Privacy Policy
1. Data Controller
The data controller responsible for your personal information is Sheldon K. Salmon, operating as AionSystem, located in Evans Mills, New York, USA. Contact email: aionsystem@outlook.com.
2. California Notice at Collection
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), we are required to inform you at or before the point of collection of the categories of personal information we collect and the purposes for which they will be used. We collect your name, email address, company, and any document details you provide solely to respond to your inquiry and deliver requested services. We do not sell or share your personal information for cross-context behavioral advertising.
3. Information We Collect
Website Visitors
This website does not use cookies, surveillance trackers, or third‑party advertising networks. We do not automatically collect personal data from visitors.
Contact Forms & Email
If you submit a form or send an email, we collect the information you provide, including your name, email address, company, and any details about your document or inquiry.
Client Documents
Documents submitted for review are treated as strictly confidential artifacts. They are used solely for the purpose of delivering the requested diagnostic services. Client documents are never used to train any AI model, and never shared with third parties except as strictly necessary to execute the diagnostic pipeline.
4. Lawful Basis for Processing (GDPR / UK GDPR)
We process personal data under the following lawful bases:
- Consent: When you voluntarily provide information via forms or email.
- Contract Performance: When processing is necessary to deliver requested services.
- Legitimate Interests: To respond to inquiries, maintain records, and protect our legal rights.
5. How We Use Your Information
- To respond to inquiries and provide requested services.
- To perform document red‑team analysis and deliver findings.
- To maintain records for legal and business purposes.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell, rent, or syndicate personal information or client artifacts. Data is processed strictly for diagnostic execution. No telemetry is monetized or used for cross-context behavioral modeling.
6. Data Sharing & Sub‑processors
We share information with trusted third parties only as strictly necessary to provide services:
- Stripe — Payment processing. Stripe's privacy policy applies to payment data.
- Microsoft Outlook — Email communication and document transmission.
- GitHub Pages — Static website hosting (does not process client documents).
- AI Instrument Providers — The AION diagnostic engine utilizes AI as a core instrument. Where cloud-based inference is required, zero-retention enterprise API endpoints are used. Your document is processed in ephemeral memory and is never stored, logged, or used for model training by the provider. If your security requirements mandate strictly local, air-gapped processing, this must be negotiated as a custom scope before engagement.
7. International Data Transfers
We are based in the United States. If you are located outside the U.S., your data may be transferred to and processed in the U.S. We rely on appropriate safeguards, such as Standard Contractual Clauses, where required by applicable law.
Data localization: We do not maintain separate international data centers. Your data may be processed in the United States regardless of your location.
8. Data Retention & Archival
We retain personal information and artifacts only as long as necessary:
- Inquiry data: Up to 12 months after last contact, unless engagement begins.
- Client engagement records (financials): 7 years (tax/legal requirements) after completion.
- Raw Client Documents: Cryptographically shredded or permanently deleted 30 days after final delivery, or immediately upon written request, unless legal retention applies.
- Diagnostic Deliverables: The final structural report is archived in a sealed, unalterable state strictly for professional liability defense and record-keeping, as governed by the Terms of Service (§35).
9. Security Measures
We implement appropriate technical and organizational measures, including:
- Encryption in transit and at rest where feasible.
- Access controls limited to authorized individuals.
- Regular review of security practices.
However, no method of electronic transmission or storage is 100% secure.
10. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you within 72 hours where required by applicable law (e.g., GDPR). For jurisdictions without a specific timeframe, we will notify you without undue delay.
11. Your Privacy Rights — Global
The table below summarizes rights that may apply depending on your location. To exercise any right, contact aionsystem@outlook.com.
| Jurisdiction | Key Rights |
|---|---|
| European Union (GDPR) / UK (UK GDPR) | Access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge complaint |
| California (CCPA/CPRA) | Know, delete, opt‑out of sale (we do not sell), non‑discrimination, correct |
| Brazil (LGPD) | Similar to GDPR; confirmation, access, correction, anonymization, portability, deletion, information about sharing |
| China (PIPL) | Access, copy, correction, deletion, withdraw consent, restrict processing |
| Canada (PIPEDA) | Access, correction, withdrawal of consent |
| Australia (Privacy Act) | Access, correction |
| South Africa (POPIA) | Access, correction, deletion, objection |
| Japan (APPI) | Access, correction, deletion, opt‑out of direct marketing |
| Singapore (PDPA) | Access, correction, withdrawal of consent |
| US States (Virginia, Colorado, Connecticut, Utah, Nevada) | Similar to CCPA rights; may include opt‑out of targeted advertising |
12. Data Subject Access Request (DSAR) Procedure
To submit a request:
- Email aionsystem@outlook.com with "Privacy Request" in the subject line.
- We may ask for identity verification to protect your data.
- We will respond within 30 days (or the timeframe required by your jurisdiction).
13. Children's Privacy
Our services are not directed to individuals under 18 years of age. For EU/UK users, we do not process data of children under 16 without parental consent. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us immediately.
14. Do Not Track Signals
We honor "Do Not Track" signals from your browser. We do not track your activity across third‑party websites.
15. Automated Decision Making
We do not use solely automated decision‑making or profiling that produces legal or similarly significant effects. The AION diagnostic pipeline utilizes AI to generate topological telemetry and failure-node mappings. However, all final dispositions, severity ratings, and resolution architectures are exclusively determined by the human analyst. The AI is an instrument; the human is the authority.
16. Cookie Policy
We do not use cookies, web beacons, or similar tracking technologies on this website. If that changes, we will update this policy and provide a consent mechanism where required.
17. Data Processing Addendum (DPA)
For clients who require a formal Data Processing Addendum (DPA) under GDPR or other privacy laws, client-provided DPAs will undergo structural red-teaming prior to execution. Asymmetrical or unenforceable clauses will be rejected. I do not maintain a pre-approved enterprise DPA template.
18. Sovereign Privacy Boundaries
I am a solo practitioner. I do not maintain formal Data Protection Impact Assessment (DPIA) documents, an enterprise privacy team, or a Data Protection Officer. My privacy model relies on extreme data minimalism and local processing, not compliance bureaucracy. If your vendor onboarding requires formal DPIA artifacts or detailed enterprise sub-processor audits, this engagement is not a fit.
19. Data Flow Summary
Personal data flows as follows: (1) Collection via email or form; (2) Processing by AionSystem (Sheldon K. Salmon) in the United States; (3) Limited sharing with sub‑processors (Stripe for payments, Microsoft Outlook for email, zero-retention AI APIs for inference); (4) Storage on secured local systems; (5) Deletion after retention period. No data is sold or used for advertising.
20. EU / UK Representative
AionSystem is a sole proprietorship based in the United States. I accept global clients but do not maintain a designated EU/UK representative under GDPR Article 27. If your compliance framework mandates an EU-based representative, this engagement is not a fit.
21. Structural Integrity of this Policy
Privacy by Adversarial Design
Our privacy practices are red‑teamed against the same adversarial frameworks we use on client documents. We test our own policy for loopholes before publishing it.
Client Document Immunity
Client documents are treated as privileged work product. They are never used for marketing, case studies, or AI training without explicit written consent.
Public Accountability
This policy is a public document. If you identify a structural seam or exploit path in this policy, transmit it via the contact protocol. Valid structural findings are patched; no bounties or public credits are issued.
Data Minimalism by Default
We collect only what is necessary to deliver the requested service. If we don't need it, we don't ask for it.
22. Third‑Party Links
This website contains links to external sites (GitHub, LinkedIn). We are not responsible for their privacy practices. Please review their policies before providing personal data.
23. Governing Law & Cross‑Reference
This Privacy Policy is governed by the laws of the State of New York, USA. For dispute resolution and other legal terms, please see our Terms of Service.
24. Version History
- v1.2 — September 10, 2026: Closed archival contradiction with Terms §35. Clarified GDPR Art. 22 AI telemetry boundaries. Stripped B2C manifesto language. Aligned pricing floor.
- v1.1 — September 10, 2026: Stripped enterprise compliance theater. Clarified AI sub-processor data handling. Aligned sovereign boundaries with Terms and FAQ.
- v1.0 — September 3, 2026: Initial privacy policy published.
End of Privacy Policy
Questions? Contact aionsystem@outlook.com