1. Who we are
This policy describes how [Legal Entity Name] ("AegisOne", "we", "us") handles personal data. Our registered address is [Registered Address] and our privacy contact is privacy@aegisone.lynxclub.ph.
This policy covers two distinct relationships. When you visit this website, contact us, or request a demonstration, we act as a data controller and decide how your data is used. When you use the AegisOne platform to manage your own estate, you are the controller of the data in your tenancy and we act as your processor. Section 8 sets out how the two differ.
2. Personal data we collect as controller
We collect only what a business enquiry and a hosted service reasonably require:
- Contact details you submit: name, business email address, telephone number, organisation, role and the content of your enquiry.
- Demo request details: estate size, deployment preference and the operational context you choose to share.
- Account data for platform operators: name, email address, role assignment, multi-factor enrolment state and authentication history including login attempt records.
- Technical data: IP address, browser and device characteristics, pages requested and referring URL.
- Communications: correspondence with our sales, support and security teams.
We do not purchase contact lists, and we do not enrich the data you give us with data acquired from brokers.
3. Why we process it, and on what basis
We process personal data for the following purposes, on the legal bases stated:
- To respond to enquiries and provide demonstrations — performance of a contract or steps taken at your request, and our legitimate interest in responding to business enquiries.
- To provide, secure and support the platform — performance of our contract with your organisation.
- To protect accounts and investigate misuse, including retaining authentication and audit records — our legitimate interest in the security of the service, and compliance with legal obligations.
- To improve the service and understand how it is used — our legitimate interest in operating a functioning product, balanced against your privacy expectations.
- To send service and security notices — performance of contract and legal obligation. These are not marketing and cannot be opted out of while an account is active.
- To send marketing communications — consent, or legitimate interest in the case of an existing business relationship. You may withdraw at any time.
4. What the platform collects from managed endpoints
The AegisOne agent collects operational telemetry from the endpoints your organisation enrols: hardware characteristics, installed software inventory, patch position, endpoint health and connectivity history, and records of actions performed by operators against the endpoint.
This telemetry describes machines rather than people, but in most deployments an endpoint is assignable to a named user, and endpoint data is therefore capable of relating to an identifiable individual. It should be treated as personal data.
The agent does not perform continuous keystroke capture, continuous screen recording, browsing-history collection, or covert monitoring of end users. Remote terminal and remote screen sessions are initiated deliberately by an operator, are authorised per session, and are recorded in the action log attributable to that operator.
Where your organisation deploys AegisOne to endpoints used by employees, your organisation is responsible for informing those employees, and for establishing a lawful basis for that monitoring under applicable employment and data protection law.
6. Sharing and subprocessors
We do not sell personal data. We share it only with:
- Subprocessors who help deliver the service, such as hosting, email delivery and error monitoring providers. Each is bound by a written contract imposing confidentiality and security obligations no less protective than those in this policy. A current subprocessor list is available on request.
- Professional advisers, where necessary and under a duty of confidentiality.
- Authorities, where we are legally compelled. We will notify the affected customer unless prohibited from doing so.
- An acquirer, in the event of a merger or sale, subject to this policy continuing to apply.
7. International transfers
Where personal data is transferred outside the jurisdiction in which it was collected, we rely on an adequacy decision where one exists, or otherwise on Standard Contractual Clauses together with a transfer risk assessment. Details of the locations in which data is processed are provided in the architecture overview available on request.
8. Retention
We keep personal data only as long as it serves the purpose it was collected for:
- Enquiry and marketing contact data: [retention period], or until you object.
- Operator account data: for the life of the account, then [retention period] after closure.
- Authentication and audit records: retained for their evidential value, in line with the retention settings configured for your tenancy.
- Endpoint telemetry: in line with the retention settings configured for your tenancy.
- Demonstration environment data: deleted at the end of the demonstration term, as set out in the Demo Terms.
9. Your rights
Subject to the applicable law, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting prior processing.
Write to privacy@aegisone.lynxclub.ph. We will respond within the period the applicable law requires, and within one month where no shorter period applies.
If the data concerns your use of a customer’s AegisOne tenancy — for example, an endpoint issued to you by your employer — that customer is the controller. We will refer your request to them and support them in answering it.
You have the right to complain to your supervisory authority. We would prefer the chance to resolve it first.
10. Security
We maintain technical and organisational measures appropriate to the risk, including transport encryption, role-based access control, multi-factor authentication for operator accounts, rate limiting, and audit logging of privileged actions. Our Security page describes these in detail and is deliberately explicit about controls we have not yet implemented.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and, where required, the relevant supervisory authority, without undue delay.
11. Changes
We will post material changes to this policy on this page and update the revision date. Where a change materially affects how we process your data, we will give notice by email before it takes effect.