Privacy Policy
Last updated: 7 March 2026
1. Controller (Pilot Phase)
ARAM Algorithm
Mano Venkatesan
15704 Shawnee Drive, Overland Park, KS 66223, United States
Contact: mano@aramalgorithm.ai
Pilot-phase disclosure. ARAM Algorithm currently operates as a US sole proprietorship in pilot phase. A German company (UG (haftungsbeschränkt) or GmbH) will be established — with German seat, German VAT ID, and German jurisdiction — after the pilot phase concludes (at the latest upon onboarding the third paying client). A representative under Art. 27 GDPR will be appointed before any processing of personal data outside the personally-verified de-identification workflow described in Section 2.
1a. Data Minimisation by Design
During the pilot phase, the service operates on a de-identification-first basis: clients run the intake locally and submit a de-identified case YAML in which names, addresses, dates of birth, employee IDs, and other direct identifiers are stripped by construction. Raw evidence and the identity of the data subject remain on the client’s device. The controller does not knowingly receive or process directly identifiable personal data of EU data subjects during the pilot phase. Where any such data is nevertheless transmitted, the controller will (a) notify the client, (b) securely delete it without processing, and (c) document the incident under Section 9.
2. Data We Collect
When you use our website, we may process the following personal data:
- Contact form data: Your name, work email address, firm/company name, role, and any message you submit through the “Request an Evidence Replay” form.
- Calendly booking data: When you book a scoping call, your name and email are passed to Calendly (calendly.com) as URL parameters. Calendly processes this data under its own privacy policy.
- Server logs: Our hosting provider (Cloudflare) may collect standard server log data including IP addresses, browser type, and access times. This is processed by Cloudflare under their privacy policy.
3. Purpose and Legal Basis
- Contact form: Processing is based on your consent (Art. 6(1)(a) GDPR) given via the consent checkbox, and on our legitimate interest in responding to business inquiries (Art. 6(1)(f) GDPR).
- Calendly booking: Processing is necessary for the performance of pre-contractual measures at your request (Art. 6(1)(b) GDPR).
- Server logs: Processing is based on our legitimate interest in ensuring website security and functionality (Art. 6(1)(f) GDPR).
4. Third-Party Data Transfers and Transfer Mechanisms
- Calendly: When you submit the contact form or book a call, your name and email are transferred to Calendly, Inc. (USA). Transfer mechanism: EU-U.S. Data Privacy Framework and Standard Contractual Clauses (Module 2: Controller-to-Processor), supplemented by a Transfer Impact Assessment available on request.
- Cloudflare: Our website is served through Cloudflare, Inc. (USA), which processes server request data (IP address, browser data, access times) for security and delivery. Transfer mechanism: EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
- Controller (ARAM Algorithm, USA): Until the German entity is established, transfers from EU data subjects to the controller take place under Standard Contractual Clauses (Module 1: Controller-to-Controller) where applicable, supplemented by the Transfer Impact Assessment referenced above. Until the Art. 27 GDPR representative is in place, the data-minimisation regime in Section 1a applies.
A full sub-processor list (with hosting region, encryption, retention, access control and incident-notification commitments) and the Transfer Impact Assessment are available on the Security & Trust page, or on request to mano@aramalgorithm.ai.
We do not use analytics, tracking cookies, advertising pixels, or any other third-party data collection tools. No client data — including de-identified YAML — is ever used to train, tune, or improve any machine-learning model.
5. Cookies
This website does not set any first-party cookies. No tracking or analytics cookies are used. Cloudflare may set technical cookies necessary for security and performance (e.g., bot protection). These are strictly necessary cookies under Art. 5(3) of the ePrivacy Directive.
6. Fonts
This website serves all fonts from privacy-preserving sources that do not collect, log, or share visitor IP addresses with third parties. No font request leaves the European Union to a US-based font CDN. The font configuration is documented on the Security & Trust page and reviewed before each release.
7. Your Rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent at any time (Art. 7(3) GDPR)
To exercise any of these rights, contact: mano@aramalgorithm.ai
8. Data Retention
Contact form data passed to Calendly is retained according to Calendly’s data retention policies. We do not independently store form submissions. Server logs are retained by Cloudflare according to their standard retention periods.
9. Supervisory Authority
You have the right to lodge a complaint with a competent supervisory authority. Until the German entity and Art. 27 GDPR representative are established, EU data subjects may lodge a complaint with the data-protection authority of their habitual residence, place of work, or the place of the alleged infringement (Art. 77 GDPR). For German data subjects without a preferred authority, the Berliner Beauftragte für Datenschutz und Informationsfreiheit may be addressed as a first contact.
9a. Personal-Data Breach Notification
In the event of a personal-data breach affecting client data, the controller will notify the affected client within 72 hours of becoming aware of the breach (Art. 33 GDPR style commitment), and will provide all information reasonably necessary for the client to fulfil its own notification obligations. The full incident-response procedure is documented in the Data Processing Agreement (Art. 28 GDPR) signed before any processing begins.
10. Changes to This Policy
We may update this privacy policy from time to time. The date at the top of this page indicates the last revision.

