Skip to main content
Legal Document

Privacy Policy

AIOXSuite.com – Privacy Policy

Effective date: June 8, 2026 • Last updated: June 8, 2026

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and the rights you have over it.

It applies to all use of the AIOX Suite platform — the aioxsuite.com marketing website, the app.aioxsuite.com customer dashboard, our APIs, the AIOX Suite WordPress plugin, and all related services (collectively, the "Services").

This Privacy Policy is incorporated by reference into our Terms of Service and should be read together with our Cookie Policy and our Subprocessors list.


1. At a glance

  • We are AIOX Suite, operating from Wyoming, USA, with infrastructure hosted in Atlanta, Georgia, USA. We act as a data controller for your customer account and as a data processor for visitor data you collect on your own websites using the AIOX Suite plugin (see §10).
  • We collect: account identity, billing and payment metadata, operational telemetry, content you submit for processing, marketing-attribution cookies, and consent records. We do not collect sensitive personal data unless you explicitly upload it.
  • We do not sell personal data.
  • We share data only with the sub-processors listed in §6 and detailed in our Subprocessors page (Stripe, Meta, Google, AI providers, hosting infrastructure).
  • You have rights under GDPR, UK GDPR, CCPA / CPRA, and equivalent laws (§12).
  • Questions? support@aioxsuite.com

2. Data Controller and Contact

  • Controller: AIOX Suite, Wyoming, USA
  • All inquiries (privacy, data rights, security, general): support@aioxsuite.com
  • Response time: within 30 days of receipt (extended once by 60 days where the request is complex, with notice)
  • EU representative (Art. 27 GDPR): appointed; contact support@aioxsuite.com for current details
  • UK representative (UK GDPR): appointed; contact support@aioxsuite.com for current details

3. Personal Data We Collect

3.1 Account identity

  • Email address
  • Display name and (optionally) first/last name
  • Company name (optional)
  • Hashed password
  • Account creation date, last-login timestamp
  • Connected website domain(s)

3.2 Billing and payment metadata

  • Stripe customer ID (we never store full payment card numbers — these are tokenised by Stripe)
  • Stripe subscription ID, plan, billing period (monthly or annual)
  • Invoice history, amounts, currency, paid-at timestamps
  • Refund history
  • Country and postal code (provided to Stripe for tax / fraud-prevention purposes)

3.3 Operational telemetry

  • API call records: endpoint, timestamp, response code, token consumption
  • App run history: which AIOX Apps you used, inputs, outputs, runtime
  • Help Concierge conversations (stored with your account so context survives reloads)
  • Support tickets and any associated correspondence
  • Authentication telemetry: login IP, user-agent, 2FA tokens, device fingerprint
  • Dashboard activity logs (page views, action timestamps)

3.4 Content you submit

  • URLs, files, text, images, audio, video, and metadata you submit to AIOX Apps
  • Content metadata pulled from your connected websites to generate AIOX Capsules (titles, authorship, dates, taxonomies, content bodies you choose to process)
  • Generated Outputs: Capsules, schemas, audits, scores, classifications, signed manifests

3.5 Marketing-attribution cookies

When you arrive from a paid advertisement on Meta or Google, our server reads any tracking cookies present in your browser at the time of signup and stores their values on your account. Specifically:

  • _ga — Google Analytics visitor ID
  • _fbp — Meta browser ID
  • _fbc — Meta click ID (set when arriving from a Meta ad with an fbclid URL parameter)

These are used for the server-side conversion events described in §9.

3.6 Consent records (legal evidence)

For each consent you provide, we record:

  • The document accepted (Terms of Service, Privacy Policy, EU/UK 14-day right-of-withdrawal waiver, training-data opt-in)
  • The version of the document accepted
  • The timestamp of acceptance
  • Your IP address at the time of acceptance
  • Your user-agent at the time of acceptance
  • The source flow (signup form, dashboard re-consent banner, settings toggle)

These records are retained for the life of your account plus 6 years (the limitation period applicable to consumer-protection claims in most jurisdictions).

3.7 Data we deliberately do NOT collect

  • Full credit card numbers — handled exclusively by Stripe
  • Government identification documents — never requested or stored
  • Health data, biometric data, religious/political affiliation, or other GDPR Article 9 sensitive categories — unless you explicitly upload such material as content to process, in which case you are responsible for the lawful basis
  • Children's data — see §13

4. How We Use Your Data and Our Lawful Bases

Under GDPR Art. 6 and equivalent regimes, every processing operation has a specific purpose and lawful basis.

Purpose Data used Lawful basis
Provide the Services you signed up for Account identity, content submitted, operational telemetry Contract (Art. 6(1)(b))
Process payments and prevent billing fraud Billing metadata, IP at checkout Contract + Legitimate interest (Art. 6(1)(b) and (f))
Send transactional emails (receipts, password resets, dunning notices) Email, account identity, billing state Contract
Send marketing emails (newsletters, product updates) Email, name Consent (Art. 6(1)(a)) — opt-in only, unsubscribe in every email
Measure paid-ad campaigns via Meta and Google conversion APIs Hashed email + name, IP, UA, marketing cookies, transaction value Consent (cookie banner)
Detect abuse, secure the platform, prevent fraud Authentication telemetry, IP, UA Legitimate interest
Improve the Services (anonymous aggregate analytics) Operational telemetry, anonymised Legitimate interest
Train AIOX-owned AI models App runs, anonymised before training use Consent (opt-in, OFF by default) — see §11 of the ToS
Comply with legal obligations (tax records, court orders, regulator requests) Billing, account, operational logs as required Legal obligation (Art. 6(1)(c))
Defend our legal position in disputes All categories as necessary Legitimate interest + Legal claim (Art. 6(1)(f), Art. 9(2)(f))

5. Who Sees Your Data Inside AIOX

Inside AIOX, access to personal data is limited to the smallest set of personnel that need it to perform their role:

  • Engineers debugging operational issues (access is logged and audited)
  • Customer-support staff handling your tickets
  • Billing staff handling refund / dispute / fraud cases
  • Security responders during an active incident

All personnel with data access are bound by confidentiality obligations.

We do not share, lease, sell, or expose your User Content or Generated Outputs to other AIOX customers. Multi-tenant isolation is enforced at both the application and database layers.


6. Sub-Processors and Third-Party Recipients

We use carefully-vetted sub-processors to deliver the Services. Each is bound by a data-processing agreement that meets GDPR Art. 28 requirements. The current list of sub-processors, with role, data shared, and processing location, is maintained at our Subprocessors page and includes:

  • Amazon Web Services, Inc. — application hosting, server infrastructure, storage, backups (Atlanta, Georgia, USA)
  • Amazon Web Services, Inc. (Amazon SES) — transactional email delivery
  • Cloudflare, Inc. — content delivery, DDoS mitigation, DNS resolution (global edge network)
  • Stripe, Inc. — payment processing, billing, subscription management
  • Meta Platforms, Inc. — advertising attribution via the Conversions API
  • Google LLC (Analytics + Measurement Protocol) — analytics and conversion attribution
  • Google LLC (Gemini API) — default AI provider for app processing
  • OpenAI, L.L.C. — optional / alternate AI provider
  • Anthropic, PBC — optional / alternate AI provider
  • Perplexity AI, Inc. — optional / alternate AI provider for Forensics
  • Sentry, Inc. — application monitoring and error reporting
  • CookieYes (Sahaj Software Solutions) — cookie-consent management

EU/UK customers will be notified of new sub-processors with at least 30 days' notice to allow objection.

We do not share data with parties not listed here or on the Subprocessors page, except where required by law (court order, regulator request, subpoena) or where you explicitly authorise the share.


7. International Data Transfers

AIOX servers are located in Atlanta, Georgia, USA (Amazon Web Services US-East region). If you are located in the EU, UK, or another region with data-transfer rules, your personal data is transferred to the United States when you use the Services.

We rely on the following transfer mechanisms:

  • EU–US Data Privacy Framework — for transfers to US sub-processors who are certified under the Framework (currently AWS, Stripe, Meta, Google, OpenAI, Anthropic)
  • UK extension to the EU–US Data Privacy Framework — for transfers from the UK
  • Standard Contractual Clauses (Module 1: Controller-to-Controller; Module 2: Controller-to-Processor) — where the Framework does not apply
  • Supplementary measures: encryption in transit (TLS 1.3), encryption at rest (AES-256), pseudonymisation where feasible, audit logging

A copy of the SCCs in use is available on request.


8. Retention Periods

We retain personal data only for as long as we need it for the purpose for which it was collected, plus any legally-mandated post-purpose retention.

Data category Retention
Account identity Life of account + 30 days deletion cascade, then 90 days encrypted backup retention
Billing and payment metadata 7 years after last transaction (tax law requirement in most jurisdictions)
Operational telemetry (API logs, app run history) 30 days rolling, then aggregated and anonymised
Generated Outputs (Capsules, audits, scores) Life of account; deleted on cancellation per §16 of the ToS
Help Concierge conversations 12 months rolling, then deleted
Marketing-attribution cookie values stored on account Deleted 90 days after subscription event fires, or immediately on opt-out request
Consent records Life of account + 6 years (consumer-protection limitation period)
Bot-traffic logs (customer-side) 30 days default (configurable up to 365 days from the Analytics → Settings → Automatic Cleanup screen); purgeable on demand
Training-tier samples (only if you opted in) Until deletion on request — withdrawn within 30 days of request, subject to backup retention
Transactional email log 90 days for delivery status, then purged
Security incident records As long as required for investigation + 2 years post-resolution

When data is deleted, it is removed from primary systems within 30 days and from encrypted rotation backups within an additional 90 days, at which point all copies are unrecoverable.


9. Marketing Analytics and Server-Side Conversion Tracking

Because this is the area where most modern privacy missteps happen, we describe it in detail.

9.1 What happens at signup

When you visit aioxsuite.com after clicking an advertisement on Meta or Google, those platforms may have set tracking cookies (_ga, _fbp, _fbc) in your browser as described in our Cookie Policy. If you accept the cookie banner and then sign up for an AIOX account, the cookie values present in your browser at that moment are sent to our server and stored as part of your account record.

9.2 What happens at first paid subscription

When you complete a paid subscription, our server fires two conversion events:

To Meta's Conversions API:

  • Event name: Subscribe
  • Deterministic event ID (for deduplication)
  • SHA-256 hash of your email address
  • SHA-256 hash of your display name
  • Your IP address at signup
  • Your user-agent at signup
  • Your _fbp and _fbc cookie values
  • Transaction value, currency, plan identifier

The raw (un-hashed) email and name do not leave our server. SHA-256 hashing is the format Meta requires; Meta re-derives the hash on their side from their own user records to match the event.

To Google's GA4 Measurement Protocol:

  • Event name: purchase
  • Deterministic event ID
  • Anonymous client_id derived from your _ga cookie
  • Transaction value, currency, plan identifier

9.3 Legal basis

For visitors in jurisdictions that require prior consent for advertising cookies (notably the EU, UK, California), we rely on the consent you give through our cookie-consent banner. For visitors in other jurisdictions we rely on our legitimate interest in measuring marketing-campaign performance, balanced against your interest in privacy. You can object at any time.

9.4 How to opt out

  • Click "Consent Preferences" on our website footer and decline marketing cookies. New events will not be sent.
  • Email support@aioxsuite.com and ask us to delete the cookie values stored on your account. We action this within 7 business days.
  • Exercise your statutory right of deletion under §12 — removing the account record removes the stored cookie values along with it.

10. AIOX as a Data Processor for Visitor Data

When you install the AIOX Suite WordPress plugin or activate the Bot Sentinel app on your own website, AIOX receives data about your visitors (notably IP addresses, user-agents, request paths, and bot-classification metadata) so we can classify and rule-handle the traffic.

For that visitor data, you are the data controller and AIOX is the data processor. Specifically:

  • You decide what data to send us by configuring the plugin
  • We process the data only on your instructions, only for the purposes you configured
  • We do not use the visitor data for any other purpose (no resale, no training, no analytics-on-our-side)
  • We act under the Article 28 / UK GDPR data-processor obligations: confidentiality, security, sub-processor disclosure, assistance with your obligations, return-or-delete at end of processing, audit rights

You are responsible for:

  • Disclosing this processing in your own privacy notice on your website
  • Listing AIOX Suite as your data processor
  • Obtaining any consent required in the visitor's jurisdiction
  • Responding to data-subject requests from your visitors (we will assist on request)

A model privacy disclosure for your own site is provided in our Customer Privacy Disclosure template. A standalone Data Processing Agreement (DPA) is available on request — email support@aioxsuite.com.


11. Consent Records

As described in §3.6, we record the timestamp, IP address, user-agent, and document version for each consent you give. This is for legal evidence and is itself a personal-data processing activity.

We retain consent records under "legitimate interest" (defending against potential legal claims) for the life of your account plus 6 years (the typical consumer-protection limitation period).

You can request a copy of your consent records at any time via support@aioxsuite.com.


12. Your Rights

Subject to your jurisdiction's law, you have the rights below. To exercise them, email support@aioxsuite.com; we respond within 30 days (or extended once by 60 days where the request is complex, with notice).

12.1 GDPR / UK GDPR rights (EU/UK customers)

  • Access — receive a copy of the personal data we hold about you (Art. 15)
  • Rectification — correct inaccurate or incomplete data (Art. 16)
  • Erasure ("right to be forgotten") — delete your account and the data associated with it (Art. 17). Cascades through every AIOX data table within 30 days, subject to encrypted backup retention for an additional 90 days, and subject to retention obligations in §8 (e.g. tax records).
  • Restriction — pause certain processing while a dispute is investigated (Art. 18)
  • Portability — receive your Capsules, audit history, and configuration in a structured machine-readable format (JSON) (Art. 20)
  • Object — to legitimate-interest processing and to direct marketing (Art. 21)
  • Withdraw consent — including for cookie-based marketing, training-data opt-in, and the EU/UK 14-day waiver (subject to consequences described in the relevant policy)
  • Lodge a complaint — with your supervisory authority. A list is at edpb.europa.eu. UK customers can complain to the UK ICO.
  • Right not to be subject to automated decision-making — we do not currently make legal or similarly significant decisions about you using automated profiling (Art. 22)

12.2 CCPA / CPRA rights (California residents)

  • Right to know — what categories of personal information we collect, the sources, the purposes, and the categories of third parties we share with
  • Right to access — receive a copy of the personal information we hold about you
  • Right to delete — request deletion of personal information we collected about you
  • Right to correct — request correction of inaccurate personal information
  • Right to opt out of sale or sharing — we do not sell personal information. We do share marketing-attribution data with Meta and Google for cross-context behavioural advertising; you can opt out via the cookie banner or by email.
  • Right to limit use of sensitive personal information — we do not deliberately collect sensitive personal information as defined by CPRA
  • Right to non-discrimination — we will not charge you differently or deny services for exercising your CCPA / CPRA rights

12.3 Other jurisdictions

Residents of other jurisdictions with comprehensive privacy laws (Brazil LGPD, Canada PIPEDA, Australian Privacy Act, Japan APPI, India DPDP Act, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, etc.) have equivalent rights. Email us and we will fulfil the request consistent with your local law.


13. Children's Privacy

The Services are not directed at children. We do not knowingly collect personal information from anyone under 16 (or the local age of digital consent — 13 in the US, 14 in Spain, 16 in Germany, etc.). If you believe a child has provided us with personal information, contact support@aioxsuite.com and we will delete it within 30 days.


14. Security

We protect your data with industry-standard measures:

  • TLS 1.3 in transit, AES-256 at rest
  • Hashed passwords using bcrypt
  • Stripe-tokenised payment data — full card numbers never touch our servers
  • Encrypted database backups
  • API keys encrypted at rest
  • Two-factor authentication available on operator and customer accounts
  • Multi-tenant isolation at the application and database layers
  • Principle of least privilege for personnel access
  • Audit logging on sensitive operations
  • Regular dependency-vulnerability scanning and timely patching

No system is unbreachable. We commit to the breach-notification process below.


15. Breach Notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms:

  • We notify the competent supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33)
  • We notify affected customers without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)
  • The notification includes the nature of the breach, the categories and approximate number of records affected, our response, and the likely consequences
  • We comply with equivalent obligations under UK GDPR, CCPA / CPRA, and other applicable laws

16. Cookies

This Privacy Policy summarises our cookie practices in §9. For the full list of cookies, durations, third-party setters, and consent-management routes, see our Cookie Policy.


17. Do Not Track

The "Do Not Track" browser signal does not have a settled industry-wide meaning. We currently do not respond to DNT signals separately from the explicit choices you make through our cookie banner. We will adopt the Global Privacy Control (GPC) signal where required by law (notably for California residents).


18. Changes to this Privacy Policy

We may update this Privacy Policy periodically. When material changes occur:

  • The "Last updated" date will be revised
  • We will notify active customers via dashboard banner or email at least 30 days before the change takes effect, unless the change is required for legal compliance or security
  • Continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy
  • Where a change materially expands a processing purpose, we will obtain a fresh consent rather than rely on continued use

19. Contact

For any privacy question, request, or complaint:

AIOX Suite
All inquiries (privacy, data rights, security, general): support@aioxsuite.com
Website: https://aioxsuite.com

EU customers may also contact our EU representative (appointed under GDPR Art. 27) via the address above.
UK customers may contact our UK representative (appointed under UK GDPR) via the same address.