Privacy Policy
AIOXSuite.com – Privacy Policy
Effective date: June 8, 2026 • Last updated: June 8, 2026
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and the rights you have over it.
It applies to all use of the AIOX Suite platform — the aioxsuite.com marketing website, the app.aioxsuite.com customer dashboard, our APIs, the AIOX Suite WordPress plugin, and all related services (collectively, the "Services").
This Privacy Policy is incorporated by reference into our Terms of Service and should be read together with our Cookie Policy and our Subprocessors list.
1. At a glance
- We are AIOX Suite, operating from Wyoming, USA, with infrastructure hosted in Atlanta, Georgia, USA. We act as a data controller for your customer account and as a data processor for visitor data you collect on your own websites using the AIOX Suite plugin (see §10).
- We collect: account identity, billing and payment metadata, operational telemetry, content you submit for processing, marketing-attribution cookies, and consent records. We do not collect sensitive personal data unless you explicitly upload it.
- We do not sell personal data.
- We share data only with the sub-processors listed in §6 and detailed in our Subprocessors page (Stripe, Meta, Google, AI providers, hosting infrastructure).
- You have rights under GDPR, UK GDPR, CCPA / CPRA, and equivalent laws (§12).
- Questions? support@aioxsuite.com
2. Data Controller and Contact
- Controller: AIOX Suite, Wyoming, USA
- All inquiries (privacy, data rights, security, general): support@aioxsuite.com
- Response time: within 30 days of receipt (extended once by 60 days where the request is complex, with notice)
- EU representative (Art. 27 GDPR): appointed; contact support@aioxsuite.com for current details
- UK representative (UK GDPR): appointed; contact support@aioxsuite.com for current details
3. Personal Data We Collect
3.1 Account identity
- Email address
- Display name and (optionally) first/last name
- Company name (optional)
- Hashed password
- Account creation date, last-login timestamp
- Connected website domain(s)
3.2 Billing and payment metadata
- Stripe customer ID (we never store full payment card numbers — these are tokenised by Stripe)
- Stripe subscription ID, plan, billing period (monthly or annual)
- Invoice history, amounts, currency, paid-at timestamps
- Refund history
- Country and postal code (provided to Stripe for tax / fraud-prevention purposes)
3.3 Operational telemetry
- API call records: endpoint, timestamp, response code, token consumption
- App run history: which AIOX Apps you used, inputs, outputs, runtime
- Help Concierge conversations (stored with your account so context survives reloads)
- Support tickets and any associated correspondence
- Authentication telemetry: login IP, user-agent, 2FA tokens, device fingerprint
- Dashboard activity logs (page views, action timestamps)
3.4 Content you submit
- URLs, files, text, images, audio, video, and metadata you submit to AIOX Apps
- Content metadata pulled from your connected websites to generate AIOX Capsules (titles, authorship, dates, taxonomies, content bodies you choose to process)
- Generated Outputs: Capsules, schemas, audits, scores, classifications, signed manifests
3.5 Marketing-attribution cookies
When you arrive from a paid advertisement on Meta or Google, our server reads any tracking cookies present in your browser at the time of signup and stores their values on your account. Specifically:
_ga— Google Analytics visitor ID_fbp— Meta browser ID_fbc— Meta click ID (set when arriving from a Meta ad with anfbclidURL parameter)
These are used for the server-side conversion events described in §9.
3.6 Consent records (legal evidence)
For each consent you provide, we record:
- The document accepted (Terms of Service, Privacy Policy, EU/UK 14-day right-of-withdrawal waiver, training-data opt-in)
- The version of the document accepted
- The timestamp of acceptance
- Your IP address at the time of acceptance
- Your user-agent at the time of acceptance
- The source flow (signup form, dashboard re-consent banner, settings toggle)
These records are retained for the life of your account plus 6 years (the limitation period applicable to consumer-protection claims in most jurisdictions).
3.7 Data we deliberately do NOT collect
- Full credit card numbers — handled exclusively by Stripe
- Government identification documents — never requested or stored
- Health data, biometric data, religious/political affiliation, or other GDPR Article 9 sensitive categories — unless you explicitly upload such material as content to process, in which case you are responsible for the lawful basis
- Children's data — see §13
4. How We Use Your Data and Our Lawful Bases
Under GDPR Art. 6 and equivalent regimes, every processing operation has a specific purpose and lawful basis.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Provide the Services you signed up for | Account identity, content submitted, operational telemetry | Contract (Art. 6(1)(b)) |
| Process payments and prevent billing fraud | Billing metadata, IP at checkout | Contract + Legitimate interest (Art. 6(1)(b) and (f)) |
| Send transactional emails (receipts, password resets, dunning notices) | Email, account identity, billing state | Contract |
| Send marketing emails (newsletters, product updates) | Email, name | Consent (Art. 6(1)(a)) — opt-in only, unsubscribe in every email |
| Measure paid-ad campaigns via Meta and Google conversion APIs | Hashed email + name, IP, UA, marketing cookies, transaction value | Consent (cookie banner) |
| Detect abuse, secure the platform, prevent fraud | Authentication telemetry, IP, UA | Legitimate interest |
| Improve the Services (anonymous aggregate analytics) | Operational telemetry, anonymised | Legitimate interest |
| Train AIOX-owned AI models | App runs, anonymised before training use | Consent (opt-in, OFF by default) — see §11 of the ToS |
| Comply with legal obligations (tax records, court orders, regulator requests) | Billing, account, operational logs as required | Legal obligation (Art. 6(1)(c)) |
| Defend our legal position in disputes | All categories as necessary | Legitimate interest + Legal claim (Art. 6(1)(f), Art. 9(2)(f)) |
5. Who Sees Your Data Inside AIOX
Inside AIOX, access to personal data is limited to the smallest set of personnel that need it to perform their role:
- Engineers debugging operational issues (access is logged and audited)
- Customer-support staff handling your tickets
- Billing staff handling refund / dispute / fraud cases
- Security responders during an active incident
All personnel with data access are bound by confidentiality obligations.
We do not share, lease, sell, or expose your User Content or Generated Outputs to other AIOX customers. Multi-tenant isolation is enforced at both the application and database layers.
6. Sub-Processors and Third-Party Recipients
We use carefully-vetted sub-processors to deliver the Services. Each is bound by a data-processing agreement that meets GDPR Art. 28 requirements. The current list of sub-processors, with role, data shared, and processing location, is maintained at our Subprocessors page and includes:
- Amazon Web Services, Inc. — application hosting, server infrastructure, storage, backups (Atlanta, Georgia, USA)
- Amazon Web Services, Inc. (Amazon SES) — transactional email delivery
- Cloudflare, Inc. — content delivery, DDoS mitigation, DNS resolution (global edge network)
- Stripe, Inc. — payment processing, billing, subscription management
- Meta Platforms, Inc. — advertising attribution via the Conversions API
- Google LLC (Analytics + Measurement Protocol) — analytics and conversion attribution
- Google LLC (Gemini API) — default AI provider for app processing
- OpenAI, L.L.C. — optional / alternate AI provider
- Anthropic, PBC — optional / alternate AI provider
- Perplexity AI, Inc. — optional / alternate AI provider for Forensics
- Sentry, Inc. — application monitoring and error reporting
- CookieYes (Sahaj Software Solutions) — cookie-consent management
EU/UK customers will be notified of new sub-processors with at least 30 days' notice to allow objection.
We do not share data with parties not listed here or on the Subprocessors page, except where required by law (court order, regulator request, subpoena) or where you explicitly authorise the share.
7. International Data Transfers
AIOX servers are located in Atlanta, Georgia, USA (Amazon Web Services US-East region). If you are located in the EU, UK, or another region with data-transfer rules, your personal data is transferred to the United States when you use the Services.
We rely on the following transfer mechanisms:
- EU–US Data Privacy Framework — for transfers to US sub-processors who are certified under the Framework (currently AWS, Stripe, Meta, Google, OpenAI, Anthropic)
- UK extension to the EU–US Data Privacy Framework — for transfers from the UK
- Standard Contractual Clauses (Module 1: Controller-to-Controller; Module 2: Controller-to-Processor) — where the Framework does not apply
- Supplementary measures: encryption in transit (TLS 1.3), encryption at rest (AES-256), pseudonymisation where feasible, audit logging
A copy of the SCCs in use is available on request.
8. Retention Periods
We retain personal data only for as long as we need it for the purpose for which it was collected, plus any legally-mandated post-purpose retention.
| Data category | Retention |
|---|---|
| Account identity | Life of account + 30 days deletion cascade, then 90 days encrypted backup retention |
| Billing and payment metadata | 7 years after last transaction (tax law requirement in most jurisdictions) |
| Operational telemetry (API logs, app run history) | 30 days rolling, then aggregated and anonymised |
| Generated Outputs (Capsules, audits, scores) | Life of account; deleted on cancellation per §16 of the ToS |
| Help Concierge conversations | 12 months rolling, then deleted |
| Marketing-attribution cookie values stored on account | Deleted 90 days after subscription event fires, or immediately on opt-out request |
| Consent records | Life of account + 6 years (consumer-protection limitation period) |
| Bot-traffic logs (customer-side) | 30 days default (configurable up to 365 days from the Analytics → Settings → Automatic Cleanup screen); purgeable on demand |
| Training-tier samples (only if you opted in) | Until deletion on request — withdrawn within 30 days of request, subject to backup retention |
| Transactional email log | 90 days for delivery status, then purged |
| Security incident records | As long as required for investigation + 2 years post-resolution |
When data is deleted, it is removed from primary systems within 30 days and from encrypted rotation backups within an additional 90 days, at which point all copies are unrecoverable.
9. Marketing Analytics and Server-Side Conversion Tracking
Because this is the area where most modern privacy missteps happen, we describe it in detail.
9.1 What happens at signup
When you visit aioxsuite.com after clicking an advertisement on Meta or Google, those platforms may have set tracking cookies (_ga, _fbp, _fbc) in your browser as described in our Cookie Policy. If you accept the cookie banner and then sign up for an AIOX account, the cookie values present in your browser at that moment are sent to our server and stored as part of your account record.
9.2 What happens at first paid subscription
When you complete a paid subscription, our server fires two conversion events:
To Meta's Conversions API:
- Event name:
Subscribe - Deterministic event ID (for deduplication)
- SHA-256 hash of your email address
- SHA-256 hash of your display name
- Your IP address at signup
- Your user-agent at signup
- Your
_fbpand_fbccookie values - Transaction value, currency, plan identifier
The raw (un-hashed) email and name do not leave our server. SHA-256 hashing is the format Meta requires; Meta re-derives the hash on their side from their own user records to match the event.
To Google's GA4 Measurement Protocol:
- Event name:
purchase - Deterministic event ID
- Anonymous
client_idderived from your_gacookie - Transaction value, currency, plan identifier
9.3 Legal basis
For visitors in jurisdictions that require prior consent for advertising cookies (notably the EU, UK, California), we rely on the consent you give through our cookie-consent banner. For visitors in other jurisdictions we rely on our legitimate interest in measuring marketing-campaign performance, balanced against your interest in privacy. You can object at any time.
9.4 How to opt out
- Click "Consent Preferences" on our website footer and decline marketing cookies. New events will not be sent.
- Email support@aioxsuite.com and ask us to delete the cookie values stored on your account. We action this within 7 business days.
- Exercise your statutory right of deletion under §12 — removing the account record removes the stored cookie values along with it.
10. AIOX as a Data Processor for Visitor Data
When you install the AIOX Suite WordPress plugin or activate the Bot Sentinel app on your own website, AIOX receives data about your visitors (notably IP addresses, user-agents, request paths, and bot-classification metadata) so we can classify and rule-handle the traffic.
For that visitor data, you are the data controller and AIOX is the data processor. Specifically:
- You decide what data to send us by configuring the plugin
- We process the data only on your instructions, only for the purposes you configured
- We do not use the visitor data for any other purpose (no resale, no training, no analytics-on-our-side)
- We act under the Article 28 / UK GDPR data-processor obligations: confidentiality, security, sub-processor disclosure, assistance with your obligations, return-or-delete at end of processing, audit rights
You are responsible for:
- Disclosing this processing in your own privacy notice on your website
- Listing AIOX Suite as your data processor
- Obtaining any consent required in the visitor's jurisdiction
- Responding to data-subject requests from your visitors (we will assist on request)
A model privacy disclosure for your own site is provided in our Customer Privacy Disclosure template. A standalone Data Processing Agreement (DPA) is available on request — email support@aioxsuite.com.
11. Consent Records
As described in §3.6, we record the timestamp, IP address, user-agent, and document version for each consent you give. This is for legal evidence and is itself a personal-data processing activity.
We retain consent records under "legitimate interest" (defending against potential legal claims) for the life of your account plus 6 years (the typical consumer-protection limitation period).
You can request a copy of your consent records at any time via support@aioxsuite.com.
12. Your Rights
Subject to your jurisdiction's law, you have the rights below. To exercise them, email support@aioxsuite.com; we respond within 30 days (or extended once by 60 days where the request is complex, with notice).
12.1 GDPR / UK GDPR rights (EU/UK customers)
- Access — receive a copy of the personal data we hold about you (Art. 15)
- Rectification — correct inaccurate or incomplete data (Art. 16)
- Erasure ("right to be forgotten") — delete your account and the data associated with it (Art. 17). Cascades through every AIOX data table within 30 days, subject to encrypted backup retention for an additional 90 days, and subject to retention obligations in §8 (e.g. tax records).
- Restriction — pause certain processing while a dispute is investigated (Art. 18)
- Portability — receive your Capsules, audit history, and configuration in a structured machine-readable format (JSON) (Art. 20)
- Object — to legitimate-interest processing and to direct marketing (Art. 21)
- Withdraw consent — including for cookie-based marketing, training-data opt-in, and the EU/UK 14-day waiver (subject to consequences described in the relevant policy)
- Lodge a complaint — with your supervisory authority. A list is at edpb.europa.eu. UK customers can complain to the UK ICO.
- Right not to be subject to automated decision-making — we do not currently make legal or similarly significant decisions about you using automated profiling (Art. 22)
12.2 CCPA / CPRA rights (California residents)
- Right to know — what categories of personal information we collect, the sources, the purposes, and the categories of third parties we share with
- Right to access — receive a copy of the personal information we hold about you
- Right to delete — request deletion of personal information we collected about you
- Right to correct — request correction of inaccurate personal information
- Right to opt out of sale or sharing — we do not sell personal information. We do share marketing-attribution data with Meta and Google for cross-context behavioural advertising; you can opt out via the cookie banner or by email.
- Right to limit use of sensitive personal information — we do not deliberately collect sensitive personal information as defined by CPRA
- Right to non-discrimination — we will not charge you differently or deny services for exercising your CCPA / CPRA rights
12.3 Other jurisdictions
Residents of other jurisdictions with comprehensive privacy laws (Brazil LGPD, Canada PIPEDA, Australian Privacy Act, Japan APPI, India DPDP Act, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, etc.) have equivalent rights. Email us and we will fulfil the request consistent with your local law.
13. Children's Privacy
The Services are not directed at children. We do not knowingly collect personal information from anyone under 16 (or the local age of digital consent — 13 in the US, 14 in Spain, 16 in Germany, etc.). If you believe a child has provided us with personal information, contact support@aioxsuite.com and we will delete it within 30 days.
14. Security
We protect your data with industry-standard measures:
- TLS 1.3 in transit, AES-256 at rest
- Hashed passwords using bcrypt
- Stripe-tokenised payment data — full card numbers never touch our servers
- Encrypted database backups
- API keys encrypted at rest
- Two-factor authentication available on operator and customer accounts
- Multi-tenant isolation at the application and database layers
- Principle of least privilege for personnel access
- Audit logging on sensitive operations
- Regular dependency-vulnerability scanning and timely patching
No system is unbreachable. We commit to the breach-notification process below.
15. Breach Notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms:
- We notify the competent supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33)
- We notify affected customers without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)
- The notification includes the nature of the breach, the categories and approximate number of records affected, our response, and the likely consequences
- We comply with equivalent obligations under UK GDPR, CCPA / CPRA, and other applicable laws
16. Cookies
This Privacy Policy summarises our cookie practices in §9. For the full list of cookies, durations, third-party setters, and consent-management routes, see our Cookie Policy.
17. Do Not Track
The "Do Not Track" browser signal does not have a settled industry-wide meaning. We currently do not respond to DNT signals separately from the explicit choices you make through our cookie banner. We will adopt the Global Privacy Control (GPC) signal where required by law (notably for California residents).
18. Changes to this Privacy Policy
We may update this Privacy Policy periodically. When material changes occur:
- The "Last updated" date will be revised
- We will notify active customers via dashboard banner or email at least 30 days before the change takes effect, unless the change is required for legal compliance or security
- Continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy
- Where a change materially expands a processing purpose, we will obtain a fresh consent rather than rely on continued use
19. Contact
For any privacy question, request, or complaint:
AIOX Suite
All inquiries (privacy, data rights, security, general): support@aioxsuite.com
Website: https://aioxsuite.com
EU customers may also contact our EU representative (appointed under GDPR Art. 27) via the address above.
UK customers may contact our UK representative (appointed under UK GDPR) via the same address.