Privacy
Privacy notice for public site and diligence intake.
Last updated: September 24, 2026
The public site is designed for business contact, proof-pack routing, security reports, and technical evaluation. It is not intended for submitting secrets, production credentials, PHI, payment-card data, or confidential corpus files through the general contact channel.
Data collected
What the public website collects.
HolonomiX collects the information a visitor submits and limited operational metadata needed to route, secure, and respond to the request.
Name, work email, company, role
Route access, proof-pack, legal, or security requests
Current stack, scale, workload notes, desired next step
Scope diligence and route technical review
Request ID, timestamp, route, delivery status
Abuse prevention, audit, reliability, and intake troubleshooting
Affected surface, reproduction details, reporter contact
Triage vulnerability reports and coordinate remediation
No advertising trackers
The site is not built around ad tracking.
HolonomiX does not intentionally deploy advertising trackers, retargeting pixels, or behavioral ad networks on the public website. Operational logs and form-delivery services may still process technical metadata needed for security and reliability.
The site uses Cloudflare Web Analytics to count page views and measure performance, and keeps anonymous totals of four actions: inquiries submitted or prepared as email, visits to our cloud marketplace listings, document downloads and in-browser verification runs. Each count records only the action, the page and the listing, document or check involved, never form contents or the files a verification checks. Action counts are skipped when a browser sends a Global Privacy Control signal. Neither sets cookies or builds visitor profiles. Cloudflare, which serves the site, runs an automated security check in the browser and may set a strictly necessary cookie, cf_clearance, to record the result. That cookie is not used for advertising.
Retention and deletion
Retention is tied to business purpose and diligence scope.
The website keeps delivery metadata for seven days, with removal on the next hourly cleanup. This metadata contains a request reference, a hash of the submitted fields, timestamps, delivery state and provider message ID; it does not contain the message text or contact fields. Inquiries delivered to our business email are retained as needed for response and business records. Evaluation materials are governed by the applicable NDA, pilot agreement, or diligence scope. Deletion or access requests can be sent to the privacy contact.
To help prevent duplicate inquiries after a reload or return visit, Contact also records a request reference, a hash of the submitted fields, status and time in that page’s browser history entry. The website uses this record for up to seven days after the first attempt; your browser controls how long the history entry remains. This record does not include your name, email address, message text or verification token. It does not save a draft or resend an inquiry automatically.
Subprocessors
External processors are limited to configured business operations.
Browser inquiries are processed through Cloudflare Workers, Turnstile and Email Sending, then routed to our sales or information mailbox in Google Workspace. Turnstile processes browser and network signals to prevent abuse. The website uses a daily salted hash of the network address for rate limiting and does not store that address in its inquiry database. Cloudflare email activity-log message previews are disabled. If you choose Prepare email instead, the message stays in your browser until you open or copy it into your email service and send it. Customer runtime data in self-hosted HX-SDP deployments remains inside the customer-controlled environment by default. Cloud providers, payment providers, or marketplace processors apply only when those deployment or billing paths are used.
Sensitive material
Use the correct channel for sensitive diligence.
Do not submit credentials, private keys, regulated health information, payment-card data, or confidential corpora through the general contact form. Use the security or legal review path so a suitable NDA, transfer channel, and retention policy can be established first.
Access
Privacy requests.