Legal document

Privacy Policy

How AethelLayer collects, uses, and protects information. Last updated: August 6, 2026.

Important legal notice: These documents are designed to protect AethelLayer and limit liability to the maximum extent permitted by law. They are not a substitute for advice from qualified legal counsel in your jurisdiction. Have an attorney review before relying on them for regulated industries, enterprise sales, or high-risk use cases.

1. Introduction and acceptance

This Privacy Policy ("Policy") describes how AethelLayer ("AethelLayer," "we," "us," or "our") processes personal data when you access our website, apply for programs, subscribe, use our platform, connect integrations, or otherwise interact with us.

BY ACCESSING OR USING OUR SERVICES, SUBMITTING INFORMATION, OR CREATING AN ACCOUNT, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS POLICY AND AGREE TO OUR DATA PRACTICES DESCRIBED HEREIN. IF YOU DO NOT AGREE, DO NOT USE THE SERVICES.

We may update this Policy at any time by posting a revised version on our website. The "Last updated" date will change. CONTINUED USE AFTER CHANGES CONSTITUTES BINDING ACCEPTANCE. Where required by law, we may provide additional notice; failure to provide notice does not limit our right to update this Policy.

This Policy is incorporated into our Terms & Conditions. In conflict, the Terms control regarding limitation of liability, dispute resolution, and indemnification.

2. Data controller and roles

AethelLayer is the data controller for personal data described in this Policy, except where we process personal data solely as a processor on your documented instructions under a separate Data Processing Agreement ("DPA").

When you connect workplace systems, you are typically the controller of employee, candidate, and vendor data; you instruct us to process such data to deliver the Services. You are responsible for lawful basis, notices, and data subject rights for that data.

Contact: privacy@aethellayer.com | [Registered Office Address , update before publication]

3. Information we collect

  • Identity and contact: name, work email, phone, company, job title, company size, billing contacts.
  • Account and commercial: subscriptions, invoices, contracts, support tickets, pilot applications.
  • Technical: IP address, device identifiers, browser, logs, cookies (see Cookie Policy), security telemetry.
  • Usage: feature interaction, session metadata, diagnostics, errors, performance metrics.
  • Customer content: data synced via integrations you authorize (HR, finance, messaging, documents).
  • Inferences: operational scores, risk signals, summaries, and agent outputs derived from permitted inputs.
  • Communications: emails, Slack messages, and meeting content where you enable such features.

4. Sources of data

We collect data directly from you, automatically from devices and browsers, from integrated third-party systems you authorize, from your users under your account, and from service providers assisting our operations.

YOU REPRESENT AND WARRANT that any personal data you provide about third parties (employees, candidates, contractors, vendors) is collected lawfully, that required notices and consents have been obtained, and that our processing as described is authorized.

5. How we use personal data

Legal bases (UK/EU): contract performance, legitimate interests (including security, fraud prevention, and service improvement — which may override your objections where permitted), consent, and legal obligation. We may rely on multiple bases simultaneously.

  • Provide, operate, maintain, secure, troubleshoot, and improve the Services.
  • Authenticate users, prevent fraud, enforce Terms, and protect our rights and users.
  • Evaluate applications, process billing, and communicate about your account.
  • Generate analytics, benchmarks, and product insights in aggregated or de-identified form.
  • Comply with legal obligations and respond to lawful requests from authorities.
  • Send service-related notices; marketing only where permitted by law or with consent.

6. AI and automated processing

Our platform uses AI, RAG, and automated agents. Outputs may be inaccurate or incomplete. YOU ARE SOLELY RESPONSIBLE FOR HUMAN REVIEW BEFORE USING OUTPUTS FOR EMPLOYMENT, FINANCIAL, LEGAL, OR COMPLIANCE DECISIONS.

We do not guarantee freedom from bias, error, or hallucination. Automated processing is not solely automated decision-making with legal effect unless you configure it that way — you assume responsibility for such configurations.

Unless expressly agreed in a signed DPA or SOW, we do not use your Customer Content to train generalized models made available to other customers.

We may use anonymized or aggregated usage data to improve reliability and safety of the Services.

7. Disclosure of data

WE DO NOT SELL PERSONAL DATA FOR MONEY. We may share aggregated or de-identified information that does not reasonably identify individuals.

  • Subprocessors (hosting, email, analytics, payment, AI infrastructure) under contractual confidentiality and security terms.
  • Professional advisers under confidentiality and privilege where applicable.
  • Authorities when required by law, court order, or to protect vital interests, our rights, or investigate fraud/abuse.
  • Successors in merger, acquisition, financing, or asset sale, subject to this Policy or successor notice.
  • With your direction (e.g., integrations you enable).

8. International transfers

Data may be processed in the United Kingdom, EEA, United States, or other countries where we or subprocessors operate. We implement appropriate safeguards (UK IDTA, EU SCCs, or equivalent) where required by law.

By using the Services and connecting cross-border integrations, you instruct us to transfer and process data as necessary to deliver the Services, including to jurisdictions that may not provide equivalent protection.

9. Retention

We retain personal data only as long as reasonably necessary for the purposes described, including backup, security, legal, accounting, audit, and dispute resolution.

Application data may be retained if you are not accepted. Account data may be retained after termination as required by law or our backup cycles.

Deletion requests are subject to exceptions (legal holds, backup latency, fraud prevention, and ongoing disputes). We are not liable for residual copies in backups beyond commercially reasonable deletion practices.

10. Your rights and limitations

Depending on jurisdiction, you may have rights to access, rectify, erase, restrict, object, portability, and withdraw consent. Submit requests to privacy@aethellayer.com with sufficient identity verification.

WE MAY REFUSE, CHARGE FOR, OR LIMIT REQUESTS that are manifestly unfounded, excessive, repetitive, jeopardize others' privacy, interfere with legal claims, or where we are legally permitted to retain data. We may require corporate authorization for workspace-related requests.

We will respond within timeframes required by law where applicable. Delays do not waive our rights.

You may lodge a complaint with a supervisory authority. We encourage you to contact us first.

11. Security

We implement measures described in our Security Policy. NO METHOD OF TRANSMISSION OR STORAGE IS COMPLETELY SECURE. WE DISCLAIM LIABILITY FOR UNAUTHORIZED ACCESS, DISCLOSURE, OR LOSS BEYOND OUR REASONABLE CONTROL, SUBJECT TO OUR TERMS & CONDITIONS.

12. Your responsibilities and indemnity

You agree to indemnify AethelLayer against claims arising from personal data you submit or cause us to process unlawfully, including failure to provide notices, obtain consents, or honor data subject rights for your users and integrations.

You are responsible for configuring retention, access, and integration scopes appropriately.

13. Children

Services are not directed to individuals under 18. We do not knowingly collect children's data. If discovered, we may delete it without notice. Contact privacy@aethellayer.com.

14. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR LIABILITY ARISING FROM OR RELATED TO THIS POLICY OR PERSONAL DATA PROCESSING IS SUBJECT TO THE DISCLAIMERS, LIABILITY CAPS, AND INDEMNITIES IN OUR TERMS & CONDITIONS. NOTHING HEREIN EXPANDS OUR LIABILITY.

YOUR EXCLUSIVE REMEDY FOR DISSATISFACTION WITH PRIVACY PRACTICES IS TO STOP USING THE SERVICES.

15. Contact

Privacy inquiries: privacy@aethellayer.com. Legal: legal@aethellayer.com. AethelLayer, [Registered Office Address , update before publication].