1. Introduction and acceptance
This Privacy Policy ("Policy") describes how AethelLayer ("AethelLayer," "we," "us," or "our") processes personal data when you access our website, apply for programs, subscribe, use our platform, connect integrations, or otherwise interact with us.
BY ACCESSING OR USING OUR SERVICES, SUBMITTING INFORMATION, OR CREATING AN ACCOUNT, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS POLICY AND AGREE TO OUR DATA PRACTICES DESCRIBED HEREIN. IF YOU DO NOT AGREE, DO NOT USE THE SERVICES.
We may update this Policy at any time by posting a revised version on our website. The "Last updated" date will change. CONTINUED USE AFTER CHANGES CONSTITUTES BINDING ACCEPTANCE. Where required by law, we may provide additional notice; failure to provide notice does not limit our right to update this Policy.
This Policy is incorporated into our Terms & Conditions. In conflict, the Terms control regarding limitation of liability, dispute resolution, and indemnification.
2. Data controller and roles
AethelLayer is the data controller for personal data described in this Policy, except where we process personal data solely as a processor on your documented instructions under a separate Data Processing Agreement ("DPA").
When you connect workplace systems, you are typically the controller of employee, candidate, and vendor data; you instruct us to process such data to deliver the Services. You are responsible for lawful basis, notices, and data subject rights for that data.
Contact: privacy@aethellayer.com | [Registered Office Address , update before publication]
3. Information we collect
- Identity and contact: name, work email, phone, company, job title, company size, billing contacts.
- Account and commercial: subscriptions, invoices, contracts, support tickets, pilot applications.
- Technical: IP address, device identifiers, browser, logs, cookies (see Cookie Policy), security telemetry.
- Usage: feature interaction, session metadata, diagnostics, errors, performance metrics.
- Customer content: data synced via integrations you authorize (HR, finance, messaging, documents).
- Inferences: operational scores, risk signals, summaries, and agent outputs derived from permitted inputs.
- Communications: emails, Slack messages, and meeting content where you enable such features.
4. Sources of data
We collect data directly from you, automatically from devices and browsers, from integrated third-party systems you authorize, from your users under your account, and from service providers assisting our operations.
YOU REPRESENT AND WARRANT that any personal data you provide about third parties (employees, candidates, contractors, vendors) is collected lawfully, that required notices and consents have been obtained, and that our processing as described is authorized.
5. How we use personal data
Legal bases (UK/EU): contract performance, legitimate interests (including security, fraud prevention, and service improvement — which may override your objections where permitted), consent, and legal obligation. We may rely on multiple bases simultaneously.
- Provide, operate, maintain, secure, troubleshoot, and improve the Services.
- Authenticate users, prevent fraud, enforce Terms, and protect our rights and users.
- Evaluate applications, process billing, and communicate about your account.
- Generate analytics, benchmarks, and product insights in aggregated or de-identified form.
- Comply with legal obligations and respond to lawful requests from authorities.
- Send service-related notices; marketing only where permitted by law or with consent.
6. AI and automated processing
Our platform uses AI, RAG, and automated agents. Outputs may be inaccurate or incomplete. YOU ARE SOLELY RESPONSIBLE FOR HUMAN REVIEW BEFORE USING OUTPUTS FOR EMPLOYMENT, FINANCIAL, LEGAL, OR COMPLIANCE DECISIONS.
We do not guarantee freedom from bias, error, or hallucination. Automated processing is not solely automated decision-making with legal effect unless you configure it that way — you assume responsibility for such configurations.
Unless expressly agreed in a signed DPA or SOW, we do not use your Customer Content to train generalized models made available to other customers.
We may use anonymized or aggregated usage data to improve reliability and safety of the Services.
8. International transfers
Data may be processed in the United Kingdom, EEA, United States, or other countries where we or subprocessors operate. We implement appropriate safeguards (UK IDTA, EU SCCs, or equivalent) where required by law.
By using the Services and connecting cross-border integrations, you instruct us to transfer and process data as necessary to deliver the Services, including to jurisdictions that may not provide equivalent protection.
9. Retention
We retain personal data only as long as reasonably necessary for the purposes described, including backup, security, legal, accounting, audit, and dispute resolution.
Application data may be retained if you are not accepted. Account data may be retained after termination as required by law or our backup cycles.
Deletion requests are subject to exceptions (legal holds, backup latency, fraud prevention, and ongoing disputes). We are not liable for residual copies in backups beyond commercially reasonable deletion practices.
10. Your rights and limitations
Depending on jurisdiction, you may have rights to access, rectify, erase, restrict, object, portability, and withdraw consent. Submit requests to privacy@aethellayer.com with sufficient identity verification.
WE MAY REFUSE, CHARGE FOR, OR LIMIT REQUESTS that are manifestly unfounded, excessive, repetitive, jeopardize others' privacy, interfere with legal claims, or where we are legally permitted to retain data. We may require corporate authorization for workspace-related requests.
We will respond within timeframes required by law where applicable. Delays do not waive our rights.
You may lodge a complaint with a supervisory authority. We encourage you to contact us first.
11. Security
We implement measures described in our Security Policy. NO METHOD OF TRANSMISSION OR STORAGE IS COMPLETELY SECURE. WE DISCLAIM LIABILITY FOR UNAUTHORIZED ACCESS, DISCLOSURE, OR LOSS BEYOND OUR REASONABLE CONTROL, SUBJECT TO OUR TERMS & CONDITIONS.
12. Your responsibilities and indemnity
You agree to indemnify AethelLayer against claims arising from personal data you submit or cause us to process unlawfully, including failure to provide notices, obtain consents, or honor data subject rights for your users and integrations.
You are responsible for configuring retention, access, and integration scopes appropriately.
13. Children
Services are not directed to individuals under 18. We do not knowingly collect children's data. If discovered, we may delete it without notice. Contact privacy@aethellayer.com.
14. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR LIABILITY ARISING FROM OR RELATED TO THIS POLICY OR PERSONAL DATA PROCESSING IS SUBJECT TO THE DISCLAIMERS, LIABILITY CAPS, AND INDEMNITIES IN OUR TERMS & CONDITIONS. NOTHING HEREIN EXPANDS OUR LIABILITY.
YOUR EXCLUSIVE REMEDY FOR DISSATISFACTION WITH PRIVACY PRACTICES IS TO STOP USING THE SERVICES.
15. Contact
Privacy inquiries: privacy@aethellayer.com. Legal: legal@aethellayer.com. AethelLayer, [Registered Office Address , update before publication].