Privacy Policy
A single global privacy framework for Aeltrix Technologies LLC, with jurisdiction-specific supplements for the United States, European Economic Area, and United Kingdom.
Aeltrix Technologies Privacy Policy
This Privacy Policy explains how Aeltrix Technologies LLC ("Aeltrix," "we," "us," or "our") collects, uses, discloses, retains, protects, and otherwise processes personal information in connection with our corporate website, accounts, services, APIs, sales, support, billing, security operations, professional services, and related business activities.
Part I applies generally. Parts II through IV supplement Part I for individuals protected by the identified jurisdictions. If a jurisdictional supplement provides an additional or different right required by applicable law, that supplement controls for the affected individual and processing. The Cookie Policy and Data Processing Addendum are separate legal instruments and form part of the broader Aeltrix privacy and data-protection framework where applicable.
Part I — Global Privacy Policy
GENERAL FRAMEWORK // SECTIONS 1–191. Scope
This Privacy Policy explains how Aeltrix Technologies LLC handles personal information in connection with:
- aeltrix.io;
- Aeltrix accounts;
- Aeltrix Network services where Aeltrix Technologies LLC is the contracting provider;
- sales;
- support;
- billing;
- APIs;
- professional services;
- security operations;
- communications; and
- related online services.
This Policy does not replace the contractual terms governing Customer Content that Aeltrix processes solely on behalf of an enterprise Customer where the Customer acts as controller and Aeltrix acts as processor. Such processing is principally governed by the Data Processing Addendum and the Customer's own privacy obligations.
2. Information We May Collect
Depending on the Service and relationship, we may process:
Identity information
Name; business title; organization; username; account identifier.
Contact information
Business email; telephone number; postal address; billing address.
Account information
Authentication events; roles; permissions; security settings.
Transaction information
Orders; subscriptions; invoices; transaction identifiers; payment status; tax information. Full payment-card information may be processed directly by payment-service providers rather than stored by Aeltrix.
Domain registration information
Registrant, administrative, technical, billing, and other registration information required by registrars or registries.
Network and device information
IP address; browser; operating system; device identifiers; timestamps; request logs; authentication logs; network activity; security telemetry.
Customer Content
Files; documents; email content; messages; infrastructure configurations; databases; prompts; AI inputs; outputs; and other information a Customer elects to process through a Service.
Communications
Support tickets; sales communications; feedback; security reports; abuse reports; telephone or electronic correspondence.
Marketing information
Communication preferences; campaign engagement; website interaction; event participation.
Cookie and online information
Cookie identifiers; session data; analytics; preferences; and advertising information where such technologies are lawfully enabled.
Security information
Fraud signals; abuse indicators; blocked activity; malware indicators; authentication risk; sanctions screening data.
3. Sources
Information may come from you; your organization; authorized account administrators; Aeltrix Services; devices and browsers; service providers; registrars; cloud providers; payment providers; security vendors; publicly available business sources; referral partners; or other parties acting with lawful authority.
4. Purposes
Aeltrix may use information to provide Services; authenticate users; provision infrastructure; register and manage domains; process billing; provide support; secure systems; prevent fraud; detect abuse; investigate incidents; maintain audit records; communicate Service information; conduct lawful B2B marketing; improve Services; develop new features; comply with legal obligations; enforce agreements; establish or defend legal claims; conduct corporate transactions; and protect users, Aeltrix, and third parties.
5. Legal Bases in the EEA and UK
Where GDPR or UK GDPR applies, Aeltrix relies upon one or more of:
- performance of a contract;
- steps requested before entering a contract;
- legitimate interests;
- compliance with legal obligations;
- consent; and
- in exceptional cases, protection of vital interests or another basis permitted by applicable law.
Legitimate interests may include business administration, network security, fraud prevention, B2B relationship management, service improvement, and direct marketing where permitted. We balance those interests against affected individuals' rights.
6. Disclosures
Information may be disclosed to cloud and hosting providers; payment processors; registrars and registries; DNS providers; communications providers; email infrastructure providers; security vendors; analytics providers where enabled; professional advisers; auditors; contractors; corporate affiliates; transaction counterparties in a merger, financing, or acquisition; law-enforcement or governmental bodies where legally required; and other persons directed by a Customer.
7. No Traditional Sale of Personal Information
Aeltrix does not sell personal information for monetary consideration as part of its ordinary business model. If an activity constitutes "sale" or "sharing" under a particular privacy statute despite no monetary exchange, Aeltrix will provide legally required rights and disclosures.
8. Behavioral Advertising
Aeltrix will not use personal information for cross-context behavioral advertising where applicable law prohibits the activity or requires an opt-out that has been exercised.
9. Global Privacy Control
Where legally applicable, Aeltrix will recognize valid browser-based opt-out preference signals such as Global Privacy Control (GPC) for processing covered by the applicable law.
10. Retention
Aeltrix retains personal information only for as long as reasonably necessary for the purpose for which it was collected and for legal, security, accounting, and dispute-resolution requirements. Retention varies according to the information and context.
Typical factors include contract duration; account status; statutory tax and accounting periods; security requirements; backup cycles; registrar requirements; limitation periods; support needs; and legal holds. Suppression records may be retained after an opt-out so that the preference can continue to be honored.
11. Security
Aeltrix uses administrative, technical, and organizational safeguards appropriate to the nature of the relevant systems and information. No method of Internet transmission or storage is absolutely secure.
12. International Transfers
Aeltrix is based in the United States and may use providers in multiple countries. Where required, transfers from the EEA, UK, or Switzerland will use a recognized transfer mechanism, which may include adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized safeguard.
13. Privacy Rights
Depending on applicable law, individuals may have rights to know whether data is processed; access data; obtain a copy; correct inaccurate data; delete data; restrict processing; object to processing; withdraw consent; request portability; opt out of sale; opt out of sharing for targeted advertising; opt out of qualifying profiling; limit certain uses of sensitive personal information; appeal certain request decisions; and complain to a competent supervisory authority. Aeltrix will provide rights as required by applicable law.
14. Privacy Requests
Requests may be sent to privacy@aeltrix.io. A web privacy-request mechanism may also be made available. We may verify identity before fulfilling a request. Authorized agents may submit requests where applicable law permits.
15. Response Period
Aeltrix will respond within the period required by applicable law. As an operational target, verified requests should ordinarily receive a substantive response within 30 days unless circumstances or applicable law permit a longer period.
16. Automated Decision-Making
Aeltrix does not intend to make decisions producing significant legal effects about website visitors solely through automated processing unless the practice is specifically disclosed and permitted by applicable law. Customer use of Aeltrix automation is governed by the Customer's own obligations.
17. Children
Aeltrix Services are business-oriented and not directed to children under 13. Aeltrix does not knowingly seek personal information directly from children under 13 for general commercial Services. Where Aeltrix learns that such information was collected contrary to applicable requirements, it will take appropriate steps. Services requiring an account are intended for adults or authorized business users unless a Service expressly states otherwise.
18. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated through appropriate channels, and the effective date above will be revised when required.
19. Contact
Aeltrix Technologies LLC
Delaware, United States
Part II — United States State Privacy Notice
U.S. JURISDICTIONAL SUPPLEMENT // SECTIONS 1–11This Part supplements Part I for residents of U.S. states that provide additional privacy rights. It applies only to the extent the relevant state privacy law applies to Aeltrix and the processing at issue.
1. Categories of Personal Information
Aeltrix may collect the categories described in Part I, including identifiers; commercial information; Internet or network activity; professional information; geolocation at a general IP-derived level; communications; account credentials; customer records; and sensitive information where necessary for security or a Service specifically requiring it.
2. Purposes
Purposes include Service delivery, security, billing, support, fraud prevention, business administration, legal compliance, analytics where enabled, and marketing where permitted.
3. California Notice at Collection
Where California law requires a notice at collection, Aeltrix will identify the categories of personal information collected, the purposes for collection or use, whether the information is sold or shared as those terms are defined by California law, and applicable retention criteria or the criteria used to determine retention. Collection interfaces should link to this Privacy Policy or an applicable just-in-time notice.
4. California Rights
Where the CCPA applies, eligible California residents may request access; specific pieces of information where legally available; deletion; correction; opt-out from sale or sharing; limitation of qualifying sensitive-personal-information processing; and non-discriminatory treatment for exercising applicable rights.
5. Rights Under Other State Privacy Laws
Depending on state law, residents may additionally have rights concerning targeted advertising, qualifying profiling, data portability, sensitive-data consent, authorized agents, and appeals.
6. Universal Opt-Out Signals
Aeltrix will honor legally required universal opt-out mechanisms for processing to which such mechanisms legally apply, including qualifying browser-based preference signals where required.
7. Sensitive Data
Aeltrix will not process sensitive data in a manner requiring consent under an applicable state privacy law without obtaining the legally required consent or relying on another lawful basis, exemption, or permitted purpose.
8. Minors
Aeltrix does not knowingly sell or share personal information of minors where prohibited by law.
9. Financial Incentives
Aeltrix does not currently operate a program that intentionally provides a price or service difference in exchange for personal information unless separately disclosed with the notice and consent mechanisms required by applicable law.
10. Appeals
Where applicable law provides a right to appeal a denied privacy request, the response will explain how to submit an appeal and any legally required further recourse.
11. Requests
State privacy requests may be directed to privacy@aeltrix.io. Aeltrix may verify the requester's identity, authority, residency, or other information to the extent permitted or required by applicable law.
Part III — EEA GDPR Supplement
REGULATION (EU) 2016/679This Part supplements Part I where Regulation (EU) 2016/679 (GDPR) applies to Aeltrix processing.
- Aeltrix may act as controller for account, billing, security, sales, marketing, corporate, and operational information for which Aeltrix determines the purposes and means of processing.
- Aeltrix generally acts as processor where an enterprise Customer submits personal data to a hosted Service solely for the Customer's documented purposes.
- Data subjects may exercise applicable rights under Articles 15–22 GDPR.
- Where Aeltrix acts solely as processor, requests concerning Customer-controlled data should ordinarily be directed to the relevant Customer, and Aeltrix will provide processor assistance as required by the applicable agreement and law.
- Transfers of personal data outside the EEA will use an applicable lawful transfer mechanism where one is required.
EU Representative
If Article 27 GDPR requires Aeltrix to appoint a European Union representative, the appointed representative's identity and contact details will be published here before relevant in-scope processing is commenced or continued.
Supervisory Authority
Individuals in the European Economic Area may have the right to lodge a complaint with a competent data-protection supervisory authority, including in the Member State of their habitual residence, place of work, or the place of the alleged infringement, as provided by applicable law.
Part IV — United Kingdom Privacy Supplement
UK GDPR // DATA PROTECTION ACT 2018This Part supplements Part I where the UK GDPR and Data Protection Act 2018 apply. Individuals may exercise the privacy rights available under UK data-protection law, subject to applicable conditions, exemptions, and limitations. International transfers from the United Kingdom will use a lawful transfer mechanism where required.
UK Representative
Where Article 27 UK GDPR requires Aeltrix to appoint a representative in the United Kingdom, the appointed representative's identity and contact details will be published here.
UK Supervisory Authority
Individuals in the United Kingdom may have the right to lodge a complaint with the Information Commissioner's Office (ICO). Information about the ICO and its complaint process is available at ico.org.uk.
Related Privacy and Data-Protection Documents
This Privacy Policy should be read together with the following documents where they apply to the relevant Service or relationship.
Questions about this legal document?
For legal notices, compliance questions, or requests relating to this document, contact Aeltrix Technologies LLC through the legal channel below.
