Start a Project

Draft — not yet reviewed by an attorney

This document was drafted in-house as a starting point. It has not been reviewed or approved by a lawyer, and it is not legal advice. It must be reviewed by qualified counsel before Advanced Artificial Solutions LLC relies on it commercially.

Legal

Privacy Policy

Effective 1 September 2026 · Advanced Artificial Solutions LLC

Who we are

Advanced Artificial Solutions LLC ("AAS", "we", "us") operates this website and the customer portal available at https://aasinnovation.com. For any question about this policy or about information we hold, write to hello@aasinnovation.com.

What we collect

When you use the public website

Nothing that identifies you. This site carries no analytics, no advertising pixels and no third-party tracking scripts of any kind. Our web server keeps standard access logs — IP address, requested page, timestamp, browser user-agent — which are used to operate and secure the service and are retained for a limited period.

When you submit the contact form

We store what you tell us, which is:

  • your name, and company name if you give one
  • your email address, and phone number if you give one
  • the project category, budget range and timeline you select
  • the description of your project that you write
  • your IP address, browser user-agent and referring page
  • the fact and time of your consent

The technical details in that last pair of items are kept to investigate abuse of the form and to demonstrate that consent was given. They are not used to build a profile of you.

When you have a customer portal account

We store:

  • your name and email address
  • a cryptographic hash of your password — never the password itself
  • the organisation your account belongs to
  • sign-in events, including failed attempts, with time and IP address
  • a record of every file you download, with time and IP address

The sign-in and download records exist so that we — and you — can tell who accessed what. They are a security control, and we would not be able to answer "did someone else get into my account?" without them.

Why we are allowed to hold it

  • Your consent, for the contact form. You tick a box, and you can withdraw it at any time by asking us.
  • Performing a contract, for customer portal accounts — we cannot deliver your project files without an account to deliver them to.
  • Legitimate interests, for security logging and abuse prevention. We consider the interest in running a secure service to outweigh the modest privacy impact of recording sign-in attempts.

Cookies

We use exactly two cookies, both strictly necessary, and neither is used for tracking:

  • A session cookie, which identifies your browser session while you are signed in to the portal. It holds a random identifier and nothing else — your session data stays on our server.
  • A CSRF token cookie, which protects forms from being submitted by another website on your behalf.

Both are marked HttpOnly (unreadable by scripts) and SameSite, and are marked Secure when the site is served over HTTPS. Neither is set until you visit a page that needs it. Because we set no analytics or advertising cookies, there is no consent banner — there is nothing to consent to.

Who we share it with

We do not sell your information, and we do not share it for advertising. Information is disclosed only:

  • to service providers strictly necessary to operate the service — principally an email delivery provider, which handles the messages we send you
  • where we are required to by law

Where we engage a provider, they may process your information only on our instructions and only for the purpose we engaged them for.

How long we keep it

  • Contact enquiries: up to 24 months, then deleted.
  • Customer accounts and project records: for the life of the relationship, and for a reasonable period afterwards for legal and accounting purposes.
  • Security and download logs: up to 12 months.
  • Web server access logs: up to 90 days.

How we protect it

  • Passwords are hashed with a modern, salted, iterated algorithm — we cannot read them, and neither could anyone who obtained the database.
  • Customer files are stored outside the web root and are only ever served after a server-side authorisation check against your account.
  • Access to your organisation's data is restricted to your organisation. This is enforced by the database query itself, not by hiding links in the interface.
  • Traffic is encrypted in transit when the site is served over HTTPS.
  • Administrative access is limited to AAS staff who need it, and is logged.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If we become aware of a breach affecting your information, we will tell you.

Your rights

You may ask us to:

  • tell you what information we hold about you
  • correct anything that is wrong
  • delete your information, where we are not required to keep it
  • provide a copy in a portable format
  • stop using it for a particular purpose

Write to hello@aasinnovation.com. We will respond within 30 days. Depending on where you live, you may also have the right to complain to a data protection authority.

Children

This is a business service and is not directed at children under 13. We do not knowingly collect their information; if we learn that we have, we will delete it.

Changes

If we change this policy we will update the effective date above, and for material changes affecting portal customers we will notify you by email.

Tell us what you are trying to fix

The first conversation is thirty minutes, free, and has no pitch in it. We will tell you whether we can help, roughly what it would cost, and if the honest answer is that you do not need us, we will say that too.