Privacy Policy

Privacy Policy

Effective Date: May 1, 2026  ·  Last Updated: May 1, 2026

Table of Contents

  1. Scope and Applicability
  2. Definitions
  3. Information We Collect
  4. Legal Basis for Processing
  5. How We Use Your Information
  6. Data Sharing and Disclosure
  7. Data Ownership and Customer Control
  8. Data Security and Technical Safeguards
  9. Entity-Level Data Segregation
  10. Audit Logging and Immutable Records
  11. AI and Automated Processing
  12. Data Retention and Deletion
  13. International Data Transfers
  14. Your Privacy Rights
  15. California Privacy Rights (CCPA/CPRA)
  16. European Privacy Rights (GDPR)
  17. Children's Privacy
  18. Cookies and Tracking Technologies
  19. Third-Party Services
  20. Delaware Governing Law
  21. Changes to This Policy
  22. Contact and Data Protection Inquiries

AegisIQ Stock Ledger Inc. ("AegisIQ," "Company," "we," "our," or "us") is a compliance-grade corporate governance infrastructure platform purpose-built for private companies, law firms, fund operators, and multi-entity organizations. We provide digital stock ledger management, shareholder registry maintenance, certificate lifecycle management, document-backed corporate action workflows, entity-scoped access controls, and Approval-First AI governance tooling.

This Privacy Policy ("Policy") describes how AegisIQ collects, uses, stores, shares, and protects Personal Information and Customer Data in connection with our platform, website, APIs, and related services (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read and understood this Policy.

Approval-First AI — Built Into the Platform
Every answer is entity-scoped, timestamped, and source-cited. AI surfaces — humans approve.
Query
Show current authorized shares and issued shares for Acme Holdings Corp as of today, with source records.
Approval-First AI Response
Acme Holdings Corp — Authorized: 10,000,000 shares (Common Class A). Issued & Outstanding: 4,250,000 shares across 12 shareholders as of May 1, 2026. Source: Board Resolution #2024-03 (Mar 15, 2024), Certificate Register entries CE-001 through CE-047.
Entity: ACME-0042 As-of: 2026-05-01T00:00:00Z 3 source records cited
Awaiting human approval before any action is executed — AI cannot modify records or execute corporate actions.

1. Scope and Applicability

This Policy applies to: Platform Users — attorneys, legal ops professionals, fund administrators, company officers, and other authorized personnel who access the AegisIQ platform under a subscription agreement; Website Visitors — individuals who visit aegisiqstockledger.com or any related AegisIQ web properties; Shareholder Data Subjects — individuals whose personal information is entered into the platform by a Customer on behalf of a managed entity; and API Integrators — developers and organizations accessing the AegisIQ API under a valid integration agreement.

AegisIQ processes shareholder and corporate data as a data processor on behalf of its Customers (who act as data controllers) with respect to Personal Information submitted through the platform. Where AegisIQ determines the purposes and means of processing (e.g., platform operations, security monitoring), it acts as a data controller.

2. Definitions

  • "Customer" — any company, law firm, fund operator, or organization that has entered into a subscription agreement with AegisIQ.
  • "Customer Data" — all data, including Personal Information, submitted to the Service by or on behalf of a Customer, including shareholder records, corporate action records, certificate data, and transactional history.
  • "Personal Information" — any information that identifies, relates to, or could reasonably be linked to an identified or identifiable natural person.
  • "Shareholder Data" — information relating to individuals holding or having held equity interests in a managed entity, including name, address, taxpayer identification, share class, share quantity, and certificate data.
  • "Managed Entity" — a corporation, limited liability company, fund, or other legal entity whose stock ledger is administered through the Service by a Customer.
  • "Approval-First AI" — AegisIQ's AI engine, which surfaces compliance-relevant answers from approved, timestamped source records, subject to mandatory human review and approval before any corporate action is executed.
  • "Record Freshness Engine" — the platform mechanism that ties every cap table view, report, and AI-generated answer to an entity ID, an as-of timestamp, and underlying source records.

3. Information We Collect

3.1 Account and Registration Information

When a Customer or User creates an account, we collect: full name, business email address, company or firm name, job title or role, billing address, and payment method information (processed through Stripe, Inc.).

3.2 Customer Data and Shareholder Records

Customers submit corporate and shareholder data including: shareholder legal names, addresses, and contact information; taxpayer identification numbers where required; share class designations, issuance dates, certificate numbers, and share quantities; transfer history and corporate action records; lost certificate affidavits, indemnification bonds, and reissuance records; officer and director signature data; and cap table reports and equity compensation records.

AegisIQ processes Customer Data solely as a processor acting on the instruction of the Customer as controller. Customers bear full responsibility for ensuring they have a lawful basis to submit Personal Information about third-party shareholders and other data subjects.

3.3 Usage and Technical Data

We automatically collect: IP address, browser type, operating system, and device identifiers; pages visited, features accessed, and session duration; API request logs including endpoints, timestamps, and response codes; session identifiers stored in sessionStorage (not persistent cookies); and error logs and diagnostic data.

3.4 Communications Data

Records of support communications including name, email, and content of inquiries are retained to respond to requests and improve our support services.

3.5 Information We Do Not Collect

AegisIQ does not collect biometric data, precise geolocation data, medical or health information, or social media profile data. We do not purchase Personal Information from data brokers.

4. Legal Basis for Processing

Processing ActivityLegal Basis
Providing the platform and fulfilling subscription agreementsContractual necessity
Maintaining platform security and fraud preventionLegitimate interests
Compliance with legal obligations (DGCL, SEC, tax)Legal obligation
Processing payment informationContractual necessity
Audit logging and immutable record maintenanceLegal obligation / Legitimate interests
AI query processing and Approval-First AI operationsContractual necessity
Marketing communications (opt-in only)Consent
Processing Customer-submitted shareholder dataProcessing on behalf of Customer (controller instructions)

5. How We Use Your Information

  • Platform Operation: Providing, maintaining, and improving the Service including stock ledger management, certificate lifecycle workflows, transfer processing, and AI-assisted governance tooling.
  • Record Integrity: Maintaining immutable audit logs, point-in-time cap table records, and document-backed corporate action histories consistent with DGCL Section 224 requirements.
  • Authentication and Security: Verifying user identities, enforcing role-based access controls, monitoring for unauthorized access, and maintaining entity-level data segregation.
  • Billing and Payments: Processing subscription fees, managing billing cycles, and maintaining payment records.
  • Customer Support: Responding to support requests, troubleshooting platform issues, and maintaining communication records.
  • Platform Analytics: Analyzing aggregate, de-identified usage data to improve user experience and guide product development.
  • Legal Compliance: Complying with applicable laws, regulations, court orders, subpoenas, and lawful governmental requests.
  • Approval-First AI Operations: Powering AI-generated answers sourced exclusively from approved, timestamped Customer Data, never used to train generalized AI models without explicit Customer consent.
AegisIQ does not sell, rent, trade, or monetize your Personal Information or Customer Data. We do not use Customer Data to train AI or machine learning models for general use beyond the specific Customer's platform instance.

6. Data Sharing and Disclosure

6.1 Service Providers and Subprocessors

We engage trusted third-party service providers under contractual data processing agreements: cloud infrastructure (SOC 2-compliant hosting and storage); Stripe, Inc. for payment processing; Netlify, Inc. for platform deployment and serverless API hosting; authentication and identity verification services; customer support tooling; and security monitoring services.

6.2 Legal Requirements

We may disclose Personal Information if required by law, subpoena, court order, or valid governmental request; to protect AegisIQ's rights or property; to prevent wrongdoing or protect user safety; or to comply with securities, corporate governance, or anti-money laundering regulations.

6.3 Business Transfers

In connection with a merger, acquisition, asset sale, or reorganization, Customer Data may be transferred to a successor entity with prior notice.

6.4 Aggregate and De-identified Data

We may share aggregate, anonymized information that cannot reasonably identify any individual, for industry research or platform performance analysis.

7. Data Ownership and Customer Control

Customer retains full legal ownership of all Customer Data submitted to the Service. AegisIQ does not claim any ownership rights over Customer Data, Shareholder Data, or Managed Entity records.

Customers may at any time: export their complete data in structured machine-readable format; request deletion of their account and associated data subject to legal retention requirements; restrict or modify data processing through role-based access controls; and designate authorized users with granular permission levels per entity.

Upon subscription termination, AegisIQ will provide a data export window of no fewer than 30 days. Following that window, AegisIQ will securely delete Customer Data from production systems subject to applicable legal retention obligations.

8. Data Security and Technical Safeguards

AegisIQ implements the following safeguards to protect Personal Information and Customer Data:

  • Encryption at Rest: AES-256 encryption for all stored data including shareholder records, certificates, and document attachments.
  • Encryption in Transit: TLS 1.3 enforced for all data transmitted between users and the platform.
  • Multi-Factor Authentication (MFA): Required for all administrative and privileged user accounts.
  • Role-Based Access Control (RBAC): Enforced at the API layer, ensuring users can only access data within their authorized entity scope.
  • Entity-Level Data Segregation: Architectural isolation preventing cross-entity data access, even within multi-entity Customer deployments.
  • Immutable Audit Logging: Write-once logs of all data access, modifications, approvals, and administrative actions.
  • Disaster Recovery: Recovery Point Objective (RPO) under 1 hour; Recovery Time Objective (RTO) under 4 hours.
  • SOC 2 Type II: Currently on a SOC 2 Type II audit roadmap with initiation targeted in Year 1 of commercial operations.
  • Penetration Testing: Annual third-party penetration testing of platform infrastructure and APIs.
  • Incident Response: Documented breach notification procedures consistent with applicable data protection law.

No security system can guarantee absolute protection. In the event of a data breach, AegisIQ will notify affected Customers and, where required, affected individuals within timeframes prescribed by applicable law.

9. Entity-Level Data Segregation

AegisIQ's architecture enforces strict entity-level data segregation as a core platform design principle. Each Managed Entity's data is logically and technically isolated from all other Managed Entities, including entities managed by the same Customer. Users may only access data for entities to which they have been explicitly granted access. API calls are scoped to a single entity per request with entity-level authorization checks enforced at the API layer. Audit logs are maintained on a per-entity basis and cannot be accessed cross-entity without explicit, logged administrative elevation.

This architecture is designed to meet the data segregation expectations of law firms managing multiple client entities and fund administrators maintaining separate portfolio company records under fiduciary obligations.

10. Audit Logging and Immutable Records

AegisIQ maintains comprehensive, immutable audit logs capturing: actor identity (authenticated user ID and role); action type (create, read, update, delete, approve, reject, export); timestamp (UTC, millisecond precision); entity scope (Managed Entity ID); document references (attached authorization documents, board resolutions); IP address and session identifier; approval chain for multi-step workflows; and AI query logs including prompt, response, source record citations, and approval status.

Audit log records are write-once and cannot be modified or deleted by any platform user, including platform administrators.

Audit logs may constitute legally significant records under Delaware corporate law and applicable securities regulations. Customers should not rely on AegisIQ audit logs as a substitute for their own legal recordkeeping obligations and should consult counsel regarding applicable retention requirements.

11. AI and Automated Processing

AegisIQ's Approval-First AI engine processes Customer Data to generate compliance-relevant answers and surface information from the platform's approved record set. The following principles govern all AI processing:

  • Source-Bound Answers: Every AI-generated answer is derived exclusively from approved, timestamped source records within the Customer's entity scope. The AI does not draw from external knowledge bases, internet sources, or other Customers' data.
  • Human Approval Required: The AI cannot execute any corporate action, modify any record, or submit any document. All AI outputs are advisory only and require explicit human approval.
  • Full Attribution: Every AI answer includes the Entity ID, as-of date, and source record citation.
  • Logged AI Queries: All AI queries and responses are captured in the entity audit log.
  • No Cross-Customer Training: Customer Data is never used to train, fine-tune, or improve AI models that serve other Customers or the general public without explicit written consent.
  • No Automated Decision-Making with Legal Effect: AegisIQ does not make automated decisions with legal or significant effects about individuals without human review.

12. Data Retention and Deletion

Data CategoryRetention PeriodBasis
Account and registration dataSubscription duration + 3 yearsLegal and contractual obligations
Shareholder and ledger recordsSubscription duration + 7 yearsDGCL, IRS, SEC requirements
Certificate records and audit logsSubscription duration + 10 yearsStatute of limitations; DGCL Section 224
Payment records7 years post-transactionIRS and accounting requirements
Security and access logs2 years rollingSecurity monitoring and incident investigation
Support communications3 years post-resolutionService improvement and legal records
Marketing communications dataUntil opt-out or 2 years inactivityConsent-based

Upon expiration of the applicable retention period, AegisIQ will securely delete or anonymize data using industry-standard methods including cryptographic erasure for encrypted data stores.

13. International Data Transfers

AegisIQ is headquartered in the United States and processes data on infrastructure located primarily in the United States. For transfers of Personal Information from the EEA or UK, AegisIQ relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate transfer mechanisms as required by applicable law. We implement supplementary technical and organizational measures to ensure equivalent protection for transferred data.

14. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights: Access — request a copy of Personal Information we hold; Rectification — request correction of inaccurate data; Erasure — request deletion subject to legal retention requirements; Restriction — request limitation of processing; Portability — receive data in structured, machine-readable format; Object — object to processing based on legitimate interests; and Withdraw Consent — where processing is consent-based, withdraw at any time.

To exercise these rights, contact us at legal@aegisiqstockledger.com. We will respond within 30 days or the timeframe required by applicable law. Identity verification may be required before processing requests.

15. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights including: the Right to Know — categories and specific pieces of Personal Information collected, sources, business purposes, and categories of third parties with whom we share; the Right to Delete — subject to legal retention exceptions; the Right to Correct — inaccurate Personal Information; and the Right to Opt-Out of Sale.

AegisIQ does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. No opt-out is required.

AegisIQ will not discriminate against you for exercising any CCPA/CPRA rights. To submit a California privacy request, contact legal@aegisiqstockledger.com with subject line "California Privacy Request." We will respond within 45 days of a verifiable consumer request.

16. European Privacy Rights (GDPR)

If you are located in the EEA or United Kingdom, the GDPR or UK GDPR applies. For Personal Information of platform Users, AegisIQ acts as a data controller. For Personal Information of shareholders submitted by Customers, AegisIQ acts as a data processor. We enter into Data Processing Agreements (DPAs) with Customers upon request.

EEA and UK residents have the right to lodge a complaint with a supervisory authority. Customers requiring a DPA for GDPR compliance may request one at legal@aegisiqstockledger.com. AegisIQ's standard DPA incorporates the Standard Contractual Clauses for controller-to-processor transfers.

17. Children's Privacy

The AegisIQ Service is intended solely for use by business professionals and is not directed at individuals under the age of 18. AegisIQ does not knowingly collect Personal Information from children under 18. If we become aware of such collection, we will promptly delete the information. Contact legal@aegisiqstockledger.com if you believe we may have collected information from a minor.

18. Cookies and Tracking Technologies

AegisIQ uses a limited set of technologies necessary for platform operation: Session Storage — authentication tokens stored in browser sessionStorage (not persistent cookies) cleared when the browser session ends; Essential Cookies — strictly necessary for platform functionality and security; and where deployed, privacy-preserving analytics that do not track users across sites or share data with advertising networks. AegisIQ does not use third-party advertising cookies, cross-site tracking pixels, or behavioral targeting technologies.

19. Third-Party Services and Integrations

The Service integrates with: Stripe, Inc. for payment processing (AegisIQ does not store full credit card numbers); Netlify, Inc. for platform deployment and serverless function hosting; and Google Fonts for typography rendering. AegisIQ is not responsible for the privacy practices of third-party services and encourages review of their respective privacy policies.

20. Delaware Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to conflict of law provisions. Disputes arising under this Policy shall be subject to the exclusive jurisdiction of state and federal courts located in the State of Delaware. Nothing herein limits data subject rights under applicable data protection law, including the GDPR or CCPA, to enforce rights before local supervisory authorities or courts.

21. Changes to This Policy

AegisIQ reserves the right to update or modify this Privacy Policy at any time. We will provide notice of material changes by posting the updated Policy with a revised "Last Updated" date; sending email notice to the primary contact on file for active Customer accounts; and, where required by applicable law, obtaining renewed consent. Changes become effective 30 days after posting, except for changes required by law which are effective immediately.

22. Contact and Data Protection Inquiries

AegisIQ Stock Ledger Inc.

Legal & Compliance

Email: legal@aegisiqstockledger.com

General Support: support@aegisiqstockledger.com

Notice to Customers regarding Shareholder Data Subject Requests: If an individual shareholder submits a data subject access, deletion, or correction request directly to AegisIQ, we will forward that request to the applicable Customer (as data controller) for handling. AegisIQ will cooperate with Customers in fulfilling valid data subject requests within the timeframes required by applicable law.