Privacy & Compliance

Data Sharing & Retention

Transparency is at the core of Aevum News. This document outlines exactly how we handle, share, and retain your personal data in accordance with global privacy standards.

📅 Last Updated: January 15, 2025⚖️ GDPR & CCPA Compliant

01 Overview & Commitment

At Aevum News, we believe that trust is earned through transparency. We do not sell your personal data to third parties or advertisers. Any data shared is strictly for the purpose of delivering, improving, and securing our journalism platform.

This policy applies to all subscribers, registered users, commenters, and visitors who interact with our digital services, including our website, mobile applications, and newsletter distribution systems.

Key Principle: We collect only what is necessary, share only what is permitted or required, and retain only what is justified for operational, legal, or security purposes.

02 What We Share

We may process or share specific categories of data under controlled circumstances:

  • Usage & Analytics Data: Anonymous browsing patterns, device information, and feature engagement metrics used to optimize content delivery and reader experience.
  • Transactional Data: Billing details, payment methods, and subscription history processed securely through certified payment gateways.
  • Communications Data: Email addresses and preference settings for newsletter delivery, account verification, and customer support.
  • Legal & Safety Data: Information shared only when required by law, court order, or to prevent imminent harm, fraud, or platform abuse.

We never share sensitive personal data (health, political affiliations, biometric data, or financial credentials) without explicit, documented consent.

03 Service Providers & Partners

We engage trusted third-party vendors to support our platform operations. All partners are bound by strict data processing agreements (DPAs) and undergo regular compliance audits.

  • Cloud & Hosting: Secure infrastructure providers for website uptime and data storage.
  • Payment Processors: PCI-DSS certified services handling subscription transactions.
  • Analytics Platforms: Aggregated, privacy-first measurement tools to understand reader engagement.
  • Email & Notification Services: Secure delivery networks for newsletters and account alerts.
  • Customer Support: Managed helpdesk systems with role-based access controls.

We do not permit partners to use your data for independent marketing, profiling, or resale purposes.

04 Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law.

  • Active Accounts: Retained for the duration of your subscription plus 12 months for account recovery and support purposes.
  • Subscription Records: Stored for 7 years to comply with tax and financial regulations.
  • Browsing & Analytics Data: Anonymized and aggregated after 14 days; raw event logs are purged after 90 days.
  • Customer Support Tickets: Retained for 24 months after resolution, then securely archived or deleted.
  • Legal & Compliance Data: Retained as long as required by jurisdiction-specific statutes or ongoing investigations.

When data is no longer needed, it is permanently deleted or irreversibly anonymized using industry-standard cryptographic shredding.

05 Your Rights & Controls

Depending on your location, you may have the following rights regarding your personal data:

  • Access & Portability: Request a copy of your data in a machine-readable format.
  • Correction: Update inaccurate or incomplete profile information via your account dashboard.
  • Deletion: Request removal of your data, subject to legal retention obligations.
  • Opt-Out: Unsubscribe from marketing communications or restrict tracking at any time.
  • Restrict Processing: Limit how we use your data during verification or legal disputes.

Requests are processed within 30 days. You may submit requests through your account settings or directly to our Data Protection Officer.

06 Security & Compliance

Protecting your data is not optional—it's foundational to our operations. We implement multi-layered security measures:

  • AES-256 encryption for data at rest and TLS 1.3 for data in transit.
  • Strict role-based access controls (RBAC) and multi-factor authentication (MFA) for internal systems.
  • Regular penetration testing, vulnerability scanning, and third-party security audits.
  • Compliance with GDPR, CCPA/CPRA, and emerging global data protection frameworks.
  • Incident response protocols with 72-hour breach notification procedures where legally required.

07 Policy Updates

We periodically review and update this policy to reflect changes in our services, technology, or applicable laws. Material changes will be communicated via email to registered users and prominently announced on our website.

Continued use of Aevum News services after updates constitute acceptance of the revised terms. The "Last Updated" date at the top of this page will reflect the most current version.

08 Contact Us

If you have questions, concerns, or wish to exercise your data rights, our Privacy & Compliance team is available to assist.

Email
privacy@aevumnews.com
Data Protection Officer
dpo@aevumnews.com
Postal Address
Aevum News Inc. • 1200 Media Plaza, Suite 450 • New York, NY 10001 • USA