ASPIS Cyber Security
LEGAL

Privacy Policy

This policy explains what personal information ASPIS Cyber Technologies, Inc. ("ASPIS", "we", "us") collects through this website, why we collect it, who we share it with, and what you can ask us to do about it.

LAST UPDATED SEPTEMBER 1, 2026

01What this policy covers

This policy covers the ASPIS public website and the forms and document downloads published on it.

It does not cover the ASPIS products. When an organization deploys ShieldiT, ManageiT or SentinelIQ, ASPIS processes data on that organization’s behalf under the agreement between ASPIS and that organization, and that organization — not ASPIS — decides what is collected and why. If you are a user of a deployed ASPIS product and want to know how your data is handled, ask the organization that provided it to you.

It also does not cover websites we link to. ShieldMe, the ManageiT administration portal and LinkedIn are separate services with their own privacy terms.

02Information we collect

There are three ways this website collects information about you.

Information you submit in a form
Our contact and demonstration forms ask for your name, business email address, organization and job title, the area of interest you select, and whatever you choose to write in the free-text field. The partner deal-registration form additionally asks for partner type, customer industry, organization size, estimated number of users, expected decision date, opportunity stage and details, deployment requirement, the products you are interested in, and whether ASPIS support is requested.
Information you submit to open a document
The published white papers and use-case documents are gated. To open one you provide your name, business email address, organization and job title. We use this to understand who is evaluating the platform and to respond if you get in touch.
Information collected automatically by our hosting provider
Like any website, requests to this site are logged by the infrastructure serving it. Those logs typically include the requesting IP address, the page requested, a timestamp, and the browser user-agent string. We use them to operate and secure the site.

Our forms also contain a hidden field that legitimate visitors never see or fill in. It exists to catch automated submissions and collects nothing about you.

03What this website does not do

Several things a visitor might reasonably expect from a corporate website are absent here, deliberately. Stated plainly so you do not have to take it on trust:

  • There is no third-party analytics on this site. No Google Analytics, no product-analytics SDK, no session recording, no heatmapping.
  • There are no advertising or marketing cookies, no tracking pixels and no conversion tags.
  • There is no cross-site tracking, and nothing on this site profiles you or makes automated decisions about you.
  • Typefaces are served from our own infrastructure rather than a font network, so loading a page does not disclose your IP address to a font provider.
  • We do not sell the personal information collected through this website, and we do not share it for cross-context behavioral advertising or targeted advertising.

This is also why you are not asked to dismiss a cookie banner. The only cookies this site sets are the two functional ones described below.

04Cookies

This site sets exactly two cookies, both first-party, and both only after you submit the document-access form. Until you do that, this site sets no cookies at all.

COOKIEPURPOSELIFETIME
aspis_doc_accessRecords that the document-access form has been completed, so published documents can be opened. Signed and marked HttpOnly, so it cannot be read by scripts in your browser.30 days
aspis_doc_okA readable flag that tells the page not to ask for your details again on a return visit. It grants no access on its own.30 days

Both are restricted to this site, sent only over HTTPS in production, and set with SameSite=Lax so they are not sent from third-party contexts. You can delete them at any time in your browser settings; the only effect is that you will be asked for your details again the next time you open a document.

Cookie Policy

05How we use your information, and our legal basis

We use the information described above for the following purposes.

Responding to you
Routing your inquiry to the right team and replying to it. Where you contacted us, our basis is your consent or the steps necessary to enter into a contract; otherwise our legitimate interest in responding to inquiries about our products.
Providing access to published documents
Confirming the form has been completed and serving the document. Our basis is the performance of your request, and our legitimate interest in knowing who is evaluating the platform.
Following up about our products
Contacting you about the subject of your inquiry. Our basis is legitimate interest, or consent where the applicable law requires it. You can ask us to stop at any time and we will.
Operating and securing the site
Keeping the site available, diagnosing faults, and detecting abuse and automated submissions. Our basis is legitimate interest, and compliance with our legal obligations where they apply.
Meeting legal obligations
Retaining records where the law requires it, and responding to lawful requests. Our basis is compliance with a legal obligation.

We do not use the information collected through this website to make automated decisions about you that have a legal or similarly significant effect.

06Who we share it with

We share personal information only in the following circumstances.

Our form-delivery provider
Submissions from the forms on this site are delivered to us through Formspree, which processes them on our instructions in order to pass them to us.
Our hosting provider
This site is hosted on infrastructure operated by a third-party hosting provider, which processes request logs in order to serve and secure the site.
Within ASPIS
The ASPIS personnel who need it to respond to you — typically the team covering the area of interest you selected.
Professional advisers and corporate transactions
Our auditors, lawyers and insurers where they need it, and a counterparty in connection with a merger, acquisition or sale of assets, subject to appropriate confidentiality.
When the law requires it
Where we are legally compelled to disclose information, or where disclosure is necessary to establish or defend legal claims, or to protect the rights and safety of others.

We do not give your information to advertising networks, data brokers or list vendors.

07International transfers

ASPIS operates internationally, and the service providers described above may process information outside the country you are in — including in the United States.

Where personal information is transferred out of the European Economic Area, the United Kingdom or Switzerland, we take steps to ensure it remains protected by a transfer mechanism recognized under applicable law. If you want to know which mechanism applies to a particular transfer, write to support@aspiscyber.com and we will tell you.

08How long we keep it

We keep personal information only as long as we need it for the purpose we collected it for, and then delete it or stop being able to identify you from it.

  • The two cookies described above expire 30 days after they are set.
  • Form submissions are kept for as long as needed to respond to you and to keep a record of the inquiry and our reply, and longer only where a legal obligation requires it.
  • Request logs are kept for the period our hosting provider retains them for operational and security purposes.

If you want your information deleted sooner, ask us at support@aspiscyber.com and we will do so unless we are required to keep it.

09Your rights in the EEA, the UK and Switzerland

If data-protection law in the EEA, the UK or Switzerland applies to our handling of your information, you have the following rights. They are not absolute, and in some cases we may be entitled or required to decline — we will tell you why if we do.

  • Access — to be told whether we hold personal information about you, and to receive a copy.
  • Rectification — to have inaccurate information corrected and incomplete information completed.
  • Erasure — to have your information deleted where there is no overriding reason for us to keep it.
  • Restriction — to have us limit what we do with your information while a dispute about it is resolved.
  • Objection — to object to processing we carry out on the basis of legitimate interest, including for direct marketing, which we will always stop on request.
  • Portability — to receive information you gave us in a structured, commonly used, machine-readable format.
  • Withdrawal of consent — to withdraw consent at any time where consent is our basis, without affecting processing that already took place.
  • Complaint — to lodge a complaint with your national data-protection authority. We would rather you raised it with us first so we can put it right.

To exercise any of these, write to support@aspiscyber.com. We will respond within the period the applicable law allows. We may need to ask you for enough information to confirm who you are before we act, so that we do not disclose your information to someone else.

10Your rights in California and other US states

If you are a resident of California or of another US state with a comprehensive privacy law, you may have the following rights in relation to the personal information described in this policy.

  • To know what personal information we have collected about you, the categories of sources, the purposes, and the categories of third parties we disclosed it to.
  • To obtain a copy of the personal information you provided to us.
  • To have your personal information corrected if it is inaccurate.
  • To have your personal information deleted, subject to the exceptions the statute allows.
  • To opt out of the sale of personal information and of sharing it for cross-context behavioral advertising. As stated above, this website does neither, so there is nothing to opt out of.
  • To opt out of profiling in furtherance of decisions with legal or similarly significant effects. As stated above, we do not do this.
  • Not to be discriminated against for exercising any of these rights. We will not deny you anything, charge you a different price, or give you a lower level of service because you asked.

Send a request to support@aspiscyber.com, stating which right you are exercising. You may use an authorized agent, in which case we will ask for proof of their authority. We do not knowingly collect or process the sensitive personal information categories those statutes single out through this website, and we do not use personal information for purposes incompatible with those described here.

11How we protect it

We take reasonable technical and organizational measures appropriate to the risk. On this website that includes serving every page over HTTPS, restricting the two cookies to this site and to secure connections, marking the access cookie HttpOnly and signing it so it cannot be forged, serving gated documents only to a request carrying a valid signed cookie, and instructing browsers and search engines not to cache or index those documents.

No method of transmission or storage is completely secure, and we do not claim otherwise. Please do not send us confidential technical detail, credentials or sensitive personal information through a web form.

If you believe you have found a security vulnerability in an ASPIS product or in this website, please use our responsible-disclosure route rather than a contact form.

Responsible disclosure

12Children

This is a business-to-business website intended for professional use. It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

13Changes to this policy

We may update this policy as our practices, our providers or the law change. The date at the top of this page is the date of the current version. Where a change materially affects how we handle information you have already given us, we will take reasonable steps to tell you rather than relying on this page alone.

14Contacting us

ASPIS Cyber Technologies, Inc. is responsible for the personal information described in this policy. For any privacy question, or to exercise any right described above, write to support@aspiscyber.com and put "Privacy" in the subject line.