Legal Framework

Privacy Policy

At Epilytix, we treat data privacy and information security as primary engineering constraints. This policy details what data we collect, how it flows through our software architecture, and the rights you possess regarding your information.

Last updated: July 10, 2026
#DATA-COLLECTION

1. Information We Collect

We collect personal and technical information to deliver bespoke software architecture, ERP implementations, and digital consulting services. This falls into two primary categories:

  • Account & Inquiry Information: Name, professional email address, corporate telephone number, job title, company name, and specific project specification payloads when submitted via contact modules.
  • Automated Telemetry Data: IP addresses, browser agent specifications, operating system architectures, network origin metrics, session timestamps, and page engagement patterns.
  • Project Data: Client-provided mock data, schema details, or system parameters required for architectural blueprinting and early staging environment builds.
  • #DATA-PROCESSING

    2. Data Processing & Flow

    All data ingestion and processing workflows strictly adhere to localized security constraints. We utilize your data for the following specific purposes:

  • Architectural Engineering: Reviewing infrastructure requirements to formulate exact system schemas, Odoo configurations, and custom application designs.
  • Service Delivery & Communication: Sending project progress updates, sprint summaries, system access keys, deployment alerts, and responding to system support tickets.
  • Platform Optimization: Analyzing telemetry data to isolate runtime bottlenecks, optimize page layout load times, and guarantee global application performance.
  • We enforce a zero-sharing policy: we do not trade, sell, or rent personal or project data to third-party brokers under any circumstances.

    #COMPLIANCE

    3. Compliance & Global Regulations

    Our data handling practices are designed to align with major international data privacy frameworks:

  • General Data Protection Regulation (GDPR): For citizens within the European Economic Area (EEA), we process personal data under the lawful bases of contractual necessity and legitimate interest. We act as Data Controller for site telemetry, and Data Processor for client project data.
  • California Consumer Privacy Act (CCPA): We respect the privacy rights of California residents, providing complete transparency regarding the collection, business use, and non-sale of personal data.
  • Cross-Border Transfer: In accordance with standard contractual clauses (SCCs), any trans-border data flow is secured via 256-bit encryption protocols at rest and TLS 1.3 protocols in transit.
  • #SECURITY

    4. Security Architecture

    We implement defense-in-depth methodologies to protect personal data from unauthorized access or alteration:

  • Cryptographic Protocols: All data transmitted is protected by Transport Layer Security (TLS 1.3). Data at rest in our databases is encrypted using AES-256 standard protocols.
  • Network Segregation: Client staging platforms and live production servers are logically isolated, protected by industry-standard Web Application Firewalls (WAF) and multi-factor authorization gateways.
  • Access Control: Strict Role-Based Access Control (RBAC) ensures only authorized developers and systems engineers have limited visibility into project configurations.
  • #USER-RIGHTS

    5. Your Legal Rights

    Depending on your geographical jurisdiction, you possess specific rights concerning your personal information:

  • Right of Access: You have the right to request a structured copy of the personal information we hold in our active records.
  • Right to Erasure ('Right to be Forgotten'): You can request the permanent deletion of your contact records, provided there are no active service delivery contracts or legal retention mandates.
  • Right to Correction: You can request immediate correction of outdated or incorrect contact details and business profiles.
  • To exercise any of these compliance rights, please submit an official request to our desk at: epilytix.official@gmail.com.

    #SUB-PROCESSORS

    6. Authorized Sub-processors

    To maintain the high uptime and robust security of our web infrastructure, we integrate services from vetted global providers. These platforms act as sub-processors and maintain independent compliance regimes:

  • Hosting Infrastructure: Vercel Inc. and Amazon Web Services (AWS) for application hosting, assets distribution, and Edge Network delivery.
  • Staging Datastores: PostgreSQL and MongoDB server clusters for transaction records and temporary application staging configurations.
  • Analytics & Communications: Google Analytics and Email dispatch services for system metrics and contact response delivery.