a possible two-month extension where necessary and notice within the first month. Other applicable deadlines must be assessed for the request.

Section 9

Cookies

The site stores a theme preference in local storage and loads first-party telemetry through shared navigation. A beacon can collect data without setting a cookie; absence of analytics cookies does not mean absence of analytics.

The current cookie/storage inventory, lawful basis and any consent controls need review across loaded components. This policy does not establish that all collection is essential or consent-gated.

Section 10

Children

Hive Civilization services are not directed at individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, contact [email protected] and we will delete it promptly.

Section 11

Changes to This Policy

This revision corrects technical and evidence claims; it does not create new contractual retention periods or establish consent through continued use. Material policy changes require the notice and approval process applicable to the deployment.

September 5, 2026: clarified readable-content processing, telemetry, Oregon compute, open retention schedules, entity verification and transfer evidence. The earlier Article 12 retention correction is preserved. review evidence includes the change log.

Section 12

Contact

Privacy inquiries: [email protected]
DPO contact: [email protected]. Designation and applicability not verified.
EU Article 27 representative: Appointment and applicability require legal review; no representative is identified in the reviewed evidence.
Supervisory authority: You have the right to lodge a complaint with the supervisory authority in your EEA member state of residence.
See also
Legal & Corporate Disclosures Terms of Service End User License Agreement
On this page Who We Are What We Collect Payload boundaries Legal Bases (GDPR) Data Retention Sub-processors International Transfers Your Rights Cookies Children Changes Contact

Privacy questions? Contact [email protected]

Hive
Hive Civilization
For Agents For Enterprises For Regulated Platform Products Solutions Compliance Trust Developers Evidence Hive-PQ Company Sovereignty Verify Definitions Security Founder Risk Legal Privacy Terms EULA [email protected] [email protected]
© 2026 Hive Civilization. All artifacts and sample outputs shown are illustrative.
Data handling by service. Client-side hashing can keep payloads local. Carnac and text-signing demos process submitted text. Receipt, log and export handling depends on the endpoint. Read the data handling policy.