01
Scope of this policy
This policy describes how Aegis Systems ("Aegis", "we") handles personal information collected through this website and during the course of a professional services engagement. It applies to prospective clients, client personnel, and visitors to this site.
Where an executed master services agreement or data processing agreement addresses a matter covered here, the terms of that agreement prevail.
02
Information we collect
We deliberately minimise collection. Through this website we collect only what is submitted voluntarily through the briefing request form:
- Name, corporate email address, organization and job title
- Stated compute footprint and regulatory operating context
- The free-text description of the challenge you wish assessed
- Technical metadata necessary for abuse prevention: source IP address and submission timestamp
03
What we do not collect
This site does not use advertising cookies, third-party analytics trackers, session replay, behavioural profiling, or cross-site tracking pixels. We do not purchase, append or enrich contact data from third-party data brokers, and we do not sell or rent personal information under any circumstances.
04
Purpose and lawful basis
Information submitted through the briefing form is used solely to assess fit, respond to your enquiry, and — where an engagement proceeds — to administer the contractual relationship. The lawful basis is our legitimate interest in responding to a business enquiry you initiated, and subsequently the performance of a contract.
Technical metadata is processed on the basis of our legitimate interest in maintaining the security and availability of the service.
05
Retention and destruction
Enquiry records are retained for the duration of the qualification process. Where no engagement proceeds, records are purged within 90 days of the last substantive contact.
Engagement records are retained only as long as required to meet professional, contractual and statutory obligations. Client technical data is governed by our zero-data-retention commitment: working copies containing client information are destroyed within 30 days of engagement close, with written attestation issued to the client sponsor.
06
Disclosure to third parties
We do not disclose personal information to third parties except where strictly necessary to deliver the service, and then only under written confidentiality and data protection terms.
We may disclose information where compelled by law, regulation, or valid legal process. Where legally permitted, we will notify the affected party before disclosure.
07
International transfers
Aegis operates from and stores enquiry data within jurisdictions agreed with the client. Where an engagement requires data residency in a specific jurisdiction, that requirement is documented in the statement of work and enforced technically, not by policy alone.
08
Security measures
Transport is encrypted using TLS. All form submissions are validated server-side against a strict schema and rate limited. Access to enquiry records is restricted to practice principals on a need-to-know basis and is logged.
A fuller description of our technical and organizational controls is published in our Security & Confidentiality Disclosures.
09
Your rights
Depending on your jurisdiction you may have rights to access, correct, delete, restrict or port your personal information, and to object to processing. To exercise a right, contact us through the briefing form or your engagement principal.
We will respond within the period required by applicable law. We may need to verify your identity before acting on a request.
10
Changes to this policy
Material changes will be reflected in the effective date above. Clients under an active engagement will be notified in writing of changes that affect the handling of their information.
Questions
Direct questions regarding this document to your engagement principal, or submit a request through the briefing form. This document is provided for informational purposes and does not constitute legal advice.