DRAFT — not yet counsel-reviewed
Privacy Policy
MultiEdge Signal Relay is auditable signal-distribution infrastructure — not execution. Last updated 2026-09-14.
Who we are
The service and this website are operated by RocketEdge.com Pte. Ltd., a company incorporated in Singapore, which is the organisation responsible for the personal data described here (the controller, in GDPR terms) except where it acts on a tenant's instructions. Our Data Protection Officer, designated under section 11 of the Personal Data Protection Act 2012, can be reached at access@multiedge.ai. Where we are required to appoint a representative in the European Union or the United Kingdom, the representative will be named here once appointed.
What we collect
- Access requests: firm, name, work email and role — used solely to evaluate and respond to the request. The work e-mail address is confirmed by a link we send to it; the questionnaire that link opens then collects the firm's registration details, regulatory status, the people who will hold credentials, intended use, directors and beneficial owners, and the politically-exposed-person and sanctions declarations the questionnaire asks for. The answers are stored in our database (Azure SQL, Central US) with the request record, and a PDF summary is e-mailed to the address given. Each submission also records technical context for anti-abuse and business-verification purposes: your IP address and the registry-published owner of its network block, its reverse-DNS name, the mail provider of your email domain, your browser and operating system, and your browser's language and time zone. We do not use a geolocation database; the network-block owner and its registration country come from the address registries' own public RDAP records, not from any attempt to locate you. This context is retained with the request record and is never used for advertising or profiling.
- Portal accounts: the work email, password hash, second-factor secrets or passkeys, and recovery-code hashes of the individuals a tenant nominates to use the portal, plus an audit trail of the actions they take.
- Operational data: tenant configuration, subscriber firm records, endpoint addresses, API-key hashes, and delivery-ledger records (timestamps, statuses, response codes) — required to operate an auditable relay.
- Signal payloads: stored to provide sequencing, delivery, retry, and replay for the retention window; never analyzed, aggregated, resold, or used to train models. For strategies in sealed mode we hold only ciphertext we cannot read. We process payloads on the publisher's instructions; the publisher remains responsible for any personal data it chooses to place in them.
- Billing: a billing contact and the customer and subscription identifiers Stripe assigns; card details are entered on Stripe's hosted page and never reach us.
- Site usage analytics: this website uses Google Analytics 4 (traffic measurement; first-party cookies _ga, _ga_*; data processed by Google under the Google Privacy Policy) and Microsoft Clarity (page interactions, session replay, heatmaps; first-party cookies _clck, _clsk, and Microsoft third-party cookies including MUID; Microsoft processes Clarity data as its own controller under the Microsoft Privacy Statement), and Azure Application Insights (page views, load timings, and JavaScript errors, plus the coarse country and city that Azure derives from the connection's IP address at ingestion — the stored IP itself is masked; configured without cookies and sampled, running in our own Azure subscription rather than a third-party service). We use these to improve the site, to diagnose faults, and for aggregate operations reporting — never for advertising.
Why we process it, and on what basis
- To evaluate and respond to access requests — your request, and our legitimate interest in verifying that a firm is who it says it is.
- To operate the relay for a tenant — performance of the tenant's contract; for payload content, the publisher's documented instructions.
- To keep an auditable delivery record — our legitimate interest, and our tenants' interest, in being able to prove what was delivered, to whom and when, and to answer disputes and regulatory enquiries.
- To secure the service and prevent abuse — our legitimate interest, including the technical context recorded with access requests.
- To bill — performance of the contract and our accounting obligations.
- Site analytics — your consent where the law requires it for cookies (see Cookies below); otherwise our legitimate interest in understanding how the site is used.
What we do not do
- No advertising and no sale of visitor data. Google Analytics and Microsoft Clarity are the only third-party analytics on this site; Application Insights runs in our own Azure subscription.
- No precise geolocation and no geolocation database of our own. Azure Application Insights derives a coarse country and city from the IP address at ingestion (the stored IP is masked), which we use only for aggregate operations reporting; for security and operations we may look up the registered owner of a network block in the public RDAP registries. We never track or store a visitor's physical location.
- No sale or sharing of tenant data with third parties, and no use of signal content for any purpose other than operating the service.
- No retail data collection — the service has no retail surface.
Where data lives
The service runs in Microsoft Azure in the United States: the relay database (tenant records, payloads, the delivery ledger) in Central US, the API and worker tier, message queues and key vault in East US, and this website in East US 2. Backups and geo-redundant copies stay within Azure's United States regions. Secrets are held in a managed key vault; logs record identifiers and hashes rather than payloads or credentials.
Sub-processors
We use the following providers to run the service. Each is bound by a written data-processing agreement, and we will give tenants notice before adding or replacing one.
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Microsoft Corporation — Azure | Hosting, database, messaging, key vault, telemetry, backups, write-once evidence archive | Tenant and subscriber records, endpoint addresses, API-key hashes, portal credentials, signal payloads, delivery ledger and evidence, logs | United States (Central US, East US, East US 2) | Microsoft Data Protection Addendum (2021 EU Standard Contractual Clauses, UK Addendum); Microsoft Corporation is certified under the EU-US Data Privacy Framework and its UK Extension |
| Microsoft Corporation — Azure Communication Services | Transactional e-mail (invites, password resets, reports, billing reminders) | Recipient address, message content while in transit, delivery logs | United States | As above |
| Stripe, LLC | Hosted checkout and subscription billing | Billing contact, payment details (held by Stripe, never by us), customer and subscription identifiers | United States | Stripe Data Processing Agreement (Standard Contractual Clauses, UK Addendum); Stripe, LLC is certified under the EU-US Data Privacy Framework and its UK Extension |
| Google LLC — Google Analytics 4 | Website traffic measurement | Pseudonymous client identifier, page and event data, coarse location | United States | Google Ads Data Processing Terms (Standard Contractual Clauses); Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension |
Microsoft Clarity is not a sub-processor: Microsoft processes Clarity data as its own controller, as described under Cookies.
International transfers
We are established in Singapore and host in the United States, so personal data leaves the country it was collected in. From Singapore, the Personal Data Protection Act's transfer limitation is met by the legally enforceable obligations in our providers' data-processing agreements. For data originating in the European Union, transfers to Microsoft, Stripe and Google rest on their EU-US Data Privacy Framework certifications, with the 2021 Standard Contractual Clauses in their agreements as a fallback; transfers to us in Singapore rest on Standard Contractual Clauses with the tenant concerned. For data originating in the United Kingdom, we rely on the UK Extension to the Data Privacy Framework (the UK-US data bridge) for those providers and on the International Data Transfer Agreement or UK Addendum with tenants. We keep a written transfer risk assessment for each route.
How long we keep it
- Signal payloads: 90 days in the relay database, then exported to an archive and deleted from the database.
- Delivery attempts: 30 days in the relay database; the delivery evidence record (destination, hash of bytes sent, signature, response) is archived to write-once storage and kept for five years, because it exists to answer disputes and regulatory enquiries. It never contains payload content.
- Tenant, subscriber and portal records: for the life of the account. A tenant's "delete" of a feed or subscriber archives the record rather than erasing it, so that the ledger stays reconcilable; we pseudonymise contact fields on request and purge archived records on the schedule above.
- Access requests: for as long as the request is open and for a further 12 months.
- Operational logs and telemetry: 180 days.
- Database backups: 35 days point-in-time, with long-term backups kept up to seven years and treated as beyond use.
Your rights
You may ask for access to, and correction of, the personal data we hold about you. If you are in the European Union or the United Kingdom you may also ask for erasure, restriction, portability, and object to processing based on our legitimate interests, and you may complain to your supervisory authority. If you are a California resident you may ask what we collect, request deletion, and opt out of any sale or sharing; we honour Global Privacy Control signals. Where a delivery record must be retained to defend legal claims or to meet an audit obligation, we will tell you which record and why. Write to the Data Protection Officer at access@multiedge.ai; we answer within 30 days.
Cookies
This site sets the analytics cookies listed above. Application Insights is cookieless. Visitors from the European Economic Area, the United Kingdom and Switzerland will be asked for consent before Google Analytics or Clarity runs; until that consent control is deployed, those tools can be blocked with your browser's cookie settings or Google's opt-out extension, and Clarity honours the Global Privacy Control signal. Clarity's session replays mask form inputs and are kept by Microsoft for 30 days.
If something goes wrong
If a breach affects your personal data we will notify the tenant whose data it is without undue delay, the Personal Data Protection Commission within three calendar days of assessing that the breach is notifiable, and the relevant European or United Kingdom authority within 72 hours where their rules apply, and we will tell affected individuals where the breach is likely to cause them significant harm.
Contact
Data questions, deletion requests, or the Data Protection Officer: access@multiedge.ai. This is a placeholder draft and will be replaced by a counsel-reviewed policy before production launch.