This Privacy Policy explains what information AetherGuard Technologies
("we," "us") collects through the client portal at client.aetherguard.xyz
(the "Portal"), why we collect it, and the choices and rights you have. It
covers the Portal specifically; our public marketing site at aetherguard.xyz
may collect information differently and is covered by its own notices.
1. Information we collect
Account and contact information
Your name, work email address, job title, and the company you're
associated with, provided when your account is created or when you update
your profile.
An optional profile photo, if you choose to add one.
Authentication and security data
Sign-in is passwordless: we generate a single-use, time-limited link and
email it to your work address. We log when links are requested and used,
the requesting IP address, and basic device/browser information, to detect
abuse and secure your account.
Session cookies (see Section 5) and CSRF tokens needed to keep you
signed in and to protect actions you take in the Portal from being
forged by another site.
An audit trail of security-relevant account actions (sign-ins, billing
changes, profile changes) for fraud detection and accountability.
Support and engagement content
The content of support tickets, chat messages, and any files or images
you attach to them.
Records related to engagements we perform for your organization:
reports, notes, and status updates we or your account team create.
Billing information
Card numbers and other sensitive payment details are collected and
stored directly by Stripe, Inc., our payment processor,
which is certified PCI DSS Level 1 compliant. Card data is entered
directly into Stripe's hosted form and never passes through or is stored
on AetherGuard's own servers.
We retain a Stripe customer reference ID and non-sensitive billing
metadata (invoice amounts, dates, order descriptions, and the last four
digits/brand of a card as reported back by Stripe) needed for
bookkeeping and customer support.
2. How we use this information
To provide, operate, and secure the Portal and the Services you've
purchased.
To respond to support requests and communicate about your account,
orders, and engagements.
To process payments and maintain accurate financial and tax records.
To detect, investigate, and prevent fraud, abuse, and security
incidents affecting you, other clients, or AetherGuard.
To comply with legal obligations, including recordkeeping requirements
tied to billing and, where applicable, security engagements.
We do not sell personal information, and we do not use ticket or
engagement content to serve advertising.
3. Who we share it with
Stripe, Inc.: payment processing, as described above.
Infrastructure and hosting providers who host the
Portal and its database, under contractual confidentiality obligations.
Law enforcement or regulators, only where required by a
valid legal process, or to protect the rights, property, or safety of
AetherGuard, our clients, or others.
A successor entity, in the event of a merger, acquisition, or sale of
assets, subject to the same or materially equivalent privacy
commitments.
We do not share ticket content, attachments, or engagement data with any
other client. Access within AetherGuard is limited to employees who need it
to do their job, and is logged.
4. Data retention
We keep account and ticket data for as long as your account is active,
and for a reasonable period afterward to answer follow-up questions, resolve
disputes, and meet legal and accounting obligations. Billing records in
particular are generally retained for the period required by applicable tax
law (commonly several years) even after an account closes. You can request
deletion of data we are not otherwise required to keep, as described in
Section 6.
5. Cookies and local storage
The Portal uses a small number of strictly necessary cookies and one
local-storage value, and nothing else:
Session cookie: keeps you signed in. Marked
HttpOnly, Secure, and SameSite=Strict,
meaning it cannot be read by page scripts and is never sent to any other
site.
CSRF token: a per-session value that protects
form submissions from being forged by another website; not used for
tracking.
Theme preference: whether you're using light or dark
mode, saved in your browser's local storage, never transmitted to us.
These are all functionally required for the Portal to work and are not
used for advertising, cross-site tracking, or analytics profiling, so no
cookie consent banner is presented.
6. Your rights and choices
Depending on where you're located, you may have rights to access,
correct, export, or delete your personal information, or to object to or
restrict certain processing (for example, under the EU/UK GDPR or the
California Consumer Privacy Act). To exercise any of these rights, open a
support ticket in the Portal or email us at the address in Section 8. We'll
verify your identity before acting on a request and respond within the time
required by applicable law. Some information, such as billing records tied
to legal retention requirements, may not be eligible for deletion until
that period has passed.
7. Data security
We use encryption in transit (TLS) for all Portal traffic, role-based
access controls, and security logging across the systems that store your
data, and we treat our own infrastructure with the same rigor we recommend
to clients. No method of transmission or storage is perfectly secure; if we
become aware of a breach affecting your data, we will notify you as
required by applicable law.
8. Contact
Questions about this policy, or requests to exercise your privacy
rights, can be sent through a support ticket in the Portal, or to
support@aetherguard.xyz.
9. Changes to this policy
We may update this policy from time to time. Material changes will be
reflected by updating the date at the top of this page.