01
Zero-Retention & Zero-Pooling Philosophy
JUMP by ADUMU is engineered for high-concurrency data engineering teams, AI retrieval agents, and cybersecurity researchers. Traditional metered proxy and scraping APIs frequently inspect, cache, and pool customer query streams to build proprietary data feeds or reduce proxy re-fetch costs.
🛡️ The ADUMU Zero-Pooling Guarantee: We never inspect, index, sell, or aggregate your target URLs, query parameters, extraction patterns, or payload results. Your execution lane is completely isolated.
All browser rendering tasks occur in ephemeral Linux execution namespaces in RAM. Once your requested records are delivered to your configured destination (SQL database, S3 bucket, webhook stream, or direct HTTP socket), the sandbox memory is reclaimed immediately.
02
Data We Collect and Process
We maintain a strict boundary between commercial account data and customer operational payloads:
| Data Category |
Information Collected |
Retention & Purpose |
| Account & Invoicing |
Full name, business email, company name, direct phone/contact, billing address. |
Retained for active subscription lifetime for invoicing, tax compliance, and support. |
| Telemetry & Health |
Active concurrency counts, bandwidth utilization, gateway latency, error rates. |
30-day rolling aggregation for SLA monitoring and capacity provisioning. |
| Scrape Payloads |
Target HTML, parsed JSON objects, network response bodies. |
Zero permanent retention. Executed in memory; diagnostic logs purge in 24 hours. |
| Credential Vaults |
Target site login credentials (if supplied for authenticated data extraction). |
AES-256 encrypted in hardware enclaves; retained only while extraction pipeline is active. |
| Enquiries & Contact Form |
Name, business email, company, phone or handle, and the message you send us, together with the originating IP address and browser user-agent string of the submission. |
Retained for 24 months in our mail system so we can follow up on an enquiry and evidence what was agreed. Deleted on request. |
| Abuse Prevention |
A one-way SHA-256 hash of the originating IP address of form submissions. We do not store the address itself for this purpose. |
Held for a rolling rate-limit window only, then discarded. Used solely to stop automated abuse of our own forms. |
Billing Security
All credit card and recurring payment processing is executed via Tier-1 PCI-DSS compliant merchant gateways. ADUMU never receives, logs, or stores raw payment card numbers on our infrastructure.
03
Cookies & Browser Storage
This website sets two cookies: one to make the contact form work, and one for
visitor counting. There is no advertising network on this site, no social embed, no
remarketing tag, and nothing that follows you to another website.
| Cookie |
Type |
Purpose & Lifetime |
PHPSESSID |
Strictly necessary |
Holds the anonymous session that carries the security token protecting our contact form against cross-site request forgery. It contains no personal data and no identifier we can link back to you. It expires when you close your browser. |
sc_is_visitor_unique |
Analytics |
Set by StatCounter so a returning reader is not counted twice. It holds a random identifier and a visit count, not personal information, and expires after two years. |
The session cookie is strictly necessary to deliver a page you asked for, so it needs no
consent. If you block it, the contact form will decline to submit; nothing else is
affected.
Visitor Analytics
We use StatCounter (Statcounter, Dublin, Ireland) to count visits and see which
pages people read. It records the page requested, the referring page, approximate location
derived from the IP address, and browser and device type. We use it to understand which
parts of this site are useful — not to build a profile of you, and never joined to a
customer account.
StatCounter processes your IP address, which is personal data under the GDPR. It is
configured here in invisible mode, so no counter or badge is displayed. We do not run
advertising or remarketing, and we do not share this data with anyone.
If you would rather not be counted, StatCounter offers a permanent opt-out that works
across every site using it:
set the StatCounter refusal cookie.
Blocking the cookie or the script has no effect on anything else on this site.
We use no other browser storage. This site writes nothing to localStorage,
sessionStorage or IndexedDB, and sets no other cookie of any kind.
04
Roles Under GDPR & CCPA/CPRA
Under the General Data Protection Regulation (GDPR), UK GDPR, and California Privacy Rights Act (CPRA):
- ADUMU as Data Controller: We act as Data Controller solely with respect to customer contact information, account profiles, and administrative communication submitted through our website.
- ADUMU as Data Processor / Service Provider: For all target web information and pipeline data retrieved through JUMP lanes, the Customer acts as the Data Controller, and ADUMU acts strictly as a Data Processor executing instructions provided via your API calls and SDK configurations.
📄 Enterprise DPA: Procurement and security teams can request our standard Data Processing Addendum incorporating EU/UK Standard Contractual Clauses (SCCs) by contacting our systems engineering advisory team.
05
Sub-Processors & Infrastructure Scope
All primary JUMP compute nodes, container sandboxes, egress proxy routers, and database connections are located in enterprise colocation data centers within the United States.
Our third-party sub-processor footprint is strictly limited to essential infrastructure providers:
- Bare-Metal & Cloud Colocation Providers: US-based data center providers supplying redundant power, physical security, and network transit.
- Egress Transit & ISP Carriers: Tier-1 telecommunications carriers providing pristine IP allocations for residential and ISP lane routing.
- Payment Gateways: PCI-DSS certified recurring payment billing systems.
- Website Analytics: StatCounter (Dublin, Ireland), used only on this marketing website to count visits. It has no access to the gateway, to customer accounts, or to any data you collect through JUMP. See Cookies & Browser Storage for what it records and how to opt out.
Every sub-processor is bound by strict confidentiality, SOC 2 compliance verification, and data protection agreements.
Requesting the Named List
We do not publish the identities of our individual providers, because the composition of
our carrier and colocation footprint is commercially sensitive and forms part of how the
service resists blocking. Customers and prospective customers under evaluation may request
the current named sub-processor list, together with our Data Processing Addendum, by
contacting us. We will provide it under NDA where
your procurement process requires one.
International Transfers
ADUMU processes and stores customer data in the United States. If you are located in the
United Kingdom, the European Economic Area, or Switzerland, using JUMP therefore involves
a transfer of personal data outside your jurisdiction.
For those transfers we rely on the European Commission's Standard Contractual Clauses,
together with the UK International Data Transfer Addendum where the UK GDPR applies. Both
are incorporated into our Data Processing Addendum, which is available on request and
which we will sign as part of onboarding. We carry out a transfer risk assessment for each
engagement where one is required, and we will support yours with the technical detail it
needs.
06
Technical & Organizational Security
We safeguard our infrastructure with enterprise-grade controls:
- TLS 1.3 Strict Enforcement: All communications between your clients and JUMP gateway endpoints enforce modern cipher suites with perfect forward secrecy.
- Isolated Kernel Namespaces: Browser execution instances are containerized with strict memory limits, no persistent root disk privileges, and immediate zeroization upon task completion.
- Hardware Credential Enclaves: Secrets and target tokens are protected by AES-256 hardware encryption keys with strict role-based access control (RBAC).
- Multi-Factor Authentication (MFA): Enforced across all internal engineering systems, code repositories, and operational infrastructure.
Breach Notification
If ADUMU becomes aware of a personal data breach affecting data we process on your behalf,
we will notify you without undue delay, and in any event within 72 hours of becoming
aware of it. That notice will describe what we know about the nature of the breach, the
categories and approximate number of records involved, the likely consequences, and the
measures we have taken or propose to take.
Where you are the controller, the obligation to notify a supervisory authority or affected
individuals is yours. We will give you the information and assistance you reasonably need
to meet it, and we will not delay telling you while we complete our own investigation.
07
Your Privacy Rights & Choices
Regardless of your location, ADUMU extends comprehensive privacy rights regarding your account profile data:
- Access & Portability: You may request a machine-readable export of your account registration and billing history.
- Correction & Erasure: You may request correction of inaccurate contact records or complete deletion of your account following subscription termination.
- Opt-Out of Communications: You can unsubscribe from non-critical product updates at any time (transactional lane alerts and invoicing notifications remain active).
- Non-Discrimination: We provide equal service pricing and quality regardless of whether you exercise privacy rights.
- Objection & Restriction: Where we rely on legitimate interests, you may object to that processing, or ask us to restrict it while a dispute about accuracy or lawfulness is resolved.
- No Automated Decision-Making: We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you. There is nothing here to opt out of.
To submit a privacy inquiry or data subject request, please reach out through our contact form.
We respond to verified requests within 30 days, and will tell you before that if we need
longer for a complex request.
We Do Not Sell or Share Your Personal Information
ADUMU has not sold personal information in the preceding twelve months, and does not
share it for cross-context behavioural advertising, as those terms are defined by the
California Consumer Privacy Act as amended by the CPRA. We run no advertising, no ad
network integrations, and no data brokerage. Because we do not sell or share, there is no
"Do Not Sell or Share My Personal Information" mechanism to offer — there is nothing
for it to switch off. California residents may still exercise every other right listed
above, and may use an authorised agent to do so.
Lodging a Complaint
If you are in the UK, EEA or Switzerland and believe we have handled your personal data
improperly, we would like the chance to put it right first. You also have the right to
lodge a complaint directly with your local supervisory authority, and nothing here
requires you to come to us before doing so.
08
Children's Data
JUMP is a commercial infrastructure product sold to businesses. It is not directed at
children, we do not knowingly collect personal information from anyone under 16, and we
have no feature intended for or attractive to minors.
If you believe a child has provided us personal information, contact us and we will delete
it. Note that this concerns data about you as our customer. Data your own
collection jobs retrieve from third-party websites is data you control and are responsible
for, and the Acceptable Use Policy in our
Terms of Service governs what you may lawfully collect.
09
Changes to This Policy
We update this policy when our practices change, and the effective date at the top of the
page always reflects the current version.
For any change that materially reduces the protections described here — a new
category of data, a new purpose, a new class of sub-processor, or a longer retention period
— we will give active customers at least 30 days' notice by email to the
address on the account before it takes effect, so that you have time to object or to
terminate. Clarifications and corrections that do not reduce your protections take effect
when published.
10
Contact & Governance
For questions regarding this Privacy Policy, compliance audits, or enterprise security reviews, please contact our data governance team: