towerops/policies/USER_PRIVACY.md
Graham McIntie 26c7b0b993 Hide RF Links UI elements from network map (TOW-44) (#46)
- Commented out 'View RF Links' button in network map node detail panel
- Commented out RF Link health legend (Good/Degraded/Critical) from map legend
- Backend code (topology.ex) left intact per instructions
- No RF tab found on device show page (nothing to hide there)
- All tests pass, compiles clean with --warnings-as-errors

Reviewed-on: graham/towerops-web#46
2026-03-16 15:19:03 -05:00

77 lines
3.5 KiB
Markdown

# User Privacy Policy
**Effective:** 2026-03-15
**Owner:** Engineering & Operations
## Purpose
TowerOps monitors network infrastructure for ISPs and managed service providers. We handle sensitive operational data — device configurations, network topologies, traffic patterns, and customer metadata. This policy defines how we protect that data.
## Core Principles
1. **Collect only what's needed.** Never store data we don't have a clear product use for.
2. **Isolate by organization.** One customer must never see another customer's data. Ever.
3. **Encrypt in transit and at rest.** No exceptions.
4. **Default to private.** New features default to most-restrictive access.
5. **Delete when asked.** Customers can request full data deletion, and we comply promptly.
## Data Classification
| Classification | Examples | Handling |
|---------------|----------|----------|
| **Critical** | SNMP community strings, API keys, integration credentials | Encrypted at rest, never logged, stripped from API responses, access-audited |
| **Sensitive** | Device configs, network topologies, alert rules, user emails | Encrypted at rest, org-scoped access only, included in data export |
| **Operational** | Metrics, performance data, SNMP poll results | Org-scoped, retained per retention policy, aggregatable |
| **Public** | Product documentation, pricing | No restrictions |
## Multi-Tenancy Isolation
- All database queries MUST scope to the current user's organization via `org_id`.
- Row-Level Security (RLS) or application-level scoping enforced on every query.
- Background jobs (SNMP polling, alert evaluation) scope to their org context.
- Shared infrastructure (TimescaleDB, Redis) uses logical separation with org-prefixed keys.
- Cross-org data access is impossible by design — no admin backdoor, no superuser query mode.
## Data Retention
| Data Type | Default Retention | Customer Override |
|-----------|------------------|-------------------|
| SNMP metrics | 90 days raw, 2 years downsampled | Configurable |
| Alert history | 1 year | Configurable |
| Audit logs | 1 year | Minimum, not reducible |
| User sessions | 30 days | Not configurable |
| Deleted accounts | 30 days grace, then purged | Immediate on request |
## Data Export & Deletion
- Customers can export all their data via API (`GET /api/export`).
- Account deletion removes all org data within 30 days.
- Deletion requests logged and confirmed via email.
- Backups rotate out deleted data within the backup retention window (30 days).
## Employee & Agent Access
- Engineers access production data only through audited tooling — no direct database shells.
- AI agents (TowerOps agent, Paperclip agents) operate within org scope and cannot access other orgs.
- All production access logged with who, when, what, and why.
- Access reviewed quarterly; unused access revoked.
## Third-Party Integrations
- Integration credentials (PagerDuty, Gaiia, Sonar, etc.) stored encrypted.
- We send only the minimum data required for the integration to function.
- Integration data flows are documented per integration.
- Customers can revoke integrations at any time; credentials are deleted immediately.
## Incident Response (Privacy)
- Data breaches reported to affected customers within 72 hours.
- Breach scope assessed within 24 hours.
- Post-mortem published internally within 1 week.
- Regulatory notifications (if applicable) within required timelines.
## Enforcement
- Code review checks org-scoping on all data access.
- Automated tests verify tenant isolation.
- Quarterly privacy review of new features.