Legal
Aegis Privacy Notice
Aegis-specific privacy notice for managed AI governance, routing, metering, audit logging, and support engagements.
Overview
This notice is written for Aegis customer engagements, not for general public website traffic.
It explains Hatchery's role in processing Customer Content, Aegis usage and token telemetry, support records, billing records, provider/model routing data, audit logs, and security events.
1. Scope and Roles
1.1 Aegis engagement privacy notice. This Aegis Privacy Notice explains how Hatchery handles personal information, Customer Content, usage data, logs, and related engagement information when Hatchery provides the Aegis service to Customer.
1.2 Not the public-site policy. This Notice is specific to Aegis engagements. Hatchery's public website privacy policy governs general public-site visits, public contact forms, and public chatbot interactions unless an Aegis engagement document expressly applies.
1.3 Customer-controlled data. For Customer Content and personal information processed on Customer's behalf through Aegis, Hatchery generally acts as Customer's service provider, processor, or similar role under applicable law. Customer determines the purpose, scope, and lawful basis for that processing.
1.4 Hatchery-controlled data. For account administration, billing, customer relationship management, security, service improvement, legal compliance, and Hatchery business records, Hatchery may act as a business, controller, or similar role under applicable law.
1.5 Contract documents control. If this Notice conflicts with a signed data processing addendum, business associate agreement, security addendum, master services agreement, order form, or other written agreement between Hatchery and Customer, the signed written agreement controls for the covered engagement.
2. Information Hatchery May Process
2.1 Account and administrative information. Names, business email addresses, phone numbers, company names, job titles, roles, permissions, administrators, authorized users, support contacts, billing contacts, authentication records, and access status.
2.2 Customer Content. Prompts, inputs, files, instructions, configuration information, policies, workflow settings, user content, system messages supplied by Customer, and outputs generated through Customer's use of Aegis.
2.3 Usage and metering data. Model or provider selected, token counts, inference counts, embedding counts, request volumes, timestamps, user or application identifiers, route decisions, policy decisions, latency, errors, cost data, Provider Costs, Hatchery service-fee calculations, budgets, alerts, audit trails, and reports.
2.4 Technical and security data. IP addresses, device and browser information, API key metadata, credential events, login events, administrative changes, integration identifiers, rate-limit events, system diagnostics, vulnerability reports, abuse signals, security logs, and incident records.
2.5 Support, billing, and business records. Support tickets, emails, meeting notes, service requests, invoices, payment status, tax records, contract records, Order details, procurement records, and communications with Customer personnel or advisors.
3. Sources of Information
3.1 Customer and users. Hatchery receives information from Customer, Customer administrators, authorized users, Customer applications, Customer systems, Customer integrations, and people who communicate with Hatchery about the Aegis engagement.
3.2 Aegis operations. Hatchery collects information automatically when Aegis routes requests, applies policies, records audit events, measures usage, calculates costs, provides support, detects abuse, monitors reliability, or generates reports.
3.3 Providers and business systems. Hatchery may receive operational, billing, support, security, error, availability, and usage information from AI providers, cloud providers, infrastructure providers, monitoring tools, identity systems, billing systems, and other service providers used to provide Aegis.
4. How Hatchery Uses Information
4.1 Provide and operate Aegis. Hatchery uses information to configure, host, route, process, secure, monitor, support, troubleshoot, maintain, and improve Aegis and to provide dashboards, audit logs, cost visibility, policy controls, guardrails, reporting, and related engagement services.
4.2 Usage-based billing. Hatchery uses usage, metering, and cost data to calculate Provider Costs, Hatchery service fees, Minimum Monthly Charges, invoices, tax obligations, disputed charges, usage reports, alerts, and financial controls.
4.3 Security and abuse prevention. Hatchery uses information to authenticate users, manage access, detect misuse, investigate security events, enforce terms, prevent fraud, protect systems, respond to incidents, and comply with provider requirements.
4.4 Support and customer relationship. Hatchery uses information to respond to support requests, manage the customer relationship, document decisions, prepare engagement records, communicate about changes, and provide administrative notices.
4.5 Service improvement. Hatchery may use usage metrics, telemetry, logs, performance data, error data, aggregated data, or de-identified data to improve Aegis, provided Hatchery does not disclose Customer Confidential Information or use Customer Content to train general-purpose AI models without written approval.
4.6 Legal compliance. Hatchery may use information to comply with legal, regulatory, tax, accounting, contract, dispute-resolution, law-enforcement, court, provider, and security obligations.
5. AI Providers and Infrastructure Providers
5.1 Provider processing. Aegis may submit Customer Content, prompts, outputs, request metadata, and usage information to AI, model, embedding, infrastructure, storage, monitoring, and hosting providers as reasonably necessary to provide Aegis.
5.2 Provider terms and settings. Provider processing is governed by the applicable provider terms, privacy terms, data-processing terms, service limits, retention settings, geographic processing practices, security practices, and model policies, as configured or selected for the engagement.
5.3 No training authorization by Hatchery. Hatchery will not intentionally authorize a provider to use Customer Content to train general-purpose AI models except with Customer's prior written approval. Provider-side no-training commitments, retention settings, and abuse-monitoring practices depend on the selected provider, model, account configuration, and written engagement terms.
5.4 Provider changes. Unless an Order expressly locks a provider or model, Hatchery may add, remove, replace, or route among providers and models for security, availability, performance, cost, provider-policy, regional, or operational reasons.
6. Disclosures
6.1 Service providers and contractors. Hatchery may disclose information to employees, contractors, advisors, AI providers, cloud providers, hosting providers, monitoring providers, identity providers, billing providers, support tools, professional service providers, and other service providers that need the information to support Hatchery or provide Aegis.
6.2 Customer and administrators. Hatchery may disclose Aegis usage, logs, reports, cost data, user activity, security events, and support information to Customer administrators or other Customer-authorized personnel.
6.3 Legal and protection disclosures. Hatchery may disclose information when required by law, subpoena, court order, governmental authority, provider requirement, security process, or when Hatchery reasonably believes disclosure is necessary to protect Hatchery, Customer, users, providers, or third parties.
6.4 Business transactions. Hatchery may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to reasonable confidentiality protections.
6.5 No sale or targeted advertising. Hatchery does not sell Aegis engagement personal information or use Aegis engagement personal information for cross-context behavioral advertising or targeted advertising unless a written engagement document expressly states otherwise and required notices and choices are provided.
7. Sensitive and Regulated Data
7.1 Written approval required. Customer must not submit protected health information, payment card data, government classified information, export-controlled technical data, children's data, biometric identifiers, financial account credentials, or other regulated or highly sensitive data to Aegis unless a signed written agreement expressly authorizes that data type and Hatchery confirms that appropriate controls are in place.
7.2 Customer responsibility. Customer is responsible for determining whether its Aegis use involves personal data, sensitive data, regulated data, confidential customer data, trade secrets, or sector-specific legal obligations and for obtaining required consents, notices, lawful bases, approvals, and agreements.
7.3 Public channels excluded. Public Hatchery contact forms, public chatbots, marketing pages, and unapproved support channels are not approved channels for confidential, regulated, source-code, credential, payment-card, trade-secret, customer confidential, or sensitive personal data.
8. Cookies, Local Storage, and Similar Technologies
8.1 Aegis portal technologies. If Aegis includes a web portal, Hatchery may use required cookies, local storage, session storage, logs, and similar technologies for authentication, session management, access control, security, routing, preferences, diagnostics, and essential service operation.
8.2 Analytics and optional tools. Hatchery may use analytics or monitoring tools to understand performance, reliability, errors, usage, and security. If Hatchery enables optional analytics or advertising-related tools for an Aegis interface, Hatchery will provide required notice and choices where applicable.
8.3 Opt-out signals. Where applicable law requires recognition of opt-out preference signals for sale, sharing, targeted advertising, or profiling, Hatchery will treat recognized browser signals as required for Hatchery-controlled processing. Hatchery does not currently use Aegis engagement personal information for sale or targeted advertising.
9. Retention and Deletion
9.1 Retention periods vary. Hatchery retains information for as long as needed to provide Aegis, maintain accounts, support billing, preserve audit logs, enforce terms, resolve disputes, comply with law, maintain security, improve service operations, and preserve legitimate business records.
9.2 Customer Content export. During the service term and for thirty days after termination, Customer may request export of Customer Content then reasonably available in Aegis in a commercially reasonable format, unless a written agreement states a different period or the data has already been deleted under the applicable retention schedule.
9.3 Deletion limits. Deletion may not remove information from provider systems, backups, security logs, billing records, dispute records, legal archives, or records Hatchery must retain for compliance, security, accounting, provider, or legitimate business purposes. Retained information remains subject to applicable confidentiality and security obligations.
10. Security
10.1 Safeguards. Hatchery uses commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Content and engagement information in Hatchery's possession or control against unauthorized access, use, disclosure, alteration, or destruction.
10.2 Shared responsibility. Security is shared. Customer is responsible for its users, administrators, devices, networks, credentials, API keys, integrations, Customer systems, data classifications, approvals, and secure use of Aegis.
10.3 No perfect security. No system, network, model, provider, or transmission method is perfectly secure. Hatchery does not guarantee that Aegis or provider systems will be uninterrupted, error-free, immune from attack, or free from unauthorized access.
10.4 Security incidents. Hatchery will notify Customer without undue delay after confirming a security incident involving unauthorized access to Customer Content in Hatchery's possession or control, subject to security, confidentiality, provider, law-enforcement, and legal limits.
11. Privacy Rights and Choices
11.1 Requests about Customer-controlled data. If Hatchery processes personal information on Customer's behalf, privacy requests about that information should generally be directed to Customer. Hatchery will reasonably assist Customer with rights requests as required by the applicable written agreement and law.
11.2 Requests about Hatchery-controlled data. For personal information Hatchery controls, individuals may request access, correction, deletion, portability, restriction, opt-out, appeal, or other rights available under applicable privacy laws. Hatchery may verify the request and may deny or limit a request where permitted by law.
11.3 State privacy laws. California, Colorado, Montana, and other state laws may provide specific privacy rights when their legal thresholds and definitions apply. Hatchery will provide required notices, choices, appeal paths, and non-discrimination protections where applicable.
11.4 Contact for requests. Privacy requests, security concerns, and data questions may be sent to Hatchery LLC at jean@hatchery.com or through the contact method stated in the applicable written agreement.
12. International Transfers, Children, Changes, and Contact
12.1 Location of processing. Aegis may involve processing in the United States and other locations where Hatchery, Customer, providers, or support personnel operate. Customer is responsible for identifying cross-border transfer requirements for Customer Content and obtaining required agreements before submitting affected data.
12.2 Children. Aegis is intended for business use and is not directed to children. Customer must not permit children to use Aegis or submit children's personal information through Aegis unless a signed written agreement expressly authorizes that use and required safeguards are in place.
12.3 Changes. Hatchery may update this Notice as Aegis, providers, legal requirements, security practices, or data practices change. The updated date shows when this Notice was last revised.
12.4 Contact. Questions about this Notice should be sent to Hatchery LLC at jean@hatchery.com or to the notice contact stated in the applicable written agreement.