Privacy Policy
What Archangel collects, why, how long, how we protect it, and how you assert your rights. Written to comply simultaneously with GDPR, UK-GDPR, CCPA/CPRA, PIPEDA, LGPD, POPI, PDPA (Singapore), and APPI. Where jurisdictions differ, the standard most protective of you applies to your Personal Data.
Table of Contents
1. Who this Policy is for
This Privacy Policy applies to (a) visitors to archangel.nexusblue.xyz, (b) individuals who install the Archangel App, (c) operators who sign into the Archangel operator console on behalf of an Authority, and (d) individuals whose Personal Data is processed incidentally in connection with the Archangel platform. Each role has a distinct data-flow, described below.
2. Who the Controller is
For the App and for the archangel.nexusblue.xyz site, the Controller is White Crown Enterprises (WCE LLC, WCE Inc., LXM Trust). For Personal Data processed on the operator console at the direction of an Authority (for example, a school, hospital, or airport), the Authority is the Controller and WCE acts as Processor under a Data Processing Addendum.
3. What we collect and why
3.1 Website visitors
Server logs (IP address, user-agent, referrer, timestamp, response status) for security, abuse-detection, and to run the site. No third-party analytics, no advertising trackers, no fingerprinting. We do not sell or share your data with advertisers.
3.2 App users
Account identifier and authentication credentials (managed via Nexus Blue Sign-In); device model and OS version (for compatibility); the Coverage Areas you subscribe to (to route Notifications to you); and diagnostic events (for stability). Biometric templates for BioLock never leave your device. We do not collect the contents of your camera, microphone, or contacts unless you explicitly grant permission for a specific feature that requires it.
3.3 Operator console (Authority Personal Data)
Operator identifier, session metadata, and Notification history. Content of Notifications is categorical (see the Capability Statement). Where an Authority attaches media or transcripts to a Notification, that media is Authority Personal Data and is governed by the DPA.
3.4 Support requests
Whatever you send us in a support ticket. Please do not send sensitive information unless it is necessary to resolve your issue.
4. Legal bases
We process Personal Data on the following bases, as applicable to you: (a) Contract — to deliver the service you asked for; (b) Legitimate interests — to secure the service, prevent abuse, and improve the product, balanced against your rights; (c) Consent — where a feature requires it (for example, marketing e-mails); (d) Legal obligation — where we are required to retain or disclose data by law. You can withdraw consent at any time; withdrawal does not affect processing that already occurred.
5. How long we keep it
Server logs: 90 days. Account records: for the life of the account plus 12 months. Support tickets: 24 months. Notification history on the operator console: as configured by the Authority under its DPA, with a default of 12 months and a maximum of 84 months where required by sector law. Data subject to a legal hold is retained until the hold is released.
6. Who we share it with
We do not sell Personal Data. We share it only with (a) sub-processors we have engaged to deliver the service (list at /legal/subprocessors.html), each bound by contract terms no less protective than this Policy; (b) our professional advisors under confidentiality; (c) an acquirer in a merger, acquisition, or asset sale (subject to a continuity commitment to this Policy); or (d) authorities where we are legally compelled, in which case we will notify you unless prohibited by law.
7. International transfers
Personal Data originating in the EEA or the UK is processed primarily in Frankfurt, Germany, with failover in Dublin, Ireland, and is not transferred outside the EEA/UK for provision of the App unless a valid transfer mechanism (Standard Contractual Clauses, UK Addendum) is in place. Personal Data originating in the United States is processed in Virginia (primary) and Oregon (failover). Personal Data originating in Canada is processed in Toronto (primary) and Montréal (failover). A current data-flow map is at /legal/data-flow.html.
8. Your rights
Depending on where you live, you may have the right to (a) access your Personal Data, (b) correct inaccurate data, (c) delete data, (d) restrict or object to processing, (e) portability, (f) withdraw consent, (g) not be subject to a decision based solely on automated processing that produces legal effects, and (h) lodge a complaint with your supervisory authority. We do not use automated decision-making with legal effects. To exercise a right, contact us at privacy@whitecrownenterprises.com. We will respond within thirty (30) days, or the timeframe required by your jurisdiction if shorter. There is no charge for the first request in a twelve-month period.
9. Cookies and similar technologies
The archangel.nexusblue.xyz site uses only strictly-necessary cookies for security and session integrity. It does not set advertising, analytics, or fingerprinting cookies. The App uses local storage on your device to hold your session; it does not use tracking cookies. Where a jurisdiction requires a consent banner even for strictly-necessary cookies, we show one; declining leaves the site fully functional.
10. Children
The App is not intended for children under 13 (U.S.) or under 16 (EU/UK, unless a member state has set a lower age of consent under Article 8 GDPR). If you learn that a child has provided us Personal Data without appropriate consent, contact us and we will delete it. Where the App is used in a school under an Authority's Order Form, additional protections apply under the Schools & K-12 Addendum.
11. Security
We maintain a written information security program aligned to ISO/IEC 27001, NIST SP 800-53 Moderate, and SOC 2 Trust Services Criteria. Personal Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is need-to-know, MFA-gated, and logged. We notify affected users of a confirmed Personal Data Breach without undue delay and within seventy-two (72) hours of confirmation.
12. Changes to this Policy
We may update this Policy from time to time. If a change is material, we will notify you through the App, by e-mail, or by a notice on the site at least thirty (30) days in advance where reasonably practicable, and we will show the effective date at the top of the Policy. Prior versions are archived at /legal/privacy-archive.html.
13. Contact and Representatives
13.1 WCE (Controller / Publisher)
White Crown Enterprises · Attn: Privacy · United States postal address in the site footer · privacy@whitecrownenterprises.com
13.2 EU Representative (Article 27 GDPR)
Nexus Blue EU Representative · [EU address in the site footer] · eu-rep@whitecrownenterprises.com
13.3 UK Representative (UK-GDPR)
Nexus Blue UK Representative · [UK address in the site footer] · uk-rep@whitecrownenterprises.com
13.4 Data Protection Officer
This Policy takes effect on the date shown at the top of this page and remains in effect until amended.