CEMFORGE · Commercial policies

Privacy Notice — CF-SCOPED-2026-09-21.1

Versioned text. A sales agreement applies only if this version was incorporated into an accepted order. Retention of this page does not establish any customer’s acceptance.

Policy suite CF-SCOPED-2026-09-21.1 · Version date: September 21, 2026

Sunnyday Technologies LLC, Wisconsin, United States, is responsible for the personal data it handles for this website, inquiries and its own sales administration. Contact privacy@sunn3d.com.

Scope and roles

This notice covers the static CEMFORGE website, communications and separately agreed sales, and explains the distinction from retained historical gateway records. It is not a statement that public checkout, an account service or new payment processing is enabled. Where we process personal data solely for a customer’s purposes, a suitable processor/service-provider agreement and instructions must be agreed before that transfer.

Privacy rights do not depend on accepting commercial terms. An acknowledgment of this notice is not consent to optional marketing, model training, benchmarking or publication. We do not sell personal information or use customer project content for advertising profiles. Customer inputs and outputs are not used for general model training, public benchmarks, case studies or marketing without a separate specific permission or agreement.

Data, purposes and applicable legal bases

Website requests: Cloudflare processes IP addresses, requested URLs, timestamps, user-agent and related network/security metadata to deliver and protect the site. Sunnyday uses necessary operational information for security, abuse prevention and availability. Where GDPR applies, the basis is our legitimate interest in operating a secure website, subject to your rights.

Inquiries and support: we receive your email address, name, organization if provided, message and necessary correspondence through our email services. We use these to answer you and evaluate requested work. The basis, where applicable, is steps requested before a contract or performance of your contract, or our legitimate interest in responding to an organization’s representative. Start with non-confidential information.

Orders and administration: we use customer/contact details, country, relevant business or tax information, agreed scope, order and invoice records, policy-version acceptance and payment/refund references to perform the contract, manage disputes and meet legal obligations. We use only the information needed for the transaction. Any law-based processing is assessed under the law applicable to us and the specific record.

Eligibility and security: we may use customer, organization, location and intended-use information for sanctions/export review, fraud prevention and access security. Where GDPR applies, a legal-obligation basis is used only where the obligation qualifies under applicable data-protection law. Other compliance or security processing requires an appropriate documented basis, such as a legitimate interest assessed against the individual’s rights. A US legal duty is not automatically a GDPR legal-obligation basis. We provide a human review route for a refusal or hold; this notice does not announce solely automated decisions producing legal or similarly significant effects.

Project inputs: we process the material agreed in the order to prepare and deliver the work. Personal data is not required merely to obtain a materials Datapack and should be removed where unnecessary. Sensitive personal data, children’s data or controlled information must not be submitted without a lawful, specifically agreed arrangement. The service is not directed to children.

Site features and cookies

The static pages do not install a CEMFORGE customer-account database, checkout, project upload form or site analytics script. An email link opens your own mail application. Cloudflare may process security and delivery information according to its role and applicable requirements. This statement does not describe a third-party site you choose to visit.

If nonessential cookies, analytics or advertising tools are introduced, the notice and any legally required choice mechanism must be updated before use. We do not infer consent from continuing to browse.

Providers and international processing

Cloudflare provides website delivery and security. Business inquiry mail at sunn3d.com is routed through Google-hosted email, which processes messages and communication metadata. Authorized hosting or computing providers may process agreed project inputs only as needed for an accepted scope; we will identify material project-processing providers and locations in the order or data agreement before transfer. Providers may have both processor and independent-controller roles, depending on the activity.

Historical Datapacks gateway records may involve Cloudflare Worker/D1, Stripe payment references, screening-service records and the CEMFORGE engine host. They are handled according to the applicable transaction, processing activity and law. Describing these records does not activate new sales or promise that a retired account can be recovered.

Sunnyday operates in the United States. Cloudflare website delivery and our email services may involve processing outside your country. We do not claim that every provider activity occurs in one country or that Sunnyday holds a transfer certification. For a restricted transfer subject to applicable data-protection law, the relevant provider arrangement and safeguards must be identified; contact privacy@sunn3d.com for the applicable information and a copy or description of safeguards where required. Before a new project transfer, we must agree and verify its providers, processing locations, data scope, applicable agreements and any required transfer mechanism.

We may disclose necessary information to professional advisers, authorized providers, a lawful successor subject to appropriate protections, or authorities where legally required, and to protect rights and security. We do not grant providers permission for unrelated use of customer project content.

Retention and deletion

We keep data only as long as needed for the stated purpose and applicable legal obligations. When an inquiry closes, we review and delete correspondence no longer needed. Any retained subset must have an identified ongoing purpose, review date and retention event or period. Necessary security logs are reviewed according to their incident, abuse-prevention or delivery purpose and removed when no longer needed. Order and accounting records may need longer retention for tax, contract, fraud, sanctions or disputes. Project-content retention and any return/deletion date must be stated in the order or data agreement. We do not apply an unverified universal seven-year term to all information.

Sunnyday’s operational target is to delete or irreversibly deidentify eligible information in active systems through the rights-request process, normally within 30 calendar days and within one month where GDPR requires it. This is not a promise that every record is erasable or that an automatic purge system has been verified. Narrow, documented legal holds or retention duties may apply; we explain applicable exceptions.

Our recovery-copy policy calls for encryption, restricted access, exclusion from ordinary processing and expiry within 90 days after removal from active use, except for a documented retention duty or lawful hold. Automated enforcement and coverage have not been verified across every historical system. For each request we check relevant copies, explain remaining deletion steps and timing or any lawful exception, and reapply approved deletion if a copy is restored. A technical gap is not a lawful retention exception. Shorter legal deadlines prevail. Independently controlled provider records may have different lawful periods; we remain responsible for our duties and for instructing processors where required.

Your rights and requests

Email privacy@sunn3d.com to request access, correction, deletion, restriction, portability or to object where those rights apply. You may also withdraw consent for a consent-based activity without affecting earlier lawful processing. We use proportionate identity checks and do not routinely require government identification. Please do not email sensitive identity documents.

We aim to acknowledge within 10 business days and respond without undue delay, normally within 30 calendar days and within one month from receipt where GDPR applies. Applicable rules on identity clarification or lawful extension govern; verification is not a blanket restart of the clock. Where an extension is permitted, we explain the reason within the required period. We explain any lawful refusal and available challenge rights. Requests are normally free unless law permits a charge.

You may complain to a competent data-protection or consumer authority, including your local supervisory authority where GDPR applies. You may seek an internal review through the same contact. Exercising privacy rights will not itself cause discriminatory treatment prohibited by law.

For deletion and recovery-copy details, see Data Requests and Deletion. We use safeguards appropriate to the data and processing, but do not promise perfect security, absolute anonymity or erasure from a public blockchain. Do not send secrets or project data through public agent or blockchain metadata.

Changes and contact

This notice is part of version CF-SCOPED-2026-09-21.1 and describes the publication’s stated scope. Material processing changes require an updated notice and any further permission required by law. A change does not silently expand purposes for previously collected data.

Privacy contact: privacy@sunn3d.com. Business and legal-notice intake: cemforge@sunn3d.com. Required transaction-specific seller or privacy-representative details, if applicable, must be supplied before the relevant sale or processing begins.

See the current policy register · Back to top