Privacy Policy
Last updated: September 9, 2025
1. Information We Collect
Personal Information
We collect information you provide directly to us, such as when you:
- Create an account or use our services
- Contact us for support
- Subscribe to our newsletter
- Participate in surveys or feedback forms
Automatically Collected Information
When you visit our website, we automatically collect certain information about your device, including:
- IP address and general location
- Browser type and version
- Operating system
- Pages visited and time spent
- Referring website
Cookies and Tracking Technologies
We use minimal cookies for essential functionality and analytics. If you're in a region requiring consent (EU/UK), you'll see a consent banner. You can manage preferences anytime through your browser settings.
2. How We Use Your Information
We use collected information to:
- Provide and improve our services
- Communicate with you about our products
- Analyze website usage and optimize performance
- Comply with legal obligations
- Help prevent fraud and security threats
2.1. Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal information based on the following lawful bases under the General Data Protection Regulation (GDPR):
Contract Performance (Article 6(1)(b))
We process the following data to perform our contract with you:
- Account registration and authentication information
- Subscription and billing data
- Service usage data necessary for platform functionality
- Customer support communications
- CAD file processing data required for our AI automation services
Legitimate Interests (Article 6(1)(f))
We process certain data based on our legitimate business interests, balanced against your rights and freedoms:
- Service improvement: Analytics data to enhance platform performance and user experience
- Security: IP addresses and device data for fraud prevention and system security
- Business development: Aggregated usage patterns for product development
- Marketing: Professional contact information for B2B communications (you can opt-out at any time)
Consent (Article 6(1)(a))
For certain processing activities, we rely on your explicit consent:
- Marketing emails and newsletters (withdrawable at any time)
- Non-essential cookies and tracking
- Sharing data with third-party integrations beyond core service functionality
- Processing special categories of data, if applicable
Legal Obligation (Article 6(1)(c))
We process certain data to comply with legal requirements:
- Tax and accounting records
- Regulatory compliance for financial services
- Data retention for legal proceedings
- Anti-money laundering and know-your-customer requirements
Vital Interests (Article 6(1)(d))
In rare circumstances, we may process data to protect vital interests, such as preventing harm or ensuring safety in emergency situations.
3. Information Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties except:
- With your explicit consent
- To service providers who assist our operations (under strict confidentiality agreements)
- When required by law or to protect our rights
- In connection with a merger, acquisition, or sale of assets
Third-Party Services
Our website may integrate with third-party services:
- Google Analytics: Website analytics and performance measurement
- Cookiebot: Cookie consent management
4. Data Security
We work to implement appropriate technical and organizational security measures to help protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Ongoing security reviews and assessments
- Access controls and authentication requirements
- Security monitoring and incident response procedures
5. Your Rights and Choices
Data Subject Rights (GDPR)
If you are located in the European Union, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing for legitimate interests or direct marketing
California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know: What categories of personal information we collect, use, disclose, and sell, including the sources and business purposes
- Access: Request specific pieces of personal information we have collected about you in the past 12 months
- Delete: Request deletion of personal information we have collected, subject to certain exceptions
- Opt-out: Direct us not to sell your personal information to third parties
- Non-discrimination: Receive equal service and pricing, even if you exercise your privacy rights
Categories of Personal Information We Collect
We may collect the following categories of personal information:
- Identifiers: Name, email address, phone number, IP address, device identifiers
- Commercial Information: Purchase history, subscription details, billing information
- Internet Activity: Website usage, search history, interaction with our services
- Professional Information: Job title, company, industry, work-related preferences
- Geolocation Data: General location based on IP address
Sources of Personal Information
We collect personal information from:
- Directly from you when you create accounts, use our services, or contact us
- Your devices when you interact with our website or applications
- Third-party integrations and service providers
- Business partners and resellers (with your consent)
Business Purposes for Collection
We collect personal information for the following business purposes:
- Providing and maintaining our services
- Processing transactions and billing
- Customer support and communication
- Service improvement and development
- Security and fraud prevention
- Legal compliance and protection of rights
- Marketing and promotional communications (with consent)
Sale of Personal Information
In the past 12 months, we may have shared certain categories of personal information with third parties in ways that could be considered a "sale" under CCPA:
- Identifiers and Internet Activity: With analytics providers and advertising networks for marketing and analytics purposes
- Commercial Information: With business partners for integration and reseller purposes (with your consent)
We do not sell personal information of minors under 16 years of age. California residents can opt-out of the sale of their personal information at /do-not-sell.
Exercising Your Rights
To exercise any of these rights, please contact us at privacy@araeo.com or use our data request form.
6. Data Retention
We retain personal information for as long as necessary to provide our services and comply with legal obligations. When personal information is no longer needed, we securely delete or anonymize it.
Retention Periods
- Account data: Until account deletion + 30 days
- Analytics data: 26 months (Google Analytics standard)
- Support communications: 3 years
- Marketing data: Until unsubscribe + 30 days
7. Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete such information immediately.
8. CAD and Engineering Data Protection
We recognize the sensitive and proprietary nature of CAD files, engineering designs, and technical documentation. We implement enhanced protections for this data:
Special Handling of Technical Data
- Intellectual Property Protection: Your CAD files, designs, and engineering data remain your exclusive property
- Confidentiality: All technical data is treated as confidential and protected under industry-standard security measures
- Local Processing: Where technically feasible, CAD file processing occurs locally on your systems to minimize data transmission
- Secure Transmission: All data transfers use end-to-end encryption with AES-256 standards
- Access Controls: Strict access controls limit who can view or process your technical data
- Data Isolation: Your project data is isolated from other users' data in our systems
Professional Use Requirements
Our services are designed for professional engineering and design use. Users acknowledge:
- You are responsible for ensuring your data processing complies with your organization's security policies
- You should not upload data subject to export controls or national security restrictions without proper authorization
- You must have appropriate rights to process any third-party intellectual property
- Critical or safety-critical designs should undergo appropriate review processes
Industry Compliance
We maintain compliance with relevant industry standards and can provide additional documentation for organizations requiring specific compliance certifications.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We work to implement appropriate safeguards for international transfers, including:
- EU Standard Contractual Clauses
- Adequacy decisions by relevant data protection authorities
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date. For material changes, we may provide additional notice such as email notification.
11. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Email: privacy@araeo.com
Address: 3723 Greenville Ave STE 41044, Dallas, TX 75206
Phone: Available via our contact page
To exercise your privacy rights, please fill out our data request form or email us directly at privacy@araeo.com.
12. Cookie Policy
This website uses cookies to enhance your browsing experience. Our cookie banner allows you to control which cookies are used. For detailed information about our use of cookies, please see our Cookie Policy.