Legal

Privacy Policy
AEOS QUANTUM™

How information is handled in connection with the AEOS QUANTUM™ enterprise intelligence operating platform, operated by AexoreX Systems LLC.

Effective August 29, 2026

1. Introduction

AexoreX Systems LLC (“AexoreX”, “we”, “us”, or “our”) operates AEOS QUANTUM™, an enterprise intelligence operating platform. This Privacy Policy explains how information is handled in connection with the AEOS QUANTUM™ platform and this website at aeosq.com.

aeosq.com is the product and platform domain for AEOS QUANTUM™. It is not the corporate website of AexoreX Systems LLC. Corporate information, including corporate privacy practices that apply outside the platform, is published separately at aexorex.com. This Policy is intended to remain consistent with the corporate policy while addressing the platform specifically.

This Policy is provided for transparency and does not create contractual obligations beyond those set out in an applicable written agreement between AexoreX and a customer.

2. Scope

This Policy applies to the aeosq.com website, account registration and authentication, enterprise inquiries and support communications, and use of AEOS QUANTUM™ platform functionality, including organizations, workspaces, Digital Labor™, Skill Systems™, knowledge and enterprise context, memory where applicable, orchestration and workflows, governance and approval records, audit records, integrations, and AI-enabled functionality.

Where an organization provides AEOS QUANTUM™ to its personnel, that organization's own policies may also apply to its users. This Policy does not govern third-party websites, applications, or services that a customer chooses to connect.

3. Information We Collect

We collect two broad categories of information: (a) account and personal information relating to individuals who register for, administer, or use the platform; and (b) enterprise customer data submitted, configured, uploaded, connected, or otherwise processed by a customer through AEOS QUANTUM™. These categories are described separately below because they are treated differently.

4. Information You Provide

Depending on how you interact with AEOS QUANTUM™, we may collect:

  • Identity and contact details such as name and corporate email address.
  • Authentication information, including credentials handled by our authentication provider and, where enabled, identity information returned by a federated sign-in provider.
  • Organization affiliation, workspace membership, and assigned role or permission level.
  • Enterprise inquiry information submitted through our demo, evaluation, or contact forms.
  • Support and other communications you send to us.
  • Billing and subscription information where a paid subscription is in place. Payment card details, where applicable, are handled by payment providers and are not stored by us.

5. Information Collected Automatically

When you access aeosq.com or the platform, certain technical information may be collected automatically, including IP address, device and browser characteristics, pages or platform areas accessed, timestamps, referring pages, coarse product-interaction events, and diagnostic or error information.

We also process security and abuse-prevention signals, which may include request metadata and abuse-mitigation identifiers used to detect automated submissions or misuse. The specific signals collected may vary depending on configuration and the environment in which the platform is deployed.

6. Enterprise Customer Data

Enterprise customer data is content and configuration that a customer or its authorized users submit to, connect to, or generate within AEOS QUANTUM™. It may include enterprise documents, knowledge-base content, workflow and orchestration configuration, Digital Labor™ configuration, prompts and instructions, integration data, operational metadata, and business information.

AexoreX does not claim ownership of enterprise customer data. Such data remains subject to the customer's rights and to the terms of any applicable agreement between the customer and AexoreX. We process enterprise customer data to provide, secure, maintain, and support the platform, and otherwise in accordance with applicable customer instructions and law.

Enterprise customer data may contain personal information about a customer's own employees, contractors, or counterparties. The customer is generally responsible for determining what information it submits and for ensuring it has an appropriate legal basis to do so.

7. AI and Model Processing

AEOS QUANTUM™ includes AI-enabled functionality and may use third-party AI model providers or AI infrastructure to deliver it. Whether, when, and how information is processed by such providers depends on the features used, the customer's configuration, and the specific services enabled.

AexoreX does not represent that every third-party AI provider applies identical data-handling, retention, or residency practices. Customers should review the terms of any relevant third-party provider where those terms are material to their use of AI functionality.

We do not claim “zero data retention” by AI providers, and we do not represent that enterprise data is never processed by an AI provider or never used for model improvement, because those outcomes depend on the provider and configuration involved. Where specific handling commitments are required, they should be addressed in a written agreement.

AI-generated output may be inaccurate or incomplete. Output should be reviewed by appropriately qualified personnel before being relied upon for consequential decisions.

8. How We Use Information

We use information for purposes including:

  • Providing, operating, maintaining, and improving AEOS QUANTUM™ and aeosq.com.
  • Creating and administering accounts, organizations, workspaces, roles, and permissions.
  • Authenticating users and maintaining session integrity.
  • Executing platform functionality requested by a customer, including Digital Labor™, workflows, knowledge retrieval, and governance workflows.
  • Maintaining audit, approval, and governance records where the platform is configured to create them.
  • Responding to enterprise inquiries, support requests, and other communications.
  • Billing, subscription administration, and account management.
  • Detecting, investigating, and preventing security incidents, fraud, abuse, and misuse.
  • Complying with legal obligations, enforcing agreements, and establishing or defending legal claims.

10. Organizations, Workspaces and Access Controls

AEOS QUANTUM™ is designed around organization and workspace boundaries. Access to platform content and functionality is designed to follow organization membership, workspace membership, and assigned roles and permissions.

Administrators of an organization may be able to view, manage, configure, export, or delete information within their organization or workspaces, including information associated with their users. Individuals using the platform under an organization's account should direct requests relating to that organization's data to their administrator in the first instance.

We describe these boundaries at a functional level only. We do not make cryptographic isolation claims in this Policy.

11. Digital Labor™ and Platform Processing

Digital Labor™ workers, Skill Systems™, orchestration, and workflow functionality operate on configuration and data provided or connected by the customer, within the permissions the customer assigns. Execution may generate operational records such as run metadata, action intents, approval decisions, and audit entries, which are designed to be reviewable by the accountable organization.

The scope of processing performed by these capabilities depends on the customer's configuration, the integrations enabled, and the instructions provided.

12. Sharing and Disclosure

We may disclose information:

  • To service providers and subprocessors that support platform hosting, authentication, storage, communications, analytics where used, AI functionality, and payment processing.
  • Within a customer's organization, in accordance with configured roles, permissions, and administrator rights.
  • To third-party services that a customer connects or authorizes through an integration, in accordance with that configuration.
  • Where required by law, legal process, or a lawful governmental request, or to protect rights, safety, security, or property.
  • In connection with a corporate transaction such as a merger, acquisition, financing, or asset transfer, subject to applicable law.
  • With consent or at your direction.

13. Third-Party Service Providers

We rely on third-party infrastructure and service providers to operate AEOS QUANTUM™, including cloud hosting and application delivery, database and authentication services, email delivery, AI model providers, and, where applicable, payment providers. Providers are engaged to process information for the purposes for which they are retained.

We do not represent that every provider offers identical security, privacy, retention, or data-residency controls. Where a customer requires specific provider commitments, those should be addressed in a written agreement.

14. Enterprise Data and Customer Instructions

Depending on the processing activity, applicable law, the customer agreement, and the context, AexoreX may act as a service provider, processor, controller or business, or in another legally recognized role. No single classification applies to every customer, jurisdiction, or processing activity.

In general, where we process enterprise customer data to deliver the platform to a customer, we do so on the customer's behalf and consistent with the customer's instructions and applicable agreement. Where we process information for our own purposes — for example, account administration, billing, security, or operating our website — we may act in a controller or business capacity where those concepts apply.

15. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide and support the platform, maintain security and platform integrity, resolve disputes, comply with legal and regulatory obligations, enforce agreements, and maintain legitimate business records.

Retention of enterprise customer data may be governed by contractual terms, customer configuration, and administrator actions where applicable. Certain records, including backups, audit entries, and logs, may persist for a period after deletion in the ordinary course of system operation.

16. Security

We use reasonable and appropriate technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction. These measures may include access controls, permissioned data access, authentication controls, encryption in transit where technically available, logging, and monitoring, implemented where applicable and depending on configuration.

No internet-based or cloud-hosted system can be guaranteed to be completely secure. We do not represent that our measures are impenetrable, and this Policy makes no certification, attestation, or absolute security guarantee. Certifications and formal attestations are published only if and when they are obtained.

17. International Data Transfers

AexoreX Systems LLC is based in the United States. Information may be processed or stored in the United States or in other jurisdictions where we or our service providers operate, which may have data protection rules that differ from those in your location.

Where a transfer mechanism is required by applicable law, we seek to rely on an appropriate mechanism. We do not represent that hosting is limited to any single country unless that has been specifically agreed in writing.

18. U.S. State Privacy Rights

Several U.S. states provide privacy rights to their residents. Where such a law applies to our processing, residents may have rights to access, correct, delete, or obtain a portable copy of personal information, to opt out of certain processing where legally applicable, and to be free from unlawful discrimination for exercising those rights.

Not every state law applies to every business or to every processing activity. Rights described here apply where and to the extent required by applicable law, and may be subject to verification, exemptions, and limitations. Where we process personal information on behalf of an enterprise customer, we will generally refer a request to that customer.

19. California Privacy Rights

Where the California Consumer Privacy Act, as amended, applies, California residents may have rights to know and access personal information collected about them, to request correction, to request deletion, to obtain a portable copy, to limit the use of sensitive personal information where applicable, and to opt out of any “sale” or “sharing” of personal information as those terms are defined by that law.

We do not sell personal information for money, and we do not knowingly share personal information for cross-context behavioral advertising. If our practices change in a manner that triggers an opt-out obligation, we will provide the required mechanism and update this Policy.

California residents may exercise applicable rights using the contact details in the Privacy Requests section. An authorized agent may submit a request where permitted, subject to verification.

20. Virginia Privacy Rights

Where the Virginia Consumer Data Protection Act applies, Virginia residents may have rights to confirm whether we process their personal data and to access it, to correct inaccuracies, to request deletion, to obtain a copy in a portable format where applicable, and to opt out of targeted advertising, sale of personal data, or certain profiling, where those activities occur.

Virginia residents may appeal a decision regarding a request by replying to our response or contacting us using the details below. Where an appeal is denied, applicable law may permit a complaint to be submitted to the Virginia Attorney General.

21. Other Jurisdictional Rights

Residents of other U.S. states or of jurisdictions outside the United States may have comparable rights under applicable law, which may include access, correction, deletion, portability, objection, restriction, withdrawal of consent, and the right to lodge a complaint with a supervisory authority. We honor such rights where they apply to our processing.

22. Cookies and Similar Technologies

aeosq.com and the platform use cookies, local browser storage, and similar technologies. These are used primarily for essential functionality, authentication and session management, preference persistence, and security and abuse prevention.

Where product-analytics or performance measurement is enabled, coarse interaction events may be recorded. Our analytics implementation is designed to exclude personally identifying form values and to record route- and feature-level identifiers only. Where required by applicable law, consent will be obtained before non-essential technologies are used.

Most browsers allow cookies and storage to be blocked or cleared. Disabling essential or authentication-related storage may prevent parts of the platform from functioning.

23. Children's Privacy

AEOS QUANTUM™ is intended for businesses and professional users. It is not directed to children, and we do not knowingly collect personal information from children. If we learn that we have collected such information contrary to applicable law, we will take appropriate steps to delete it.

25. Your Choices

You may update certain account information through the platform where that functionality is available, manage cookies and browser storage through your browser, and opt out of non-essential communications using the mechanism provided in those communications. Administrative and transactional messages relating to your account or the platform may still be sent.

Where you use AEOS QUANTUM™ under an organization's account, certain choices may be controlled by that organization.

26. Privacy Requests

Privacy requests relating to AEOS QUANTUM™ may be submitted through the enterprise contact channels published on this site, or through the corporate contact channels published at aexorex.com. We may need to verify your identity and, where a request concerns an enterprise customer's data, we will generally refer the request to that customer.

Security vulnerability reports should be submitted through the security reporting channel published by AexoreX rather than through privacy channels, so that they can be triaged appropriately.

27. Enterprise Agreements and Data Processing Terms

Enterprise customers may have additional or differing rights and obligations under their customer agreement, order form, enterprise terms, or any data processing terms executed with AexoreX. Where such an agreement conflicts with this Policy in respect of enterprise customer data, the agreement governs to the extent of the conflict.

Where a customer requires specific data processing terms, subprocessor commitments, residency arrangements, or retention terms, those should be requested and agreed in writing.

28. Changes to this Privacy Policy

We may update this Policy from time to time to reflect changes to the platform, our practices, or applicable law. The effective date above indicates when this version took effect. Material changes will be indicated through this page and, where appropriate, other reasonable means. Continued use of the platform after an update constitutes acknowledgment of the revised Policy to the extent permitted by law.

29. Contact Information

AexoreX Systems LLC — operator of AEOS QUANTUM™. Corporate information is published at aexorex.com. Platform enterprise contact channels are published on this site, including the enterprise inquiry form.

For enterprise privacy and procurement review, use the enterprise contact form or the corporate channels at aexorex.com.