Legal
Privacy Policy
What AIONYX SOLUTIONS collects, why, who sees it, how long we keep it, and how to make us delete it.
- Who we are
- Information we collect
- How we use information
- Cookies and your choices
- Legal basis for processing
- Who we share information with
- We do not sell or share your information
- How long we keep it
- How we protect information
- Your rights and how to use them
- US state privacy rights
- International transfers
- Children
- Changes to this policy
- Contact us
Who we are
AIONYX SOLUTIONS (“AIONYX SOLUTIONS”, “we”, “us”) provides AI automation and cyber security services to businesses and public bodies. Our place of business is [full street address], Illinois, USA.
This policy covers the information we handle as a business — visitors to this website, people who contact us, prospective clients and job applicants. It is written in plain language on purpose.
Where we monitor or automate systems for a client, the client decides what personal information those systems hold and why. In that role we act on the client’s written instructions under our services agreement and any data processing agreement, and this policy does not govern that data — the client’s own privacy notice does.
Our privacy contact is [name or role], reachable at contact@aionyxsolutions.com.
Information we collect
We collect four categories, and no more than we need for each:
- Information you give us. Name, work email, phone number, company, job title, approximate company size and whatever you write in an enquiry or assessment request. All of it is optional except the fields marked required on the form.
- Information collected automatically. IP address, browser and device type, operating system, referring page, pages viewed and time on page. Server logs are collected for security and reliability whatever your cookie choice; analytics beyond that runs only if you opt in.
- Client service data. Information inside systems we monitor, secure or automate for a client — including security telemetry and, depending on the engagement, documents the automation reads. Handled strictly under the services agreement, never used to train any model, and never reused for our own purposes.
- Recruitment information. Applications, résumés, work history and interview notes for people who apply to us.
- We do not ask for and do not want sensitive personal information — government ID numbers, financial account numbers, health information, biometric identifiers or precise geolocation — through this website. Please do not include any of it in a contact form.
How we use information
We use personal information to:
- Respond to your enquiry and prepare a proposal or scope of work
- Deliver, support, monitor and improve the services you have engaged us for
- Manage the contract, invoice you and keep our accounting records
- Meet legal, tax and regulatory obligations, and establish or defend legal claims
- Keep this website secure, available and free of abuse
- Understand which pages are useful, if you have opted in to analytics
- Send occasional updates, only if you asked for them — every message has a one-click unsubscribe and we honor it immediately
- Assess job applications
Cookies and your choices
A cookie is a small file this site asks your browser to store. When you first arrive you are asked to choose. Nothing beyond the strictly necessary category is set until you accept it, and declining costs you no functionality on this site.
You can change your mind at any time — use the cookie settings link, which is also in the footer of every page. Your choice is stored on your own device for twelve months and is not sent to us as an identifier.
| Category | What it does | Set without consent? | Typical lifetime |
|---|---|---|---|
| Strictly necessary | Keeps the site working — page delivery, security, load balancing, and remembering your cookie choice itself. | Yes — the site cannot function without these | Session to 12 months |
| Analytics / performance | Counts visits, shows which pages are read and where people leave. Aggregated; we do not use it to identify you. | No — off until you opt in | Up to 13 months |
| Functional | Remembers preferences such as a form part-completed or a region choice, so you do not re-enter them. | No — off until you opt in | Up to 12 months |
| Marketing / advertising | Would let advertising networks build a profile across sites. We do not use this category at all. | Not used | — |
Two further points worth stating plainly. First, we do not run advertising or cross-site tracking cookies, so there is no advertising profile of you to opt out of. Second, your browser’s own controls still apply: you can block or delete cookies in browser settings, and this site respects Global Privacy Control (Sec-GPC) as a valid opt-out signal where the law requires it.
[If you add Google Analytics, a chat widget, a marketing automation pixel or an embedded video player, list each one here with its provider, its purpose and its cookie lifetime, and make sure the consent banner actually gates it.]
Legal basis for processing
US privacy law does not generally require a stated legal basis, but where the EU or UK GDPR applies to a visitor or client we rely on: performance of a contract, for delivering services and responding to enquiries; our legitimate interests in running, securing and marketing the business, balanced against your rights; compliance with a legal obligation; and consent for optional cookies and marketing email, which you can withdraw at any time without affecting anything already done.
Who we share information with
We share personal information only with service providers who process it on our behalf under a written contract that limits them to our instructions. The categories are:
- Website hosting and content delivery
- Email delivery and business productivity (our office suite)
- Customer relationship management and proposal tooling
- Security tooling used to run and monitor client services
- Accounting, invoicing and payment processing
- Professional advisors — lawyers, accountants, insurers — where genuinely needed
- [Maintain the current named list of sub-processors here, or link to it, and update it when you change a provider.]
- We will also disclose information where the law, a court order or a regulator requires it, and in connection with a merger or sale of the business — in which case we will say so on this page before it takes effect.
We do not sell or share your information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California and other US state privacy laws. We have not done so in the preceding twelve months. We do not use personal information to train any AI model, our own or a vendor’s.
Where an AI service is used to deliver work for a client, we use enterprise or private endpoints configured so that inputs and outputs are not retained by the model provider for training. That is a contractual requirement of every engagement, not a preference.
How long we keep it
We keep information only as long as it is doing a job:
- Enquiries that do not become work — [24] months, then deleted
- Client records and contracts — the engagement plus [7] years, to meet contractual, tax and limitation-period obligations
- Security telemetry and logs — per the retention schedule in the relevant services agreement; website server logs [90] days
- Recruitment records — [12] months after a decision, unless you ask us to keep them on file for future roles
- Marketing list — until you unsubscribe, plus a suppression record so we do not contact you again by mistake
How we protect information
We hold ourselves to the controls we sell. In practice that means encryption in transit and at rest, phishing-resistant multi-factor authentication on every account that can reach client data, least-privilege access with periodic review, centralized logging and monitoring, endpoint detection and response, background-checked staff and contractors under written confidentiality terms, annual security training, vendor risk review before onboarding, and tested backups.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your personal information we will notify you and the relevant authorities within the timeframes the law requires — including, where Illinois law applies, notification under the Personal Information Protection Act.
Your rights and how to use them
Wherever you live, you can ask us to:
- Tell you what personal information we hold about you and why
- Give you a copy in a portable format
- Correct anything inaccurate
- Delete it, where we have no overriding legal reason to keep it
- Stop or limit a particular use, including marketing
- Withdraw a consent you previously gave
- To exercise any of these, email contact@aionyxsolutions.com with “Privacy request” in the subject line. We will acknowledge within [10] business days and respond within 45 days, extending once by a further 45 days only if the request is complex — and we will tell you if that happens. We may need to verify your identity, and we will ask for the minimum needed to do it. There is no charge, and using these rights will never affect the service you get from us.
- If we decline a request we will explain why and how to appeal it. You can also complain to your state attorney general, or to your supervisory authority if you are in the EU or UK.
US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Texas and other states with comprehensive privacy laws have the rights listed above, plus the right not to be discriminated against for using them. California residents may also designate an authorized agent to make a request, and may ask for the specific pieces of information collected in the preceding twelve months.
We do not use personal information for profiling that produces legal or similarly significant effects, and we do not process sensitive personal information as those laws define it. [Confirm this remains true if you add new tooling, and check whether your revenue and data volumes bring you within scope of each statute — several have thresholds a small firm may fall below.]
International transfers
We are based in the United States and our providers are primarily US-based, so information you give us is processed in the US. If you are in the EU, UK or another jurisdiction restricting outbound transfers, we rely on standard contractual clauses with a transfer risk assessment. A copy is available on request.
Children
This site and our services are for businesses and public bodies. We do not knowingly collect personal information from anyone under 16, and we have no reason to. If you believe a child has given us information, tell us and we will delete it.
Where we deliver work for a school district or university, student data is handled under the client’s instructions and applicable law, including FERPA and the Illinois Student Online Personal Protection Act, as set out in the engagement contract.
Changes to this policy
We will update this page when our practices change, with a revised date at the bottom. If a change materially affects how we use information you have already given us, we will tell you directly and, where consent is required, ask again rather than assume.
Contact us
Privacy questions, requests and complaints: contact@aionyxsolutions.com, or write to [full postal address]. A person reads that inbox — you will not get an autoresponder and nothing else.
Last updated: 25 July 2026. We will post material changes on this page and, where required, notify you directly.
Your choice about cookies
We use cookies that are strictly necessary to run this site. We would also like to set optional cookies to understand which pages are useful and to remember your preferences — but only if you say yes. Declining changes nothing about how the site works for you. Read our privacy policy.
