Product Privacy Notice
Trust Center Navigation
1. This notice explains how Aetos handles personal information in its products
Aetos Data Consulting LLC ("Aetos," "we," or "us"), 8 The Green, Suite B, Dover, DE 19910, provides trust, privacy, and AI governance consulting. This notice covers:
- the free TPS Risk Snapshot on aetos-data.com (the "Snapshot");
- the paid TPS Report;
- the Aetos tabletop exercise platform, including the Talon Peak scenarios (the "Tabletop"); and
- the Aerie client workspace at aerie.aetos-data.com ("Aerie"), including beta features of any of these products.
It works alongside the Aetos Terms (the Free and Beta Terms and the Paid Terms), any signed agreement with your organization, and our Data Processing Addendum. Cookies and similar technologies, on our website and in these products (for example, to keep you signed in or to record link clicks), are described here.
2. Most of the time, we handle information for your organization
When you take the Snapshot, buy a TPS Report, join a Tabletop session your organization arranged with us, or use Aerie, you do so for an organization. That organization (our "client") decides what information it shares with us and why. We handle that information for the client, following its instructions, under the data processing agreement in our Terms. In privacy law, the client is the "controller" and Aetos is its "processor."
We decide how to handle some information ourselves, as a controller:
- public Tabletop sessions that Aetos runs itself, not for a client;
- our own business records, such as contact details, marketing, billing, and account security; and
- our use of Snapshot results to tailor follow-up about the item you requested (Section 4).
The same email address can appear in both. If you have a question about information we handle for your organization, you can ask your organization or us. We will help either way (Section 11).
3. We collect only what each product needs
| Product | What we collect | Source |
|---|---|---|
| Snapshot | Name, work email, company details, questionnaire answers, and results. For rate limits, we store your IP address only as a keyed hash, with your browser type | You and your browser |
| TPS Report | The Snapshot information, payment status, and the report we prepare, with a hashed IP address and browser type for rate limits. Card details go straight to Stripe and never reach Aetos | You and Stripe |
| Checkout link | A personal "Get my full report" payment link, and a record in HubSpot, our CRM, when it is clicked | The link we send you |
| Tabletop | A nickname for the live session (deleted when it ends), your team's choices, ratings, and written responses by session, team, and role, and the time you accepted the session acknowledgement. We do not ask for email addresses, but written responses may include identifying details | You and your team |
| Tabletop, paid engagement | The above, plus a client profile: company basics, systems and vendors, participants' names, titles, and exercise roles (no emails or phone numbers), insurance and contract details, and any policies, plans, contracts, or other documents your organization provides to build a custom scenario | Your organization, through Aerie |
| Aerie | Name, work email, role, password (stored securely), authenticator setup, documents and forms your organization uploads, questions to Aetos, and an activity log of sign-ins, file views, downloads, and changes | You, your organization, and Aerie |
Each form marks its required fields. Without them, we may not be able to produce results, process an order, set up an account, or run an exercise.
Please do not put sensitive information, such as health details, government ID numbers, payment card numbers, or passwords, into answers, Tabletop responses, or Aerie uploads unless your organization has agreed this with us in writing.
4. Each use of information has a stated purpose
For our clients. We use client information only to provide, support, and secure the product the client requested, following its instructions. The client chooses the legal basis for sharing it with us. Under our data processing agreement, clients also allow us to:
- send ourselves an internal notification when a Snapshot is submitted, and follow up as needed to deliver or explain the results; and
- use de-identified, aggregated information, which identifies no client or person, to improve our products and methods.
For our own purposes. As a controller, we use only your name, work email, role, and company details, and your organization's risk bands and top gaps, to tailor follow-up about the item you requested. Those details are kept with your contact record in our CRM and follow the Snapshot retention in Section 8. We do not use answers, detailed scores, or reports for our own marketing, and we email you about our other services only if you opt in. Our purposes and their basis under the UK and EU GDPR are below. The same purposes apply everywhere.
| Purpose | Basis under UK and EU GDPR |
|---|---|
| Manage business contacts, answer inquiries, and administer purchases | Legitimate interest in working with business contacts. Contract applies only where you personally are a party and the processing is needed to perform it or take steps you request before entering it |
| Use Snapshot results to tailor follow-up about the requested item | Legitimate interest in following up on an organization's request for an assessment. You can object at any time (Section 11) |
| Send that limited follow-up by email | Legitimate interest, within email marketing rules, with an unsubscribe link in every email (Section 6) |
| Send The Aerial View newsletter, or emails about our other services | Your consent, given by opting in. You can withdraw it at any time |
| Record clicks on your checkout link, to see interest in the full report | Legitimate interest in responding to that interest, within the rules on tracking technologies |
| Keep accounts secure, prevent abuse, and apply rate limits and country restrictions | Legitimate interest in security |
| Run public Tabletop sessions and debriefs that Aetos hosts itself | Legitimate interest in providing the exercise you joined |
| Improve our methods using de-identified, aggregated information | Legitimate interest in improving our products |
| Keep payment, invoice, and tax records | Legal obligation where one applies; otherwise legitimate interest in accurate records |
We do not make decisions about you as an individual that have legal or similarly significant effects. The Snapshot scores your organization's practices from the answers given; it does not assess you personally.
5. AI helps draft the paid TPS Report and custom Tabletop scenarios, and a person reviews every one
The Snapshot does not use AI, and neither do Tabletop sessions that use a standard scenario, whether free or paid. For the paid TPS Report, we send the answers and scores to Anthropic's Claude to help draft the narrative. For a paid Tabletop engagement with a custom scenario, we send the client profile and the documents your organization provides, such as policies, plans, and contracts, to Claude to complete the profile and draft the scenario. Your organization's real name and the names of key people are sent so they can be kept out of the result; the finished scenario uses fictional names. Aetos reviews and edits every report and scenario before it is released or used.
Anthropic is our subprocessor for this drafting. It does not use this information to train its models, and it deletes it within 30 days. If its systems flag content under its usage policy, it may keep that content for up to two years and the related safety scores for up to seven years, or longer where the law requires. Anthropic holds those records, so a deletion request to Aetos cannot erase them. We help with deletion requests about information sent to Anthropic and explain any exception when we respond.
Aerie's planned AI gap analysis is switched off. Before we switch it on, we will tell your organization's administrators what it does and which provider it uses, and update this notice.
6. You choose which emails you receive from us
Results and follow-up. When the Snapshot is submitted, we email the results. We may also send a short series of emails about the item you requested, including how to get the full TPS Report based on it. Every one of these emails has an unsubscribe link.
The Aerial View. We send our newsletter, and emails about services other than the item you requested, only if you opt in.
The submission checkbox. Ticking it accepts our Terms and data processing agreement. It is not consent to marketing.
Your checkout link. The "Get my full report" link in our emails is a personal payment link that does not expire. When it is clicked, HubSpot records the click against you. If you forward the link and someone else clicks it, the click may be recorded as yours. The separate link for downloading a purchased report expires after 90 days.
Opting out. Every marketing email has an unsubscribe link, or you can write to privacy@aetos-data.com. Opting out stops marketing, but you will still receive results and any service, account, or security messages you need. It does not delete Snapshot information; ask for deletion separately if you want it. We keep a minimal suppression record, such as your email address, so your opt-out keeps working. We do not add Tabletop participants or Aerie users to marketing just because they use those products.
7. Who can see or receive information
Service providers. We use providers for:
- hosting, databases, and file storage;
- file scanning and document previews;
- email delivery, including our internal email, which receives a notification each time a Snapshot is submitted;
- customer relationship management through HubSpot, including recording checkout link clicks;
- payments;
- AI drafting of the TPS Report and custom Tabletop scenarios;
- forms, scheduling, and workflow automation;
- recording and transcribing calls, with notice to participants;
- AI assistants we use in our own work, on business terms that bar training on your information;
- our own work tracking, which receives task names and time entries.
They handle information on our instructions, under contracts that require them to protect it. A few also act on their own account for limited purposes, such as Stripe for fraud prevention and tax records; their own privacy notices cover that. Our provider list, with what each does and how it protects international transfers, is at https://www.aetos-data.com/dpa.
Within your organization. In Aerie, administrators see all of their organization's content, and contributors see only what is assigned to them. In Tabletop sessions, facilitators and teammates see your responses, and the client's authorized people receive results, decision logs, and debriefs. Please do not treat Tabletop responses as private from them.
At Aetos. Only the Aetos personnel who need information to deliver, support, or secure a product, or to carry out the follow-up in Section 6, can access it.
Other disclosures. We may disclose information when the law requires it, to protect the rights, safety, or security of Aetos, our clients, or others, or as part of a merger, acquisition, or sale of assets. In that case, this notice continues to apply.
We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.
8. We keep information only as long as each product needs it
| Information | How long we keep it |
|---|---|
| Snapshot answers and results, including the results kept with your CRM contact record | Until an authorized deletion request, or 24 months after submission, whichever comes first |
| Our business contact and marketing record, including checkout link clicks | Until a deletion request, or 24 months after your last contact with us, whichever comes first. A minimal suppression record is kept after an opt-out |
| Internal Snapshot notification email | Deleted with the Snapshot record, whether on request or on schedule |
| Hashed IP address and browser type | 30 days, for rate limits. Removed on that schedule even when the related report is kept longer |
| Checkout links | Do not expire. The information linked to them follows the rows above |
| Report download links and other links in our emails | Expire 90 days after they are sent |
| Paid TPS Report and its data | 24 months after delivery, unless deletion is requested sooner or a signed agreement sets another period |
| Tabletop nickname | Deleted when the session ends |
| Records of public Tabletop sessions Aetos runs itself | 24 months |
| Tabletop records kept for a client in the Tabletop app, including the client profile and documents provided for a custom scenario | 90 days after the engagement closes, unless the signed agreement says otherwise |
| Paid Tabletop deliverables kept in Aerie, such as the decision log and after-action report | The period for the related engagement files, measured from that engagement's close. Copying into Aerie does not restart the clock |
| Aerie content | As the client's agreement and retention settings provide. By default: project files 90 days after the project closes, retainer and hourly-engagement files up to 2 years after the engagement ends, and signed agreements 7 years after the agreement ends. The latest version of a document follows the period for its engagement's files; an unrelated active order does not extend it. An authorized deletion request can shorten any period |
| Aerie account and activity log | For the engagement, then 90 days after it closes, unless the client's agreement sets another period |
| Payment, invoice, and tax records | As long as tax and accounting rules require. Stripe keeps its own records under its terms |
Each type of information keeps one schedule wherever we store it, and copying a record does not restart its clock. A paid Tabletop deliverable placed in Aerie follows the period for its engagement's files, measured from that engagement's close. De-identified, aggregated information that identifies no client or person may be kept longer to improve our products.
9. Deletion follows a set schedule
Snapshot and TPS Report. Email privacy@aetos-data.com. A request about yourself deletes your own personal information, including your name and contact details in your organization's assessment. Deleting the whole assessment takes a request from someone authorized to act for your organization. The 30-day clock starts when we receive the request. We may ask you to confirm your identity or your authority to act for your organization; asking does not restart the clock. Within 30 calendar days, we delete the information from our active systems and confirm when it is done. That includes the internal notification email, the hashed IP address and browser type, checkout link click records, and results kept with your CRM contact record. If we cannot complete a request, we explain why within that period.
Copies in our providers' backups and logs expire on their normal cycles, generally within 40 days of deletion. The exception is our internal email provider, whose backups may hold a deleted notification for up to 180 days. We do not use backup copies for business or marketing, and if a backup is restored, we delete the information again.
If you object to our sales follow-up, we stop using your organization's results for it.
Tabletop. Nicknames are deleted when the session ends. Saved responses are organized by session, team, and role, which is not the same as anonymous: a role, the session context, or something written in a response can point to a person. To request deletion, give us enough detail to find the information, such as the session, team, and role. We handle requests about public sessions we run ourselves, and help the client handle requests about sessions run for it, whether paid or free.
Aerie. Your organization can download its content during the engagement and for 30 calendar days after access ends. Scheduled deletion waits until that window closes, even if a retention date falls earlier. Administrators get at least 7 days' notice before a scheduled deletion and a confirmation afterwards. An authorized request can delete content sooner, and a legal hold pauses deletion. Deleted content leaves our active systems at once and our backups within 7 days.
What we may keep. We keep only:
- records the law requires, such as tax records, or information under a valid legal hold;
- a minimal suppression record, which may include your email address, so a marketing opt-out keeps working; and
- a record that a request was handled, without your name or email address.
Each is used only for its purpose and deleted when that purpose ends. Records Anthropic keeps under Section 5 are separate from our backups. We explain any exception when we respond.
10. We protect information with layered safeguards
- Aerie requires a password and an authenticator code at every sign-in, and ends sessions after 30 minutes of inactivity.
- Every Aerie upload is scanned for viruses before anyone else can open it.
- Aerie records every sign-in, file view, download, and change.
- Our providers encrypt information at rest and in transit. Our database, file storage, and AI drafting provider use AES-256 at rest and TLS 1.2 or higher in transit.
- Email links are signed. Report download links expire after 90 days; checkout links lead only to payment.
- IP addresses are stored only as keyed hashes, and our scoring method runs only on our servers.
No system is perfectly secure. If we learn of a security incident affecting information we hold for a client, we notify the client without undue delay, and within the deadline in our agreement with it. Where the law requires, we also notify you or the authorities directly.
11. You can access, correct, and delete your information
Wherever you are, you can ask us to:
- confirm whether we hold your information and give you a copy, in a portable format where possible;
- correct information that is wrong;
- delete your information;
- stop using your organization's Snapshot results for our sales follow-up;
- stop marketing to you, which we will always do; and
- explain how we use it.
We offer this to everyone, even where no privacy law requires it. Legal rights vary by country and state, and by whether we are acting for a client. We may confirm your identity, or your authority if you are asking for someone else. If we cannot meet all or part of a request, we will explain why and tell you how to appeal.
How requests are handled. Email privacy@aetos-data.com. For our own records and our sales use of Snapshot results, we respond directly. For information we hold for a client, we respond with the client's agreement, or pass your request to the client promptly and help it respond.
Response times. We respond within one month under the UK and EU GDPR, and within 45 days elsewhere, unless the law requires sooner. If a request is complex and the law allows more time, we will tell you within the first period. Snapshot and TPS Report deletions always follow the 30-day commitment in Section 9.
UK and EU. Where the UK or EU GDPR applies, you can also object to uses based on legitimate interest, ask us to restrict processing, and complain to your data protection authority, such as the UK Information Commissioner's Office.
United States. Some state laws give access, correction, deletion, and portability rights. Several, including Virginia's, do not cover people acting in a business or employment role, which describes most of our users; our request process is available regardless. We do not sell personal information, use it for targeted advertising, or use it for profiling with legal or similarly significant effects.
Appeals and agents. If we decline a request, you can appeal by replying with "Appeal" in the subject line. We will answer within 45 days, or sooner where the law requires, and tell you where to complain if you are still not satisfied: your state attorney general in the US, or your data protection authority in the UK or EU. You can also complain to a regulator directly at any time. An authorized agent may make a request for you if we can confirm their authority. We will not treat you differently for making a request.
12. Information is stored in the United States
We and our main providers store information in the United States. Two kinds of transfer are involved, and each has its own safeguards.
- From a client to Aetos. Where a client in the UK or EU sends us information, our data processing agreement includes the EU Standard Contractual Clauses and, for UK transfers, the UK Addendum. A provider's certification does not cover this transfer.
- From Aetos to our providers. Before we rely on a provider, we confirm a valid safeguard for it: the Standard Contractual Clauses with the UK Addendum in its data processing terms, or a Data Privacy Framework certification we have checked covers that provider and that transfer. The clauses used match Aetos's role in each activity. Our provider list shows which applies to each provider.
You can ask privacy@aetos-data.com for details or a copy of these safeguards, with confidential details removed.
13. Our products are for adults acting for a business
Our products are for people 18 or older using them for business. We do not knowingly collect information from anyone under 18. If you believe we have, tell us and we will delete it.
14. We will tell you when this notice changes
We will post any update with a new effective date. If a change is material, we will tell you by email where we have your address, and tell Aerie administrators in advance. Updates apply only going forward.
15. Contact us
Aetos Data Consulting LLC, 8 The Green, Suite B, Dover, DE 19910. Privacy questions and requests: privacy@aetos-data.com. Security issues: security@aetos-data.com.