Privacy Policy
Last updated: June 2026

AegisGrid Privacy Policy

Last updated: June 2026

1. Introduction

AegisGrid is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

2. Data We Collect

  • Account data: Name, email, company, billing address
  • Payment data: Processed by Paystack — we do not store raw card details
  • Usage data: IP addresses, browser info, API logs, node telemetry, event logs
  • Customer data: Telemetry, incidents, and operator data you transmit through the Service
  • Communications: Support emails and messages
  • 3. How We Use Your Data

  • To provide and operate the Service
  • To process payments and send billing communications
  • To send service notifications (downtime, security, policy changes)
  • To respond to support requests
  • To detect fraud and security incidents
  • To improve the platform
  • We do NOT sell your personal information.

    4. Data Sharing

    We share data only with:

  • Paystack — payment processing
  • SendGrid/SMTP provider — transactional email delivery
  • Supabase/Render — infrastructure hosting
  • Legal authorities — when required by law
  • All processors are contractually bound to protect your data.

    5. Data Retention

  • Account data: Duration of account + 30 days post-deletion
  • Billing records: 7 years (legal/tax compliance)
  • Node check-in logs: Auto-purged after 30 days
  • Audit logs: 12 months
  • 6. Security

  • Passwords hashed with scrypt (N=16384, salted)
  • HTTPS/TLS encryption in transit
  • HttpOnly session cookies
  • Rate limiting on all auth endpoints
  • No direct public database access
  • 7. Cookies

    We use only session cookies necessary to maintain your login. No advertising or tracking cookies are used.

    8. Your Rights

    You have the right to access, correct, delete, export, or object to processing of your personal data. Contact p***@a***.io. We respond within 30 days.

    9. GDPR

    EEA users have additional rights under GDPR. Our lawful bases: contract performance, legitimate interests, and legal obligation. Contact p***@a***.io for GDPR requests.

    10. Children

    The Service is not for individuals under 18. We do not knowingly collect data from minors.

    11. Changes

    Material changes notified by email 14 days in advance. Continued use constitutes acceptance.

    12. Contact

    p***@a***.io | s***@a***.io