AEO Digital ("Company," "we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and otherwise process personal data when you visit our website, use our Services, install and use our Chrome Extension, contact us, or submit information through our Contact Forms.
This Privacy Policy should be read together with our Terms of Service. In case of conflict, the more restrictive provision applies.
1. Introduction and Scope
1.1 Overview
This Privacy Policy applies when you visit https://www.aeodigital.ai/, use our Services, install and use our Chrome Extension, contact us through any communication channel, or submit information through our Contact Forms.
1.2 Company Information
- Name: Glocify Technologies Private Limited
- Location: Sahibzada Ajit Singh Nagar, Punjab, India
- Website: https://www.aeodigital.ai/
- Email: work@aeodigital.ai
- Phone: +1 (541) 230 7066
1.3 Who This Applies To
This Privacy Policy applies to all users of our website and Services, regardless of location. Special provisions apply for users in the EU/EEA (GDPR) and California (CCPA).
1.4 Controller and Processor
For the purposes of data protection law, Glocify Technologies Private Limited is the Controller of personal data. We use third-party Processors to process data on our behalf (outlined in Section 6).
1.5 Relationship to Terms of Service
This Privacy Policy should be read together with our Terms of Service. In case of conflict, the more restrictive provision applies.
2. Information We Collect
2.1 Information You Provide Directly
2.1.1 Contact Form Information
When you submit our Contact Form, we collect:
- First and Last Name (required)
- Email Address (required)
- Phone Number (optional)
- Company Name (optional)
- Inquiry Details/Message (required)
- Any other information you choose to provide
2.1.2 Email Communications
If you email us directly, we collect:
- Your email address
- The content of your message
- Any attachments you send
- Metadata about the communication (timestamp, etc.)
2.1.3 Phone Communications
When you call us, we may record:
- Your phone number
- Call date and time
- Content of conversation (if recorded; notice will be provided)
2.1.4 Service Requests
For formal service engagements, we may collect:
- Business information
- Website details
- Project specifications
- Payment and billing information (if applicable)
2.1.5 Feedback and Surveys
If you participate in surveys or provide feedback, we collect:
- Responses to surveys
- Feedback content
- Your contact information (if provided)
2.2 Information Automatically Collected
2.2.1 Website Interaction Data
When you visit our website, we automatically collect:
- Device information: device type, operating system and version, browser type and version, and device identifiers
- Network information: IP address, internet service provider (ISP), and internet connection type
- Behavior information: pages visited and viewed, time spent on each page, links clicked, scroll depth, referring website/source, search terms used to find us, and exit pages
2.2.2 Geographic Data
- Approximate location based on IP address
- Country and city level (anonymized)
- Time zone
- Latitude/longitude (city-level accuracy only)
2.2.3 Log Files
Our servers automatically log:
- Access logs (pages accessed, timestamps)
- Error logs (technical errors encountered)
- Security logs (unauthorized access attempts)
- Performance metrics
- Request duration and response times
2.3 Cookies and Tracking Technologies
2.3.1 Cookies
Cookies are small data files stored on your device. We use session cookies (deleted when you close the browser), persistent cookies (stored for extended periods), and third-party cookies (placed by analytics partners).
2.3.2 Types of Cookies Used
- Essential cookies: required for website function (session identification, security tokens). Retention: session duration. These cannot be refused without affecting site function.
- Functionality cookies: remember your preferences such as language or layout. Retention: up to 1 year. You may refuse them, but some features may not work.
- Analytics cookies: help us understand how you use our site. Retention: up to 2 years. You may refuse them using opt-out mechanisms.
- Marketing/advertising cookies: personalize ads and marketing. Retention: up to 2 years. You may refuse them using opt-out mechanisms.
2.3.3 Other Tracking Technologies
- Pixels/web beacons: tiny images that track page activity
- Local storage: browser storage similar to cookies
- Server-side tracking: data collected via analytics platforms
- Device fingerprinting: identifying devices through characteristics
2.4 Third-Party Data Collection
2.4.1 Analytics Data
When you visit our site, these third parties collect data:
- Google Analytics: page views and navigation, device and browser info, geographic location, time on site and bounce rate, traffic sources and referrers
- Google Tag Manager (GTM): deployment of tracking codes, event tracking data, custom metrics
- Google Search Console: search queries that drive traffic, click-through rates, average position in search results, device and location data
- Microsoft Clarity: session recordings (anonymized), page interaction heatmaps, click tracking, scroll tracking
These services collect data through tracking pixels, cookies, and JavaScript. See Section 6 for each service's privacy policy.
2.5 Information from Third Parties
2.5.1 Service Providers
We may receive information from Odoo CRM (when you submit a contact form), email service providers, payment processors, and customer support platforms.
2.5.2 Business Partners
Information may come from partners or referral sources.
2.5.3 Publicly Available Sources
We may collect information from public business directories, social media profiles, search engines, and news articles.
3. How We Use Your Information
3.1 Service Delivery and Operations
We use your information to:
- Respond to your inquiries and requests
- Provide and maintain the Services
- Process and fulfill service requests
- Communicate with you about your account or services
- Send transactional emails (confirmations, receipts, etc.)
- Troubleshoot technical issues
- Provide customer support
3.2 Lead Management
Contact Form information is used to:
- Identify and qualify potential clients
- Follow up on service inquiries
- Manage leads in our Odoo CRM system
- Send marketing emails about our services (with consent)
- Track and analyze lead quality and sources
3.3 Analytics and Improvement
We analyze data to:
- Understand how users interact with our website
- Identify popular content and features
- Improve website performance and user experience
- Fix technical issues and bugs
- Optimize page load times
- Analyze traffic patterns and trends
3.4 Marketing and Business Development
We use your information to:
- Send promotional emails about our services
- Create targeted marketing campaigns
- Conduct market research
- Develop new products/services
- Conduct A/B testing
- Create user segments for personalization
3.5 Legal Compliance and Protection
We may use your information to:
- Comply with legal obligations
- Enforce our Terms of Service
- Prevent fraud and abuse
- Protect our legal rights
- Respond to lawful requests from authorities
- Maintain security and prevent unauthorized access
3.6 Legitimate Business Interests
We process data for:
- Improving our business operations
- Developing new services
- Conducting business analytics
- Protecting against fraud
- Advertising and marketing
- Customer retention and relationship management
3.7 Consent-Based Uses
Where we request your consent, we use data for:
- Marketing emails and campaigns
- Personalized recommendations
- Analytics beyond what's necessary for operations
- Retargeting advertisements
- Any other use you explicitly consent to
4. Legal Basis for Processing (GDPR Compliance)
4.1 Legal Basis
Under GDPR, we process personal data based on the following legal bases:
4.1.1 Consent (Article 6(1)(a))
Used for marketing emails (with express consent), analytics beyond the necessary level, personalization features, and retargeting advertisements. You can withdraw consent at any time.
4.1.2 Contract Performance (Article 6(1)(b))
Used for responding to your inquiries, providing Services, executing service agreements, and processing transactions.
4.1.3 Legal Obligation (Article 6(1)(c))
Used for compliance with laws, tax obligations, regulatory requirements, and court orders.
4.1.4 Legitimate Interests (Article 6(1)(f))
Used for analytics and improvements, marketing and business development, fraud prevention, security and system administration, and website performance. Our legitimate interests do not override your fundamental rights. We conduct impact assessments before processing.
4.1.5 Vital Interests (Article 6(1)(d))
Used only in life/death situations (rare).
4.1.6 Public Task (Article 6(1)(e))
Not applicable to our business.
4.2 Special Category Data
We do not collect Special Category data (racial origin, political opinions, religious beliefs, genetic data, biometric data, health data, etc.) unless you voluntarily provide it. We process any such data only with explicit consent.
4.3 Automated Decision-Making
We do not use fully automated decision-making for significant life decisions. We may use automated personalization for content recommendations.
5. Data Sharing and Disclosure
5.1 Internal Sharing
Personal data is shared within the Company on a need-to-know basis with the customer service team (for inquiry responses), marketing team (for lead management and marketing), operations team (for service delivery), and management (for business purposes).
5.2 Service Providers and Processors
We share data with third parties who process it on our behalf:
- Odoo CRM: lead and inquiry management, including contact info, inquiry details, and communication history. A Data Processing Agreement is in place.
- Google Analytics: website usage analysis of anonymized visit data and device info. Google's Privacy Policy applies.
- Email service providers: communication delivery, including email addresses and message content. Service agreements are in place.
- Web hosting providers: server infrastructure for website data and server logs. Service agreements are in place.
5.3 Business Transfers
We may share your information in connection with a merger or acquisition of the Company, sale of Company assets, bankruptcy or reorganization, or business succession. In such cases, acquiring parties must agree to maintain privacy protections.
5.4 Legal Requirements
We may disclose information when required by court orders or subpoenas, government agencies, law enforcement, regulatory authorities, or legal proceedings.
5.5 Protection of Rights
We may disclose information to protect Company rights and property, prevent fraud or abuse, enforce Terms of Service, respond to security threats, or protect public safety.
5.6 Aggregated and Anonymized Data
We may share aggregated or anonymized data that cannot identify individuals. This data may be provided to business partners, used for research, shared for analytics, or published in reports.
5.7 Third-Party Marketing
We do not sell your personal data to unrelated third parties for marketing purposes without explicit consent.
6. Third-Party Services and Processors
6.1 Google Services
6.1.1 Google Analytics
Purpose: website traffic and user behavior analysis. Data collected includes anonymized IP address, pages visited, time on site, device and browser info, geographic location (city level), and referral source. Retention: up to 26 months.
Opt-out options include:
- Google Analytics Opt-out Browser Add-on
- Browser privacy settings
- Google ads technologies
Privacy Policy: https://policies.google.com/privacy. Data processing is covered by Google Standard Contractual Clauses.
6.1.2 Google Tag Manager (GTM)
Purpose: deployment and management of tracking codes. Data collected: event and conversion data. GTM itself does not collect data; it manages other data collection. Privacy Policy: https://policies.google.com/privacy.
6.1.3 Google Search Console
Purpose: search performance and indexation monitoring. Data collected includes search queries, impressions and click-through rates, average position in search results, and geographic and device data. Privacy Policy: https://policies.google.com/privacy.
6.2 Microsoft Clarity
Purpose: session recording and interaction heatmaps. Data collected includes anonymized session recordings, click tracking, scroll depth, page interactions, and device info. Retention: 24 months by default.
Privacy protections include:
- Automatically masks passwords and email addresses
- IP addresses not stored
- Recording can be disabled for sensitive pages
Privacy Policy: https://privacy.microsoft.com/. Opt-out controls are available in the Clarity dashboard. Data processing uses Microsoft Standard Contractual Clauses.
6.3 Odoo CRM
Purpose: lead management and customer relationship management. Data collected includes contact information from Contact Forms, communication history, inquiry and lead details, and any additional information you provide. Data is sent upon submission of a Contact Form on our website and when you request services. Retention: 7 years for business records.
Privacy Policy: odoo.com/privacy. A Data Processing Agreement is in place. Odoo acts as a Data Processor on our behalf.
6.4 Your Rights with Processors
All processors have agreed to:
- Process data only per our instructions
- Implement appropriate security measures
- Comply with data protection laws
- Provide data subject assistance
- Notify us of breaches
- Delete or return data upon request
6.5 Emerging Services
As our business evolves, we may use additional services. Updates will be made to this policy and posted on our website.
7. Cookies and Tracking Technologies
7.1 What Are Cookies?
Cookies are small text files placed on your device when you visit our website. They can be session cookies (deleted when you close your browser), persistent cookies (stored on your device for extended periods), first-party cookies (placed by our website), or third-party cookies (placed by partners like Google Analytics).
7.2 Why We Use Cookies
- Website functionality (essential)
- User preferences (functional)
- Performance monitoring (analytics)
- Marketing and personalization (marketing)
- Security and fraud prevention (security)
7.3 Controlling Cookies
7.3.1 Browser Settings
Most browsers allow you to block all cookies, block third-party cookies, clear cookies upon browser close, or receive warnings before cookies are set.
- Chrome: manage cookies in Chrome
- Firefox: enable and disable cookies
- Safari: manage cookies in Safari
- Edge: manage cookies in Edge
7.3.2 Cookie Consent
Upon first visit, you should see a cookie consent banner. You can accept all cookies, reject non-essential cookies, customize cookie preferences, or later modify choices in privacy settings.
7.3.3 Opt-Out Tools
- Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout
- Browser Do Not Track: available in most browsers
- Privacy-focused extensions: available for all major browsers
7.4 Impact of Disabling Cookies
Some website features may not work properly if cookies are disabled: login functionality may be impaired, preferences may not be saved, some interactive features may not function, and analytics will be incomplete.
7.5 Third-Party Cookie Information
Third parties that place cookies on our site include Google (Analytics, GTM, Search Console), Microsoft (Clarity), content delivery networks (CDNs), and service providers. Each has their own cookie management preferences.
8. Your Privacy Rights
8.1 Universal Rights (All Users)
8.1.1 Right to Access
You have the right to request and receive a copy of your personal data that we hold. We will provide it in a clear, understandable format.
8.1.2 Right to Correct
You can request correction of inaccurate or incomplete information.
8.1.3 Right to Delete (Right to be Forgotten)
You can request deletion of your data, subject to legal retention requirements and legitimate business needs.
8.1.4 Right to Data Portability
You can request your data in a portable, machine-readable format to move it to another service.
8.1.5 Right to Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time.
8.1.6 Right to Opt-Out of Marketing
You can opt-out of promotional emails by:
- Clicking "Unsubscribe" in any marketing email
- Contacting us at work@aeodigital.ai
- Using the Contact Form at aeodigital.ai/contact-us
8.1.7 Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority (if applicable in your country).
8.2 GDPR Rights (EU/EEA Users Only)
Users in the European Union and European Economic Area have these additional rights under GDPR:
- Right to restrict processing: you can request that we limit our processing of your data.
- Right to object: you can object to processing based on legitimate interests or direct marketing.
- Right to human review: you have the right to human review of automated decision-making.
- Right to complaint to a supervisory authority: find your authority
- No discrimination: we will not discriminate against you for exercising your rights.
8.3 CCPA Rights (California Users Only)
California residents under the California Consumer Privacy Act (CCPA) have these rights:
- Right to know what personal information we collect, use, and share
- Right to delete personal information we've collected
- Right to opt-out of the "sale" or "sharing" of personal information
- Right to correct inaccurate information
- Right to limit use to what's necessary for service provision
- No discrimination for exercising rights
8.4 Other US State Laws
If you live in Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Louisiana, Missouri, Montana, New Hampshire, New Jersey, Nevada, Tennessee, Texas, Utah, Virginia, or Wyoming, similar rights may apply under your state's privacy laws.
8.5 How to Exercise Your Rights
8.5.1 Submitting a Request
To exercise your rights, submit a request to:
- Email: work@aeodigital.ai
- Contact Form: aeodigital.ai/contact-us
- Mail: Glocify Technologies Private Limited, Sahibzada Ajit Singh Nagar, Punjab, India
Include your full name, email address, the specific right you're exercising, and details of your request.
8.5.2 Verification
We may request information to verify your identity before processing requests. This is to protect your privacy and prevent unauthorized access.
8.5.3 Response Timeline
- EU/EEA (GDPR): 30 days (can extend 60 days for complex requests)
- California (CCPA): 45 days (one 45-day extension available)
- Other: reasonable timeframe, typically 30 days
8.5.4 No Fees
We will not charge fees for reasonable requests. We may charge for manifestly unfounded or excessive requests.
8.5.5 Authorized Representatives
If you have an authorized representative (parent, guardian, attorney), they can submit requests on your behalf with proper documentation.
9. Data Security
9.1 Security Measures
We implement appropriate technical and organizational security measures.
Technical Measures
- SSL/TLS encryption for data in transit
- HTTPS on all website pages
- Firewalls and intrusion detection
- Regular security updates and patches
- Database encryption for data at rest
- Secure password hashing
- Multi-factor authentication for admin access
Organizational Measures
- Limited access controls (need-to-know basis)
- Employee confidentiality agreements
- Data protection training
- Vendor security assessments
- Incident response procedures
- Regular security audits
9.2 Limitations
While we strive to protect your information, no system is 100% secure. Risks include internet transmission interception, unauthorized access despite safeguards, security vulnerabilities in third-party services, insider threats, and advanced cyber attacks.
Your responsibility includes:
- Keep passwords strong and confidential
- Do not share account information
- Report suspicious activity
- Use secure networks
- Update your device software
9.3 Breach Notification
In case of a data breach, we will:
- Notify affected individuals as required by law
- Notify relevant authorities
- Provide information about the breach
- Suggest protective measures
- Follow GDPR notification requirements (72 hours)
10. Data Retention
10.1 Retention Principles
We retain data only as long as necessary for:
- Fulfilling the purposes for which it was collected
- Complying with legal obligations
- Resolving disputes
- Protecting our legal rights
- Running our business operations
10.2 Specific Retention Periods
10.2.1 Contact Form Information
- Active lead period: 12 months or until converted/declined
- CRM records: 7 years (business record requirements)
- Odoo CRM: 7 years
- Communication history: 7 years
10.2.2 Email Subscribers
- Active subscribers: duration of subscription
- Unsubscribed users: 30 days after unsubscription, then deletion
- Bounced emails: 6 months, then deletion
10.2.3 Website Analytics Data
- Google Analytics: up to 26 months (configurable)
- Microsoft Clarity: 24 months by default
- Server logs: 12 months
- Session data: 30 days
10.2.4 Cookies
- Session cookies: deleted at session end
- Persistent cookies: up to 2 years
- Analytics cookies: up to 24 months
- Marketing cookies: up to 24 months
10.2.5 Account Information
- Active accounts: duration of account plus 24 months
- Deleted accounts: 24 months for business records
- Service records: 7 years
10.2.6 Payment Records (if applicable)
- Transaction records: 7 years (tax and accounting requirements)
- Payment methods: deleted after transaction completion
10.2.7 Server Logs
- Access logs: 12 months
- Error logs: 12 months
- Security logs: 24 months
10.3 Deletion and Anonymization
Upon retention period expiration, data is:
- Permanently deleted, or
- Anonymized (removed of identifying information), or
- Archived for legal compliance
Requests for earlier deletion can be submitted per Section 8.
11. Chrome Extension Privacy
11.1 Extension Purpose
The AEO Digital Chrome Extension provides website audit and testing functionality for users who install it in their browser.
11.2 Data Collection by Extension
The extension operates with a privacy-first approach. The extension does not:
- Collect or send user data to our servers
- Collect browsing history
- Track websites visited
- Store analysis results
- Transmit analyzed website data to our servers
- Require an account or login
- Use cookies or persistent storage
11.3 Local Analysis Only
All analysis performed by the extension:
- Occurs locally on your device
- Uses only data you explicitly choose to analyze
- Is processed in your browser only
- Is not transmitted anywhere
- Is deleted after analysis completion
- Requires no internet connection to run
11.4 Extension Permissions
- Active tab permission: allows the extension to see the website you're currently viewing, used to analyze the current page only. Data stays on your device.
- Tabs permission: allows the extension to identify active tabs for local identification only. No data is sent to servers.
- Content script injection: allows the extension to inject analysis code into webpages. Analysis runs locally in your browser and no results are transmitted.
- Storage permission (if applicable): used for local preferences/settings only. No data is shared with external services.
11.5 Extension Privacy Policy
The extension is also governed by Google Chrome Web Store Terms of Service, Google Chrome Privacy Policy, our Terms of Service, and this Privacy Policy.
11.6 Extension Settings
Users can:
- Review all permissions granted
- Revoke permissions any time
- Disable the extension
- Uninstall the extension
- Clear extension data
11.7 Updates and Changes
If we modify the extension's data collection practices, we will notify users before implementation, provide a 30-day notice period, allow users to accept/reject updated permissions, and allow users to uninstall if they disagree.
12. Children's Privacy
12.1 Age Restriction
AEO Digital's website and services are not directed to children under the age of 18. We do not knowingly collect personal information from anyone under 18.
12.2 Parental Involvement
If you are under 18, do not use this Service, do not submit any information, and ask a parent or guardian for permission.
12.3 Compliance with Child Protection Laws
We comply with the Children's Online Privacy Protection Act (COPPA) in the US, the General Data Protection Regulation (GDPR) in the EU, and all applicable child protection laws.
12.4 Accidental Collection
If we discover we've collected information from anyone under 18, we will immediately delete such information, will not use such information, and will not retain it for any purpose.
12.5 Parental Concerns
If you are a parent or guardian with concerns, contact us at work@aeodigital.ai. We will address your concerns promptly and may request proof of guardianship.
13. International Data Transfers
13.1 Transfer Mechanisms
The Company operates from India and stores data in India and potentially other locations. When we transfer data internationally, we use Standard Contractual Clauses (SCCs) approved by the EU Commission, adequacy decisions when applicable, and explicit consent with clear notification.
13.2 Transfers to the US
If data is transferred to US-based processors (Google, Microsoft), transfers are governed by Standard Contractual Clauses, processor privacy policies, and legal safeguards in US law.
13.3 Transfers to India
As the Company is based in India, data is stored and processed there. India's data protection framework applies.
13.4 Legal Process Requests
Non-EU users should note that data stored in India may be subject to legal requests from Indian authorities. EU users receive additional GDPR protections.
13.5 User Consent
By using the Service, you consent to:
- International data transfers
- Processing in different jurisdictions
- Applicable laws in those jurisdictions
14. California Privacy Rights (CCPA/CPRA)
14.1 California Consumer Privacy Act (CCPA)
If you are a California resident, you have rights under CCPA:
- Right to know categories of personal information collected, purposes for collection, sources of the data, and how data is used and shared
- Right to delete personal information, except data necessary to complete a transaction, required for legal obligations, needed for security, or needed to fulfill your explicit request
- Right to correct inaccurate information
- Right to limit use to providing Services, preventing fraud, and enabling service functionality
- Right to opt-out of sale of personal information and sharing of personal information for cross-context behavioral advertising
- Right not to be discriminated against, including denial of services, higher prices, or lower quality service for exercising your rights
14.2 California Privacy Rights Act (CPRA)
Additional rights under CPRA include:
- Right to correct information
- Right to limit automated decision-making
- Right to human review
- Right to deletion of inferences
- Additional opt-out rights
14.3 Shine the Light Law
California residents can request what information we've shared with third parties for their marketing. Submit requests as outlined in Section 8.5.
14.4 Data Sale/Sharing Disclosure
We do not sell personal information as defined by CCPA. We may share data with service providers who process it on our behalf. This is not a "sale."
14.5 Submitting CCPA Requests
Submit requests to work@aeodigital.ai or via the Contact Form. Response timeline: 45 days (one 45-day extension available). Please reference "CCPA Request" in your subject line.
15. EU/EEA User Rights (GDPR)
15.1 GDPR Applicability
Users in the European Union, European Economic Area, or Switzerland have rights under the General Data Protection Regulation (GDPR) and equivalent laws.
15.2 Data Protection Officer
Although not required for our business, we maintain data protection practices that meet GDPR standards. For GDPR inquiries, email work@aeodigital.ai and reference "GDPR Inquiry."
15.3 Legal Basis for Processing
We have identified our legal bases in Section 4. We maintain records of processing activities.
15.4 Data Protection Impact Assessment
For processing activities with high risk, we conduct Data Protection Impact Assessments (DPIAs) to assess risks and safeguards.
15.5 Data Processing Agreements
For all processors, we have Data Processing Agreements that include GDPR-required terms, Standard Contractual Clauses for international transfers, data subject assistance commitments, and breach notification obligations.
15.6 GDPR Rights (Detailed)
- Right of access: a copy of your personal data, information about how it's processed, and the scope of access free of charge
- Right to rectification: correct inaccurate or incomplete data. We'll inform third parties of corrections where applicable.
- Right to erasure: request deletion except where processing is necessary for the original purpose, legal obligations require retention, public interest reasons apply, or vital interests need the data
- Right to restrict processing: limit processing to storage only, specific uses, or while you contest legality
- Right to data portability: request your data in a portable, machine-readable format
- Right to object: object to processing based on legitimate interests, direct marketing, scientific or historical research, or statistical purposes
- Rights related to automated decision-making: human review and the right to contest decisions that produce legal effects
- Right to lodge a complaint with your national data protection authority: find your authority
15.7 International Transfers
For transfers outside the EEA, we use European Commission Adequacy Decisions (if applicable), Standard Contractual Clauses, and Binding Corporate Rules (if applicable).
15.8 Lawful Basis for Processing
We have outlined lawful bases in Section 4. Processing is not consent-dependent for essential services, but is necessary for contract performance, legal obligations, and legitimate interests.
15.9 Response to GDPR Requests
Timeline: within 30 days (extendable 60 days for complex requests). Cost: free (no charge unless the request is manifestly unfounded).
16. Changes to This Privacy Policy
16.1 Right to Update
We may update this Privacy Policy at any time to reflect changes in our practices, new features or services, legal requirement changes, or business needs.
16.2 Notification of Changes
For material changes:
- We'll provide notice via email to users with accounts
- We'll post prominent notice on our website
- We may require affirmative consent for some changes
- Notice period: 30 days before material changes take effect
16.3 Non-Material Changes
Minor updates may be made without notice, such as formatting improvements, clarifications, contact information updates, and correcting errors.
16.4 Your Acceptance
Continued use of the Service after notice constitutes acceptance of changes. If you disagree with changes, you may stop using the Service, request data deletion, or exercise your other privacy rights.
16.5 Version History
We maintain records of policy versions. Request historical versions at work@aeodigital.ai.
17. Contact and Data Protection
17.1 Contact Information
For privacy questions, data access requests, or concerns:
- Email: work@aeodigital.ai
- Phone: +1 (541) 230 7066
- Website: https://www.aeodigital.ai/
- Contact Form: aeodigital.ai/contact-us
- Mailing address: Glocify Technologies Private Limited, Sahibzada Ajit Singh Nagar, Punjab, India
17.2 Response Time
We aim to respond to all inquiries within 2–3 business days. For formal data subject requests (access, deletion, portability), we follow the timelines specified in Section 8.
17.3 Verification
We may request information to verify your identity before processing requests, to protect your privacy from unauthorized disclosure.
17.4 Data Protection Officer
While not legally required, we prioritize data protection principles. You can reach our data protection contact at the email address above.
17.5 Complaints and Escalation
If you're not satisfied with our response:
- Request escalation to our management
- File a complaint with your local data protection authority
- Contact your country's regulator
18. Acknowledgment
By using AEO Digital's website and services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
You further acknowledge:
- You understand how we collect and use your data
- You understand the third parties involved in data processing
- You understand your privacy rights and how to exercise them
- You understand the limitations of data security
- You consent to data processing as described herein
If you do not agree with this Privacy Policy, please do not use the Service.
Effective date: August 19, 2026. Next review scheduled: August 19, 2027. For formal requests, use the process outlined in Section 8.5.
