Skip to content
AIPHINX
Services Approach What we build Industries Engagements About Contact us

Legal

Privacy Policy

Effective 9 September 2026. Applies to aiphinx.com and www.aiphinx.com.

This policy explains what personal data we collect when you use this website or contact us, why we collect it, how long we keep it, and the rights you have over it. We have tried to keep it short and plain. If anything is unclear, email us at contact@aiphinx.com.

On this page

  1. Who we are
  2. The short version
  3. What we collect and why
  4. Our legal grounds
  5. How long we keep data
  6. Who we share data with
  7. International transfers
  8. Cookies and similar technologies
  9. How we protect data
  10. Your rights
  11. Children
  12. Automated decisions
  13. Changes to this policy
  14. Contact and complaints

1. Who we are

This website is operated by AIphinx LLC ("AIPHINX", "we", "us"), a limited liability company organised under the laws of the State of New Mexico, United States (New Mexico Secretary of State entity ID 0008127625), with its principal place of business at 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States. We are the controller of the personal data described in this policy, which means we decide why and how it is processed.

We have not appointed a data protection officer because the scale of our processing does not require one. Questions about personal data go to contact@aiphinx.com. Put "Privacy" in the subject line so it reaches the right person quickly.

2. The short version

  • We collect personal data in one place only: the contact form and any email you send us. We use it to reply to you.
  • We do not run analytics, advertising, session recording or social media trackers on this site. The public pages set no cookies.
  • We do not sell personal data, and we do not use it for marketing you did not ask for.
  • Your enquiry is stored on our own infrastructure, not in a third-party marketing tool.
  • You can ask us at any time to show you, correct or delete what we hold about you.

3. What we collect and why

3.1 When you send an enquiry

The contact form asks for your full name, work email address, company, the area you are interested in, and a free-text message. All of these except the area of interest are required, because we cannot reply to an enquiry without knowing who sent it and what it is about. If you would rather not use the form, you can email us directly instead.

When the form is submitted, our server also records the date and time, the internet protocol (IP) address the message came from, and the browser identification string (user agent) your browser sends with every request. We keep these alongside the message so that we can recognise and block spam or abuse of the form.

Please do not include sensitive personal data in your message, such as health information or details about other identifiable people, unless it is genuinely needed to describe your enquiry. If a later engagement requires such data, it will be covered by a separate written data processing agreement.

Data collected through the contact form
DataWhy we need itRequired
Full nameTo address you correctly when we replyYes
Work email addressTo reply to youYes
CompanyTo understand who you represent and prepare a useful replyYes
Area of interestTo route the enquiry to the right engineerNo
MessageTo understand what you needYes
IP address, browser user agent, timestampSpam and abuse prevention; security investigationsCollected automatically

3.2 When you email us

If you write to contact@aiphinx.com, we keep the email and our reply in our mailbox for as long as described in section 5. We use it only to deal with your enquiry and any engagement that follows.

3.3 When you browse the site

Like almost every website, our web server writes a log entry for each request. A log entry contains your IP address, the page or file requested, the date and time, the referring page if your browser sends one, and your browser user agent. We use these logs to keep the site running, to diagnose faults, to rate-limit abusive traffic, and to investigate security incidents. We do not use them to build profiles of visitors.

The site also loads its typefaces (Sora and Inter) from Google Fonts. To do that, your browser sends a request to Google's servers, and that request includes your IP address. Google states that it does not use Google Fonts requests to set cookies or to track users across sites. See section 7 for what this means for international transfers.

3.4 What we do not collect

We do not use analytics tools, advertising pixels, heat maps, session replay, chat widgets, or social media buttons on this site. There are no third-party scripts on the public pages. We do not collect precise location data, and we do not attempt to identify you from your browsing.

4. Our legal grounds

Where the EU or UK General Data Protection Regulation (GDPR) applies, we need a legal ground for each use of personal data. These are ours:

Purposes and legal grounds
PurposeLegal ground
Replying to your enquiry, scoping a possible engagement, preparing a proposalSteps taken at your request before entering into a contract (Article 6(1)(b))
Recording IP address and user agent with a submission; keeping server logs; rate limitingOur legitimate interest in keeping the site and the enquiry form secure and free of spam (Article 6(1)(f), Recital 49)
Loading typefaces from Google FontsOur legitimate interest in displaying the site consistently across devices (Article 6(1)(f))
Keeping records we are required to keep, or responding to a lawful request from an authorityCompliance with a legal obligation (Article 6(1)(c))
Establishing, exercising or defending legal claimsOur legitimate interest in protecting our legal position (Article 6(1)(f))

Where we rely on legitimate interests, we have checked that the processing is limited to what is needed and that it does not override your interests. You can object to it at any time (see section 10). We do not rely on consent for anything on this site, so there is nothing to withdraw; if that ever changes, we will ask you clearly and separately.

5. How long we keep data

Retention periods
DataHow longWhy
Contact form enquiries and email correspondence that do not lead to an engagementUp to 24 months from our last exchange with you, then deletedLong enough to follow up a conversation that resumes after a pause
Enquiries and correspondence that lead to an engagementFor the life of the engagement and for 6 years after it endsContract records and the limitation period for legal claims
IP address and user agent stored with a submissionDeleted with the enquiry, or earlier once no longer needed for abuse preventionSecurity
Web server logsUp to 30 daysFault diagnosis and security
Backups of the enquiry databaseRotated so that no backup is older than 90 daysRecovery from data loss

If you ask us to delete your enquiry, we remove it from the live database straight away. It may persist in a backup until that backup is rotated out, but backups are not used for any other purpose.

6. Who we share data with

We do not sell personal data, and we do not share it with anyone for their own marketing. We share it only with:

  • Our hosting provider, a cloud infrastructure company headquartered in the European Union, which runs the servers where this site and the enquiry database live. It processes data only on our instructions under a written data processing agreement. We will tell you which company it is if you ask.
  • Google LLC, which receives your IP address when your browser loads typefaces from Google Fonts, as described in section 3.3.
  • Zoho Corporation, which provides the Zoho Mail service that handles email sent to and from contact@aiphinx.com.
  • Professional advisers, such as lawyers, accountants or insurers, where needed to run the business or defend a claim.
  • Courts, regulators or law enforcement, where the law requires it or where we need to protect our rights.

Enquiries are stored in a private database on infrastructure we control and are read by AIPHINX staff through a password-protected dashboard. They are not loaded into a customer relationship management system or a marketing platform.

7. International transfers

Our servers are run by a cloud infrastructure company headquartered in the European Union. We are a United States company, and our staff access the enquiry database from the United States. If you contact us from the European Economic Area, the United Kingdom or Switzerland, the details you send are therefore accessible from, and may be transferred to, the United States, which those jurisdictions do not treat as providing equivalent protection by default.

We rely on the following grounds for that transfer. First, sending us an enquiry is a step you take at your own request towards a possible contract, which is a recognised derogation for occasional transfers (GDPR Article 49(1)(b)). Second, where an engagement follows, the transfer is covered by standard contractual clauses approved by the European Commission, together with the UK addendum where relevant, which we include in our engagement agreements. We apply the technical and organisational measures in section 9 to all data we hold regardless of where it came from.

Google Fonts requests may be answered by Google servers outside the EEA and the UK. Google LLC is certified under the EU-US Data Privacy Framework and its UK extension, which the European Commission and the UK government have recognised as providing adequate protection. You can obtain a copy of the safeguards we rely on by contacting us.

8. Cookies and similar technologies

The public pages of this website do not set any cookies, and they do not store anything in your browser's local storage. That is why you do not see a cookie banner: there is nothing to consent to.

One cookie exists on the site, and it is used only by AIPHINX staff who sign in to the enquiry dashboard. It is listed here for completeness:

Cookies set by this site
NameSet whenPurposeLifetimeType
aiphinx_adminA staff member signs in to the enquiry dashboardKeeps the staff member signed in and protects the dashboard against cross-site request forgeryUntil the browser is closedStrictly necessary, first party

This cookie is strictly necessary for the sign-in service the staff member has requested, so it is exempt from the consent requirement in Article 5(3) of the ePrivacy Directive. It is never set for ordinary visitors.

If we ever add analytics or other non-essential technologies, we will update this policy first and ask for your consent before setting anything.

9. How we protect data

We are an engineering firm and we apply the same discipline to our own site that we recommend to clients. Measures in place include:

  • All traffic between your browser and the site is encrypted with TLS.
  • The enquiry database sits on a private network. Only the web server can reach it, and it is not exposed to the internet.
  • The staff dashboard requires a username and password, uses a session cookie that cannot be read by scripts, and protects state-changing actions against cross-site request forgery.
  • Sign-in attempts and form submissions are rate-limited per IP address to slow down brute-force and spam attempts.
  • The site ships a strict Content Security Policy. Only our own scripts run, and the only external resources permitted are the typefaces described above.
  • We collect the minimum data needed for the enquiry, and we delete it when the periods in section 5 expire.
  • Deployment secrets are kept outside the code and container images.

No system is perfectly secure. If we discover a breach that is likely to put your rights at risk, we will tell you and the relevant supervisory authority without undue delay, as the law requires.

10. Your rights

Under the GDPR and similar laws you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Correct data that is inaccurate or incomplete.
  • Delete your data, for example if you no longer want us to keep your enquiry.
  • Restrict how we use your data while a dispute about it is resolved.
  • Object to processing that we base on legitimate interests. We will stop unless we can show compelling grounds to continue.
  • Port the data you gave us to another provider, in a common machine-readable format, where we process it to take steps towards a contract.
  • Complain to a supervisory authority (see section 14).

To exercise any of these rights, email contact@aiphinx.com with "Privacy" in the subject line. We will respond within one month. If a request is complex we may need up to two further months, and we will tell you within the first month if so. Requests are free of charge. If we cannot match your request to data we hold, we may ask for enough information to confirm who you are; we will not ask for more than we need.

Providing personal data through this site is entirely voluntary. The only consequence of not providing it is that we cannot reply to you.

If you are in California or another US state with a consumer privacy law, note that we do not sell or share personal information for cross-context behavioural advertising, and we do not process sensitive personal information beyond what you choose to write in your message. The access, correction and deletion rights above are available to you in the same way.

11. Children

This site is aimed at organisations and the people who work for them. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.

12. Automated decisions

We do not make decisions about you based solely on automated processing, and we do not profile visitors. The only automation applied to your data is a spam filter on the contact form. A human reads every genuine enquiry.

13. Changes to this policy

We will update this policy when the site changes in a way that affects personal data, for example if we add a new tool or start using a new provider. The effective date at the top always shows the current version. If a change is significant and we hold your contact details, we will let you know by email.

14. Contact and complaints

Questions, requests and complaints about personal data: contact@aiphinx.com, or by post to AIphinx LLC, 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States.

If you are not satisfied with our response and you are in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with the data protection authority in the country where you live or work. In the United Kingdom that is the Information Commissioner's Office (ico.org.uk). The European Data Protection Board publishes a list of EU authorities at edpb.europa.eu. We are established in the United States and do not have a lead supervisory authority in the EU.

AIPHINX

AI services and consulting for organisations that need working systems.

Services

  • AI strategy
  • Generative AI
  • Data engineering
  • Computer vision
  • Governance
  • Managed operations

Company

  • About
  • Approach
  • What we build
  • Engagements
  • Contact

Get in touch

  • contact@aiphinx.com

© 2026 AIPHINX. All rights reserved.

Privacy · Terms · Security