1. Introduction
AEGIS SOFTWARE SOLUTIONS LTD ("Aegis", "we", "us" or "Controller"), with registered office at 20 Wenlock Road, London N1 7GU, England, acts as Data Controller and respects the privacy of users of its SaaS platform and related services.
This Privacy Policy transparently describes which personal data we collect, how we use it, who we share it with and which rights you can exercise under Regulation (EU) 2016/679 ("GDPR") and applicable national law.
Effective date: June 4, 2026.
2. Data we collect
We collect only the data necessary to deliver and improve our services. The categories of data processed are:
2.1 Registration data
- Personal data: first name, last name, email address, phone number (optional), login credentials (hashed password).
- Business data: company name, VAT number / tax ID, billing and registered address, tax regime where applicable.
2.2 Platform usage data
- Access logs, IP address, user agent, browser type and version, operating system.
- Pages visited, features used, interaction timestamps, session duration.
- Two-factor authentication (MFA) data, IP allowlist, active sessions.
2.3 AI-generated data
- Content, documents, analyses and outputs produced through the platform's AI modules.
- Prompts, inputs and files uploaded by the user for AI processing.
- Usage metadata (tokens consumed, model used, cost in credits).
Data processed by the AI is not used to train third-party models. See section 5 for the list of providers.
2.4 Payment and billing data
- Payment data is handled entirely by Stripe Payments Europe Ltd (PCI-DSS Level 1). Aegis does not store credit card data.
- Invoice history, amounts, subscriptions, AI credit top-ups, transactions.
3. Purposes of processing
Your data is processed only for the following purposes:
- SaaS service delivery — creating and managing your account, access to the platform, delivery of subscribed modules, storage of your documents.
- Account management and support — responding to assistance requests, support tickets, service communications, credential recovery.
- AI processing — executing requests against the AI models to generate outputs, analyses and documents.
- Service improvement — aggregated and anonymous analytics to identify bugs, optimise performance and develop new features.
- Billing and accounting — invoice issuance, accounting record-keeping, fulfilment of tax obligations.
- Security — fraud and abuse prevention, prevention of unauthorised access, anomaly detection (e.g. account sharing, suspicious logins).
- Legal compliance — responding to lawful requests from judicial or supervisory authorities.
- Marketing — sending promotional communications, newsletters and product updates only with explicit consent, always revocable.
4. Legal basis for processing
Processing is based on the following legal grounds (Art. 6 GDPR):
| Purpose | Legal basis |
|---|---|
| Service delivery | Performance of a contract — Art. 6(1)(b) |
| Billing and tax obligations | Legal obligation — Art. 6(1)(c) |
| Security and fraud prevention | Legitimate interest — Art. 6(1)(f) |
| Marketing and newsletter | Consent — Art. 6(1)(a) |
| Product improvement | Legitimate interest — Art. 6(1)(f) |
6. Data security
We adopt appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration or disclosure (Art. 32 GDPR):
- Encryption in transit — TLS 1.3 on all connections.
- Encryption at rest — AES-256 on databases and storage.
- Authentication — bcrypt password hashing, optional MFA, recovery codes, HIBP check (compromised-password detection).
- Access control — Row Level Security (RLS) at the database level, strict tenant isolation, optional IP allowlist.
- Document watermarks — documents downloaded from the platform include watermarks with the user's identifier and timestamp for traceability.
- Audit log — comprehensive logging of critical operations, available to the admin.
- Backups — automated daily backups with 30-day retention.
- Monitoring — anomaly detection, security alerts, vulnerability management.
7. Data subject rights
As a data subject you have the right, at any time, to exercise the following rights guaranteed by Arts. 15-22 GDPR:
Access (Art. 15)
Obtain confirmation of processing and a copy of your data.
Rectification (Art. 16)
Correct inaccurate or incomplete data.
Erasure (Art. 17)
Request deletion of your data (right to be forgotten).
Restriction (Art. 18)
Restrict processing in specific cases.
Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV).
Object (Art. 21)
Object to processing based on legitimate interest or marketing.
Withdraw consent
Withdraw consent previously given at any time.
Complaint
Lodge a complaint with your competent data protection authority.
How to exercise your rights
- Self-service: open the
Privacysection of your account to autonomously request export or deletion of your data. - Email: write to info@aegissystem.net.
- We respond within 30 days of receiving the request (extendable by 60 days in complex cases).
8. Data retention
We keep your data only as long as necessary for the purposes for which it was collected:
| Category | Period |
|---|---|
| Active account | Duration of the contractual relationship |
| Closed account | 30-day grace period, then deletion/anonymisation |
| Invoices and accounting documents | As required by applicable tax law (typically 6-10 years) |
| Security and audit logs | 12 months |
| Support communications | 24 months after ticket closure |
| Backups | 30 days |
10. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy to reflect regulatory, technological or product changes. In case of material changes we will notify you by email or via a prominent in-platform notice at least 30 days in advance.
The last-updated date is always shown at the top of the document.
11. Contact
Data Controller
AEGIS SOFTWARE SOLUTIONS LTD
20 Wenlock Road, London N1 7GU, England, United Kingdom
Company No. 16640141
General email
info@aegissystem.netPrivacy requests
info@aegissystem.netA Data Protection Officer (DPO) has not been appointed as the conditions of Art. 37 GDPR do not apply. For any data protection matter please contact the Controller directly at the addresses above.
You may also lodge a complaint with your competent supervisory authority. A list of EEA authorities is available at edpb.europa.eu.