GDPR & CCPA Compliant

Privacy Policy & Data Protection

Your privacy is fundamental to our mission. This comprehensive policy explains how we collect, use, and protect your personal data in compliance with global privacy regulations including GDPR, CCPA, and other applicable laws.

Last updated: January 15, 2025
Effective: January 15, 2025

What Data We Collect

Account Information

Name, email address, company information, billing details, and profile preferences you provide when creating an account.

Usage Data

Information about how you interact with our platform, including feature usage, workflow patterns, and performance metrics.

Technical Data

IP addresses, browser types, device information, and system logs necessary for platform security and optimization.

Communication Data

Records of your communications with our support team, feedback, and survey responses.

How We Use Your Data

Service Provision

To provide, maintain, and improve our AI automation platform and deliver the services you request.

Personalization

To customize your experience, recommend relevant AI agents, and optimize workflows for your specific needs.

Security & Fraud Prevention

To detect, prevent, and respond to security threats, fraudulent activities, and unauthorized access attempts.

Communication

To send service updates, security alerts, and respond to your inquiries with your explicit consent.

Data Sharing & Disclosure

Third-Party Services

We share minimal necessary data with trusted service providers for payment processing, analytics, and infrastructure management.

Legal Compliance

We may disclose information when required by law, court order, or to protect our rights and the safety of our users.

Business Transfers

In the event of a merger or acquisition, user data may be transferred as part of the business assets with continued privacy protection.

No Data Sales

We never sell, rent, or trade your personal information to third parties for marketing purposes.

Data Storage & Security

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption with regularly rotated keys.

Access Controls

Strict access controls ensure only authorized personnel can access user data on a need-to-know basis.

Data Centers

Data is stored in SOC 2 Type II certified data centers with 24/7 monitoring and physical security measures.

Backup & Recovery

Regular backups are maintained with the same security standards to ensure data availability and integrity.

Your Privacy Rights

Access Rights

You can request a copy of all personal data we hold about you in a structured, machine-readable format.

Correction Rights

You can update, correct, or modify your personal information at any time through your account settings.

Deletion Rights

You can request deletion of your personal data, subject to legal retention requirements and legitimate business needs.

Portability Rights

You can export your data and transfer it to another service provider in standard formats.

Cookies & Tracking

Essential Cookies

Required for platform functionality, authentication, and security. These cannot be disabled without affecting service operation.

Analytics Cookies

Help us understand platform usage patterns to improve user experience. You can opt-out through your browser settings.

Preference Cookies

Remember your settings and preferences to provide a personalized experience across sessions.

Third-Party Cookies

Limited use of trusted third-party cookies for payment processing and customer support functionality.

Data Retention Periods

We retain your data only as long as necessary for the purposes outlined in this policy

Account Data
Duration of account + 7 years for legal compliance
Usage Logs
24 months for platform optimization
Security Logs
12 months for threat monitoring
Support Communications
3 years for service improvement
Billing Records
10 years for tax and audit purposes
Marketing Data
Until consent withdrawal or 2 years of inactivity

Privacy Contact Information

Have questions about your privacy rights or this policy? We're here to help.

Data Protection Officer

For data protection inquiries and privacy rights requests

dpo@autopilot.monster

Legal Department

For legal compliance and policy questions

legal@autopilot.monster

Security Team

For security-related privacy concerns

security@autopilot.monster

Important Legal Notice

This privacy policy is governed by the laws of Delaware, United States. For users in the European Union, our GDPR representative can be contacted at gdpr-rep@autopilot.monster. We respond to privacy rights requests within 30 days.