TDH AI Labs

PRIVACY POLICY — TDH AI LABS

EFFECTIVE DATE: August 31, 2026 PROVIDER: Adam Matar, an individual and sole proprietor doing business as (d/b/a) Vibehard ("Vibehard", "We", "Us", "Adam Matar") WEBSITE: https://tdhailabs.com


1. OVERVIEW & SCOPE

Vibehard provides custom private-cloud AI workflow automation, dedicated server container orchestration (e.g., self-hosted n8n instances on dedicated Hostinger VPS environments), and ongoing Site Reliability Engineering (SRE) infrastructure maintenance to commercial business clients.

This Privacy Policy describes how we collect, handle, process, and protect information when you visit our website, interact with our communications (including WhatsApp and Email), or engage our services.


2. STRICT GEOGRAPHIC & REGULATORY LIMITATIONS (NO GDPR / NO CCPA)

IMPORTANT: TERRITORIAL LIMITATION: TDH AI LABS OFFERS SERVICES EXCLUSIVELY TO COMMERCIAL BUSINESSES OPERATING WITHIN THE UNITED STATES UNDER STANDARD US COMMERCIAL LAW.

1. No European Union (GDPR / UK GDPR) Personal Data: Vibehard does NOT market to, offer services to, or target individuals located in the European Economic Area (EEA), European Union, or United Kingdom. We do NOT knowingly collect or process personal data subject to the EU General Data Protection Regulation (GDPR) or UK GDPR. Clients are strictly prohibited from submitting EU/UK data subject information through our systems. 2. No California (CCPA / CPRA) Consumer Personal Data: Vibehard operates exclusively on a Business-to-Business (B2B) commercial basis. We do NOT collect, sell, share, or monetize consumer personal information subject to the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA). 3. No Protected Health (HIPAA) or Regulated Data: We do NOT collect or store Protected Health Information (PHI) under HIPAA, payment card numbers subject to PCI-DSS, or classified/defense data under ITAR.


3. INFORMATION WE COLLECT & DUAL-PLANE ARCHITECTURE

A. Information You Provide Directly

  • Commercial Inquiries & Contact Details: When you contact us via WhatsApp, SMS, web form, or email, we collect your name, business email, company name, phone number, software stack details, and operational requirements.
  • Billing Information: Payments are processed directly through our PCI-compliant payment provider (Stripe, Inc.). Vibehard does NOT store or have access to your full credit card numbers or banking passwords.
  • B. Client Workflow Data (Dual-Plane Processing Architecture)

  • Dedicated Local Storage Plane: When we deploy dedicated private server instances (e.g., n8n Docker containers on client-dedicated VPS environments), your core databases, operational credentials, and workflow configurations remain strictly isolated on your dedicated server.
  • Inference Transit Plane: When automated workflows utilize external foundational AI models (such as OpenAI, Google Gemini, Anthropic, or DeepSeek), sanitized text prompts and payload data transit via encrypted Transport Layer Security (TLS 1.3) directly to the respective API endpoint. Client acts as the independent Data Controller for all data submitted to automated workflows.

  • 4. HOW WE USE YOUR INFORMATION

    We use commercial information strictly to: 1. Provide, engineer, stage, and maintain custom workflow automation architectures. 2. Communicate with you regarding project milestones, technical architecture, and system health. 3. Process payments and issue milestone invoices via Stripe. 4. Maintain 24/7 container uptime and error monitoring under our SRE retainer.

    WE NEVER SELL, RENT, MONETIZE, OR TRADE CLIENT DATA TO THIRD PARTIES FOR ADVERTISING OR MARKETING PURPOSES. WE DO NOT USE CLIENT DATA TO TRAIN SHARED PUBLIC AI MODELS.


    5. THIRD-PARTY SERVICE PROVIDERS & CLOUD DEPENDENCIES

    We rely on trusted, independent, third-party technology providers to operate our business:
  • Payment Processing: Stripe, Inc. (PCI-DSS Level 1 certified).
  • Cloud VPS & Infrastructure: Hostinger International Ltd., Docker Inc., Cloudflare, Inc.
  • Communication & Messaging: Twilio, Inc. and Meta Platforms, Inc. (WhatsApp Business API).
  • Foundation AI APIs: OpenAI LLC, Google LLC, Anthropic PBC, DeepSeek AI.
  • These providers process data according to their own independent enterprise security standards and privacy policies.


    6. DATA SECURITY & RETENTION

    We implement defensive engineering practices including TLS 1.3 encryption in transit, isolated private virtual server environments, SSH key access controls, and rate-limiting safeguards. We retain commercial relationship records only for as long as necessary to fulfill contractual obligations and comply with applicable US tax and accounting regulations.


    7. GOVERNING LAW & DISPUTE RESOLUTION

    This Privacy Policy and all matters arising out of the use of our services shall be governed by and construed in accordance with the laws of the State of Oregon, United States, without regard to conflict of law principles. Any dispute shall be resolved through confidential, binding individual arbitration administered by the American Arbitration Association (AAA).


    8. CONTACT INFORMATION

    For any privacy questions or notices regarding this policy:
  • Provider: Adam Matar d/b/a Vibehard
  • Email: legal@tdhailabs.com (or via WhatsApp: +1 877 916 3440)
  • Website: https://tdhailabs.com