Global Privacy Policy
Document Revision Date: September 05, 2026
Dhwaz Tools is committed to protecting your personal information and your right to privacy. We have engineered our platform with an uncompromising "Privacy-First" and "Data Minimization" architecture. This document explains what information we collect, how we use it, and what rights you possess under international privacy frameworks (including GDPR, CCPA, and VCDPA).
Notice to Users: The vast majority of our computational utilities process data exclusively inside your local browser memory (Client-Side Execution). We mathematically cannot view, intercept, log, or commercialize data processed through these specific tools.
1. Client-Side Execution (Zero-Knowledge Architecture)
To ensure absolute cryptographic privacy, the following tools execute 100% locally via Javascript and the HTML5 Web Crypto API. Data entered here never leaves your device's RAM:
- Secure Password Generator: Entropy generation happens locally. No passwords ever hit our server logs or databases.
- Cryptographic Hashes (SHA-256/512): File and string hashing is computed entirely by your local CPU.
- Text Formatting & Fancy Fonts: Unicode replacement algorithms and text manipulation execute locally.
2. Information We Explicitly Collect
We act as a "Data Controller" only for information you explicitly submit to us. We collect data in the following strictly operational scenarios:
A. Voluntarily Provided Data
When you use our Contact form or support channels, we collect your Name, Email Address, and Phone Number. This data is utilized solely for customer service resolution. We do not aggregate this into marketing mailing lists without explicit, secondary double-opt-in consent.
B. File Uploads (Cloud Storage)
Files uploaded via our R2 Media Hub are transmitted securely via TLS 1.3 to Cloudflare's Edge Network. We store file metadata (Key Name, File Size, MIME type, Upload Timestamp) in our server environment to allow administrators to manage the bucket. The file contents are stored securely on the edge and are public only if a public access link is generated.
C. Automated Telemetry and Log Data
Our servers and perimeter firewalls automatically collect standard diagnostic data including your masked IP Address, Browser User Agent, Operating System, referring URLs, and Access Timestamps. This is strictly for DDoS mitigation, load balancing, and detecting malicious penetration attempts. Log data is rotated and automatically purged every 30 days.
3. Bot Mitigation (Cloudflare Turnstile)
We utilize Cloudflare Turnstile to protect our endpoints from spam and automated abuse. Unlike legacy CAPTCHA systems that track users across the internet to serve targeted ads, Turnstile verifies human behavior locally and anonymously, evaluating browser telemetry. It ensures your privacy remains intact while keeping our platform secure from credential stuffing.
4. Third-Party Data Processors (Sub-Processors)
We do not sell, rent, trade, or commercialize your identifiable data. We share necessary operational data exclusively with compliant infrastructure partners under strict Data Processing Agreements (DPAs):
- Cloudflare Inc.: Acts as our reverse proxy, WAF firewall, and R2 Object Storage provider.
- Payment Processors (Razorpay, PayPal, Stripe): If you choose to donate, your financial data goes directly to their PCI-DSS Level 1 compliant gateways. Our servers never touch, process, or store your credit card numbers.
- SMTP Providers (Google/AWS): Used strictly for transmitting system alerts and authorized ProMail dispatches.
5. Your International Privacy Rights
Depending on your geographic location (e.g., the European Economic Area, California, Virginia), you possess stringent rights over your digital footprint:
- Right to Access: You can request complete copies of your personal data held by us.
- Right to Erasure (Right to be Forgotten): You can request that we erase your personal data from all active databases.
- Right to Restrict Processing: You can request that we restrict the processing of your personal data under certain conditions.
- Right to Data Portability: You can request data in a machine-readable format (JSON/CSV).
To exercise any of these rights, please email our Data Protection Officer at info@dhwaz.com. We are mandated to respond to authenticated requests within 30 calendar days.