Legal · GDPR Compliant

Privacy Policy

Your privacy is a priority. This document explains in clear terms which data we collect, how we process it and what rights you have under Regulation (EU) 2016/679 (GDPR).

Last updated: June 4, 2026 Version 2.0 GDPR-compliant

1. Introduction

AEGIS SOFTWARE SOLUTIONS LTD ("Aegis", "we", "us" or "Controller"), with registered office at 20 Wenlock Road, London N1 7GU, England, acts as Data Controller and respects the privacy of users of its SaaS platform and related services.

This Privacy Policy transparently describes which personal data we collect, how we use it, who we share it with and which rights you can exercise under Regulation (EU) 2016/679 ("GDPR") and applicable national law.

Purpose of this document: give you full awareness and control over your data. If anything is unclear, contact us at any time using the channels in section 11.

Effective date: June 4, 2026.

2. Data we collect

We collect only the data necessary to deliver and improve our services. The categories of data processed are:

2.1 Registration data

  • Personal data: first name, last name, email address, phone number (optional), login credentials (hashed password).
  • Business data: company name, VAT number / tax ID, billing and registered address, tax regime where applicable.

2.2 Platform usage data

  • Access logs, IP address, user agent, browser type and version, operating system.
  • Pages visited, features used, interaction timestamps, session duration.
  • Two-factor authentication (MFA) data, IP allowlist, active sessions.

2.3 AI-generated data

  • Content, documents, analyses and outputs produced through the platform's AI modules.
  • Prompts, inputs and files uploaded by the user for AI processing.
  • Usage metadata (tokens consumed, model used, cost in credits).

Data processed by the AI is not used to train third-party models. See section 5 for the list of providers.

2.4 Payment and billing data

  • Payment data is handled entirely by Stripe Payments Europe Ltd (PCI-DSS Level 1). Aegis does not store credit card data.
  • Invoice history, amounts, subscriptions, AI credit top-ups, transactions.

3. Purposes of processing

Your data is processed only for the following purposes:

  • SaaS service delivery — creating and managing your account, access to the platform, delivery of subscribed modules, storage of your documents.
  • Account management and support — responding to assistance requests, support tickets, service communications, credential recovery.
  • AI processing — executing requests against the AI models to generate outputs, analyses and documents.
  • Service improvement — aggregated and anonymous analytics to identify bugs, optimise performance and develop new features.
  • Billing and accounting — invoice issuance, accounting record-keeping, fulfilment of tax obligations.
  • Security — fraud and abuse prevention, prevention of unauthorised access, anomaly detection (e.g. account sharing, suspicious logins).
  • Legal compliance — responding to lawful requests from judicial or supervisory authorities.
  • Marketing — sending promotional communications, newsletters and product updates only with explicit consent, always revocable.

5. Data sharing

We do not sell your data. We share it only with qualified third parties, appointed as Data Processors under Art. 28 GDPR, that help us deliver the service:

  • Stripe Payments Europe Ltd (Ireland) — payment and subscription management.
  • Supabase Inc. / cloud hosting (EU — Frankfurt, Germany) — database, authentication and storage.
  • Cloudflare Inc. — CDN, DDoS mitigation, perimeter security.
  • AI providers — OpenAI, Anthropic, Google (LLM models accessed via a secure gateway; data not used for training).
  • Transactional email provider — delivery of service communications and notifications.
  • Professional advisors — accountants and lawyers, bound by professional secrecy.

Transfers outside the EU

When data is transferred outside the European Economic Area (e.g. US-based AI providers), the transfer relies exclusively on:

  • European Commission adequacy decisions (e.g. EU-US Data Privacy Framework).
  • Standard Contractual Clauses (SCCs) approved by the Commission.
  • Supplementary security measures (end-to-end encryption, pseudonymisation).

6. Data security

We adopt appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration or disclosure (Art. 32 GDPR):

  • Encryption in transit — TLS 1.3 on all connections.
  • Encryption at rest — AES-256 on databases and storage.
  • Authentication — bcrypt password hashing, optional MFA, recovery codes, HIBP check (compromised-password detection).
  • Access control — Row Level Security (RLS) at the database level, strict tenant isolation, optional IP allowlist.
  • Document watermarks — documents downloaded from the platform include watermarks with the user's identifier and timestamp for traceability.
  • Audit log — comprehensive logging of critical operations, available to the admin.
  • Backups — automated daily backups with 30-day retention.
  • Monitoring — anomaly detection, security alerts, vulnerability management.
In case of a data breach, we commit to notifying the competent supervisory authority within 72 hours and the affected users without undue delay, as required by Arts. 33-34 GDPR.

7. Data subject rights

As a data subject you have the right, at any time, to exercise the following rights guaranteed by Arts. 15-22 GDPR:

Access (Art. 15)

Obtain confirmation of processing and a copy of your data.

Rectification (Art. 16)

Correct inaccurate or incomplete data.

Erasure (Art. 17)

Request deletion of your data (right to be forgotten).

Restriction (Art. 18)

Restrict processing in specific cases.

Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV).

Object (Art. 21)

Object to processing based on legitimate interest or marketing.

Withdraw consent

Withdraw consent previously given at any time.

Complaint

Lodge a complaint with your competent data protection authority.

How to exercise your rights

  • Self-service: open the Privacy section of your account to autonomously request export or deletion of your data.
  • Email: write to info@aegissystem.net.
  • We respond within 30 days of receiving the request (extendable by 60 days in complex cases).

8. Data retention

We keep your data only as long as necessary for the purposes for which it was collected:

CategoryPeriod
Active accountDuration of the contractual relationship
Closed account30-day grace period, then deletion/anonymisation
Invoices and accounting documentsAs required by applicable tax law (typically 6-10 years)
Security and audit logs12 months
Support communications24 months after ticket closure
Backups30 days

9. Cookies and tracking

We use cookies and similar technologies strictly necessary for the platform to work (authentication, session, user preferences) and, with consent, aggregated analytics cookies.

For the full list of cookies used and to manage your preferences, see our Cookie Policy.

10. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy to reflect regulatory, technological or product changes. In case of material changes we will notify you by email or via a prominent in-platform notice at least 30 days in advance.

The last-updated date is always shown at the top of the document.

11. Contact

Data Controller

AEGIS SOFTWARE SOLUTIONS LTD

20 Wenlock Road, London N1 7GU, England, United Kingdom
Company No. 16640141

Privacy requests

info@aegissystem.net

A Data Protection Officer (DPO) has not been appointed as the conditions of Art. 37 GDPR do not apply. For any data protection matter please contact the Controller directly at the addresses above.

You may also lodge a complaint with your competent supervisory authority. A list of EEA authorities is available at edpb.europa.eu.