Privacy Policy
How R-ESM LLC processes personal data in the StateNull and StateNull-SecoM services. Effective 12 July 2026 · last updated 3 August 2026. Questions: media.supply@statenull.com.
Who we are (data controller)
The data controller is R-ESM LLC (Royal Enterprise Service Management), 30 N Gould St # 38144, Sheridan, WY 82801, USA (see the Impressum). For organisations that enrol their members, that organisation is the controller for its members' work data and R-ESM acts as its processor.
What we process
- Account data — your e-mail address, optional display name and @handle, and a one-way (scrypt) hash of your password. Used to create and secure your account.
- Subscription & billing data — your plan, trial/renewal status, and the billing details you provide at checkout (handled by Paddle — see Payments).
- Communications & files — your messages, calls and shared files are end-to-end encrypted. Our servers act as a blind relay and store only opaque ciphertext; R-ESM LLC cannot read your content (zero-knowledge). To operate the service our servers do process account, request and delivery metadata — file names, sizes, types, recipients and timestamps — never the contents.
- Captured media (StateNull-SecoM) — photos, scans, PDFs, video and voice notes are encrypted on your device and uploaded as opaque ciphertext under your own keys.
- Managed devices — on devices enrolled by an organisation (MDM), the organisation administrator can view device inventory (model, OS, battery, installed-app list, compliance) and issue management actions (e.g. lock/wipe). This is controlled by the organisation, not by R-ESM LLC.
- Support & cancellation requests — the e-mail address and message you send us.
- Operational & security logs — minimal logs needed to run the service securely and prevent abuse.
Legal bases for processing (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)) — to create your account and provide the subscription you signed up for.
- Legal obligation (Art. 6(1)(c)) — to keep the billing and tax records required by law.
- Legitimate interests (Art. 6(1)(f)) — to secure the service, prevent fraud and abuse, and maintain reliability.
- Consent (Art. 6(1)(a)) — where we specifically ask for it (e.g. optional communications); you can withdraw consent at any time.
What we do NOT do
- We do not sell or rent your personal data.
- We do not read your end-to-end-encrypted content.
- We do not use your content for advertising or profiling.
Security
Transport is TLS 1.3 with certificate pinning; content is encrypted with AES-256-GCM. Every photo, scan and PDF capture is signed with a hybrid of classical (RSA-PSS) and post-quantum (ML-DSA-65 / FIPS-204) signatures, so any later change to a sealed file is detectable on verification — the signature scheme is chosen to stay robust even against future quantum computers. Encryption is on by default. (Post-quantum key exchange for the transport channel — ML-KEM / FIPS-203 — is on our roadmap, not yet shipped; our post-quantum protection today is in the signatures.)
Payments
When you purchase a subscription, payment is processed by our reseller and Merchant of Record, Paddle.com Market Ltd ("Paddle"). To process your order and calculate tax, Paddle receives the billing data it needs — such as your name, e-mail, billing address and payment-method details — under Paddle's own privacy policy. R-ESM LLC does not receive or store your full payment-card number.
Sub-processors
We use a small number of vetted service providers who process data on our behalf under data-processing terms:
- Paddle.com Market Ltd (United Kingdom) — payment processing & Merchant of Record.
- Hetzner Online GmbH (European Union) — cloud hosting / infrastructure; the service and its encrypted stores are hosted in the EU.
- Google (Google Workspace) — transactional and support e-mail.
We will update this list as our providers change.
International data transfers
The service and your encrypted data are hosted in the EU. R-ESM LLC is established in the United States, and some sub-processors are outside the EEA (e.g. the USA and the UK). Where personal data is transferred outside the EEA, we rely on an appropriate safeguard — an adequacy decision (the UK benefits from EU adequacy) or the EU Standard Contractual Clauses — or on your explicit consent.
Cookies & analytics
Our website and portal use only essential / session cookies needed to sign you in and keep the service secure. We do not use advertising, cross-site tracking, or third-party analytics cookies. Because there are no non-essential trackers, no cookie-consent banner is required.
Retention
- Account data — kept while your account is active. A verified deletion request runs a fixed erasure inventory across every server-side store: the account record, sessions and tokens, encrypted content and backups, support tickets, proof-request jobs and guest uploads, messages, shares, meetings, certificates metadata, agent workspaces and avatars; device records are pseudonymised and the organisation record is scrubbed. Completed within about 30 days of the request, unless a longer period is legally required.
- What remains after deletion, and why — only records with an explicit rule: billing rows referenced by opaque Paddle identifiers with the e-mail address blanked (statutory bookkeeping), issued certificates and public-key history (so records you sealed and signatures you made before deletion remain independently verifiable), and the deletion entry in the tamper-evident audit log (the retained fact that an erasure happened).
- Encrypted content — kept per your storage settings; removed when you delete it or close the account.
- Support & cancellation records — kept for up to about 24 months.
- Billing & tax records — retained by Paddle (and by us where required) for the period required by tax law, typically up to 6–10 years in the EU/UK.
- Security logs — minimal and rotated, typically within about 90 days.
Your rights
Subject to applicable law (including the EU/UK GDPR), you have the right to access, rectify, erase (be forgotten), restrict, and port your personal data, to object to certain processing, and to withdraw consent at any time. To exercise any of these, contact media.supply@statenull.com; we respond within the statutory time limits. You also have the right to lodge a complaint with a supervisory authority — for EU/EEA residents this is your local Data Protection Authority (in Germany, the DPA of your federal state), and in the UK the Information Commissioner's Office (ICO).
Age requirement (18+)
StateNull is for adults: you must be 18 or older to create an account or use the services. The services are not directed to anyone under 18, we do not knowingly collect personal data from anyone under 18, and if we learn that we have, we delete it. The same 18+ rule is stated in our Terms of Service and User Policy.
Changes & contact
We may update this policy; we will change the "last updated" date above and, for material changes, provide reasonable notice. Contact: media.supply@statenull.com · R-ESM LLC, 30 N Gould St # 38144, Sheridan, WY 82801, USA.