Privacy Notice

We process account data to run your workspace, and deliberately coarse traffic data that cannot identify your visitors. No advertising, no profiling, no third-party trackers.

Who is responsible

AegiFlow operates the platform described at aegiflow.com. For the account data of the people who sign in to AegiFlow, we act as the controller. For the operational data we process about the web services you ask us to protect, we act as a processor on your instructions — that relationship is set out in the Data Processing Agreement.

Questions about this notice, or any request under the sections below, go to [email protected]. Security reports go to [email protected].

What we collect, and what we deliberately do not

Account data. Your email address, display name, the organization you belong to, your role, and the authentication factors you register (password hash, passkey, TOTP). This is what lets you sign in and what lets us show who approved a sensitive action.

Operational records. For every action taken in the platform — a domain added, a control applied, a rollback executed — we keep who did it, what changed, and when. An audit trail is only useful if it names the actor, so this cannot be switched off.

Traffic measurements. For the web services you protect, the edge writes aggregate counters: a time bucket, a normalized route, a country code, request and error counts, status-code classes, bytes served, and latency histograms.

What that list does not contain is the point. We do not store your visitors’ IP addresses. We do not store query strings, request bodies, headers, cookies, or user agents. We do not store full URLs — only the normalized route pattern. There is no field anywhere in the platform that holds a visitor identifier, because none is collected.

Messages you send us. If you use the contact form, we keep the message and the address you gave us, on our own infrastructure. It is not forwarded to a marketing platform.

What we never do. No advertising. No profiling. No selling or sharing of data. No analytics scripts, no tag managers, no session recording. The public website loads nothing from any third party — you can verify that in your browser’s network panel.

Cookies

The public website sets two cookies, both strictly functional: aegiflow_locale remembers the language you chose, and aegiflow_theme remembers light or dark. Neither identifies you and neither is used for measurement, which is why you are not asked to consent to them.

The dashboard additionally sets a session cookie once you sign in. It is opaque — it carries a reference, not your data — and it is required for the service to work at all.

Why we are allowed to process it

  • Account and operational data — performance of the contract you entered into when you created a workspace (GDPR Art. 6(1)(b)).
  • Audit trail and security measures — our legitimate interest, and yours, in an accountable and defensible platform (Art. 6(1)(f)). Where we act for you as a processor, your own legal basis applies.
  • Messages you send us — your request, ahead of any contract (Art. 6(1)(b)).

We do not rely on consent for anything described here, because nothing described here is optional to the service.

How long we keep it

Data Retained
Account data While the account exists, then 30 days
Audit trail 90 days by default
Event receipts 7 days
Traffic measurements 30 days on the free and starter plans, 90 or 180 days on higher plans
Contact messages 12 months
Backups 14 days locally, encrypted; monthly restore drills

A retention sweep runs every hour rather than as an occasional cleanup, so expiry is a property of the system rather than a promise about it.

Where it is processed

The platform runs on infrastructure we operate in Romania (EU). Traffic reaches it through a global content delivery network, which necessarily terminates connections in the region closest to your visitor; the operational records described above are written and stored in the EU.

Who else is involved

We keep the list short on purpose. The current sub-processors are named in the Data Processing Agreement, together with what each one does and where. We publish changes to that list before they take effect.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or hand it to another provider. You can object to processing we base on legitimate interest. You can withdraw consent wherever we rely on it — though, as above, we do not.

Write to [email protected]. We answer within 30 days. If we get it wrong, you can complain to your national supervisory authority; in Romania that is ANSPDCP.

There is no automated decision-making that produces legal effects about you. Automated controls act on web traffic, never on people, and every one of them is bounded, reversible and recorded.

Security

Identity is self-hosted, with passkeys and step-up verification before sensitive actions. Every row of operational data is scoped to one organization by database-enforced row-level security, and the identity that serves requests holds no bypass rights. Backups are encrypted and restore-tested monthly. Releases are immutable, checksummed, and carry a rehearsed rollback.

If you believe you have found a vulnerability, our disclosure channel is published at /.well-known/security.txt.

Changes

We keep the version and effective date at the top of this page, and we do not backdate. Material changes are announced in the product before they take effect.