DWG NO. AEGIS-LEGAL-001 REV. C
PRIVACY POLICY
AEGIS AI Cooperative is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.
DOCUMENT INFO
LAST UPDATED: January 20, 2026 | VERSION: 1.2.0 | COMPLIANCE: GDPR / CCPA
DATA CONTROLLER
KEY FACTS
We do NOT sell your personal information
90-day retention for agent logs
End-to-end encryption in transit
You can request data deletion
1. INFORMATION WE COLLECT
We collect information you provide and data generated automatically:
- -Account Information: Email, name, and authentication credentials when you create an account.
- -Payment Information: Billing details processed through our payment processor (we do not store full card numbers).
- -Usage Data: Features used, timestamps, API calls, and interaction patterns.
- -Device Information: Browser type, operating system, and device identifiers.
- -Agent Interaction Data: Prompts, responses, tool calls, and execution traces for audit and safety.
2. LEGAL BASIS FOR PROCESSING (GDPR)
If you are in the EEA, we process data under these legal bases:
- -Contract Performance: Processing necessary to provide our services.
- -Legitimate Interests: Improving services, security, and fraud prevention.
- -Consent: Where you have given explicit consent (e.g., marketing).
- -Legal Obligation: Compliance with applicable laws.
3. HOW WE USE YOUR INFORMATION
- -Service Provision: Provide, maintain, and improve our services.
- -Transactions: Process payments and send related information.
- -Support: Respond to your questions and support requests.
- -Analytics: Monitor usage patterns to improve experience.
- -Security: Detect, prevent, and address security issues.
4. DATA SHARING
We do not sell your personal information. We may share data with:
- -AI Model Providers: Anthropic, OpenAI, Google for AI request processing.
- -Infrastructure: Cloud hosting, authentication, and analytics.
- -Payment Processors: Secure transaction processing.
- -Legal Requirements: When required by law or court order.
5. DATA RETENTION
- -Account Data: Retained while active, plus 30 days after deletion.
- -Agent Logs: 90 days for audit, then anonymized or deleted.
- -Payment Records: 7 years as required by tax regulations.
- -Usage Analytics: Aggregated and anonymized after 12 months.
6. YOUR RIGHTS (GDPR)
EEA residents have the following rights:
- -Access: Request a copy of your personal data.
- -Rectification: Request correction of inaccurate data.
- -Erasure: Request deletion ("right to be forgotten").
- -Restriction: Request restriction of processing.
- -Portability: Request data in machine-readable format.
- -Object: Object to processing based on legitimate interests.
Contact: [email protected]
7. CALIFORNIA PRIVACY RIGHTS (CCPA)
- -Right to Know: Request disclosure of data collected, used, and shared.
- -Right to Delete: Request deletion of your personal information.
- -Non-Discrimination: We will not discriminate for exercising rights.
Submit requests: [email protected] with subject "CCPA Request"
8. SECURITY
We implement industry-standard security including encryption in transit (TLS) and at rest, access controls, and regular security audits. No method is 100% secure, but we are committed to protecting your data.
9. CONTACT
Email: [email protected]
Subject: Privacy Inquiry