Privacy Policy
Last updated: June 18, 2026 · Effective: June 18, 2026
1. Scope
This Privacy Policy explains how AAREI Global Inc., a Wyoming corporation (“AAREI,” “we,” “us”), collects, uses, and shares information in connection with the Agent Sentry platform, websites, and applications (the “Service”). When we provide the Service to a business customer, we generally process Customer Data as a processor on that customer’s behalf and under our agreement with them; this Policy describes our practices and, where we act as a controller (for example, for account and billing data), our role as such.
2. Who we are
AAREI Global Inc. is the entity responsible for the Service. For privacy questions or requests, contact privacy@aarei.ai.
3. What we collect
- Account information — name, work email, organization, role, and authentication identifiers from your identity provider.
- Billing information — plan, subscription status, and billing email. Card and payment details are collected and stored by our payment processor (Stripe); we do not store full card numbers.
- Usage & evidence metadata — records of governed agent actions: the action type, decision, approval, outcome, timestamps, the acting agent/user identifiers, and cryptographic hashes. These power the tamper-evident audit ledger. We do not store the file contents (bytes) of attachments in the ledger — only metadata and content hashes.
- Connected-system metadata — identifiers and metadata needed to carry out governed actions on the systems you connect; access credentials for those systems are stored encrypted.
- Support & communications — messages you send us.
- Technical data — log data, device/browser information, and similar diagnostics; the marketing site uses no third-party advertising trackers.
4. How we use it
- provide, operate, secure, and support the Service;
- evaluate policy, create evidence records, and route approvals for governed actions;
- process subscriptions, billing, and account administration;
- monitor, troubleshoot, and improve reliability and security;
- communicate about the Service and respond to requests;
- comply with law and enforce our Terms.
We do not sell personal information, and we do not use Customer Data to train models for other customers.
5. Payments
Payments are processed by Stripe. When you subscribe, Stripe collects and processes your payment details under Stripe’s Privacy Policy. We receive limited billing metadata (such as subscription status and the last digits/brand of a card) but not full card numbers.
6. How we share
- Service providers (subprocessors) who host and support the Service under contract (see below).
- Connected services you choose (your Systems of Record and identity provider), to carry out governed actions and authenticate users.
- Legal & safety — to comply with law, enforce agreements, or protect rights and safety.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
7. Subprocessors
We use reputable providers to deliver the Service, including:
- Google Cloud Platform — hosting, storage, and key management.
- Stripe — subscription billing and payments.
- Auth0 (Okta) — authentication and organization identity.
- Amazon Web Services (SES) — transactional email (e.g., approval notifications).
- Slack — optional approval notifications, where you enable it.
This list may change as the Service evolves; we will keep it current here.
8. Retention
We retain account and billing data for as long as your account is active and as needed for legitimate business and legal purposes. Audit Evidence Records are retained in tamper-evident, write-once storage for a defined period (by default, seven years) for audit and compliance integrity, and are kept independent of subscription status. Other Customer Data is retained per our agreement with the business customer and deleted or de-identified when no longer needed, subject to legal requirements.
9. Security
We use technical and organizational measures designed to protect information, including encryption of credentials and sensitive data, access controls, and an append-only, independently anchored audit ledger. No method of transmission or storage is perfectly secure, but the Service is built to fail closed: if a governed action cannot be securely evidenced, it does not execute.
10. International transfers
We operate in the United States and may process information there and in other countries where our subprocessors operate. Where required, we rely on appropriate safeguards for cross-border transfers.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. Where we process data on behalf of a business customer, we will refer your request to that customer or assist them in responding. To make a request, contact privacy@aarei.ai. We will respond consistent with applicable law and may need to verify your identity.
12. Children
The Service is for business use and is not directed to children under 18, and we do not knowingly collect their personal information.
13. Changes
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date and, where appropriate, by additional notice. Your continued use of the Service after changes take effect constitutes acceptance.
14. Contact
Privacy questions or requests: privacy@aarei.ai. General support: support@aarei.ai.