Privacy Policy
This policy explains what personal information AetherStack Technologies collects, why we collect it, who we share it with, and what choices you have.
1. Overview
AetherStack Technologies (“AetherStack”, “we”, “us”) is a cloud infrastructure and DevOps engineering consultancy based in Austin, Texas. This policy covers our public website, our marketing communications, and our business relationships with clients and prospective clients.
We work with companies, not consumers. Most of the personal information we handle is basic business contact data — a name, a work email address, a job title — and we keep collection to what we need in order to answer an inquiry, run a project, or meet a legal obligation.
This policy does not cover data stored inside a client's own cloud environment. When we operate infrastructure on a client's behalf, that client decides what data is processed there. We act on their instructions under a separate services agreement and, where applicable, a data processing addendum.
2. Information We Collect
Information you provide. This includes:
- Contact details you send by email or through a consultation request — name, work email, company, role, and a phone number if you choose to include one.
- The content of your message, including any technical details you share about your infrastructure.
- Billing and account information for clients under contract.
- Records of our correspondence, meeting notes, and project documentation.
Information collected automatically. When you visit our website, our hosting and analytics tools record standard technical data: IP address, browser type and version, device type, referring page, pages viewed, and the time of your visit. Section 5 explains how cookies fit in.
Information from other sources. We may receive your details from a colleague who refers you, from a public professional profile such as LinkedIn, or from a business partner introducing a project.
We do not sell personal information, and we do not knowingly collect it from anyone under 16.
3. How We Use Information
We use the information described above to:
- Respond to inquiries, schedule consultations, and prepare proposals or scoping documents.
- Deliver contracted work — infrastructure assessments, migrations, platform engineering, and ongoing support.
- Manage the commercial relationship, including contracts, invoicing, and support requests.
- Understand how our website is used so we can improve its content and structure.
- Send occasional updates about our services to existing clients and to people who asked to hear from us. Every such message includes an unsubscribe link.
- Protect our systems against fraud, abuse, and unauthorized access.
- Meet accounting, tax, and other legal requirements.
We do not use your information to make automated decisions that produce legal effects for you, and we do not build advertising profiles.
4. Legal Bases and Business Purposes
Where the EU or UK General Data Protection Regulation applies to our processing, we rely on the following legal bases:
- Contract. Processing needed to enter into or perform a services agreement with you or your employer.
- Legitimate interests. Running and securing our business, responding to inquiries, and marketing our services to business contacts in a way that is proportionate and does not override your rights.
- Consent. Non-essential cookies and, where required, marketing email. You can withdraw consent at any time.
- Legal obligation. Retaining records we are required by law to keep.
For visitors in the United States, the equivalent framing is our business purposes: providing services, security, analytics, customer communication, and compliance.
5. Cookies and Tracking Technologies
Our website uses a small number of cookies. Essential cookies keep the site working and remember your cookie choice. Analytics cookies help us count visits and see which pages people read; they are set only after you accept them in our cookie banner, and you can decline without losing access to any part of the site.
Most browsers let you block or delete cookies through their settings, though blocking essential cookies may affect how the site behaves. Full details, including the categories we use, are in our Cookie Policy.
6. Data Sharing and Subprocessors
We share personal information only where there is a reason to. That includes:
- Service providers. Companies that host our website, deliver our email, run our analytics, hold our CRM records, and process payments. They act on our instructions and are bound by contract.
- Cloud platforms. Where a project requires it, we work within infrastructure operated by providers such as AWS and Microsoft Azure, under our client's account or our own.
- Professional advisers. Accountants, auditors, and lawyers, where their work requires it.
- Legal and safety reasons. When we are required to disclose information by law, or where disclosure is necessary to protect our rights, our clients, or the security of our systems.
- Business transfers. If AetherStack is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We would notify affected clients.
Some of these providers are located in the United States. Where we transfer personal data out of the EEA or the UK, we use Standard Contractual Clauses or another approved transfer mechanism.
7. Data Security
Access is granted on a least-privilege basis, administrative accounts require multi-factor authentication, data is encrypted in transit and at rest with our providers, and access to client environments is logged. Employees and contractors are bound by confidentiality terms and receive access only to what their role requires.
No system is completely secure, and we do not claim otherwise. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires it.
8. Data Retention
We keep personal information for as long as we need it for the purpose it was collected, then delete or archive it in line with our retention schedule. In practice:
- Inquiries that do not lead to a project: up to 24 months.
- Client records and project documentation: for the term of the engagement and up to 7 years afterwards, mainly for contractual and tax reasons.
- Financial and billing records: as required by US tax law, generally 7 years.
- Website analytics: aggregated after 14 months.
- Marketing contacts: until you unsubscribe, plus a suppression record so we do not contact you again.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights: to access the personal information we hold about you, to correct it, to delete it, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent.
California residents. Under the CCPA as amended by the CPRA, you may request disclosure of the personal information we have collected, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the statute, so there is no “Do Not Sell or Share” mechanism to use. We will not discriminate against you for exercising these rights, and you may use an authorized agent to submit a request.
Clients and visitors in the EU and UK. Under the GDPR you have the rights listed above, plus the right to lodge a complaint with your local supervisory authority. Where we process data on behalf of a client as a processor, please direct your request to that client; we will support them in responding.
To exercise a right, email us at [email protected]. We will verify your identity before acting on a request and respond within the time the applicable law allows — generally 45 days under the CCPA and 30 days under the GDPR.
10. Updates to This Policy
We update this policy when our practices, tools, or legal obligations change. The date at the top of the page shows when the current version took effect. If a change materially affects how we handle your information, we will give notice by email or on this site before it takes effect.
11. Contact Us
Questions about this policy, or about how we handle your information, can go to our team directly.
AetherStack Technologies
Austin, Texas, United States
Email: [email protected]
If you are not satisfied with our response, EU and UK residents may contact their national data protection authority, and California residents may contact the California Privacy Protection Agency.