Privacy
Privacy notice for public site and diligence intake.
The public site is designed for business contact, proof-pack routing, security reports, and technical evaluation. It is not intended for submitting secrets, production credentials, PHI, payment-card data, or confidential corpus files through the general contact channel.
Data collected
What the public website collects.
HolonomiX collects the information a visitor submits and limited operational metadata needed to route, secure, and respond to the request.
Name, work email, company, role
Route access, proof-pack, legal, or security requests
Current stack, scale, workload notes, desired next step
Scope diligence and route technical review
Request ID, timestamp, route, delivery status
Abuse prevention, audit, reliability, and intake troubleshooting
Affected surface, reproduction details, reporter contact
Triage vulnerability reports and coordinate remediation
No advertising trackers
The site is not built around ad tracking.
HolonomiX does not intentionally deploy advertising trackers, retargeting pixels, or behavioral ad networks on the public website. Operational logs and form-delivery services may still process technical metadata needed for security and reliability.
Retention and deletion
Retention is tied to business purpose and diligence scope.
Website intake is retained only as needed for routing, response, abuse prevention, and business records. Evaluation materials are governed by the applicable NDA, pilot agreement, or diligence scope. Deletion or access requests can be sent to the privacy contact.
Subprocessors
External processors are limited to configured business operations.
Contact intake is email-based today; if a contact form is offered, delivery may use an email provider such as Resend or a configured webhook. Customer runtime data in self-hosted HX-SDP deployments remains inside the customer-controlled environment by default. Cloud providers, payment providers, or marketplace processors apply only when those deployment or billing paths are used.
Sensitive material
Use the correct channel for sensitive diligence.
Do not submit credentials, private keys, regulated health information, payment-card data, or confidential corpora through the general contact form. Use the security or legal review path so a suitable NDA, transfer channel, and retention policy can be established first.
Contact
Privacy requests.