Legal

Privacy Policy

Last updated: 12 March 2026 · Effective: 12 March 2026 · Controller: AEGIS OS (operated by Ben Carkaxhia)

Plain-language summary: We collect only what we need to run your AI team. We never sell your data. You can delete everything at any time. Under GDPR, you have real rights — and we make them easy to exercise.

1. Who we are and how to reach us

AEGIS OS is an AI Operating System for businesses, operated by Ben Carkaxhia ("we", "us").

Data Controller: Ben Carkaxhia, operating AEGIS OS
Contact: [email protected]
Response time: We aim to respond to all privacy enquiries within 72 hours.

This policy covers the AEGIS OS platform at aegis-agents.work and any related mobile or API access.

2. What data we collect and why

2.1 Account & subscription data

Lawful basis: Contract performance (GDPR Article 6(1)(b)) — necessary to provide the service.

2.2 AI interaction data

Lawful basis: Contract performance — this is the core service you pay for. Your agent conversations are stored in your tenant schema, isolated from other customers.

2.3 Usage & audit data

Lawful basis: Legitimate interests (GDPR Article 6(1)(f)) — fraud prevention, security monitoring, and service improvement.

2.4 Integration credentials

Lawful basis: Contract performance — required to deliver integrations you have enabled.

2.5 Technical & analytics data (with your consent)

Lawful basis: Consent (GDPR Article 6(1)(a)) — only collected if you accept analytics/marketing cookies. You can withdraw consent at any time via our cookie banner.

3. How we use AI to process your data

AEGIS OS is an AI-powered platform. When you interact with your agents:

AI transparency (EU AI Act awareness): AEGIS OS AI agents are decision-support tools. They assist your business processes but do not make final binding decisions. You remain in control of all outcomes.

4. Data retention

Data typeRetention period
Account & subscription dataDuration of account + 90 days after deletion
AI agent conversations (Omni, tasks)Duration of subscription, or until you delete
Audit logs12 months rolling
Integration credentialsUntil you disconnect the integration
Cookie consent records3 years (required for demonstrable consent)
Support chat transcripts90 days
Billing records (Stripe)7 years (tax/legal obligation)

5. Sub-processors and international transfers

We share your data with the following sub-processors solely to deliver the service:

Sub-processorPurposeLocationSafeguard
Groq, Inc.LLM inference (primary AI processing)USASCCs / Groq DPA
Google (Gemini)LLM inference (fallback)USASCCs / Google DPA
Telegram MessengerMessage delivery (if integration enabled)UAE/GlobalUser-consented channel
Twilio (WhatsApp)WhatsApp message delivery (if integration enabled)USASCCs / Twilio DPA
Stripe, Inc.Payment processing & subscription managementUSA/EUSCCs / PCI-DSS
Hetzner OnlineVPS hosting (production infrastructure)Germany (EU)GDPR-native

For transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission.

6. Your rights under GDPR

As a data subject, you have the following rights. We will respond within 30 days (extendable to 3 months for complex requests):

To exercise any right: [email protected] or use our Data Request form.

7. Cookies

Essential cookies (no consent required)

CookiePurposeDuration
sessionAuthentication session — keeps you logged inSession / 24h
aegis-theme-v2Light/dark theme preference1 year (localStorage)
aegis-cookie-consentStores your cookie consent choice1 year

Analytics cookies (consent required)

We do not currently use third-party analytics trackers. If we add them in the future, we will request your consent first via the cookie banner.

Marketing cookies (consent required)

We do not use retargeting or advertising cookies.

8. Security

9. Children's data

AEGIS OS is a B2B platform intended for businesses and professionals. We do not knowingly collect personal data from individuals under 16. If you believe a minor has registered, please contact us immediately.

10. Changes to this policy

We will notify registered users of material changes via email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after the effective date constitutes acceptance.

11. Contact & supervisory authority

For privacy questions: [email protected]

You have the right to lodge a complaint with your national data protection authority. In the EU, you can find your authority at edpb.europa.eu.