1. Diagnostic Log Anonymization & FERPA / HIPAA Scope

DBPros.Net mandates that all diagnostic logs, trace files, and system metrics submitted for health audits be anonymized locally using our zero-dependency CLI log sanitizer script prior to upload. We do not seek, store, or require access to confidential student records (FERPA), Protected Health Information (PHI under HIPAA), or cleartext database credentials.

HIPAA Business Associate Disclaimer & Inadvertent Receipt Procedure: DBPros.Net is not a Covered Entity or HIPAA Business Associate. Client institutions remain solely responsible for ensuring PHI and PII are scrubbed locally before submitting diagnostic logs. In the event that un-sanitized PHI or sensitive PII is inadvertently transmitted, DBPros.Net's strict policy mandates immediate, permanent deletion and purging of the diagnostic trace file upon discovery.

2. Data Retention & Volatile Storage Purging

Diagnostic trace archives uploaded to the Intake Portal are stored in encrypted volatile storage accessible exclusively by your assigned principal advisor. All uploaded diagnostic files are permanently scrubbed and deleted 30 business days following delivery of your audit debrief report.

3. Information Collection & PCI-DSS Payment Processing

We collect institutional contact details (work email address, institution name) solely to process audit intake tickets and deliver reports. All commercial transactions and checkout operations are handled securely by third-party, PCI-DSS Level 1 compliant payment processors (Stripe and Gumroad). DBPros.Net never processes or stores raw payment card numbers on our infrastructure.

4. Zero Third-Party Data Sharing

We do not sell, rent, lease, or monetize client architecture logs, diagnostic metrics, or contact details to third-party marketers, advertisers, or data brokers.

5. Data Controller, GDPR & Trinidad and Tobago Data Protection Act

DBPros.Net operates as a Data Controller based in the Republic of Trinidad and Tobago. We process all personal information in accordance with the general principles of the Data Protection Act (No. 13 of 2011) of Trinidad and Tobago. By submitting intake inquiries or diagnostic logs, clients consent to secure, encrypted cross-border processing on cloud infrastructure in accordance with Section 42 of the Data Protection Act 2011.

GDPR / EU Data Subject Notice: For European Economic Area (EEA) and UK data subjects, personal contact information (limited to work email addresses and institutional affiliation) is processed on the lawful bases of performance of contract and legitimate interest. Data subjects retain full rights to access, rectification, restriction, and erasure by contacting advisory@dbpros.net.