Legal
Compliance Center
We are committed to protecting your data and maintaining strong compliance practices across our platform. Pawan.Krd is built with privacy, security, and regulatory compliance at its core.
Data Protection Regulations
GDPR
General Data Protection Regulation
We design our data handling practices to meet GDPR requirements for users in the European Economic Area (EEA).
- Lawful basis for processing personal data
- Right to access, correct, and delete personal data
- Data portability upon request
- Data minimization and purpose limitation
- Breach notification procedures
CCPA
California Consumer Privacy Act
We respect the privacy rights of California residents under the CCPA.
- Right to know what personal information is collected
- Right to request deletion of personal information
- Right to opt out of the sale of personal information (we do not sell personal data)
- Non-discrimination for exercising privacy rights
COPPA
Children's Online Privacy Protection Act
We take the protection of minors seriously. Pawan.Krd is strictly an 18+ service.
- Our service is not directed at children under 18
- We do not knowingly collect data from minors
- Accounts found to belong to minors are immediately terminated and their data deleted
- Age confirmation is required at account creation
PCI-DSS
Payment Card Industry Data Security Standard
All payment processing is handled by Stripe, a PCI-DSS Level 1 certified provider.
- We never store, process, or transmit full card details on our servers
- Payment forms are served directly by Stripe's secure infrastructure
- Tokenization is used for all stored payment methods
- No cardholder data ever touches Pawan.Krd systems
Security Practices
Data Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- Sensitive data at rest is encrypted using AES-256
- Database connections are encrypted end-to-end
Access Controls
- Role-based access control (RBAC) for all internal systems
- Principle of least privilege enforced across all services
- Multi-factor authentication for administrative access
- Regular access reviews and audit logging
Application Security (OWASP Top 10)
- Protection against injection attacks (SQL, NoSQL, command injection)
- Cross-site scripting (XSS) and CSRF protections
- Secure session management and authentication
- Security misconfiguration and sensitive data exposure prevention
Incident Response
- Defined incident response procedures
- Prompt notification of affected users in case of a data breach
- Root cause analysis and remediation for all incidents
- Continuous monitoring and anomaly detection
Responsible AI Practices
As an AI model platform, we are committed to responsible and ethical use of artificial intelligence. Our policies are designed to prevent harm while enabling legitimate personal use.
- Transparency about AI model capabilities and limitations
- Content moderation and abuse prevention - illegal content (CSAM, terrorism, etc.) is actively filtered and blocked
- Acceptable use policies enforced to prevent harmful outputs
- Rate limiting and monitoring to prevent misuse
- Clear documentation of all data processing practices