Table of Contents
1. Introduction & Commitment
At Aevum News, trust is the foundation of journalism. We recognize that digital news consumption carries inherent privacy and safety risks. This document outlines our commitment to transparency, the risks we actively monitor, the safeguards we implement, and the shared responsibilities required to maintain a secure information ecosystem.
Our Promise: We do not sell personal data to third-party brokers. All analytics are aggregated and anonymized by default. Reader safety and editorial integrity remain our highest priorities.
2. Data Privacy & Information Handling
We collect minimal data necessary to deliver content, personalize reading experiences, and maintain platform security. Your privacy is protected through strict access controls and encryption standards.
2.1 Data Collected
- Account Data: Email, subscription tier, payment processing tokens (never raw card numbers)
- Usage Analytics: Page views, session duration, device type, approximate geographic location (city/region level)
- Communications: Support tickets, newsletter preferences, and voluntary survey responses
- Cookies: Strictly necessary, functional, and analytics cookies. Ad-tracking cookies are disabled by default.
2.2 Data Retention & Deletion
Account data is retained for the duration of your subscription plus 24 months post-cancellation. Analytics data is anonymized after 13 months. You may request full account deletion at any time via Settings or by contacting our privacy team.
3. Identified Safety Risks
Operating a global digital news platform exposes users and infrastructure to several risks. We actively monitor and mitigate the following:
⚠ Account Compromise & Phishing: Attackers may attempt to mimic Aevum News communications to steal credentials. We never request passwords via email. Enable two-factor authentication (2FA) immediately.
⚠ Malicious Links & Drive-By Downloads: Third-party ads or embedded media may occasionally host compromised assets. Our content delivery network (CDN) runs real-time scanning, but users should avoid clicking unverified external links.
⚠ Data Scraping & Credential Stuffing: Automated bots may attempt to harvest content or test leaked passwords against our systems. Rate limiting, CAPTCHA challenges, and anomaly detection are active.
⚠ Misinformation & Deepfake Distribution: While editorial verification is rigorous, user-shared content or third-party syndication may occasionally bypass initial filters. Reporting tools are available on all articles.
4. Security Architecture
Aevum News employs defense-in-depth strategies aligned with industry best practices:
- Encryption: TLS 1.3 in transit, AES-256 at rest. End-to-end encryption for sensitive communications.
- Infrastructure: Isolated microservices, zero-trust network access, automated patching, and DDoS mitigation via cloud providers.
- Access Control: Role-based permissions, mandatory MFA for staff, quarterly access audits, and principle of least privilege.
- Content Safety: AI-assisted moderation, human editorial review, hash-matching against known malicious URLs, and image/video integrity verification.
5. User Guidelines & Responsibilities
Safety is a shared responsibility. We recommend the following practices while using Aevum News:
- Use Strong, Unique Passwords and enable Two-Factor Authentication (2FA) in your account settings.
- Verify URLs before clicking. Official Aevum News domains end with `aevumnews.com`. Beware of lookalike domains.
- Keep Software Updated including browsers, operating systems, and security tools.
- Report Suspicious Activity immediately via the in-app report button or security@aevumnews.com.
- Review Cookie & Privacy Settings regularly to ensure your preferences align with your comfort level.
6. Incident Response Protocol
In the event of a confirmed security incident or data breach, Aevum News follows a structured response framework:
- Detection & Containment: Automated alerts trigger immediate isolation of affected systems.
- Assessment: Security engineers and third-party auditors evaluate scope, impact, and root cause.
- Notification: Affected users will be notified within 72 hours via email and in-app alerts, with clear guidance on protective steps.
- Remediation: Patches, credential resets, and system hardening are deployed immediately.
- Post-Incident Review: A public transparency report is published within 30 days detailing what occurred, what was learned, and how safeguards were improved.
7. Regulatory Compliance & Updates
Aevum News complies with applicable data protection regulations including GDPR, CCPA, LGPD, and PECR. We conduct annual third-party security audits and maintain ISO 27001 certification for information security management.
This document will be updated as technology, threats, or regulations evolve. Significant changes will be announced via email and platform banner notifications. Continued use of our services constitutes acknowledgment of these terms.
8. Contact & Support
Questions, concerns, or reports regarding privacy, security, or safety risks can be directed to the appropriate channels below: