Scope and responsibility
Iacon Autonomics ("Iacon," "we," "us") provides the Iacon website, arkenOS, Optimus, and associated research, consulting, and commercial services (the "Services"). This Privacy Policy describes the personal information we process in connection with the Services, why we process it, and the choices available to you. "Personal information" means information relating to an identified or identifiable individual, including information given equivalent protection by applicable privacy law.
Iacon is responsible for determining the purposes and means of processing account, billing, business-contact, and service-security information that it uses for its own operations. Where applicable law uses that term, Iacon acts as a controller for this processing.
An organization may separately determine how personal information is used in its projects. Where Iacon processes that information on the organization's behalf, Iacon acts as its processor or service provider, subject to applicable law, the organization's lawful instructions, and the relevant data processing agreement. This policy does not replace an agreement required by law or authorize processing outside its scope.
Questions and privacy requests should be addressed to Iacon Autonomics at dev@iaconautonomics.com.
Information collected and its sources
We receive information from you, from an organization that administers your access, from activity through the Services, and from providers supporting that activity. The categories depend on the features you use.
Account and organization records. These include names, email addresses, authentication and account identifiers, organization membership, roles, and subscription details supplied during registration or account administration.
Customer content. This includes prompts, responses, uploaded or selected files, code, datasets, experiment artifacts, tool results, and other material submitted to or generated through a service request. Optimus may assemble a request using relevant context from a workspace or integration you authorize it to access. Customer content may contain personal information about you or other people.
Usage and technical records. These include request identifiers and timestamps, model selections, token and compute usage, error information, security events, and infrastructure access logs. Logs may include IP addresses and browser or device information. A content-bearing request or response retained for security is subject to the content restrictions below, even when it is stored with technical metadata.
Billing records. These include purchases, invoices, payment status, subscription cancellation dates, refund amounts and status, billing-contact details, and transaction identifiers. Payment providers process payment-card information for their payment functions; Iacon receives the records needed to administer and reconcile charges and refunds.
Communications. We receive information you send when requesting support, discussing an engagement, submitting a privacy request, or communicating about a partnership. You should avoid including unrelated confidential material in these communications.
Local workspaces and external processing
A local workspace and a cloud service request are different storage locations. A file can remain on your device while selected portions are included in a request sent through Iacon's infrastructure to a model provider. Similarly, a tool or integration can transmit information to the service you instruct it to contact.
Iacon's request-content retention applies to records held by Iacon. It does not determine how long you keep local files or how a provider separately retains information it receives. Deleting a local conversation or removing a workspace does not, by itself, delete an existing cloud security record. Privacy requests concerning Iacon-held information can be made using the contact details in this policy.
Purposes and legal grounds
We process information for the following purposes, subject to the content-use and access limits in this policy:
- Providing requested functionality, routing model requests, executing authorized operations, and returning results.
- Establishing accounts, administering team access and subscriptions, measuring consumption, processing cancellations and refunds, and collecting or reconciling payments.
- Answering communications and carrying out agreed research, consulting, or commercial engagements.
- Detecting misuse, investigating security incidents, protecting the Services, and enforcing lawful access restrictions.
- Meeting legal duties, responding to valid legal process, and preserving evidence where legally required.
Where a legal basis is required, processing necessary to provide a service you contract for relies on performance of that contract. Business administration and service security may rely on legitimate interests, after considering the impact on individuals and their rights. For example, we have an interest in preventing unauthorized access and verifying billed usage. Processing required by law relies on the relevant legal obligation. Where consent is necessary, we request it for the specified purpose; you may withdraw it without affecting the lawfulness of earlier processing.
An organization's instructions govern processing performed solely on its behalf. A general reference to service operation or legitimate interests does not expand the permitted uses of customer content.
No training and restricted content access
We do not use customer content to train Iacon's models. We do not sell customer content, license it as training data, or grant third parties permission to use it for their own model training or marketing. A customer's separate agreement with a provider connected using the customer's own credentials governs permissions the customer grants directly to that provider; Iacon does not control those permissions. Paying for or using the Services does not waive these commitments. Reporting a security issue does not convert the associated content into training material.
Automated systems process content to perform the work you request. Human access within Iacon to retained request content is restricted to authorized security personnel who need access for a misuse investigation, a security incident, or compliance with a legal requirement. Retained content is not available for general employee browsing, product research, or sales activity.
Material you separately provide for an agreed consulting deliverable or support request is handled for that engagement under its confidentiality terms. That separate engagement does not grant its staff access to retained request-content records.
Retention and deletion
Standard content retention. Iacon's standard policy is to retain request content and associated security records for no more than 180 days from collection, followed by deletion. The purpose of this storage is service security and misuse investigation. Continued account activity does not restart the retention period for an earlier record.
Required preservation. A binding legal obligation, court order, or applicable duty to preserve evidence may require retention of specific records beyond 180 days. Preservation is limited to the relevant material and required period. Access restrictions continue to apply while it is preserved. We delete the material when that requirement ends and it is otherwise due for deletion.
Other records. Account, transaction, and correspondence records follow the purposes for which they are held. We retain account records needed for an active relationship and billing records required for accounting, tax, payment disputes, or fraud prevention. Their retention depends on those purposes and applicable recordkeeping duties. This does not permit us to reclassify request content as billing information to avoid the content limit.
Cancellation of a subscription or issuance of a refund does not itself constitute a request to erase personal information. Existing records remain subject to the retention limits and privacy rights described in this policy; cancellation does not restart a record's retention period. Refund eligibility and calculation are governed by the Terms and Conditions.
Copies outside Iacon. You control your local copies. Information sent to a customer-selected integration or BYOK provider is also subject to that provider's applicable terms. Deleting an Iacon record does not automatically delete independently held provider records. For providers processing information on Iacon's behalf, Iacon remains responsible for applicable contractual and legal obligations concerning deletion; this distinction does not remove those obligations.
Optional sensitive-work arrangements
Iacon offers customers with sensitive workloads a separately contracted opt-out from its standard request-content retention. This arrangement has an additional service charge and requires the customer's own API keys with providers recommended by Iacon.
The arrangement must be agreed and activated before covered requests are submitted. The written terms specify the covered services, activation date, content handling, necessary account or billing records, and legally required preservation. Providing your own API key alone does not disable Iacon's standard capture or retention.
The arrangement does not, by itself, change a provider's independent retention or processing terms. Provider settings and contractual restrictions must be suitable for the workload. Contact us before submitting material that requires this arrangement.
The additional charge is for a specially configured service. It is not a charge for exercising statutory privacy rights, and those rights do not depend on purchasing this option.
Recipients and permitted disclosures
We distinguish processing necessary to deliver your requested service from disclosure for another party's independent use.
Providers supporting the Services may process the information required for their function. Model providers receive the request context necessary for inference; infrastructure providers host and transmit service records; payment and communications providers process information needed for their respective services. Such processing must remain subject to applicable contractual and legal safeguards. Our use of a provider does not authorize it to use customer content for unrelated marketing or model training.
When you connect an external service or use your own provider credentials ("bring your own key" or "BYOK"), the provider's processing, retention, training permissions, and use restrictions depend on your agreement and account settings with that provider. Iacon's no-training commitment covers Iacon's own use of customer content; it does not change permissions you separately grant to a BYOK provider. Review those terms and settings before transmitting sensitive information. Iacon remains responsible for its own handling of requests passing through its systems, including the retention and access restrictions described above. Organization administrators may manage membership, permissions, and billing within their available controls; this does not grant them access to Iacon's restricted security archive.
We may disclose information in response to legally binding process. We review the request, limit disclosure to what is required, and provide notice to the affected customer where permitted by law and appropriate to the circumstances. Confidentiality obligations and access restrictions continue to apply to retained copies.
We may also disclose specified material at your direction. For example, a partnership listing requires separate authorization identifying what may be shown to prospective buyers. Creating an asset with Optimus is not permission to publish it or describe it in a case study.
International processing
Processing may occur in countries where Iacon or a relevant provider operates. Those countries may have different privacy laws. Where a transfer requires a legal safeguard, the transfer must be covered by an applicable lawful mechanism, such as an adequacy decision or appropriate contractual safeguards, as relevant to that transfer.
This policy does not represent that a particular region, residency option, or certification applies to every service. Contact us for the processing locations and safeguards relevant to a proposed engagement. Location restrictions should be included in the agreement before affected information is submitted.
Privacy rights and requests
Depending on the law that applies, you may have rights to obtain access to personal information, correct it, request deletion, receive a portable copy, restrict processing, object to certain processing, or withdraw consent. Where applicable, you may use an authorized agent, appeal a decision on your request, and complain to the relevant privacy authority. We will not unlawfully discriminate against you for exercising these rights.
Send requests to dev@iaconautonomics.com. Identify the account or relationship involved and the action requested. We may seek information reasonably necessary to verify your identity or an agent's authority. We will respond within the period required by applicable law and explain a refusal, limitation, or permitted extension, including any available appeal process.
Rights may be subject to lawful exceptions, including protection of another person's information and required evidence preservation. The standard retention period does not override an earlier deletion obligation imposed by law. If your organization controls the information, we may refer the request to that organization and assist it in fulfilling its obligations.
Browser storage and communications
The public website uses the local-storage key iacon.analytics-consent to remember your cookie choice. This essential preference storage remains until you clear browser data or change your choice through Cookie settings in the website footer.
If you accept analytics, Google Analytics 4 may set the first-party cookies _ga and _ga_<container-id> for up to two years. They help distinguish visits and preserve session state so we can measure page use and interactions such as downloads, demo requests, and contact links. We disable advertising personalization and Google Signals. If you choose Essential only, these analytics cookies are not loaded. Withdrawing analytics consent stops further analytics collection and removes accessible Google Analytics cookies from this site.
Browser controls allow you to clear or block cookies and similar storage, although blocking necessary storage means the website cannot remember your choice. See Google's information about Analytics cookies for additional technical details.
Where we send optional marketing communications, you can use the unsubscribe mechanism provided or contact us. Essential account, billing, security, and legal notices may still be sent while relevant to your relationship with Iacon.
Safeguards and policy updates
We use technical and organizational safeguards intended to protect information and restrict access. No service can guarantee absolute security. Report suspected unauthorized access or disclosure to dev@iaconautonomics.com. We will handle any legally required incident notifications under the applicable law and customer agreement.
An updated policy will identify its effective date. We will give additional notice of material changes and obtain consent where required. Posting an update does not itself authorize a new use of previously collected content that requires separate permission.