Legal
Privacy Policy & GDPR Notice
This notice explains how AEGISfo, operated byAEGISfo LLC (“AEGISfo”, “we”, “us”), processes personal data, and your rights under the EU General Data Protection Regulation (GDPR) and the UK GDPR. AEGISfo is a private wealth-intelligence platform for family offices.
1. Controller and processor roles
For the data a family office and its members upload and manage in the platform (portfolio holdings, entities, documents, family details), the customer (the family office) is the data controller and AEGISfo acts as a processor on their documented instructions, under a Data Processing Agreement (DPA). For the limited data we collect to operate our own business (account/contact details, billing, product usage), AEGISfo is the controller.
2. What we process
- Account data - name, email, authentication factors (magic-link, passkey/WebAuthn).
- Customer content - portfolios, valuations, legal entities, uploaded documents, family members, governance records.
- Connection data - read-only tokens/metadata for linked bank/brokerage accounts you choose to connect.
- Usage & security data - audit logs (who did what, when), IP/session metadata for security.
3. Legal bases (GDPR Art. 6)
- Contract - to provide the service you signed up for.
- Legitimate interests - security, fraud prevention, product improvement, and operating our business (balanced against your rights).
- Consent - for optional features you switch on (e.g. AI insights, Telegram notifications). You can withdraw consent at any time.
- Legal obligation - where we must retain records to comply with law.
4. Data residency & storage
Customer data is stored in the European Union. The primary database is hosted in Frankfurt, Germany (eu-central-1). Uploaded documents are additionally mirrored to an off-site backup in Ireland (eu-west-1). All backups remain within the EU. Data is encrypted at rest (AES-256) and in transit (TLS 1.3), and each family office is isolated at the database layer by row-level security.
5. Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (primary) | Database, authentication, document storage | EU - Frankfurt |
| Supabase (backup) | Off-site document backup | EU - Ireland |
| Vercel | Application hosting & content delivery | Global edge |
| Resend | Transactional & briefing email | US |
| Anthropic | AI insights & chat (optional feature) | US |
| Telegram | Chat notifications (optional feature) | Global |
6. International transfers
Certain optional features transfer data outside the EU/EEA: email delivery (Resend, US), AI insights and chat (Anthropic, US), and Telegram notifications (global). These transfers are governed by Standard Contractual Clauses and equivalent safeguards. If you require that no personal data leaves the EU, you can disable the AI and Telegram features, and use in-app delivery - contact us to configure this.
7. Retention
We retain customer content for as long as your account is active. On termination, data is deleted or returned per the DPA, subject to any legal retention obligations. Backups roll off on their retention schedule. You can delete individual records (assets, documents, entities) in the app at any time.
8. Your rights (GDPR Art. 15–22)
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (“right to be forgotten”);
- Restrict or object to processing;
- Data portability (receive your data in a structured, machine-readable format);
- Withdraw consent for optional features at any time;
- Lodge a complaint with your supervisory authority.
Where AEGISfo is a processor, we will refer or assist requests from data subjects to the controlling family office. To exercise any right, email john@infinitacm.com.
9. Security
We apply encryption at rest and in transit, row-level tenant isolation, least-privilege access, layered authentication (password, magic link, and/or passkeys), and an immutable audit trail. Our infrastructure runs on SOC 2 Type II certified providers. See our Security overview for more.
10. Cookies
We use only strictly-necessary cookies for authentication and session security. We do not use advertising or third-party tracking cookies.
11. Changes
We may update this notice; material changes will be communicated in-app or by email. The “last updated” date above reflects the current version.
12. Contact
Privacy enquiries and data-subject requests: john@infinitacm.com. General: john@infinitacm.com. Operated by AEGISfo LLC.