Enterprise Privacy Policy & Data Security Directive
NEX-TRACE GLOBAL, INC. RESPECTS INSTITUTIONAL TRADE PRIVACY AND CLIENT CONFIDENTIALITY. THIS DIRECTIVE GOVERNS HOW SCREENED COUNTERPARTY DATA, BENEFICIAL OWNERSHIP TREES, API TELEMETRY, AND CRYPTOGRAPHIC AUDIT CERTIFICATES ARE INGESTED, PURGED, ENCRYPTED, AND STATUTORILY RETAINED.
1.0 Institutional Privacy Commitment & Scope
Nex-Trace Global, Inc. ("Nex-Trace", "Company", "we", "us") delivers high-assurance, defense-grade corporate graph screening to regulated exporters. Unlike consumer data brokers, Nex-Trace operates under strict business-to-business confidentiality covenants. We do not track users across the public internet, deploy tracking cookies for advertising networks, or monetize search queries.
This Privacy Policy applies to all services provided under the Nex-Trace domain, our FastAPI HTTP endpoints (/api/v1/screen, /api/v1/audit/{id}/pdf, /api/v1/webhooks/erp-pre-check), the FastMCP screening servers, and the Web Dashboard.
2.0 Information We Ingest and Process
In providing export compliance screening, we process the following distinct categories of data:
3.0 The Technical "Context Economy" Protocol
In accordance with our internal security directives, the Platform enforces an automated Context Economy Protocol via backend.app.engine.context_cleaner:
✓ Data Minimization: When resolving commercial networks from external APIs, our ingestion pipeline strips all irrelevant administrative noise, annual return boilerplate, scanned filing attachments, and raw HTML descriptions.
✓ Essential Graph Topology Only: We store only the mathematical minimum required for deterministic NetworkX calculations: normalized entity identifier, legal name, jurisdiction ISO, ownership stake percentage (equity_pct), and board control flags.
4.0 Statutory 5-Year Retention (EAR ยง 762 Compliance)
4.1 Mandatory Federal Retention: Under 15 CFR § 762.6, all records relating to export transactions, pre-screening evaluations, and license determinations must be retained for a mandatory statutory period of five (5) years from the date of export or assessment.
4.2 Cryptographic Immutability: Every audit determination executed via POST /api/v1/screen is stored with its microsecond timestamp, full graph topology, and a tamper-evident SHA-256 digital signature in our compliance repository (TrackedCounterparty). Customer may export and archive signed Safe Harbor PDF certificates at any time.
4.3 Ephemeral Caching Lifecycle: External registry lookup caches in Redis operate on a strict 14-day Time-To-Live (TTL). Once expired, cached shareholder trees are purged automatically.
5.0 Data Security Architecture & Multi-Tenant Isolation
Nex-Trace implements physical, administrative, and technical safeguards engineered for high-consequence enterprise environments:
- FIPS 140-2 Validated Encryption: All database storage volumes and backups are encrypted at rest using AES-256.
- Transport Layer Security: All external API communications require TLS 1.3 with forward secrecy cipher suites.
- HMAC Webhook Authentication: Outgoing ERP compliance hold notifications dispatched to customer systems are signed with HMAC-SHA256 tokens to prevent spoofing.
- Tenant Isolation: Customer audit trails are logically segmented using unique enterprise tenant identifiers with strict row-level security.
6.0 Law Enforcement, Subpoena, & Regulatory Disclosures
Nex-Trace will not disclose Customer screening logs to third parties except where strictly required by applicable federal law:
In the event Nex-Trace receives a formal subpoena, national security letter, or court order from the U.S. Department of Justice (DOJ), BIS Office of Export Enforcement (OEE), or OFAC, Nex-Trace will notify Customer prior to disclosure unless explicitly prohibited by a federal non-disclosure order (gag order) issued by a court of competent jurisdiction.
7.0 International Data Transfers & Global Compliance
While the Platform is hosted in accredited United States data centers, we maintain compliance protocols for international customers:
- EU GDPR & UK Data Protection Act: Where screening queries involve European corporate entities or sole proprietors, transfers are protected by Standard Contractual Clauses (SCCs).
- UAE & Middle East Trade Hubs: Counterparty screenings routed through Dubai (DIFC) comply with DIFC Data Protection Law No. 5 of 2020 and UAE Federal Decree Law No. 45/2021.
8.0 Data Subject Rights & Security Contact
Enterprise customers may request verification of their historical audit volumes, request deletion of expired temporary caches, or report security vulnerabilities by contacting our designated Chief Information Security Officer (CISO) and Data Protection Officer at:
