1. Who we are
AAES stands for Autonomous Agentic Enterprise Systems. It is the governance layer for enterprise AI agents.
The aaes.ai website and its correspondence are operated by the AAES project team pending incorporation of the company ([Legal entity name: to be confirmed on incorporation]; [Registered address: to be confirmed on incorporation]). The operator is responsible for the personal data described in this policy and acts as its controller where applicable data protection law uses that term. This controller statement covers the website and business-correspondence processing described here; where AAES processes personal data on a client's behalf as part of support (section 4), the role depends on the activity and the applicable agreement, and AAES may act as processor for that activity. You can contact us at hello@aaes.ai.
What the website collects
We measure aggregate website traffic (page views, referring sources, and approximate geography) using Google Analytics 4, configured without cookies or client storage: the tag does not set or read cookies, does not store an identifier on your device, and cannot follow you across sessions. Google Analytics 4 does not log or store IP addresses; approximate geography is derived from the connection address transiently and is not retained. Advertising features and personalization are not enabled. We do not use tracking pixels or fingerprinting, and we do not build browsing profiles. Serving pages also involves processing connection information, including an IP address, through hosting infrastructure.
This website is hosted by Render in Singapore. Render processes connection information, including IP address, to serve the site.
When you contact us through the form on this website, the browser posts to /api/contact. We receive the information you send, such as your name, work email address, company, topic, and message contents. An optional ref query value is copied into the email only when it is on an allowlist. Please do not include credentials, sensitive personal information, or client product data in an inquiry.
On the contact form, the connection IP address is also processed to rate-limit submissions. If you email us directly, we receive whatever you include in that message.
How we use your information
We use the contact form and email correspondence to respond to demo requests, evaluation questions, design partner inquiries, and related questions, including privacy requests. We may follow up where it is relevant to that conversation.
We do not sell personal data. We do not share it with advertising networks or data brokers, and we do not use it for advertising profiles.
Contact-form messages are intended for hello@aaes.ai. When email delivery is configured, the form sends the message through Resend. If the form cannot send your message, we do not claim it was delivered. Email hello@aaes.ai directly.
For website and correspondence handling, the recipients and service providers are the AAES project team ([Legal entity name: to be confirmed on incorporation]), Render (website hosting, Singapore region), Google (aggregate website analytics, Google Analytics 4 configured as described in section 2), PrivateEmail, a Namecheap product (mailbox hosting for hello@aaes.ai; mailbox contents are stored under Namecheap's privacy policy), and, when the contact form is configured to send mail, Resend (email delivery). This website handling is separate from client-operated AAES software.
Client-operated product data
AAES is client-operated software. Client data, agent identities, approvals, budgets, and sealed action records live on the client's own infrastructure. There is no hosted service today. Clients operate the cell, so AAES does not receive that traffic. That is not a claim that AAES never sees any data from a client. A planned hosted cell is not offered today. Processor, subprocessor, and DPA terms for a hosted cell would need to be written against its actual data handling before that service is offered. Those terms do not apply now.
Optional support may involve client-authorized transfers of logs, screenshots, attachments, or other diagnostic information to AAES. Before receiving that information, we agree its permitted contents, purpose, access, recipients, security arrangements, and retention or deletion with you. Remove credentials and unnecessary personal data before sending anything. Where AAES processes personal data on a client's behalf as part of support, applicable processing terms are required for that support activity; this is separate from any future hosted service.
Deployment options are a single VM using Docker Compose, Kubernetes using Helm or Terraform, and environments that are air-gapped or on-premises. AAES runs on the client's stack, including Microsoft Entra, Okta, Google Workspace, Slack, HashiCorp Vault, and Splunk.
The client operates the deployment and is responsible for its handling of personal data, including access and retention. If your information is held in a client's AAES deployment, direct requests about that information to the client operating it.
Legal bases and your rights
Where the GDPR or UK GDPR applies, we rely on legitimate interests to respond to business inquiries and maintain relevant correspondence. Those interests are understanding your request and communicating with you, while respecting your privacy rights.
We also rely on legitimate interests for the aggregate, cookieless website measurement described in section 2: it does not identify you, does not store anything on your device, and helps us understand which pages are useful. You can object to it by emailing us, or independently by blocking the googletagmanager.com domain in your browser, which stops the measurement without affecting the site.
Where you ask us to take steps toward a contract with you, processing may instead be necessary for those steps. We may also process information where necessary to comply with a legal obligation, including applicable data protection requirements.
Depending on your location and the applicable law, including the GDPR, UK GDPR, and similar laws, you may have the following rights:
- Access
- Ask whether we hold personal data about you and request a copy.
- Correction
- Ask us to correct information that is inaccurate or incomplete.
- Deletion
- Ask us to delete your personal data where the law provides that right.
- Objection
- Object to processing based on legitimate interests, including further follow up.
You may also have rights to restrict processing and to receive certain data in a portable format, where applicable. These rights are subject to the conditions and exceptions in the relevant law.
To exercise a right, email hello@aaes.ai and tell us what you would like us to do. We may ask for limited information to confirm your identity. We will respond within the period required by applicable law, generally within one month under the GDPR or UK GDPR, and explain any lawful extension.
You also have the right to complain to your local data protection authority. In the United Kingdom, this is the Information Commissioner's Office.
How long we keep correspondence
We keep correspondence only as long as needed for the conversation and legitimate follow up. When it is no longer needed, we delete it from the records we control, including the active mailbox, unless a legal obligation requires us to retain it. Residual copies in provider-held systems are subject to the applicable providers' retention and deletion practices; the schedules we could verify are described below, and we state none where the provider does not publish one.
Contact-form rate-limit data (the connection IP address and submission timestamps) is held in memory by the hosting function to enforce the submission limit (5 messages per 10 minutes per address) and is not persisted by that mechanism. Analytics event data is retained in Google Analytics for 2 months, the minimum available retention setting, and is not linked to an identifiable visitor. Provider retention is documented by the providers themselves where a schedule is published: Render does not publish a fixed retention schedule for service logs, so we state none. Resend retains email content, metadata, delivery status and logs for 30 days on Free, Pro and Scale plans, persists backups for 7 days, and deletes remaining customer data within 90 days of account termination. Mailbox contents at PrivateEmail are held until we delete them; we do not state a PrivateEmail retention period because Namecheap does not publish one for mailboxes.
The AAES project team operates pending incorporation; no corporate place of establishment exists yet ([Place of establishment: to be confirmed on incorporation]). This site and its contact form are hosted on Render in Singapore. Render and Resend are US-based companies, and mailbox contents are held by Namecheap's PrivateEmail; the email portion of correspondence you send us is processed in the United States. Render and Resend document their transfer safeguards: Render is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. DPF) and its Data Processing Addendum incorporates the EU Standard Contractual Clauses and the UK Addendum; Resend is certified under the EU-U.S. Data Privacy Framework and UK Extension, and its pre-signed DPA (in force for every Resend account) incorporates the EU Standard Contractual Clauses (Module Two, or Module Three where we act as a processor), the UK Addendum, and the Swiss modifications. Resend's primary processing and storage is in the United States. Google processes analytics event data in the United States and is certified under the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. DPF. PrivateEmail mailbox contents are processed under Namecheap's Universal Terms of Service and Privacy Policy; we do not name a separate transfer mechanism for Namecheap because we have not verified one. A provider's certification does not by itself establish coverage for every transfer. For ordinary correspondence, the arrangements are those described in this paragraph; for optional support material under section 4, the permitted contents, recipients and arrangements are agreed separately before anything is sent. See Render's privacy policy, Render's data processing addendum, Resend's GDPR overview, and PrivateEmail's privacy policy.
You can ask us to delete your correspondence or stop following up by emailing hello@aaes.ai. These retention practices concern our correspondence, not records held in client-operated deployments.
Changes to this policy
We may update this policy as our practices or legal obligations change. We will publish the revised policy on this page and update the “Last updated” date above. Where applicable law requires additional notice, we will provide it.
This policy describes our current practices. A planned service is not a service available today.
Contact us about privacy
For a question about this policy or a request concerning your personal data, write to hello@aaes.ai.
