This Privacy Notice explains how Aperium AI (“we,” “us,” or “our”) collects, uses, and discloses information about you when you access or use our platform and services (collectively, the “Services”). By using the Services, you acknowledge that you have read and understood this Privacy Notice.
1. Information We Collect
1.1 Information You Provide
When you register for or use the Services, we may collect:
- Name and email address (e.g., when you create an account or authenticate via a third-party service)
- Account credentials and authentication tokens used to connect third-party integrations (e.g., Google OAuth tokens to access Gmail or Google Calendar on your behalf)
- Communications and content you submit through the Services, including queries, configurations, and any data you direct us to process on your behalf
1.2 Information Collected Automatically
When you interact with the Services, we may automatically collect:
- Usage data, including features accessed, actions taken, and session duration
- Log data, including IP address, browser type, device identifiers, and access timestamps
- Cookies and similar tracking technologies (see Section 5 below)
1.3 Information from Third-Party Integrations
If you connect the Services to a third-party platform (such as Google Workspace), we may receive and process data from that platform to provide the Services you request. Your use of third-party services is subject to those services’ own terms and privacy policies.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Services
- To authenticate your identity and manage your account
- To execute tasks you direct us to perform via third-party integrations
- To monitor and analyze usage patterns to improve the Services
- To detect, prevent, and address technical issues, fraud, or security incidents
- To communicate with you regarding your account or the Services, including responding to support inquiries
- To comply with applicable legal obligations
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing personal data are:
- Performance of a contract: Processing necessary to provide the Services you have requested
- Legitimate interests: Provide the Services, security, fraud prevention, and service improvement, where those interests are not overridden by your rights
- Compliance with a legal obligation: Processing required by applicable law
- Consent: Where you have provided consent to specific processing activities (which you may withdraw at any time without affecting prior processing)
4. Disclosure of Your Information
We may share information in the following limited circumstances:
- Service providers: We may engage third-party vendors that process information on our behalf to support the operation of the Services (e.g., cloud hosting, analytics). Such vendors are contractually bound to process data only as instructed and in accordance with applicable privacy law.
- Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction.
- Legal compliance: We may disclose information if required to do so by law, court order, or government authority, or when we believe disclosure is reasonably necessary to protect our rights, your safety, or the safety of others.
5. Cookies and Tracking Technologies
We may use cookies and similar technologies (e.g., local storage, session tokens) to authenticate users, maintain session state, and collect usage analytics. You may control cookie settings through your browser; however, disabling certain cookies may impair functionality of the Services.
6. Data Retention
We retain personal information for as long as necessary to provide the Services and fulfill the purposes described in this Privacy Notice, unless a longer retention period is required by law. When information is no longer needed, we will delete or de-identify it in accordance with our data retention practices.
7. Data Security
We implement reasonable technical and organizational measures designed to protect your information against unauthorized access, disclosure, alteration, or destruction. However, no security system is impenetrable, and we cannot guarantee absolute security.
8. International Data Transfers
The Services are operated from the United States. If you are located outside the United States, please be aware that your information may be transferred to and processed in the United States or other jurisdictions that may not provide the same level of data protection as your home jurisdiction. Where required by applicable law, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) for cross-border transfers of personal data from the EEA, UK, or Switzerland.
9. Your Privacy Rights
9.1 Rights Under GDPR (EEA, UK, Switzerland)
If you are located in the EEA, UK, or Switzerland, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to applicable legal obligations
- Object to or request restriction of certain processing
- Request portability of your data in a structured, machine-readable format
- Lodge a complaint with your local supervisory authority
9.2 Rights Under CCPA/CPRA (California Residents)
California residents have the following rights under the CCPA/CPRA:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which it is used, and the categories of third parties with whom it is shared.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
To exercise any of the rights described above, or any similar rights offered where you are, please contact us using the information in Section 12. We will respond to verifiable requests within the timeframes required by applicable law.
10. Children’s Privacy
The Services are not available to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us and we will take steps to delete it.
11. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. We will indicate the date of the most recent update at the top of this document. We encourage you to review this notice periodically.
12. How to Contact Us
If you have questions about this Privacy Notice or wish to exercise your privacy rights, please contact us at:
Email: legal@aperium.aiIf you are located in the EEA and wish to raise a concern or complaint, you have the right to contact your local data protection supervisory authority.