Global Privacy & Security Charter
This legally binding charter governs all data operations across our public domain (aetriumgroup.com) and our AI/Application Core (app.aetriumgroup.com). Engineered specifically for European Union (GDPR) and global enterprise security mandates.
In-Flight Zero Data Retention (ZDR)
APP.AETRIUMGROUP.COM CORE WARRANTY
Aetrium Core (app.aetriumgroup.com) guarantees strict In-Flight Zero Data Retention. When client payloads—including shipping manifests, corporate MSAs, financial PDFs, or proprietary datasets—are ingested for AI processing, they exist strictly within volatile, isolated RAM enclaves during inference.
Zero Model Training Covenant
LEGAL COVENANT AGAINST AI PROFILING
Under no circumstances are client inputs, documents, OCR extractions, or generated outputs ever used to train, fine-tune, validate, or benchmark generalized Foundation Models, public LLMs (including OpenAI, Anthropic, Mistral, Llama), or cross-tenant AI architectures.
01.Scope & Jurisdictional Authority
This Privacy & Security Charter applies to all digital ecosystems operated by Aetrium Group ("We", "Us", "Our"), specifically governing our primary corporate portal (aetriumgroup.com) and our sovereign AI platform application environment (app.aetriumgroup.com).
For enterprises and entities operating within the European Economic Area (EEA), European Union (EU), United Kingdom (UK), and Switzerland, this charter explicitly establishes our compliance with the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (FADP), and the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA).
02. Weaponized Zero Data Retention (ZDR) Architecture
Aetrium Core (app.aetriumgroup.com) is engineered from the silicon up to operate under strict In-Flight Zero Data Retention (ZDR) protocols. We recognize that European and global enterprise client documents—such as supply chain shipping manifests, corporate Master Services Agreements (MSAs), patient health records, proprietary source code, and confidential financial statements—require absolute sovereignty.
03.Lawful Basis of Processing & Data Minimization (GDPR Article 6)
We strictly adhere to the principle of Data Minimization (GDPR Article 5(1)(c)). We reject ad-tech surveillance, third-party behavioral retargeting, and unauthorized cross-site tracking across both our marketing site and application core.
Where processing of personal data occurs, it is conducted under the following lawful bases pursuant to GDPR Article 6:
- Contractual Necessity (Article 6(1)(b)): Processing essential technical telemetry, authentication session tokens, and direct project communications required to fulfill our 30-day velocity sprints and software deliverables.
- Legitimate Interests (Article 6(1)(f)): Monitoring edge-network performance, defending against Distributed Denial of Service (DDoS) attacks, enforcing API rate-limiting, and maintaining zero-trust system integrity.
- Explicit Consent (Article 6(1)(a)): When you voluntarily submit inquiries via our contact forms or opt-in to architectural newsletters. You maintain the right to withdraw consent at any time.
04. European Subject Data Sovereignty (GDPR Articles 12–23)
If you reside within the European Economic Area (EEA), UK, or California, you possess absolute sovereignty and non-negotiable rights regarding your personal information under statutory data protection laws:
Right of Access & Portability
You may request a comprehensive, structured, machine-readable export (JSON/CSV) of all metadata or account telemetry linked to your identity within 30 days.
Right to Cryptographic Erasure
You may exercise your "Right to be Forgotten" (GDPR Art. 17). We will execute an immediate cryptographic wipe of your contact records across all origin and backup shards.
Right to Rectification & Restriction
You maintain absolute authority to correct inaccurate organizational data or restrict specific automated processing streams without impacting contractual deliverables.
Right against Automated Profiling
Aetrium does not subject European subjects to legal or significant automated decision-making or behavioral profiling (GDPR Art. 22).
05.Cross-Border Data Transfers & Standard Contractual Clauses (SCCs)
To achieve sub-50ms latency across global corridors, Aetrium routes traffic through enterprise-grade edge networks (including Cloudflare, Vercel Edge, and AWS infrastructure). When personal data originating in the EEA, UK, or Switzerland is transferred to sub-processors outside those jurisdictions, it is protected by:
- European Commission Standard Contractual Clauses (SCCs): Executed across all sub-processor tiers pursuant to Commission Implementing Decision (EU) 2021/914.
- UK International Data Transfer Addendum (IDTA): Enforced for data originating within the United Kingdom.
- Data Transfer Impact Assessments (DTIAs): Continuous risk evaluation ensuring recipient jurisdictions maintain strict technical safeguards equivalent to EU standards.
06. Military-Grade Cryptographic Infrastructure
Aetrium secures all communication and data routing via state-of-the-art cryptographic standards:
In-Transit Encryption: All traffic between client terminals, aetriumgroup.com, and app.aetriumgroup.com is strictly encrypted using TLS 1.3 protocols enforcing Perfect Forward Secrecy (PFS) and HTTP Strict Transport Security (HSTS). Legacy protocols (TLS 1.1, TLS 1.2) are blocked at edge firewalls.
Zero-Trust Access Control: We enforce strict Role-Based Access Control (RBAC) and multi-factor hardware-key authentication across internal engineering teams. Site Reliability Engineers (SREs) cannot access client private environments or metadata without explicit multi-signature cryptographic authorization and permanent, immutable audit logging.
07.Cookie Sovereignty & First-Party Tokens
Aetrium does not deploy third-party advertising pixels (such as Meta Pixel, TikTok Pixel, or Google AdSense tracking scripts) across aetriumgroup.com or app.aetriumgroup.com.
We utilize only strictly necessary, first-party HttpOnly, Secure, SameSite=Strict session cookies and cryptographic verification tokens designed exclusively to maintain secure user state, prevent Cross-Site Request Forgery (CSRF), and preserve application security boundaries.
Data Protection Officer (DPO) Inquiries
To exercise your GDPR subject rights, request a formal Data Processing Agreement (DPA) execution, or submit an enterprise security audit questionnaire, contact our dedicated compliance office.
Primary Dispatch: [email protected]