Skip to content
HolonomiX
Menu

Privacy

Privacy notice for public site and diligence intake.

Last updated: September 24, 2026

The public site is designed for business contact, proof-pack routing, security reports, and technical evaluation. It is not intended for submitting secrets, production credentials, PHI, payment-card data, or confidential corpus files through the general contact channel.

Data collected

What the public website collects.

HolonomiX collects the information a visitor submits and limited operational metadata needed to route, secure, and respond to the request.

Identity and contact

Name, work email, company, role

Route access, proof-pack, legal, or security requests

Evaluation context

Current stack, scale, workload notes, desired next step

Scope diligence and route technical review

Operational metadata

Request ID, timestamp, route, delivery status

Abuse prevention, audit, reliability, and intake troubleshooting

Security reports

Affected surface, reproduction details, reporter contact

Triage vulnerability reports and coordinate remediation

No advertising trackers

The site is not built around ad tracking.

HolonomiX does not intentionally deploy advertising trackers, retargeting pixels, or behavioral ad networks on the public website. Operational logs and form-delivery services may still process technical metadata needed for security and reliability.

The site uses Cloudflare Web Analytics to count page views and measure performance, and keeps anonymous totals of four actions: inquiries submitted or prepared as email, visits to our cloud marketplace listings, document downloads and in-browser verification runs. Each count records only the action, the page and the listing, document or check involved, never form contents or the files a verification checks. Action counts are skipped when a browser sends a Global Privacy Control signal. Neither sets cookies or builds visitor profiles. Cloudflare, which serves the site, runs an automated security check in the browser and may set a strictly necessary cookie, cf_clearance, to record the result. That cookie is not used for advertising.

Retention and deletion

Retention is tied to business purpose and diligence scope.

The website keeps delivery metadata for seven days, with removal on the next hourly cleanup. This metadata contains a request reference, a hash of the submitted fields, timestamps, delivery state and provider message ID; it does not contain the message text or contact fields. Inquiries delivered to our business email are retained as needed for response and business records. Evaluation materials are governed by the applicable NDA, pilot agreement, or diligence scope. Deletion or access requests can be sent to the privacy contact.

To help prevent duplicate inquiries after a reload or return visit, Contact also records a request reference, a hash of the submitted fields, status and time in that page’s browser history entry. The website uses this record for up to seven days after the first attempt; your browser controls how long the history entry remains. This record does not include your name, email address, message text or verification token. It does not save a draft or resend an inquiry automatically.

Subprocessors

External processors are limited to configured business operations.

Browser inquiries are processed through Cloudflare Workers, Turnstile and Email Sending, then routed to our sales or information mailbox in Google Workspace. Turnstile processes browser and network signals to prevent abuse. The website uses a daily salted hash of the network address for rate limiting and does not store that address in its inquiry database. Cloudflare email activity-log message previews are disabled. If you choose Prepare email instead, the message stays in your browser until you open or copy it into your email service and send it. Customer runtime data in self-hosted HX-SDP deployments remains inside the customer-controlled environment by default. Cloud providers, payment providers, or marketplace processors apply only when those deployment or billing paths are used.

Sensitive material

Use the correct channel for sensitive diligence.

Do not submit credentials, private keys, regulated health information, payment-card data, or confidential corpora through the general contact form. Use the security or legal review path so a suitable NDA, transfer channel, and retention policy can be established first.

Access

Privacy requests.

Privacy and access requests legal@holonomx.com
Security reports security@holonomx.com