Policy 01

Privacy Policy

This policy explains the limited information used by the L3 DC OTP Mailer to deliver and verify secure login codes.

Effective: 24 August 2026

1. Service scope

L3 DC OTP Mailer supports authentication for the private L3 DC Template — WEST DEPOT. It is not a public account service. The recipient mailbox is fixed in server configuration and cannot be selected by a visitor.

2. Information processed

To protect the private application, the authentication service processes limited security information such as request timestamps, short request references, attempt counters, and cryptographic hashes derived from one-time codes, sessions, and source identifiers.

The authentication database does not store raw one-time codes, raw session tokens, raw IP addresses, or the full authorized mailbox address. The public information pages do not contain forms, advertising trackers, or application analytics.

3. Gmail API data

The dedicated Gmail sender grants only the https://www.googleapis.com/auth/gmail.send permission. The service uses it solely to send a login-code email to the fixed authorized mailbox. It does not request permission to read messages, contacts, profile information, or files.

Use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

4. Purpose and sharing

Information is used only to deliver login codes, validate them, maintain authenticated sessions, prevent abuse, diagnose service availability, and protect the private application. Authentication email content is processed by Google for delivery, while hosting and security requests are processed by Cloudflare. Information is not sold or used for advertising.

5. Retention and security

One-time codes expire after a short period, sessions expire automatically, and expired authentication records are periodically removed. Security controls include one-time use, rate limits, cryptographic hashing, secure cookies, server-side validation, and restricted service credentials.

6. Your choices

Do not request a code if you are not authorized to use the L3 DC Template. If you receive an unexpected code, ignore it and do not share it. Authorized operational access questions should follow the established internal support process.

7. Contact

Questions about this policy can be sent to l3dc.login@gmail.com. Do not include passwords, one-time codes, or operational information in email.