⚠ PRE-PUBLICATION NOTICE — REMOVE BEFORE POSTING

This Policy describes the federated identity access model (Option A): Google login used only for sign-in, and cloud environment access granted directly by the customer through their own cloud IAM configuration.

Do not publish this Policy until that change is live in production and cloud-platform has been removed from the application. Until then, the description in Section 2.3 does not match what the product actually does, and publishing it would be an inaccurate public representation of our data practices.

Owner of the gate: [ABE]. Trigger to publish: engineering confirms the split is deployed and the legacy scope is removed.


LEVIATHAN SOLUTIONS INC.

PRIVACY POLICY

Effective Date: [DATE]

Last Updated: [DATE]


1. Who We Are and What This Policy Covers

Leviathan Solutions Inc. ("Leviathan," "we," "us") is a Delaware corporation that provides a Kubernetes and cloud optimization platform and related professional services.

This Policy explains how we handle personal information in two distinct capacities. The distinction determines which rules apply and who you should contact.

We act as a controller — meaning we decide why and how personal information is used — for:

We act as a processor — meaning we handle information solely on a customer's documented instructions — for personal information contained in or derived from a customer's cloud environment that we access in delivering the platform or our services.

This Policy governs only the first category. Our handling of customer environment data is governed by the Master Services Agreement and Data Processing Agreement between Leviathan and that customer, not by this Policy. If you are an employee or end user of one of our customers and have questions about that data, contact that customer directly. They control it, and we act on their instructions.


2. Information We Collect

2.1 Information You Give Us

| Category | Examples | Why We Collect It | |----|----|----| | Identifiers | Name, business email address, employer, job title | To respond to inquiries, create and administer accounts, provide the platform | | Account credentials | Authentication identifiers; passwords, where used, are stored only in hashed form | To authenticate you and secure your account | | Communications | Messages you send us, demo requests, support tickets | To respond to you and maintain records of our dealings | | Billing information | Billing contact, address, purchase order and invoice details | To invoice and collect payment |

We do not intentionally collect special categories of personal data (GDPR Article 9) or sensitive personal information (as defined under California law), and we ask that you not send it to us.

2.2 Information We Collect Automatically

[CONFIRM WITH ENGINEERING BEFORE PUBLICATION — the table below describes typical practice. It must be verified against what leviathaninc.com and app.leviathaninc.com actually deploy. An inaccurate description here is a deception exposure, not a drafting nicety.]

| Category | Examples | Why We Collect It | |----|----|----| | Device and connection data | IP address, browser type, operating system, referring page | To operate and secure the site and diagnose problems | | Usage data | Pages viewed, features used, timestamps, session duration | To understand how the platform is used and improve it | | Cookies and similar technologies | Session cookies, and [analytics / preference] cookies | See Section 8 |

2.3 Google Sign-In

You may sign in to the platform using your Google account. We describe this separately because Google requires it and because we want it to be unambiguous.

What we receive. Through Google Sign-In we receive your Google account email address and basic profile information (name and, where you have set one, profile image). We use this solely to identify you, authenticate you, and create and administer your account.

What we do not receive. Google Sign-In does not give us access to your Google Cloud resources, your Google Workspace data, your Gmail, your Drive files, your calendar, or your contacts. We do not request those permissions.

How we use it. Consistent with the Google API Services User Data Policy, including its Limited Use requirements, we use information obtained through Google APIs only to provide the user-facing sign-in and account features you have asked for. Specifically:

You may revoke our access at any time through your Google account settings. Revocation will disable Google Sign-In for your account; you may still access the platform through any other authentication method we support.

2.4 Access to Customer Cloud Environments

Access to a customer's cloud environment is separate from Google Sign-In and is not obtained through any individual's personal account.

A customer grants Leviathan access directly, within their own cloud provider's identity and access management console, using federated identity. That grant is defined, controlled, audited, and revocable by the customer. It involves no long-lived credentials issued to us, and it does not depend on any individual employee's login remaining active.

We ask customers to grant only the permissions necessary for the services they have engaged us to perform. The scope of that grant, our permitted use of what we access, and our confidentiality and security obligations are set out in the Master Services Agreement and Data Processing Agreement with that customer.

What the platform is designed to access. The platform operates on configuration data and operational telemetry — resource specifications, utilization metrics, scheduling and placement data, and cost data. It is not designed to access, and we do not seek, the content of applications running in a customer environment, the data those applications process, or the payload of network traffic between them.

Personal information we encounter in a customer environment is handled as a processor, under that customer's instructions and the Data Processing Agreement — not under this Policy.


3. How We Use Personal Information

We use personal information to:

We do not use personal information for automated decision-making that produces legal or similarly significant effects concerning individuals.

Providing the information described in Section 2.1 is necessary to enter into and perform a contract with us or to create an account. If you do not provide it, we may be unable to provide the platform or respond to your request.


4. Legal Bases (EEA, UK, Switzerland)

| Purpose | Legal Basis | |----|----| | Providing the platform and services under a contract | Performance of a contract (Art. 6(1)(b)) | | Security, fraud prevention, service improvement, business administration | Legitimate interests (Art. 6(1)(f)) | | Marketing communications where consent is required | Consent (Art. 6(1)(a)) | | Non-essential cookies and similar technologies | Consent (Art. 6(1)(a)) | | Tax, accounting, and other legal obligations | Legal obligation (Art. 6(1)(c)) |

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You may object to that processing as described in Section 9.


5. How We Share Personal Information

Service providers. We use vendors to host infrastructure, process payments, provide support tooling, and deliver communications. They act on our instructions, are bound by written contracts restricting their use of personal information, and may not use it for their own purposes. A current list of subprocessors used in providing the platform is available at [URL] or on request. [CONFIRM: hosting, analytics, payment, support, and email vendors actually in use.]

Our customers. If you are a user on a customer account, we may share information about your use of the platform with that customer's administrators.

Legal and safety. We disclose personal information where required by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or a security incident. Where legally permitted, we will notify the affected customer before disclosing information from their environment.

Corporate transactions. In a merger, acquisition, financing, or sale of assets, personal information may be transferred, subject to the acquirer's commitment to honor this Policy or provide notice of any material change.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.


6. International Transfers

We are based in the United States and process personal information there. Where we transfer personal information from the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum or Swiss equivalents, as applicable), together with supplementary measures where required. A copy of the relevant transfer mechanism is available on request at the address in Section 12.


7. Retention and Security

Retention. We retain personal information for as long as needed for the purposes described in this Policy, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements.

| Category | Retention Period | |----|----| | Account information | Life of the account, plus [PERIOD — CONFIRM] | | Operational telemetry and usage data | [PERIOD — CONFIRM] | | Communications and support records | [PERIOD — CONFIRM] | | Billing and financial records | As required by applicable tax and accounting law |

Security. We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls on a least-privilege basis, logging and monitoring, and periodic review of our security practices. No system is perfectly secure, and we do not represent that ours is.


8. Cookies and Similar Technologies

[CONFIRM WITH ENGINEERING — this section must match what the site actually deploys. If the site uses no non-essential cookies, shorten this section accordingly and no consent banner is required.]

We use strictly necessary cookies to operate the site and keep you signed in. We may also use [analytics] cookies to understand how the site is used.

Where required by law, we obtain consent before setting non-essential cookies, and you may withdraw consent at any time through [the cookie preference control on our site]. You may also control cookies through your browser settings, though disabling strictly necessary cookies may prevent the site from functioning.

We do not respond to browser "Do Not Track" signals, as no common standard has been adopted. Where required by California law, we honor Global Privacy Control signals as a valid opt-out request.


9. Your Rights

EEA, UK, and Switzerland. You have the right to request access to your personal information; to have inaccurate information corrected; to have information erased; to restrict or object to processing; to receive your information in a portable format; and to withdraw consent where we rely on it. You also have the right to lodge a complaint with your supervisory authority — in the EEA, the authority in your country of residence, work, or the place of the alleged infringement; in the UK, the Information Commissioner's Office.

California. You have the right to know what personal information we collect, use, disclose, and retain; to request deletion; to request correction; to opt out of sale or sharing (we do neither); to limit the use of sensitive personal information (we do not collect it for purposes that trigger this right); and not to be discriminated against for exercising these rights.

Other US states. Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — have substantially similar rights, including the right to appeal a denied request. We honor them on the same terms.

How to exercise these rights. Contact us at [privacy@leviathaninc.com]. We verify your identity before acting, typically by confirming control of the email address associated with the information. We respond within the time required by applicable law — generally forty-five days under US state laws (extendable once, with notice) and one month under the GDPR. You may use an authorized agent where the law permits; we will require proof of authorization. If we deny your request, we will explain why and, where the law provides one, tell you how to appeal.

Requests about data in a customer's environment. We will refer you to that customer, who controls it, and assist them in responding as required by our agreement with them.


10. Children

The platform and site are intended for business use by adults. We do not knowingly collect personal information from anyone under sixteen. If you believe a child has provided us information, contact us and we will delete it.


11. Changes to This Policy

We will update this Policy as our practices change. When we make material changes, we will update the "Last Updated" date and provide notice through the platform or by email before the change takes effect. Where a change materially expands how we use information you have already provided, we will obtain consent where the law requires it.


12. Contact Us

Leviathan Solutions Inc.

[STREET ADDRESS]

[CITY, STATE ZIP]

Email: [privacy@leviathaninc.com]

[CONFIRM: An Article 27 representative in the EU and/or UK may be required if we offer services to individuals there without an establishment. Assess once the EU/UK customer position is known.]

[CONFIRM: Whether a Data Protection Officer is required under GDPR Article 37. On current facts — no large-scale systematic monitoring of individuals, no large-scale special category processing — likely not required. Reassess if the customer base or data practices change.]