Privacy Policy
Last updated: June 2026. This Privacy Policy explains how Grant Infra Services Inc., a company organized under the laws of the Republic of Korea and the company behind the Aegis BioCryption product (“Aegis,” “we”), collects, uses, discloses, and protects information in connection with our website and the Aegis BioCryption platform (the “Service”).
1. Protected Health Information is handled under the BAA, not this Policy
When the Service processes Protected Health Information (“PHI”) on behalf of a covered entity or business associate, Aegis acts as a HIPAA Business Associate, and that PHI is governed exclusively by the executed Business Associate Agreement (“BAA”) and HIPAA, not by this Privacy Policy. We do not use PHI for our own purposes, do not sell PHI, and do not use PHI for advertising. PHI is never placed in our marketing, analytics, or billing systems. This Privacy Policy covers only the non-PHI information described below.
2. Information We Collect
Account information: name, work email, organization, role, and password (stored only as a salted hash). Inquiry and support information: messages, tickets, and details you submit through our contact forms. Billing information: metered usage and payment status processed through our third-party merchant of record; we do not store full card numbers. Usage and log data: IP address, device and browser type, pages viewed, and timestamps, collected to operate and secure the Service. Cookies and analytics: see Section 6.
3. How We Use Information
We use non-PHI information to: create and manage accounts; provide, maintain, and secure the Service; process payments and meter usage; respond to inquiries and provide support; detect and prevent fraud and abuse; comply with legal obligations; and improve the Service. We rely on our legitimate business interests, performance of our agreement with you, and your consent where required.
4. How We Share Information
We do not sell personal information. We share non-PHI information only with: subprocessors that help us run the Service (cloud hosting, transactional email, payment/merchant-of-record, and website analytics), under contractual confidentiality and security obligations; legal and safety recipients when required by law or to protect rights and safety; and a successor in connection with a merger, acquisition, or asset sale, subject to this Policy. Subprocessors do not receive PHI except as permitted by the BAA and only those acting as subcontractors under HIPAA.
5. Data Location and Retention
The Service is operated within access-controlled cloud infrastructure in the region agreed with the customer. We retain account and transactional records for as long as your account is active and as needed to comply with legal, tax, and audit obligations, after which we delete or de-identify them. PHI retention and destruction are governed by the BAA, including time-boxed access and irreversible destruction of released studies.
6. Cookies and Analytics
Our public marketing website uses strictly necessary cookies and privacy-respecting analytics (Google Analytics) to understand aggregate traffic. We do not deploy third-party analytics or advertising trackers on authenticated clinical pages, the imaging viewer, or any page where PHI may be present. You can control cookies through your browser settings.
7. Security
We implement administrative, physical, and technical safeguards designed to protect information, including encryption in transit (TLS 1.2+) and at rest, least-privilege and time-boxed access, salted password hashing, and a tamper-evident, hash-chained audit trail anchored to a public timestamp. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction (for example, California residents under the CCPA/CPRA, or data subjects under Korea’s Personal Information Protection Act (“PIPA”)), you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. We do not sell or “share” personal information for cross-context behavioral advertising. To exercise rights, contact us using Section 11; we will verify your request and respond as required by law. Rights regarding PHI are governed by HIPAA and your provider relationship.
9. Children’s Privacy
The Service is intended for business use by organizations and is not directed to children. We do not knowingly collect personal information from children under 13 through the Service.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last updated” date and, for material changes, provide additional notice.
11. Contact
Questions or privacy requests: contact us or email support@aegisbiocryption.com.
This document is provided for transparency and does not constitute legal advice. Please have your counsel review your privacy practices and disclosures.