1. Introduction

Dawnpoint Labs LLC is an applied research and computer systems design studio. This Privacy Policy describes the information we collect when you visit our website, speak with our team, engage us for research and engineering services, or otherwise interact with our organisation. We wrote this document in plain language on purpose, because a privacy notice that cannot be understood is not a meaningful notice. We encourage you to read it in full and to contact us with any question that remains open.

The developer and operator of this website is DawnPoint Labs. All references to the Company, we, us and our mean Dawnpoint Labs LLC throughout this document. Our registered business address is 2279 N University Pkwy, Provo - 84604-1543, United States (US). You can reach our team at labs@dawnpointlabs.mom or by telephone at +17179247521 for any privacy related request described below.

Privacy at Dawnpoint Labs LLC is treated as an engineering constraint rather than a paperwork exercise. When we design a data platform for a client, or run a field trial, or prototype a product, we ask what personal information the system truly needs and we remove everything else. That same discipline governs how we handle information about the visitors and clients who come to this website.

2. Who We Are

Dawnpoint Labs LLC provides computer systems design and related professional services. Our work includes applied research programmes, product prototyping sprints, systems integration engineering, data platform design, usability and field trials, and technology advisory retainers. In each of those activities we may receive information about people, and in each of those activities the rules in this policy apply.

For the purposes of applicable data protection law, Dawnpoint Labs LLC is the controller of personal information collected through this website and through our direct business communications. Where we process information on behalf of a client as part of a research or engineering engagement, Dawnpoint Labs LLC generally acts as a processor and the client acts as the controller. In that situation the client decides the purposes of processing, and our obligations are set out in the written engagement agreement between us.

Our office is located at 2279 N University Pkwy, Provo - 84604-1543, United States (US). The Company operates from that address, and correspondence delivered there reaches our principals directly.

3. Scope Of This Policy

This policy applies to information collected through the Dawnpoint Labs LLC website, through electronic mail and telephone conversations with our team, through proposals and contracts exchanged with prospective and current clients, and through any other interaction that links to this policy. It also applies to information we receive from visitors who submit a message through our contact form or who subscribe to occasional research updates.

This policy does not apply to information that our clients collect and control on their own systems, even where we helped to design those systems. It also does not apply to third party websites that we may link to for reference. Where a separate agreement governs a research or engineering engagement, the data protection terms of that agreement prevail over this policy for the processing described there.

We keep our records of what this policy covers deliberately simple. If you are unsure whether a given interaction falls inside the scope described here, write to labs@dawnpointlabs.mom and we will tell you plainly which document applies.

4. Information We Collect

We collect information in three broad categories. The first category is information you give us directly. The second category is information generated automatically as you use this website. The third category is information produced during the delivery of client engagements. Each category is described below in detail.

Information You Provide Directly

Information Collected Automatically

Information Produced In Client Work

We do not seek sensitive categories of personal information such as health details, political opinions or precise location history, and we ask that you do not send such information to us through the website contact form.

5. How We Collect Information

Most information reaches us because a person chooses to send it. When you complete our contact form, your browser prepares a message and hands it to your email client, which sends it to our mailbox. When you telephone the studio, our notes from that conversation are recorded in our engagement system. When you reply to a proposal, the reply itself becomes part of the correspondence record.

A smaller portion of information is generated automatically by the web server that hosts this site. That server writes a log line for each request, which is standard practice and helps us detect abuse, diagnose faults and understand which pages are useful. We do not combine those log lines with your identity, and we do not attempt to reconstruct an individual browsing history from them.

During field trials, information is collected according to a protocol that is written down in advance and reviewed with the client. Participants are told what will be observed, how long the session will last, and how they can withdraw. We collect only what the protocol calls for, and we destroy the raw material when the agreed retention period ends.

6. Why We Use Information

We use personal information for a narrow set of purposes, each of which is tied to a legitimate business need. The purposes are the following.

We do not sell personal information. We do not rent personal information. We do not trade personal information with advertising networks. We do not use information you send us to train external models or to seed third party marketing systems.

8. Client And Research Data

Research and engineering engagements often involve information that belongs to a client or to a research participant. We treat that material under stricter rules than our own marketing records. Access is limited to the engineers assigned to the engagement, the material is stored in the client workspace rather than in general company storage, and the retention period is set out in the engagement agreement.

Where an engagement involves human participants, we prepare a written protocol describing the purpose of the study, the data that will be recorded, the measures taken to reduce identifiability, and the way participants can ask for their data to be removed. We do not publish participant level data. When we publish findings, we aggregate or synthesise them so that no individual can reasonably be re-identified.

Client source code, system diagrams and datasets remain the property of the client. On completion of an engagement we transfer the agreed artifacts to the client and delete our working copies within a period stated in the agreement, unless a shorter or longer period was negotiated in writing. Backup copies are purged as the backup rotation rolls forward.

9. Cookies And Local Storage

This website is deliberately lightweight. We do not operate advertising cookies and we do not embed third party tracking pixels. The pages you are reading are static documents served with a stylesheet and a small script that improves navigation on narrow screens.

If a cookie or a local storage entry is ever required for a functional purpose, such as remembering whether a mobile menu has been opened, it is used only to make the interface behave sensibly and is not used to identify you. You can delete cookies and local storage at any time through your browser settings, and the site will continue to work.

We may measure aggregate traffic using a privacy respecting analytics method that does not set a persistent identifier. Where that method is used, the resulting numbers describe page views and referrers, not individuals.

10. How We Share Information

We share personal information only in the limited circumstances described in this section. We never sell data and we never hand information to an advertising broker.

When disclosure is compelled by law, we review the request carefully, provide only the information actually required, and notify the affected person where the law permits us to do so. If a reorganisation occurs, the receiving entity must honour the commitments made in this policy or give notice of a changed policy before further processing.

11. Service Providers And Processors

Like most professional practices we rely on a small number of suppliers. These may include a hosting provider for this website, an electronic mail provider for correspondence, a cloud storage provider for engagement documents, and an accounting service for invoicing. Each supplier is chosen with care and bound by a written agreement that restricts the use of the information to the service we asked for.

We review our supplier list periodically and remove any supplier whose security posture or privacy commitments no longer meet our requirements. Where a supplier processes personal information in a country outside your own, we take the contractual steps required by applicable law to protect the transfer, as described in the international transfer section below.

We do not authorise any supplier to use our client information for its own marketing, for product improvement outside the contracted service, or for sale to another party.

12. Data Retention

We keep personal information only for as long as it serves the purpose for which it was collected, plus any period required by law. The following retention framework describes our ordinary practice.

When a retention period ends we delete the information or, where deletion is not immediately practical, we anonymise it so that it can no longer be linked to a person. If you ask us to delete your information earlier and no legal obligation prevents it, we will do so and confirm the action in writing.

13. Security Measures

Security at Dawnpoint Labs LLC is handled as an engineering discipline. We apply the same threat modelling to our own systems that we apply to client systems. The measures below describe our baseline.

No system is perfectly secure, and we will not claim otherwise. We can promise that we treat the protection of your information as a first class requirement, that we review our controls on a scheduled basis, and that we will tell you promptly if something goes wrong in a way that affects you.

14. International Transfers

Dawnpoint Labs LLC is based in the United States, so information we receive is ordinarily stored and processed there. If you contact us from another country, your information will be transferred to the United States for the purpose of answering you. We take steps to ensure that such transfers are protected, including the use of recognised contractual clauses with our suppliers and a review of the legal environment in each destination.

Where an engagement requires information to remain in a particular jurisdiction, we are willing to discuss regional storage and to record that commitment in the engagement agreement. Several of our clients operate under sector rules that restrict where data may reside, and we are used to working within those constraints.

You may write to us at any time to ask which countries are involved in a particular processing activity, and we will answer with the specific suppliers and locations rather than a general statement.

15. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights in relation to your personal information.

To exercise any of these rights, write to labs@dawnpointlabs.mom with enough detail for us to locate your records. We will acknowledge your request promptly and normally complete it within thirty days. If the request is complex or covers a large volume of material we will explain the reason for any extension rather than leaving you to wonder.

Where a client is the controller of your information, we may need to forward your request to that client. We will tell you when that happens and will assist the client in answering you within the time the law allows.

16. Privacy For Children

This website and our services are directed at organisations and adult professionals. We do not knowingly collect personal information from children. If you believe that a child has sent information to us, please contact labs@dawnpointlabs.mom and we will delete the material promptly.

In the rare engagement where a study might involve younger participants, the protocol is designed with the client and includes documented guardian consent, age appropriate explanations, and additional restrictions on what may be recorded. Such work proceeds only after our internal review confirms the safeguards are adequate.

17. Automated Decisions And Profiling

We do not make decisions that produce legal effects about individuals through automated processing alone. We do not build behavioural profiles for advertising. We do not score visitors to this website.

Where a client engagement calls for a machine learning component, that component is designed with human review in the loop for any decision that affects a person materially. We document the training data sources, the evaluation method and the known limitations of the model, and we hand that documentation to the client at the close of the engagement.

18. Third Party Links

Our pages may reference external resources that we find useful, such as standards bodies, research publications or open source projects. Those destinations have their own privacy practices, which we do not control and cannot describe here. We encourage you to read the privacy notice of any site before submitting information to it.

A link from our site does not imply that we endorse the privacy practices of the destination. We include links because the material is relevant, and we review them when we notice that they have changed, but the responsibility for each external site remains with its operator.

19. Data Breach Response

If we become aware of a security incident that affects personal information, we follow a written response procedure. The procedure begins with containment, moves through forensic assessment, and ends with notification and remediation. The team practises the procedure so that the first time it is used is not during a real incident.

Where notification is required by law, we contact the relevant supervisory authority and the affected individuals without undue delay. Our notice explains what happened, what information was involved, what we have done to contain the incident, and what steps the affected person can take to reduce risk.

We keep a record of every incident and of the lessons drawn from it, and we adjust our controls accordingly. A breach that produces no change in practice would mean the review failed.

20. Changes To This Policy

We review this policy at least once each year and whenever our practices change in a material way. When we make a change we update the effective date at the top of the page and, for significant changes, we place a short notice on the homepage so that returning visitors are aware.

Continued use of the website after a change takes effect indicates acceptance of the revised policy. If you do not agree with a revision, you may ask us to delete the information we hold about you, subject to any legal retention obligation.

Earlier versions of this policy are available on request. If you need to know what the policy said on a particular date, perhaps because of a contract, write to labs@dawnpointlabs.mom and we will provide the relevant version.

21. How To Contact Us

Questions, requests and complaints about privacy are welcome and are handled by our principals directly. Please include the nature of your request and any detail that helps us locate the relevant records.

If you are not satisfied with our response, you may have the right to lodge a complaint with the data protection authority in your country of residence. We would rather resolve the matter with you directly first, and we will cooperate fully with any authority that reviews the case.