Privacy Policy
Aerca ("Aerca", "we", "us", or "our") is developing finance-operations software for service businesses, starting with agencies, studios, and consultancies. This Privacy Policy explains what information we currently collect through the website and founding-access process, how we use it, and how future product data will be handled as Aerca develops.
Aerca currently refers to the unincorporated project operating this website from India. The responsible company and updated contact details will be identified here before paid services or production financial-data processing begin.
1. Scope of Applicability
This Privacy Policy applies to visitors to the Aerca website, people who contact us or book a call, founding-access applicants, and future users of the product. Aerca is currently in early development; references to future integrations or product processing describe intended functionality rather than a representation that every feature is presently available.
2. Data Collection and Categorization
2.1. Information Provided Directly by You
- Founding-Access Data: When you apply, we may collect your name, business email, business type, team size, revenue range, operational challenges, and an estimate of financial leakage. Applying currently requires no payment or card information.
- Communications Data: We securely log and retain correspondence initiated through our contact forms, direct emails, or customer support channels to facilitate issue resolution and quality assurance.
2.2. Information Acquired via Authorized Third-Party Integrations
The current prototype may process information that a user deliberately imports, such as CSV or Excel project and invoice data. Planned integrations may include accounting, project-management, time-tracking, invoicing, email, and payment tools. When those integrations become available, their permissions, data categories, and revocation controls will be disclosed before connection, with read-only and least-privilege access preferred wherever practical.
2.3. Automated Telemetry and Usage Metrics
- Technical Infrastructure Data: We automatically log infrastructure metrics including IP addresses (which are anonymized prior to storage), browser user-agent strings, referring URLs, and device identifiers to ensure platform security and optimize performance.
- Marketing Attribution: We utilize standard UTM parameters and campaign identifiers to accurately measure the efficacy of our marketing and acquisition channels.
- Cookies and Tracking Technologies: Please refer to Section 8 for detailed disclosures on our deployment of essential and analytics cookies.
3. Utilization of Collected Data
We process your data strictly for legitimate commercial and operational purposes, including:
- Managing founding-access applications, workflow interviews, design-partner selection, and product communications.
- Researching, engineering, securing, and improving the Aerca product.
- Providing technical support, responding to inquiries, and issuing critical administrative notices.
- Aggregating anonymized usage telemetry to iteratively improve platform architecture and user experience.
- Monitoring against fraudulent activities, unauthorized access attempts, and ensuring strict regulatory compliance.
4. Legal Bases and Applicable Privacy Rights
We process personal data for the purposes stated in this Policy and as permitted by applicable law, including India's Digital Personal Data Protection framework. Where the GDPR or UK GDPR applies, our lawful bases may include consent for optional communications, legitimate interests in operating and securing the website and improving the product, contractual necessity when providing an agreed service, and legal obligations where required.
5. Information Sharing and Sub-processors
Aerca does not sell or rent personal or corporate data to data brokers or advertisers. We may share limited information with service providers that help us operate the website and founding-access process, subject to their applicable terms and safeguards:
- Hosting and Infrastructure: providers used to host and deliver the website.
- Forms and Communications: Google Apps Script or related Google services used to route application and contact-form submissions.
- Scheduling: Cal.com when you choose to book a call.
- Analytics and Attribution: Google Analytics, Meta Pixel, and campaign parameters where enabled.
- Future Product Providers: model, accounting, project, and infrastructure providers selected for product pilots, which will be disclosed as those workflows are introduced.
We reserve the right to disclose information to public authorities if legally compelled by a valid subpoena, court order, or binding regulatory mandate, or during a formal corporate restructuring, merger, or acquisition (in which case you will receive prior notification).
6. Data Retention Protocols
We retain information only as long as reasonably necessary for the purposes described here, including evaluating founding applications, maintaining relevant correspondence, operating the website, meeting legal obligations, and resolving disputes. We will review or delete application and contact records when they are no longer needed, and verified deletion requests will be handled subject to applicable law and reasonable backup-retention periods.
7. User Rights and Data Subject Access Requests (DSAR)
Depending on your jurisdiction, you possess comprehensive rights concerning your personal data. These include the right to access, rectify, port, or erase your data, as well as the right to restrict processing or withdraw previously granted consent. To execute a Data Subject Access Request, please contact our privacy team via the contact form on our homepage. We are committed to responding to all verified requests within the statutory timeframes mandated by applicable law.
8. Cookies and Session Management
Our platform utilizes localized cookies and equivalent session management technologies to maintain authentication states, secure user sessions, and aggregate anonymous traffic patterns. You maintain full control over non-essential cookies via your browser preferences. Restricting analytics cookies will not impede your access to the core platform functionalities.
9. International Data Transfers
Aerca operates globally. Data processed by Aerca and our sub-processors may be transferred to, and maintained on, servers located outside your state, province, or country, including the United States. When transferring data from the EEA or the UK, we rely on legally validated transfer mechanisms, including Standard Contractual Clauses (SCCs), to ensure equivalent levels of protection.
10. Security Posture
We use safeguards appropriate to Aerca's current development stage and the sensitivity of the information involved. The desktop prototype uses encrypted local storage and operating-system credential storage for supported secrets. Production safeguards, integrations, access controls, and audit capabilities are still being developed and will be documented as they become available. No system can guarantee absolute security.
11. Children's Privacy
Aerca provides strictly B2B enterprise software. Our Services are not directed at, nor do we knowingly collect personal information from, any individual under the age of eighteen (18).
12. Policy Modifications
We reserve the right to amend this Privacy Policy to reflect technological advancements, regulatory changes, or evolving business practices. Updated iterations will be published on this URL. Material revisions will be communicated directly to registered users via email.
13. Contact Information
For inquiries regarding this Privacy Policy, your data rights, or our security practices, please direct your correspondence to our compliance team using the contact form on our homepage.