Effective Date: September 17, 2026 Radiome Health Private Limited

Enterprise Privacy Policy

This Privacy Policy governs the collection, utilization, and architectural protection of technical telemetry by Genix BaseScale™, an enterprise genomics FinOps and compute orchestration middleware owned and operated by Radiome Health Private Limited ("Radiome Health", "we", "us", or "our").

Critical Architecture Guarantee

1. The HIPAA § 164.312 Zero-Payload Commitment

Unlike traditional cloud APM or monitoring tools, Genix BaseScale does not collect, inspect, store, or transmit raw genomic sequences or Protected Health Information (PHI).

Our eBPF kernel agent operates at the Linux OS layer (cgroup v2 and kernel scheduler tracepoints). The software architecture strictly prevents reads from biological data formats, including but not limited to:

  • • FASTQ / .fq
  • • BAM / CRAM
  • • VCF / BCF
  • • Clinical EHR / PHI

Kernel probes are cryptographically gated. Any byte stream matching raw biological ASCII/binary sequences is architecturally dropped at the kernel boundary before socket egress.

2. Categories of Information We Process

To compute container right-sizing recommendations, spot pre-warming wave triggers, and FinOps audit savings, BaseScale collects strictly non-PHI machine telemetry:

A. Compute & Memory Consumption Telemetry Physical memory RSS (high-water mark), swap usage, CPU execution microseconds, block I/O bandwidth, and cgroup memory limits.
B. Workflow Execution Metadata Nextflow DSL2 and WDL 1.0 process names (e.g., ALIGN_STAR, HAPLOTYPE_CALLER), task attempt indices, container image digests, and process return codes.
C. Cloud Spot Infrastructure Events AWS EC2 Spot IMDSv2 120-second preemption notices, GCP Preemptible stop signals, instance types (e.g. c6i.4xlarge), and cloud availability zones.
D. Enterprise Account & Contact Data Name, institutional email address, company name, cloud environment parameters, and cryptographic tenant public keys.

3. Purpose of Processing Telemetry Data

Radiome Health Private Limited processes technical telemetry strictly for legitimate enterprise infrastructure objectives:

  • Automated Right-Sizing: Calculating P95 actual memory utilization plus 25% safety headroom buffer to eliminate overprovisioned container RAM costs.
  • Predictive Node Pre-Warming: Analyzing DAG task dependencies to pre-spin Spot instance pools T-120 seconds in advance, eliminating cold-start queuing delay.
  • Preemption Checkpointing: Orchestrating memory snapshots to customer-controlled S3/GCS buckets when Spot evictions are intercepted.
  • Immutable SOC 2 Audit Chaining: Creating SHA-256 cryptographic audit blocks recording all provisioning adjustments.

4. Cryptographic Wire Security (mTLS 1.3)

All telemetry flowing between worker node agents and the centralized FinOps control plane is encrypted in transit using pure-Rust hardware-accelerated mTLS 1.3 with ephemeral X.509 certificates.

Telemetry is framed using our proprietary binary codec (GENX) with fixed 10-byte packet headers. Any attempt to pass unauthorized payloads triggers immediate connection termination and an automated security audit alert.

5. Multi-Tenant Isolation & Sovereign Clouds

Radiome Health enforces strict multi-tenant isolation. Telemetry is partitioned by customer tenant ID and encrypted at rest with customer-managed AWS KMS keys (SSE-KMS) or Cloud KMS keys. Customers may configure on-premises control plane deployments or VPC-peered private links (AWS PrivateLink) where telemetry never touches the public internet.

6. HIPAA Compliance & Business Associate Agreements (BAA)

While BaseScale's architecture does not access or store PHI, Radiome Health Private Limited routinely executes standard HIPAA Business Associate Agreements (BAA) with enterprise biopharma, clinical genomics diagnostics labs, and academic medical centers to formalize technical safeguards under 45 CFR § 164.312.

7. Data Protection Officer & Corporate Entity

For questions, data subject requests under GDPR/CCPA, or BAA execution, contact:

Legal Entity: Radiome Health Private Limited
Parent Brand: Genix.ai Ecosystem
Data Protection Officer: privacy@genix.ai
Security Incident Desk: security@genix.ai
Enterprise Inquiries: contact@genix.ai