Privacy Policy

Effective Date: June 2, 2026

Important Notice: Samba is a single-tenant integration platform. Your deployment runs in your own isolated infrastructure. Cirrus Tempo does not have access to your integration data, credentials, or business records. This policy covers only the limited data we collect to operate the platform and provide support.

1. Introduction

Cirrus Tempo, LLC ("Cirrus Tempo," "we," "us," or "our") provides Samba, a REST API integration platform designed for organizations with strict data isolation requirements. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services.

We are committed to protecting your privacy and maintaining SOC 2 Type II compliance. This policy applies to all users of the Samba platform.


2. Information We Collect

2.1 Account and Authentication Information
  • Identity Information: When you authenticate via Azure AD OIDC, we receive your email address, display name, and organizational identifiers provided by your identity provider
  • User Profile Data: Role assignments, permissions, and activity timestamps within the Samba application
  • API Keys: Encrypted API keys you generate for programmatic access (stored in HashiCorp Vault)
2.2 Configuration and Metadata
  • Integration Definitions: System configurations, endpoint URLs, field mappings, and flow definitions you create
  • Deployment Configuration: Environment variables, feature flags, and deployment settings
  • License Information: Subscription tier, deployment ID, and license validation data from Control Hub
2.3 Operational and Diagnostic Data
  • Execution Logs: Timestamps, status codes, record counts, and error classifications for integration runs
  • Application Logs: System health metrics, service status checks, and application events
  • Audit Trail: User actions, configuration changes, and administrative operations (timestamp, user ID, action type)
  • Diagnostic Bundles: When you generate support bundles, we collect redacted configuration, health data, and recent logs
2.4 Telemetry Data (Optional)

You control whether telemetry is enabled via Administration → System Setup.

  • Service health status (Vault connectivity, database health, Python engine status)
  • Aggregate execution statistics (success rates, error categories, throughput)
  • Feature usage metrics (wizard completions, integration counts, API call volumes)
2.5 Information We Do NOT Collect

Data We Never Access:

  • Your integration payloads (source/target system data)
  • External system credentials (stored encrypted in your Vault instance)
  • Business records processed through integrations
  • Personally identifiable information from your source systems

3. How We Use Information

3.1 Service Delivery
  • Authenticate and authorize users
  • Execute and monitor integration workflows
  • Validate licenses and enforce subscription limits
  • Deliver product updates and feature flags via Control Hub
3.2 Support and Operations
  • Troubleshoot issues and respond to support tickets
  • Analyze diagnostic bundles you submit
  • Monitor system health and proactively address outages
  • Provide operational guidance and best practices
3.3 Security and Compliance
  • Detect and prevent unauthorized access
  • Maintain audit logs for compliance and forensic analysis
  • Investigate security incidents
  • Enforce data retention and purge policies
3.4 Product Improvement
  • Analyze aggregated usage patterns (no individual tracking)
  • Identify common failure modes to improve error handling
  • Inform roadmap decisions based on feature adoption

4. Data Security

4.1 Technical Safeguards
  • Encryption at Rest: All data in PostgreSQL is encrypted using Azure Database encryption
  • Encryption in Transit: TLS 1.2+ for all API and UI communication
  • Credential Management: All secrets stored in HashiCorp Vault with encryption and access controls
  • Network Isolation: Each deployment runs in a dedicated Kubernetes namespace with network policies
  • Access Controls: Role-based access control (RBAC) enforced via Azure AD claims
4.2 Operational Safeguards
  • Regular security assessments and penetration testing
  • Automated vulnerability scanning of container images
  • Incident response procedures and breach notification protocols
  • Employee background checks and security training
  • SOC 2 Type II audit controls and continuous monitoring
4.3 Single-Tenant Architecture

Samba's single-tenant design provides inherent isolation:

  • Your deployment is the only tenant in your Kubernetes namespace
  • No shared compute resources with other customers
  • Dedicated database and Vault instances (or fully isolated schemas)
  • Infrastructure-level separation if deployed in your Azure subscription

5. Data Retention

5.1 Retention Periods
  • Execution Logs: Retained for 90 days by default (configurable in System Setup)
  • Audit Logs: Retained for 7 years for compliance purposes
  • Configuration Data: Retained while your subscription is active
  • Diagnostic Bundles: Retained for 30 days after resolution of associated support ticket
  • Telemetry Data: Aggregated and anonymized after 90 days
5.2 Data Deletion

Upon subscription termination:

  • Active integrations are paused immediately
  • Configuration data is retained for 30 days to allow for reactivation
  • After 30 days, all data is permanently deleted unless required for legal/compliance purposes
  • You may request immediate deletion by contacting privacy@cirrustempo.com

6. Data Sharing and Third-Party Services

6.1 Service Providers

We share limited data with trusted service providers who assist in platform operations:

  • Microsoft Azure: Infrastructure hosting (compute, storage, networking)
  • Azure AD: Authentication and identity management
  • HashiCorp Vault: Secrets management (self-hosted or enterprise cloud)
  • All providers are contractually bound to SOC 2 compliance requirements
6.2 Control Hub

The Cirrus Tempo Control Hub receives:

  • Deployment health status (service availability only, no data payloads)
  • Subscription status and license validation requests
  • Support ticket submissions (only information you explicitly provide)
  • Aggregate feature usage metrics (if telemetry is enabled)
6.3 No Data Sales or Marketing

We do not:

  • Sell your data to third parties
  • Use your data for advertising or marketing purposes
  • Share your data with third parties except as described in this policy

7. Your Rights

7.1 Access and Portability
  • Export integration configurations via Templates (Administration → Template Export)
  • Download execution logs and audit trails via the UI
  • Request a copy of all data we hold about you
7.2 Correction and Deletion
  • Update user profile information via your Azure AD administrator
  • Delete integrations, systems, and configurations directly in the UI
  • Request account deletion by contacting privacy@cirrustempo.com
7.3 Control Over Telemetry
  • Enable or disable telemetry at any time via Administration → System Setup
  • No penalty for disabling telemetry
  • Telemetry data is deleted within 90 days of opt-out

8. Cookies and Tracking

Samba uses minimal cookies strictly necessary for authentication and session management:

  • .AspNetCore.Session: Session identifier (HttpOnly, Secure, SameSite=Lax)
  • .AspNetCore.Antiforgery: CSRF protection token
  • .AspNetCore.OpenIdConnect.Nonce: OIDC flow state management

We do not use third-party tracking cookies, analytics cookies, or advertising cookies.


9. International Data Transfers

Samba deployments are region-specific:

  • Your deployment runs in the Azure region you select during provisioning
  • Control Hub runs in Azure US East (encrypted communications only)
  • We implement Standard Contractual Clauses (SCCs) for international transfers where applicable
  • No data crosses borders without encryption and legal safeguards

10. Children's Privacy

Samba is a B2B enterprise platform not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.


11. Changes to This Policy

We may update this Privacy Policy to reflect:

  • Changes in applicable laws or regulations
  • New features or capabilities in Samba
  • Feedback from customers and auditors

Material changes will be communicated via:

  • In-app bulletin (System Alerts component)
  • Email to registered administrators
  • 30-day notice period before changes take effect

Continued use after the effective date constitutes acceptance of the revised policy.


12. Regulatory Compliance

Cirrus Tempo maintains compliance with:

  • SOC 2 Type II: Annual audit covering Security, Availability, and Confidentiality
  • GDPR: For EU/EEA customers (data processing agreements available)
  • CCPA: For California customers (honored globally)
  • HIPAA: Business Associate Agreements available for healthcare customers

Compliance documentation and audit reports available upon request.


13. Contact Information

Privacy Inquiries:

Email: privacy@cirrustempo.com

Response time: Within 5 business days

Data Protection Officer:

Email: dpo@cirrustempo.com

Support and Technical Issues:

Use Administration → Support Tickets in the Samba application

Email: support@cirrustempo.com

Mailing Address:

Cirrus Tempo, LLC

Attn: Privacy Officer

[Your Business Address]

[City, State ZIP]

EU Representative: [If applicable for GDPR compliance]


Last Updated: June 2, 2026
Version 1.0
© 2026 Cirrus Tempo, LLC. All rights reserved.