Privacy, copyright and billing procedures.
Owner operating procedures
Effective September 29, 2026. Owner: Brian Bateman, DOYJO LLC. These instructions support the published policies; they do not certify legal compliance or create an automatic deletion schedule.
Cancellation and billing
- Review recurring requests each business day and before renewal collection. Treat the recorded account request, or a verified support request, as sufficient. Never require another customer email confirmation or new policy acceptance to cancel.
- Stop the correct provider agreement, or reduce it for mailbox removals. Combined hosting cancellation includes its mailboxes; separately added email agreements need separate handling. For a support request, record the original received time and scope in the case record, stop collection directly, and reconcile the account state.
- Check same-day and later invoices and payment settlement. Complete any necessary void or refund in the provider, record the transaction reference, then mark the outcome here. Do not mark a promised refund as completed. Do not treat an internal pending state as customer authorization to renew.
- Record provider cancellation evidence. Verify paid access continues only for the appropriate period, send the customer a confirmation through the normal support process, and keep the original request and resolution. Accounting API reconciliation does not itself cancel the provider's schedule.
Copyright and repeat infringement
- Monitor brianbateman@doyjo.com for copyright notices. Create a private case record with case ID, receipt time, claimant, customer/site, URLs, alleged works, signature and declarations, and the response deadline. Limit access to authorized staff.
- Review promptly. Seek missing required information where appropriate and act expeditiously on valid notices. Preserve the minimum evidence necessary and disable the specific material. Inform the customer and retain proof of action. Do not circulate unrelated personal data.
- Forward a qualifying counter-notice to the complainant. Track the statutory 10–14 business-day restoration window and any lawsuit notice or applicable exception. Record the grounds before restoring or continuing a restriction. Escalate disputed legal issues for advice.
- Check previous cases for that account, including withdrawn notices and valid counter-notices. Record the repeat-infringer decision and terminate in appropriate circumstances. Do not use a fixed unreviewed strike count or let a repeat infringer bypass a restriction with a new account.
- Before relying on DMCA safe-harbor protection, verify or complete the Copyright Office agent registration for DOYJO LLC with alternate names Contreol and contreol.com, matching the public contact. Save the registration ID and renewal date, and keep it current. Registration has not been verified by this deployment.
Privacy requests and retention
- Monitor the published email and telephone contact. Log receipt, scope, jurisdiction, identity/agent checks, applicable deadline and case owner in a private record. Verify proportionately; never request passwords or unnecessary ID documents.
- Identify controller/processor roles and the applicable law before promising a deadline or applying an exception. Acknowledge and route customer-website visitor requests appropriately. Explain denials and appeal routes when required; do not discriminate unlawfully.
- Before export or deletion, map the account across the stores below, preserve any justified legal hold, and document its reason and review date. Cancellation and dismissal of an AI recovery item are not deletion requests.
- Use a reviewed, account-scoped operation. Export securely; stop new writes before deletion where necessary. Check active storage, public copies, queues, caches, and provider requests. Review cascades before deleting an account. Confirm outcomes without disclosing other customers' information.
- Record each exception, backup expiry or residual provider record. Reapply deletion instructions after any backup restore. Do not promise immediate removal from providers' independent legal records or recall of copies acquired by visitors.
- Review the retention inventory at least quarterly and when adding a feature. Until an automated schedule is implemented and tested, review retained data and requests manually. Do not market indefinite storage or universal automatic expiry.
Retention inventory
| Record category | Current handling and review |
|---|---|
| Accounts, identity, sessions and consent | Private account store. Accounts have no uniform automatic expiry; session expiry follows authentication rules. Retain justified consent and dispute evidence separately when closing an account; do not alter historic acceptance versions. |
| Drafts, uploads and publication | Private project and asset stores plus hosted/preview copies. Account closure requires checking all locations and access routes. User-supplied originals and publicly copied material are separate. |
| AI requests, received output and task checkpoints | Private recovery and build stores; request/output encryption where documented. No uniform automatic expiry. Review resumed, completed and dismissed items; reconcile usage before removing evidence. |
| Visitor posts, attachments and application data | Customer-directed stores. Confirm website ownership, instructions, legal duties and any required processing agreement; include related media and public visibility. |
| Mailboxes and setup credentials | Mail server plus private setup queue. Confirmed setup passwords leave the queue; messages persist after cancellation. Verify a specific deletion instruction before removing mailbox data. |
| Billing, usage and security | Private records, audit logs and provider records. Retain only what service, accounting, disputes, security or applicable law require; document the reason and review date. No new universal retention period is promised. |
| Measurement and browser data | Optional consent, local delivery queue and browser storage. Existing queue cleanup and configured Analytics retention remain in place. Consent withdrawal must stop future measurement; handle prior data requests separately. |
| Support, complaints and backups | Support inboxes including existing forwarding, private case evidence and backup copies. Review necessity at closure and periodic review. Confirm actual backup retention/restore behavior before promising a deletion date. |
Customer markets and processing contracts
Before accepting a use that requires a DPA, transfer safeguards, regional disclosures, or regulated-data terms, confirm the customer's and visitors' jurisdictions, data categories, purposes, providers and actual tracking settings. Complete the applicable contracts and notices first. The Privacy Policy does not substitute for a DPA, SCCs or a HIPAA business associate agreement. The standard service prohibits regulated sensitive records and child-directed collection needing consent without a separate written arrangement.
Policy releases
Retain immutable policy bundles and acceptance events. New accounts and new or resumed orders expressly accept the current bundle. Existing records are not rewritten, and an existing account is not deemed to have accepted this new amendment clause merely because it is published. For future updates, record each affected agreement version, notice text, recipient or in-service delivery, delivery time, effective date and the acceptance basis. Provide a prominent notice or account email with the revised text, effective date and material-change summary before relying on continued use. Ordinarily allow at least 30 days for material changes; document any narrowly necessary legal, security or abuse exception and check applicable law. Obtain express consent whenever required and preserve its evidence. If relying on continued use where lawful, retain evidence of qualifying use after notice and the effective date separately from express acceptance records. Never treat cancellation-only access as assent or obstruct cancellation. Do not apply new terms retroactively, alter paid authorizations, or use continued use as a substitute for required privacy consent. Current bundle: 2026-09-29.2. Notice delivery and legal review for future releases remain operator procedures; publishing a bundle does not send a notice.
Government demands
Do not voluntarily disclose nonpublic customer information to government agencies. Route demands for legal review, verify the requesting authority and binding legal basis, record scope and deadlines privately, and disclose only what is legally required. A valid subpoena or mandatory reporting duty may require action without a separate court order. Preserve records when legally required without treating preservation as authorization to disclose. Notify the affected customer before disclosure where legally permitted; record any prohibition and review it as appropriate. Do not publish demands, customer information or legal case records on this page.