Confidentiality Policy

Effective Date: August 2, 2026

Last Updated: August 2, 2026

1. Introduction

Trust is foundational to the work DREOS STUDIO LLC ("DREOS STUDIO," "we," "us," or "our") does with business Clients ("Client," "you"). Our engagements routinely involve access to sensitive business information — including proprietary source code, credentials, financial data, and strategic plans — and we recognize that protecting this information is central to our responsibility as a technical partner. This Confidentiality Policy describes how we define, handle, and protect confidential information shared with us, and it is incorporated by reference into our Terms of Service.

2. Definition of Confidential Information

For purposes of this Policy, "Confidential Information" means any non-public information disclosed by the Client to DREOS STUDIO, or accessed by DREOS STUDIO in the course of delivering Services, whether disclosed orally, in writing, electronically, or through system access, including but not limited to:

  • Business documents, strategic plans, and internal communications.
  • Credentials, API keys, passwords, tokens, and cloud access details.
  • Source code, technical documentation, system architecture, and repositories.
  • Financial information, including revenue figures, pricing, and cost structures.
  • Customer, vendor, and partner information.
  • Proprietary business processes, methodologies, and trade secrets.
  • Product roadmaps, unreleased features, and competitive strategy.
  • Any other information reasonably understood to be confidential given its nature or the circumstances of disclosure.

Confidential Information does not include information that: (a) is or becomes publicly available through no fault of DREOS STUDIO; (b) was already known to DREOS STUDIO prior to disclosure, without an obligation of confidentiality; (c) is independently developed by DREOS STUDIO without reference to the Client's Confidential Information; or (d) is rightfully obtained from a third party without a duty of confidentiality.

3. Scope of Application

This Policy applies to all Confidential Information shared with or accessed by DREOS STUDIO in connection with:

  • Pre-engagement discussions, proposals, and discovery calls.
  • Active development projects.
  • Ongoing maintenance and support engagements.
  • Consulting and advisory work.

This Policy applies regardless of the communication channel used (Email, Slack, Microsoft Teams, Discord, WhatsApp, Telegram, Google Meet, Zoom, or otherwise), and regardless of whether a separate, standalone non-disclosure agreement ("NDA") has been signed. Where a Client requires a separate, more detailed NDA prior to sharing especially sensitive information, DREOS STUDIO is generally willing to execute one; in the absence of a separate NDA, this Policy governs the confidentiality obligations of the parties.

4. Confidentiality Even Before a Signed Agreement

Confidentiality obligations under this Policy begin to apply from the point information is first shared with DREOS STUDIO, including during early-stage discovery calls or proposal discussions that occur before a formal Project Agreement is signed. This means that Clients can share the business context, technical details, and requirements necessary for an accurate proposal without waiting for a contract to be finalized first. This also applies to prospective Clients who ultimately do not proceed with an engagement — information shared during discovery remains subject to this Policy even if no Project Agreement is ultimately signed.

5. Our Commitments

DREOS STUDIO agrees to:

  • Use Confidential Information solely for the purpose of delivering the agreed Services to the Client, and not for any unrelated purpose.
  • Restrict access to Confidential Information to personnel and contractors who require it to perform work on the Client's engagement.
  • Not disclose Confidential Information to third parties, except: (a) to subcontractors or service providers bound by confidentiality obligations at least as protective as this Policy and engaged to assist in delivering the Services; (b) as required by law, regulation, or court order, in which case we will, where legally permitted, provide the Client with reasonable notice; or (c) with the Client's prior written consent.
  • Apply reasonable technical and administrative safeguards to protect Confidential Information, consistent with our Security Policy.
  • Not use Confidential Information to compete with the Client or to benefit any other party to the Client's detriment.
  • Not use Client Confidential Information to train general-purpose AI models or share it across unrelated Client engagements.
  • Limit internal discussion of a Client's Confidential Information to what is reasonably necessary for team members to perform their assigned role on the engagement.

6. Handling of Credentials and System Access

Where the Client provides credentials, API keys, or system access to DREOS STUDIO:

  • Access will be used strictly for purposes related to the agreed Services.
  • Credentials will be stored using secure secrets management practices wherever technically feasible, rather than shared insecurely or stored in plain text.
  • Access will be limited to personnel actively working on the engagement.
  • Where technically supported, DREOS STUDIO will prefer scoped or role-based access credentials over full administrative access, consistent with the least-privilege principle described in our Security Policy.
  • Upon completion or termination of the engagement, DREOS STUDIO will cooperate in good faith with the Client to revoke or hand back access, except where continued access is required for an active maintenance agreement.

7. Handling of Documents and Physical Materials

Where a Client shares physical documents, printed materials, or hardware containing Confidential Information (for example, during an in-person meeting), DREOS STUDIO will take reasonable steps to store or dispose of such materials securely, and will return or securely destroy them upon request once they are no longer needed for the engagement. In practice, the substantial majority of information exchanged in our engagements is digital, and this Policy's protections apply equally to information in electronic form regardless of the channel through which it was received.

8. Client Confidentiality Obligations

Confidentiality is a two-way commitment. Where the Client receives non-public information from DREOS STUDIO — such as our proprietary methodologies, internal tools, pricing structures, or technical approaches not otherwise available to the public — the Client agrees to treat such information as confidential and not disclose it to third parties or use it to replicate DREOS STUDIO's internal tools or processes outside of the Deliverables the Client owns under the applicable Project Agreement.

9. Subcontractors and Personnel

DREOS STUDIO may, from time to time, engage subcontractors, specialized consultants, or additional personnel to assist in the delivery of Services. Where this occurs, DREOS STUDIO ensures that such individuals are bound by confidentiality obligations consistent with this Policy before being granted access to Client Confidential Information. DREOS STUDIO remains responsible for ensuring subcontractor compliance with these confidentiality commitments, and remains liable to the Client for any breach of confidentiality caused by a subcontractor engaged by DREOS STUDIO.

10. Multiple Clients and Conflicts of Interest

DREOS STUDIO works with multiple business Clients, potentially including businesses operating in similar industries. We maintain strict separation between the Confidential Information of different Clients and do not disclose one Client's Confidential Information to another, regardless of any overlap in industry or business focus. If DREOS STUDIO identifies a direct and material conflict of interest in taking on a new engagement (for example, a request to build a materially similar competing product for a direct competitor of an active Client using knowledge specific to that Client), we will address the conflict directly with the affected parties, which may include declining the new engagement or implementing additional information barriers.

11. Duration of Confidentiality Obligations

Confidentiality obligations under this Policy survive the completion or termination of an engagement and continue for as long as the relevant information remains confidential in nature, or for a period of three (3) years following the end of the engagement, whichever is longer — except with respect to trade secrets, which remain protected for as long as they retain trade secret status under applicable law.

12. Return or Destruction of Confidential Information

Upon written request following the completion or termination of an engagement, DREOS STUDIO will use reasonable efforts to return or securely delete Client Confidential Information in its possession, except where: (a) retention is required to comply with legal, tax, or accounting obligations; (b) the information is retained in routine backup systems that are not readily accessible for deletion on demand, in which case it will be deleted in the ordinary course of backup rotation; or (c) continued retention is necessary to support an active maintenance agreement. DREOS STUDIO will confirm in writing once a return or deletion request has been completed.

13. No License Implied

Nothing in this Policy grants either party a license or right to use the other party's Confidential Information beyond what is necessary to fulfill the purposes of the engagement, as further clarified in our Intellectual Property Policy.

14. Breach and Remedies

A breach of confidentiality obligations under this Policy may cause irreparable harm for which monetary damages alone may be an inadequate remedy. Accordingly, in addition to any other remedies available at law, the non-breaching party may be entitled to seek injunctive or equitable relief to prevent or curtail an actual or threatened breach of confidentiality, without the necessity of posting a bond, to the extent permitted by applicable law. This remedy is in addition to, and not a limitation of, the general dispute resolution process described in our Terms of Service.

15. Legally Compelled Disclosure

If DREOS STUDIO is legally compelled (such as by subpoena, court order, or regulatory demand) to disclose Confidential Information, we will, where legally permitted, notify the Client promptly so the Client may seek a protective order or other appropriate remedy. If no protective order or equivalent remedy is obtained, DREOS STUDIO will disclose only the portion of Confidential Information legally required and will use reasonable efforts to ensure confidential treatment of any information so disclosed.

16. Publicity and Case Studies

DREOS STUDIO will not publicly reference a Client's name, logo, project details, or Confidential Information in marketing materials, case studies, portfolio content, or elsewhere without the Client's prior written consent. Where a Client agrees to be featured (for example, in a case study or portfolio entry), the specific scope of information that may be shared publicly will be agreed upon separately and in writing, and the Client retains the right to review and approve the specific content before it is published.

17. Internal Confidentiality Practices

DREOS STUDIO maintains internal practices intended to reinforce confidentiality across engagements, including limiting cross-project access to Client information, using access-controlled project management and file-storage systems, and ensuring that any personnel or subcontractors joining an engagement are briefed on the applicable confidentiality obligations before receiving access to Client materials.

18. A Practical Framework for Sensitivity

Not all Confidential Information carries the same level of risk if mishandled, and we generally think about the information we receive in three rough tiers to guide how carefully it is stored and who can access it. The first tier covers general business context, such as a Client's industry, team size, or high-level goals, which carries relatively low risk but is still treated as confidential and not shared externally. The second tier covers technical and operational detail, such as source code, system architecture, and internal documentation, which is restricted to the personnel actively working on the engagement. The third and most sensitive tier covers credentials, financial data, and anything that could directly enable unauthorized access to a Client's systems or funds, which receives the highest level of access restriction and, where feasible, secure secrets management rather than being stored in general project files. This framework is descriptive of our general practice rather than a rigid classification system requiring the Client to label information in advance; DREOS STUDIO applies reasonable judgment to determine the appropriate handling of information based on its nature.

19. Confidentiality vs. Non-Compete Obligations

This Policy governs how information is handled and protected; it is distinct from, and does not by itself impose, any non-compete restriction on either party's ability to work with other businesses, including businesses in similar industries. DREOS STUDIO's ability to serve other Clients, including those in industries similar to a given Client's business, is addressed in Section 10 above and is not restricted by this Policy beyond the specific protections against misuse of a particular Client's Confidential Information.

20. Illustrative Examples of Confidential Information

To make this Policy more concrete, examples of information that would typically be treated as Confidential Information under this Policy include: a Client's unreleased product roadmap shared during a planning call; database credentials and API keys provided so DREOS STUDIO can configure an integration; a Client's internal pricing model shared to inform the design of a billing system; and customer lists or usage data shared for the purpose of building a CRM or analytics dashboard. This list is illustrative only; the general definition in Section 2 governs what qualifies as Confidential Information in any specific circumstance.

21. Offboarding of Personnel and Subcontractors

When a DREOS STUDIO team member or subcontractor who has had access to a Client's Confidential Information ceases to work on that Client's engagement — whether due to reassignment, the end of a subcontractor relationship, or departure from DREOS STUDIO — we take reasonable steps to revoke that individual's access to the Client's systems, credentials, and shared files as soon as practicable, consistent with the access control principles described in our Security Policy. Confidentiality obligations owed by that individual continue to apply even after their access has been revoked and their involvement in the engagement has ended.

22. Encryption and Secure Transmission

Where reasonably practicable given the tools and platforms involved in a specific engagement, DREOS STUDIO favors encrypted channels for transmitting particularly sensitive Confidential Information, such as credentials or financial data, over unencrypted channels such as plain email attachments. Where a Client has a specific secure-transmission requirement (such as a preferred password manager or encrypted file-sharing tool), we are generally happy to accommodate that preference as part of the engagement's working arrangements.

23. Confidentiality in Group or Multi-Stakeholder Engagements

Some engagements involve multiple stakeholders on the Client side — for example, a startup's founders, an internal engineering lead, and an outside advisor, all participating in project discussions. In such cases, this Policy's protections apply to information shared by any authorized representative of the Client, and DREOS STUDIO will treat information from any such representative as the Client's Confidential Information. The Client is responsible for managing which of its own personnel or advisors are authorized to share and receive information on its behalf in connection with the engagement.

24. Statutory Disclosure Notice

Certain U.S. federal and state laws provide immunity from liability for disclosing a trade secret in specific, limited circumstances — for example, disclosures made in confidence to a government official or attorney solely for the purpose of reporting a suspected violation of law, or disclosures made in a court filing under seal. Nothing in this Policy is intended to conflict with, or to penalize a party for exercising, any such statutory right where applicable. This Section is provided for general informational purposes and does not constitute legal advice regarding any specific situation.

25. Comparing DREOS STUDIO's and the Client's Obligations

While the specific categories of information differ, both parties owe each other a comparable duty under this Policy: to use the other party's confidential information only for purposes of the engagement, to protect it with reasonable care, and not to disclose it to unauthorized third parties. DREOS STUDIO's obligations, given the volume and sensitivity of business and technical information we typically receive, are described in greater detail throughout this Policy; the Client's corresponding obligations with respect to DREOS STUDIO's own proprietary information are addressed principally in Section 8.

26. Why This Matters to Us

We understand that entrusting an outside technical partner with source code, credentials, and business data is a significant act of trust, particularly for founders and growing companies where a single leak of strategic information could carry real competitive consequences. This Confidentiality Policy is written to reflect how we actually operate, not just to satisfy a legal formality, and we encourage Clients to raise any specific confidentiality concern at any point in the engagement so it can be addressed directly.

27. Relationship to Other Policies

This Confidentiality Policy works together with our Security Policy (which describes the technical safeguards applied to protect confidential information) and our Intellectual Property Policy (which governs ownership rights, as distinct from confidentiality obligations). In the event of any conflict specifically regarding confidentiality, this Policy governs.

28. Changes to This Policy

DREOS STUDIO may update this Confidentiality Policy from time to time. Material changes will be communicated to active Clients. The version of this Policy in effect at the time a Project Agreement is signed will generally govern the confidentiality obligations of that engagement, unless the parties agree otherwise in writing.

29. Contact

Questions regarding this Confidentiality Policy, or requests related to the handling of Confidential Information, should be directed to:

DREOS STUDIO LLC

Wyoming, United States

Email: [Insert Contact Email]