Privacy Policy
Effective Date: May 1, 2026 · Last Updated: May 1, 2026
Table of Contents
- Scope and Applicability
- Definitions
- Information We Collect
- Legal Basis for Processing
- How We Use Your Information
- Data Sharing and Disclosure
- Data Ownership and Customer Control
- Data Security and Technical Safeguards
- Entity-Level Data Segregation
- Audit Logging and Immutable Records
- AI and Automated Processing
- Data Retention and Deletion
- International Data Transfers
- Your Privacy Rights
- California Privacy Rights (CCPA/CPRA)
- European Privacy Rights (GDPR)
- Children's Privacy
- Cookies and Tracking Technologies
- Third-Party Services
- Delaware Governing Law
- Changes to This Policy
- Contact and Data Protection Inquiries
AegisIQ Stock Ledger Inc. ("AegisIQ," "Company," "we," "our," or "us") is a compliance-grade corporate governance infrastructure platform purpose-built for private companies, law firms, fund operators, and multi-entity organizations. We provide digital stock ledger management, shareholder registry maintenance, certificate lifecycle management, document-backed corporate action workflows, entity-scoped access controls, and Approval-First AI governance tooling.
This Privacy Policy ("Policy") describes how AegisIQ collects, uses, stores, shares, and protects Personal Information and Customer Data in connection with our platform, website, APIs, and related services (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read and understood this Policy.
1. Scope and Applicability
This Policy applies to: Platform Users — attorneys, legal ops professionals, fund administrators, company officers, and other authorized personnel who access the AegisIQ platform under a subscription agreement; Website Visitors — individuals who visit aegisiqstockledger.com or any related AegisIQ web properties; Shareholder Data Subjects — individuals whose personal information is entered into the platform by a Customer on behalf of a managed entity; and API Integrators — developers and organizations accessing the AegisIQ API under a valid integration agreement.
AegisIQ processes shareholder and corporate data as a data processor on behalf of its Customers (who act as data controllers) with respect to Personal Information submitted through the platform. Where AegisIQ determines the purposes and means of processing (e.g., platform operations, security monitoring), it acts as a data controller.
2. Definitions
- "Customer" — any company, law firm, fund operator, or organization that has entered into a subscription agreement with AegisIQ.
- "Customer Data" — all data, including Personal Information, submitted to the Service by or on behalf of a Customer, including shareholder records, corporate action records, certificate data, and transactional history.
- "Personal Information" — any information that identifies, relates to, or could reasonably be linked to an identified or identifiable natural person.
- "Shareholder Data" — information relating to individuals holding or having held equity interests in a managed entity, including name, address, taxpayer identification, share class, share quantity, and certificate data.
- "Managed Entity" — a corporation, limited liability company, fund, or other legal entity whose stock ledger is administered through the Service by a Customer.
- "Approval-First AI" — AegisIQ's AI engine, which surfaces compliance-relevant answers from approved, timestamped source records, subject to mandatory human review and approval before any corporate action is executed.
- "Record Freshness Engine" — the platform mechanism that ties every cap table view, report, and AI-generated answer to an entity ID, an as-of timestamp, and underlying source records.
3. Information We Collect
3.1 Account and Registration Information
When a Customer or User creates an account, we collect: full name, business email address, company or firm name, job title or role, billing address, and payment method information (processed through Stripe, Inc.).
3.2 Customer Data and Shareholder Records
Customers submit corporate and shareholder data including: shareholder legal names, addresses, and contact information; taxpayer identification numbers where required; share class designations, issuance dates, certificate numbers, and share quantities; transfer history and corporate action records; lost certificate affidavits, indemnification bonds, and reissuance records; officer and director signature data; and cap table reports and equity compensation records.
3.3 Usage and Technical Data
We automatically collect: IP address, browser type, operating system, and device identifiers; pages visited, features accessed, and session duration; API request logs including endpoints, timestamps, and response codes; session identifiers stored in sessionStorage (not persistent cookies); and error logs and diagnostic data.
3.4 Communications Data
Records of support communications including name, email, and content of inquiries are retained to respond to requests and improve our support services.
3.5 Information We Do Not Collect
AegisIQ does not collect biometric data, precise geolocation data, medical or health information, or social media profile data. We do not purchase Personal Information from data brokers.
4. Legal Basis for Processing
| Processing Activity | Legal Basis |
|---|---|
| Providing the platform and fulfilling subscription agreements | Contractual necessity |
| Maintaining platform security and fraud prevention | Legitimate interests |
| Compliance with legal obligations (DGCL, SEC, tax) | Legal obligation |
| Processing payment information | Contractual necessity |
| Audit logging and immutable record maintenance | Legal obligation / Legitimate interests |
| AI query processing and Approval-First AI operations | Contractual necessity |
| Marketing communications (opt-in only) | Consent |
| Processing Customer-submitted shareholder data | Processing on behalf of Customer (controller instructions) |
5. How We Use Your Information
- Platform Operation: Providing, maintaining, and improving the Service including stock ledger management, certificate lifecycle workflows, transfer processing, and AI-assisted governance tooling.
- Record Integrity: Maintaining immutable audit logs, point-in-time cap table records, and document-backed corporate action histories consistent with DGCL Section 224 requirements.
- Authentication and Security: Verifying user identities, enforcing role-based access controls, monitoring for unauthorized access, and maintaining entity-level data segregation.
- Billing and Payments: Processing subscription fees, managing billing cycles, and maintaining payment records.
- Customer Support: Responding to support requests, troubleshooting platform issues, and maintaining communication records.
- Platform Analytics: Analyzing aggregate, de-identified usage data to improve user experience and guide product development.
- Legal Compliance: Complying with applicable laws, regulations, court orders, subpoenas, and lawful governmental requests.
- Approval-First AI Operations: Powering AI-generated answers sourced exclusively from approved, timestamped Customer Data, never used to train generalized AI models without explicit Customer consent.
6. Data Sharing and Disclosure
6.1 Service Providers and Subprocessors
We engage trusted third-party service providers under contractual data processing agreements: cloud infrastructure (SOC 2-compliant hosting and storage); Stripe, Inc. for payment processing; Netlify, Inc. for platform deployment and serverless API hosting; authentication and identity verification services; customer support tooling; and security monitoring services.
6.2 Legal Requirements
We may disclose Personal Information if required by law, subpoena, court order, or valid governmental request; to protect AegisIQ's rights or property; to prevent wrongdoing or protect user safety; or to comply with securities, corporate governance, or anti-money laundering regulations.
6.3 Business Transfers
In connection with a merger, acquisition, asset sale, or reorganization, Customer Data may be transferred to a successor entity with prior notice.
6.4 Aggregate and De-identified Data
We may share aggregate, anonymized information that cannot reasonably identify any individual, for industry research or platform performance analysis.
7. Data Ownership and Customer Control
Customer retains full legal ownership of all Customer Data submitted to the Service. AegisIQ does not claim any ownership rights over Customer Data, Shareholder Data, or Managed Entity records.
Customers may at any time: export their complete data in structured machine-readable format; request deletion of their account and associated data subject to legal retention requirements; restrict or modify data processing through role-based access controls; and designate authorized users with granular permission levels per entity.
Upon subscription termination, AegisIQ will provide a data export window of no fewer than 30 days. Following that window, AegisIQ will securely delete Customer Data from production systems subject to applicable legal retention obligations.
8. Data Security and Technical Safeguards
AegisIQ implements the following safeguards to protect Personal Information and Customer Data:
- Encryption at Rest: AES-256 encryption for all stored data including shareholder records, certificates, and document attachments.
- Encryption in Transit: TLS 1.3 enforced for all data transmitted between users and the platform.
- Multi-Factor Authentication (MFA): Required for all administrative and privileged user accounts.
- Role-Based Access Control (RBAC): Enforced at the API layer, ensuring users can only access data within their authorized entity scope.
- Entity-Level Data Segregation: Architectural isolation preventing cross-entity data access, even within multi-entity Customer deployments.
- Immutable Audit Logging: Write-once logs of all data access, modifications, approvals, and administrative actions.
- Disaster Recovery: Recovery Point Objective (RPO) under 1 hour; Recovery Time Objective (RTO) under 4 hours.
- SOC 2 Type II: Currently on a SOC 2 Type II audit roadmap with initiation targeted in Year 1 of commercial operations.
- Penetration Testing: Annual third-party penetration testing of platform infrastructure and APIs.
- Incident Response: Documented breach notification procedures consistent with applicable data protection law.
No security system can guarantee absolute protection. In the event of a data breach, AegisIQ will notify affected Customers and, where required, affected individuals within timeframes prescribed by applicable law.
9. Entity-Level Data Segregation
AegisIQ's architecture enforces strict entity-level data segregation as a core platform design principle. Each Managed Entity's data is logically and technically isolated from all other Managed Entities, including entities managed by the same Customer. Users may only access data for entities to which they have been explicitly granted access. API calls are scoped to a single entity per request with entity-level authorization checks enforced at the API layer. Audit logs are maintained on a per-entity basis and cannot be accessed cross-entity without explicit, logged administrative elevation.
This architecture is designed to meet the data segregation expectations of law firms managing multiple client entities and fund administrators maintaining separate portfolio company records under fiduciary obligations.
10. Audit Logging and Immutable Records
AegisIQ maintains comprehensive, immutable audit logs capturing: actor identity (authenticated user ID and role); action type (create, read, update, delete, approve, reject, export); timestamp (UTC, millisecond precision); entity scope (Managed Entity ID); document references (attached authorization documents, board resolutions); IP address and session identifier; approval chain for multi-step workflows; and AI query logs including prompt, response, source record citations, and approval status.
Audit log records are write-once and cannot be modified or deleted by any platform user, including platform administrators.
11. AI and Automated Processing
AegisIQ's Approval-First AI engine processes Customer Data to generate compliance-relevant answers and surface information from the platform's approved record set. The following principles govern all AI processing:
- Source-Bound Answers: Every AI-generated answer is derived exclusively from approved, timestamped source records within the Customer's entity scope. The AI does not draw from external knowledge bases, internet sources, or other Customers' data.
- Human Approval Required: The AI cannot execute any corporate action, modify any record, or submit any document. All AI outputs are advisory only and require explicit human approval.
- Full Attribution: Every AI answer includes the Entity ID, as-of date, and source record citation.
- Logged AI Queries: All AI queries and responses are captured in the entity audit log.
- No Cross-Customer Training: Customer Data is never used to train, fine-tune, or improve AI models that serve other Customers or the general public without explicit written consent.
- No Automated Decision-Making with Legal Effect: AegisIQ does not make automated decisions with legal or significant effects about individuals without human review.
12. Data Retention and Deletion
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and registration data | Subscription duration + 3 years | Legal and contractual obligations |
| Shareholder and ledger records | Subscription duration + 7 years | DGCL, IRS, SEC requirements |
| Certificate records and audit logs | Subscription duration + 10 years | Statute of limitations; DGCL Section 224 |
| Payment records | 7 years post-transaction | IRS and accounting requirements |
| Security and access logs | 2 years rolling | Security monitoring and incident investigation |
| Support communications | 3 years post-resolution | Service improvement and legal records |
| Marketing communications data | Until opt-out or 2 years inactivity | Consent-based |
Upon expiration of the applicable retention period, AegisIQ will securely delete or anonymize data using industry-standard methods including cryptographic erasure for encrypted data stores.
13. International Data Transfers
AegisIQ is headquartered in the United States and processes data on infrastructure located primarily in the United States. For transfers of Personal Information from the EEA or UK, AegisIQ relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate transfer mechanisms as required by applicable law. We implement supplementary technical and organizational measures to ensure equivalent protection for transferred data.
14. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights: Access — request a copy of Personal Information we hold; Rectification — request correction of inaccurate data; Erasure — request deletion subject to legal retention requirements; Restriction — request limitation of processing; Portability — receive data in structured, machine-readable format; Object — object to processing based on legitimate interests; and Withdraw Consent — where processing is consent-based, withdraw at any time.
To exercise these rights, contact us at legal@aegisiqstockledger.com. We will respond within 30 days or the timeframe required by applicable law. Identity verification may be required before processing requests.
15. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights including: the Right to Know — categories and specific pieces of Personal Information collected, sources, business purposes, and categories of third parties with whom we share; the Right to Delete — subject to legal retention exceptions; the Right to Correct — inaccurate Personal Information; and the Right to Opt-Out of Sale.
AegisIQ will not discriminate against you for exercising any CCPA/CPRA rights. To submit a California privacy request, contact legal@aegisiqstockledger.com with subject line "California Privacy Request." We will respond within 45 days of a verifiable consumer request.
16. European Privacy Rights (GDPR)
If you are located in the EEA or United Kingdom, the GDPR or UK GDPR applies. For Personal Information of platform Users, AegisIQ acts as a data controller. For Personal Information of shareholders submitted by Customers, AegisIQ acts as a data processor. We enter into Data Processing Agreements (DPAs) with Customers upon request.
EEA and UK residents have the right to lodge a complaint with a supervisory authority. Customers requiring a DPA for GDPR compliance may request one at legal@aegisiqstockledger.com. AegisIQ's standard DPA incorporates the Standard Contractual Clauses for controller-to-processor transfers.
17. Children's Privacy
The AegisIQ Service is intended solely for use by business professionals and is not directed at individuals under the age of 18. AegisIQ does not knowingly collect Personal Information from children under 18. If we become aware of such collection, we will promptly delete the information. Contact legal@aegisiqstockledger.com if you believe we may have collected information from a minor.
18. Cookies and Tracking Technologies
AegisIQ uses a limited set of technologies necessary for platform operation: Session Storage — authentication tokens stored in browser sessionStorage (not persistent cookies) cleared when the browser session ends; Essential Cookies — strictly necessary for platform functionality and security; and where deployed, privacy-preserving analytics that do not track users across sites or share data with advertising networks. AegisIQ does not use third-party advertising cookies, cross-site tracking pixels, or behavioral targeting technologies.
19. Third-Party Services and Integrations
The Service integrates with: Stripe, Inc. for payment processing (AegisIQ does not store full credit card numbers); Netlify, Inc. for platform deployment and serverless function hosting; and Google Fonts for typography rendering. AegisIQ is not responsible for the privacy practices of third-party services and encourages review of their respective privacy policies.
20. Delaware Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to conflict of law provisions. Disputes arising under this Policy shall be subject to the exclusive jurisdiction of state and federal courts located in the State of Delaware. Nothing herein limits data subject rights under applicable data protection law, including the GDPR or CCPA, to enforce rights before local supervisory authorities or courts.
21. Changes to This Policy
AegisIQ reserves the right to update or modify this Privacy Policy at any time. We will provide notice of material changes by posting the updated Policy with a revised "Last Updated" date; sending email notice to the primary contact on file for active Customer accounts; and, where required by applicable law, obtaining renewed consent. Changes become effective 30 days after posting, except for changes required by law which are effective immediately.
22. Contact and Data Protection Inquiries
AegisIQ Stock Ledger Inc.
Legal & Compliance
Email: legal@aegisiqstockledger.com
General Support: support@aegisiqstockledger.com