Master Legal Governance &
Operational Trust Frameworks.
Sovereign technical agreements engineered with absolute transparency. Review our institutional privacy mandates, 100% intellectual property transfer terms, binding 99.99% availability SLAs, and zero-trust cloud security standards.
Privacy Governance & Data Vault Security
1.1 Zero-Trust Operational Mandate & Data Minimisation
pineX digital operates strictly on a zero-trust architecture. We collect, store, and process only the minimal dataset technically essential to formulate architectural specifications, deliver custom engineering codebases, administer the authenticated client portal, and fulfill statutory UK tax accounting requirements.
Under no circumstances do we sell, rent, monetize, license, or exchange client data, system telemetry, or user interaction metadata with commercial data brokers, advertising aggregators, or unauthorized third-party platforms.
1.2 Information Categories & Ingestion Pathways
We process information across three distinct operational categories:
- Commercial Account Metadata: Corporate entity details, designated executive contact credentials, billing and tax registration identifiers, and encrypted transaction receipts.
- Technical Architecture Inputs: Git repository links, database schema definitions, API keys, CAD schematics, and performance telemetry submitted to configure project deliverables.
- System Logs & Security Telemetry: Anonymized source IP addresses, cryptographic session tokens, TLS handshake telemetry, and access timestamps monitored solely to enforce firewall rate-limiting and prevent malicious intrusion.
1.3 AI Model Weights & Training Data Quarantine
Proprietary enterprise data, technical specifications, and corporate documentation uploaded into vector databases, semantic RAG pipelines, or private fine-tuning environments are quarantined in isolated compute nodes.
pineX digital guarantees that client corpora are never ingested into shared public models or used to train multi-tenant foundation algorithms. Your intellectual data remains isolated within your dedicated tenant scope.
1.4 Cryptographic Storage & Retention Policies
All transactional and client portal records are secured at rest using AES-256 block ciphers with rotating keys. Inactive client project records and staging database backups are scrubbed 90 calendar days post-completion, except where longer retention is mandated under UK commercial law.
1.5 Data Subject Rights (UK GDPR & DPA 2018)
Pursuant to the UK Data Protection Act 2018 and UK GDPR, authorized data subjects hold irrevocable rights to access, rectify, port, or demand the permanent cryptographic erasure of their data records. Requests submitted to privacy@pinex.co.uk are verified and processed within 30 business days.
Terms of Engagement & Retainer Contracts
2.1 Scope Definition & Statements of Work (SOW)
All engineering initiatives, robotics prototyping, AI model integrations, and growth infrastructure retainers are governed by a mutually executed Statement of Work (SOW). The SOW explicitly defines architectural deliverables, acceptance criteria, deployment milestones, and financial terms.
Any architectural refactoring or feature expansion requested outside the agreed SOW requires an authenticated change request submitted via the client portal ticketing desk.
2.2 Milestone Invoicing & Financial Settlement
Services execute under structured milestone schedules. Project commencement requires an initial milestone commitment. Invoices issued upon milestone completion are payable within 14 calendar days via electronic funds transfer or authorized payment rails.
Late settlements exceeding 30 calendar days incur statutory commercial interest pursuant to the Late Payment of Commercial Debts (Interest) Act 1998.
2.3 Client Acceptance & Priority QA Windows
Upon delivery of software artifacts to the secure client vault, the client receives a 14-calendar-day evaluation window to test the build against agreed acceptance criteria.
Technical defects reported via the portal within this window are corrected in priority sprints at zero supplementary cost. Absence of written notice within 14 days constitutes final acceptance.
2.4 Termination & Sprint Settlement
Either party may terminate an engagement for material breach upon 30 calendar days’ written notice, provided the breach remains uncured. In the event of early termination, the client is liable only for completed milestones and verified work-in-progress up to the date of notice.
2.5 Mutual Non-Disclosure Covenants
Both parties covenant to maintain strict confidentiality regarding technical specifications, unreleased code repositories, commercial pricing, and strategic plans. This non-disclosure obligation survives termination of the commercial engagement for five (5) full calendar years.
2.6 Governing Law & Venue
These Terms of Engagement, Statements of Work, and commercial agreements are governed by and construed in accordance with the laws of England and Wales. Both parties irrevocably submit to the exclusive jurisdiction of the courts of England to resolve any disputes.
100% Sovereign Code Ownership Policy
3.1 Principle of Non-Custodial Engineering
pineX digital operates on an uncompromising non-custodial software philosophy. We reject predatory vendor lock-in models that rely on proprietary compilers, runtime licensing checks, or hidden platform fees.
Upon milestone settlement, all custom code, schemas, and assets transfer entirely to client ownership without ongoing royalty encumbrances.
You retain full legal freedom to migrate, refactor, self-host, or fork the delivered systems across any infrastructure provider globally.
3.2 Deliverables Transferred to Client Ownership
The legal intellectual property transfer encompasses:
- Complete unminified source code across all delivered languages (PHP 8.5, Swift, Kotlin, C++, Python, JavaScript).
- Dedicated database migration scripts, table schemas, and indexing blueprints.
- Vector design tokens, component UI definitions, and master Figma design assets.
- Embedded C++ firmware source trees, register definition mappings, and CAD hardware drawings.
- Deployment manifests, environment configuration templates, and comprehensive architectural documentation.
3.3 Open-Source & Permissive Libraries
Where custom solutions incorporate open-source libraries (e.g., WordPress core, FreeRTOS, ROS 2, Linux kernel modules), those components remain licensed under their respective permissive terms (GPL, MIT, Apache 2.0). All bespoke business logic built on top remains 100% proprietary client property.
3.4 Pre-Existing Developer Knowledge
pineX digital retains ownership of generalized architectural patterns, algorithmic foundations, and developer tools created prior to the engagement. Clients receive an irrevocable, royalty-free, perpetual commercial license to use and adapt these components within their deliverables.
99.99% Infrastructure SLA Standards & Rebates
4.1 Availability Guarantee & Target Scope
For clients enrolled in managed operations and cloud engineering retainers, pineX digital guarantees a 99.99% monthly system availability SLA.
Availability is calculated as the percentage of total minutes in a calendar month where primary transactional endpoints, databases, and APIs respond to synthetic health checks in < 1,200ms.
Incident Classification & Target Response Times
| Severity Tier | Classification | Initial Response | Resolution Target |
|---|---|---|---|
| P1 - Critical Outage | Total service unavailability, checkout failure, or database lock. | < 15 Minutes | < 2 Hours |
| P2 - Major Degradation | Core system online but experiencing significant latency or tool-call failures. | < 45 Minutes | < 6 Hours |
| P3 - Minor Impairment | Non-blocking UI bugs, minor telemetry errors, or non-critical reporting issues. | < 2 Hours | < 24 Hours |
| P4 - Technical Inquiry | General guidance, architecture consultation, or configuration queries. | < 4 Hours | Next Sprint |
Financial Service Credit Rebates
| Monthly Uptime Percentage | Operational Status | Service Credit Applied to Next Invoice |
|---|---|---|
| 99.99% - 100.00% | Fully Compliant Target | Standard Retainer Invoicing |
| 99.90% - 99.98% | Minor SLA Degradation | 10% Credit Applied |
| 99.00% - 99.89% | Moderate SLA Outage | 25% Credit Applied |
| < 99.00% | Critical SLA Breach | 50% Credit Applied |
4.2 SLA Exclusions & Scheduled Maintenance
Uptime calculations exclude planned maintenance windows notified at least 72 hours in advance and executed during off-peak hours (02:00 - 05:00 UTC), force majeure events, or upstream upstream network transit outages outside our direct control.
Zero-Trust Cloud Security Architecture
5.1 Defense-in-Depth Security Philosophy
Security is an architectural foundation, not an afterthought. Every edge endpoint, database table, asynchronous request, and administrative action is governed by verified defense-in-depth principles.
AES-256 block ciphers deployed across all persistent database tables, encrypted deliverables, and transaction ledgers.
Mandatory TLS 1.3 across all REST endpoints, GraphQL connections, WebSockets, and transactional SMTP relays.
Parameterized queries with prepared statements, strict type-casting, and deep input sanitization across every ingest vector.
5.2 Client Portal Security & Quarantine Zone
The client management portal (`/portal/*`) is architected as an isolated environment. HTTP response headers enforce `X-Robots-Tag: noindex, nofollow, noarchive, nosnippet`, preventing deliverable vaults and tickets from search indexing.
Authentication uses cryptographically signed session nonces with rate-limited brute-force interception and automatic credential invalidation upon anomaly detection.
5.3 Penetration Testing & Vulnerability Disclosure
Our production theme architectures, APIs, and microservices undergo recurring security scans covering OWASP Top 10 vectors. Security researchers identifying potential vulnerabilities are invited to report findings directly to security@pinex.co.uk under our coordinated disclosure policy.