Privacy Policy
Privacy Policy & Safe Harbor Governance for SpaceJat by JATDEV.
Custodial Architecture Summary: SpaceJAT is structured to afford organizations complete custodial dominion over their communications. In Customer self-hosted and air-gapped deployments, JATDEV has no access to customer infrastructure, databases, or cryptographic key vaults. For end-to-end encrypted (E2EE) communications, JATDEV retains no decryption keys.
1. Introduction & Foundational Roles
This Privacy Policy governs the manner in which JATDEV collects, uses, maintains, and discloses information acquired through the SpaceJAT platform, its APIs, desktop clients, mobile applications, and web interfaces (the “Services”).
To establish rigorous legal and operational clarity inspired by global enterprise standards, we delineate the following roles:
- Customer as Data Controller / Data Owner: When an enterprise, institution, government entity, or commercial subscriber establishes an organization or workspace, that entity is the Data Controller of all content, logs, messages, documents, recordings, and identities created within (“Customer Data”).
- JATDEV as Data Processor / Technical Vendor: JATDEV processes Customer Data strictly pursuant to documented Customer instructions, Service Agreements, or acts merely as a software licensor in customer-hosted architectures.
- Authorized End Users: Individuals accessing the platform via an organizational workspace must direct data inquiries, retention policies, and access requests to their organizational administrator.
2. Architecture & Data Sovereignty Models
SpaceJAT offers distinct operational topologies tailored to enterprise sovereignty requirements:
- Self-Hosted & On-Premises: The platform is installed on Customer hardware or private cloud tenants. JATDEV operates zero remote monitoring, zero content storage, and zero telemetry collection unless explicitly authorized via a technical maintenance contract.
- Managed Cloud (Dedicated/Multi-Tenant): Customer Data is segmented cryptographically and logically in certified regional data centers under strict access controls.
- Cryptographic Enclaves & E2EE: For rooms and calls designated as End-to-End Encrypted, cryptographic ratchets and session keys reside exclusively on authenticated client devices. Plaintext cannot be decrypted, reconstructed, or inspected by JATDEV servers.
3. Information We Collect
JATDEV distinguishes between operational account metadata and customer-managed content:
3.1 Account & Administrative Metadata (Collected by JATDEV)
- Subscriber Identifiers: Name, corporate email address, enterprise billing domicile, administrative contact phone numbers, and company registration details.
- Commercial Transaction Details: Billing records, licensing tiers, seat allocations, payment settlement confirmations, and corporate tax compliance records.
- Diagnostic Telemetry: Anonymized client application versions, IP network routing metadata, OS architecture, crash tracebacks, and handshake latency measurements (configurable/deactivatable on self-hosted builds).
3.2 Customer Content (Controlled Solely by Customer)
Chat messages, shared files, media payloads, whiteboard captures, voice streams, and room structures constitute Customer Data. JATDEV does not access Customer Content except:
- Upon explicit, authenticated written instruction from the Customer administrator for technical recovery;
- Transiently in computer memory as strictly required to route real-time signaling and WebRTC media streams across relay nodes; or
- Pursuant to an unavoidable, mandatory court order issued by a competent judicial authority under binding legal jurisdiction.
4. Safe Harbor, Acceptable Use, & User Misuse Defenses
SpaceJAT operates as a neutral technology provider and telecommunications conduit. To safeguard the company against unlawful actions committed by third-party users:
- Sole User Liability: Workspace administrators and individual users bear exclusive criminal and civil liability for all content, statements, files, and links distributed through the platform.
- Prohibited Misuse: The platform shall not be employed to distribute malware, orchestrate cyberattacks, propagate illicit sexual materials, carry out state sabotage, or breach regional penal codes.
- No Affirmative Duty to Monitor: JATDEV disclaims any general duty to surveil, screen, or moderate real-time private communications or private workspaces.
- Right of Immediate Suspension: JATDEV reserves the unilateral right to terminate license keys, revoke API access, or sever hosted relays if an account is discovered conducting distributed denial-of-service attacks, automated spamming, or gross criminal conduct.
5. Government Requests, Subpoenas, & Law Enforcement
JATDEV complies with the statutory framework of the Arab Republic of Egypt (including Personal Data Protection Law No. 151 of 2020 and Anti-Cyber and Information Technology Crimes Law No. 175 of 2018), and applicable regional laws:
- Judicial Process Requirement: JATDEV will never divulge account records without a valid, legally enforceable court order, formal subpoena, or search warrant issued by an accredited judicial body of competent jurisdiction.
- Technical Impossibility Defense: For air-gapped instances, customer-hosted clusters, or E2EE conversations, JATDEV possesses no cryptographic means to decrypt or reconstruct plaintext communications. Any legal response is strictly limited to records within JATDEV’s immediate custody.
- Customer Notice: Unless explicitly prohibited by a legally binding gag order or statutory national security directive, JATDEV will notify the customer administrator prior to complying with governmental data production requests.
6. Security Posture & User Rights
JATDEV enforces industry-standard technical safeguards: TLS 1.3 in transit, AES-256 at rest, strict separation of tenant environments, and regular code reviews. Individuals wishing to exercise statutory privacy rights (access, correction, or deletion under Egypt Law 151/2020 or regional counterparts) must submit requests directly to their organizational administrator, who manages the workspace data life-cycle.
Privacy & Compliance Directorate: JATDEV — SpaceJAT Operations
Cairo, Arab Republic of Egypt | Regional Hub: Dubai, UAE
Email: privacy@spacejat.com | info@spacejat.com | Web: www.spacejat.com