Legal Center & Regulatory Compliance
The legal framework governing developer rights, source code licensing, privacy, data sovereignty, service level agreements, and acceptable usage across Kontyra.
1. Overview & Governance
Kontyra operates under a developer-first transparency model. We believe software developers should have complete clarity on who owns their code, how data is processed, and the cryptographic protections guarding their projects.
You retain 100% ownership and copyright over code deployed in DevOS.
We never sell developer source code or behavioral telemetry to third parties.
All persistent database records and storage buckets are encrypted with AES-256.
2. Kontyra Public License (KPL-1.0)
The Kontyra Public License (KPL-1.0) grants broad rights for developers to inspect, modify, fork, and self-host our open-source tools while preserving attribution:
Kontyra Public License Version 1.0 (KPL-1.0)
Copyright (c) 2026 Kontyra Technologies.
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files, to deal in the Software
without restriction, including without limitation the rights to use, copy,
modify, merge, publish, distribute, and/or sublicense copies of the Software...3. Acceptable Use Policy (AUP)
To safeguard system resources and prevent abuse of free sandboxes, the following activities are strictly forbidden on DevOS and API execution nodes:
- Cryptocurrency Mining: Running proof-of-work miners or computational coin farming.
- Denial of Service (DoS): Launching network floods, port scans, or packet amplification attacks.
- Malware & Phishing: Hosting malicious payloads, command-and-control servers, or credential harvesting pages.
- Automated Scraping: Aggressive unthrottled crawling that degrades platform responsiveness.
4. Data Protection: GDPR & NDPR Compliance
Kontyra complies with both the European General Data Protection Regulation (GDPR) and the Nigeria Data Protection Regulation (NDPR). Users have enforceable rights to data portability, rectification, and erasure (the "Right to be Forgotten").
5. Responsible Security Disclosure
We welcome vulnerability reports from security researchers. Please report potential vulnerabilities directly to our security engineering team at security@kontyra.name.ng with proof-of-concept steps. We provide safe harbor for good-faith research conducted in accordance with our policy.
6. Data Retention & Deletion Lifecycle
When an account or project is deleted, active compute containers are terminated immediately. Associated database records, storage objects, and cached assets are permanently expunged within 30 days. Immutable audit logs are retained for 365 days for regulatory compliance before automated purge.
7. Complete Legal Directory
General conditions governing accounts and platforms.
Personal data collection, cookies, and telemetry protection.
Prohibitions against malware, scraping, and mining.
Internal least-privilege administrative standards.
Backup schedules and atomic deletion procedures.
Official open-source dual licensing terms.
GDPR, NDPR, and ISO-aligned controls.
Essential session cookies and privacy preferences.
Third-party infrastructure providers (Cloudflare, Resend, Paystack).
99.9% uptime commitments for enterprise customers.
Cryptographic architecture and vulnerability handling.
Emergency response and customer breach notification timelines.