Data Collection and Purpose
Centipid Technologies collects specific information necessary for the operation of our ISP billing services. The information we collect includes customer identification details, service usage data, and payment information. This data is essential for processing payments, maintaining service quality, and ensuring system functionality. We maintain records of service usage for billing accuracy, technical maintenance, and the workspace reporting and diagnostic features described in this policy.Staff Access Protocol
Our staff access protocol limits technical support access to authorized personnel for system debugging and support resolution. This is separate from access by authorized workspace operators and the connected services described below. Each debugging session is thoroughly documented, including the reason for access, duration, and actions taken. This ensures complete transparency and maintains the integrity of our privacy commitment.No Contact Policy
Centipid Technologies maintains a strict no-contact policy regarding customer communications. We do not initiate contact with your clients for marketing, promotional, or sales purposes. Our communication is limited to:- Automated billing notifications
- System maintenance alerts
- Direct responses to customer-initiated support requests
- Legal or service-affecting notifications
Data Protection Measures
We implement comprehensive security measures to protect your information. All data is encrypted using industry-standard protocols during transmission and storage. Our security infrastructure includes:- Multi-layer firewall protection
- Regular security audits and updates
- Strict access control protocols
- Continuous system monitoring
- Secure data backup systems
Data Sharing and Connected AI Services
Centipid does not sell customer data or share it with advertising or marketing agencies. Information may be shared with service providers to deliver features you use, including payment processing as described below and authorized connections to external AI services.Connections authorized by your workspace
When an authorized workspace operator connects an external AI service, such as ChatGPT, Centipid provides that service with the information returned by the tools the operator uses. Access follows the operator’s existing permissions and is limited to the connected workspace. Depending on the request, tool results may include subscriber names and contact details, account and subscription information, payment amounts and references, usage and session data, and router information. Operators should connect only services they are authorized to use for their workspace’s data. The external service processes information under its own terms and privacy policy. Disconnecting a service prevents future access through that connection; it does not automatically remove information already returned to that service. Operators should use the external service’s controls to manage previously shared information.Diagnostic features
Some diagnostic features may send diagnostic context to a configured AI provider to generate explanations. Centipid saves diagnostic audits and findings, and may save the associated AI interaction. A diagnostic request does not change router configuration. Network-changing MCP requests require separate confirmation by an authorized operator within Centipid before execution.Data Retention and Management
We retain customer data only for the duration necessary to provide services and comply with legal requirements. Upon service termination, non-essential data is securely deleted from our systems. Financial records are maintained according to applicable laws and regulations, with strict security protocols governing their storage.Customer Rights
As a Centipid Technologies customer, you maintain control over your personal information. You have the right to:- Request a comprehensive report of your stored data
- Correct any inaccurate information
- Export your data in a standard format
- Request deletion of your information upon service termination
- Receive notification of any security incidents affecting your data
Compliance and Updates
This privacy policy complies with current data protection regulations and industry standards. We regularly review and update our privacy practices to ensure continued compliance and optimal data protection.Payment Data Protection
We implement additional security measures specifically for payment-related data:- Payment card information is encrypted using PCI DSS compliant protocols
- Bank account details are stored with enhanced encryption standards
- Payment processing logs are maintained with restricted access
- Automated monitoring systems detect unusual payment patterns
- Regular PCI compliance audits are conducted
Financial Data Retention
Our financial data retention policies include:- Transaction records are maintained for 7 years as per regulatory requirements
- Payment method details are securely stored only until account closure
- Audit logs of financial transactions are preserved for compliance purposes
- Automated data purging occurs after retention periods expire
Automated Billing Data Processing
Our billing system employs automated processing to ensure accuracy and efficiency:- Usage data is automatically collected and processed for billing purposes
- Automated notifications are sent for payment due dates, successful payments, and failed transactions
- System algorithms analyze usage patterns for billing accuracy and the reporting and diagnostic features described above
- Automated data validation checks ensure billing information integrity
- All automated processes are regularly audited for compliance and accuracy
Third-Party Payment Processors
When using third-party payment processors:- We select only PCI-compliant payment processors with strong security records
- Minimal necessary information is shared with payment processors to complete transactions
- We maintain contractual agreements requiring processors to protect your data
- Payment processor interactions are logged and monitored
- We regularly review and assess the security practices of our payment partners
Data Breach Response Protocol
In the unlikely event of a data breach affecting billing information:- We will notify affected customers within 72 hours of breach confirmation
- Detailed information about the breach scope and affected data will be provided
- We will cooperate fully with law enforcement and regulatory authorities
- Remediation steps will be implemented immediately to prevent further exposure
- Credit monitoring services may be provided for affected customers when appropriate
Billing System Access Logs
Our billing system maintains detailed access logs:- All administrator access to billing data is logged with timestamps and action details
- Customer account access is recorded for security monitoring
- Failed login attempts are monitored and flagged for security review
- Access logs are retained for as long as your account is active
- Regular access pattern analysis is conducted to detect potential security issues
