Ackaia Corporation General Privacy Policy#
Ackaia Corporation v1.01.00 August 30, 2026 1233 York Avenue, Apt. 301 New York, NY 10065 United States of America www.ackaia.com
Effective Date: August 30, 2026
Entity: Ackaia Corporation, 1233 York Avenue, Apt. 301, New York, NY 10065, United States
(“Ackaia”, “Ackaia Corp.”, “we”, “our”, “us”)
Applies To: Ackaia-operated websites, Ackaia ID, shared account and subscription services, customer-facing applications, APIs, support channels, and other products or services that link to this General Privacy Policy, except where a product-specific privacy policy provides more specific information.
Document Owner: Ackaia Corp. Privacy / Legal / Security
Primary Privacy Contact: privacy@ackaia.com
---
Revision History#
| Version | Changes | Date |
|---|---|---|
| 1.01.00 | Added disclosures for Ackaia ID identity and credential verification, including MFA checks, encrypted document review, access controls, purposes, legal bases, document destruction, metadata retention, and unrecognized-request handling. | 08/30/2026 |
| 1.00.00 | Initial Publication | 07/24/2026 |
---
1. Purpose#
This General Privacy Policy explains how Ackaia collects, uses, stores, protects, shares, transfers, and otherwise processes personal information across the Ackaia ecosystem.
Ackaia builds privacy-first infrastructure. We seek to minimize unnecessary collection, limit access, use security and privacy by design, explain material processing clearly, and avoid business models based on selling personal information.
This Policy also explains the choices and privacy rights that may be available to you. Those rights vary by jurisdiction and may be subject to verification, exceptions, and limitations under applicable law.
2. Who We Are#
Ackaia Corporation is a company headquartered in New York, United States. Depending on the context and applicable law, Ackaia may act as a:
- controller or business that determines why and how personal information is processed;
- processor or service provider acting on documented instructions from a customer;
- joint or independent controller with another organization where responsibilities are shared or separately determined;
- operator of a Service that processes account, security, billing, and operational information.
Where Ackaia processes personal information for an organizational customer under a separate agreement, that customer’s privacy notice and instructions may also apply.
3. Scope#
This Policy applies to personal information processed through:
- Ackaia websites, dashboards, and public pages;
- Ackaia ID registration, authentication, account recovery, and security;
- shared subscriptions, entitlements, billing, offers, and account services;
- customer-facing Ackaia products and applications;
- Ackaia-operated APIs and developer services;
- support, feedback, legal, trust, safety, and security-reporting channels;
- communications from Ackaia;
- events, research, beta programs, and community participation where this Policy is presented;
- internal security, fraud-prevention, abuse-prevention, and service-reliability operations associated with those activities.
This Policy does not apply to:
- third-party services not controlled by Ackaia;
- employment or applicant information governed by a separate notice;
- information processed exclusively by an organizational customer for its own purposes;
- processing covered by a more specific notice to the extent that notice states different or additional practices.
4. Relationship to Product-Specific Privacy Policies#
Some Ackaia products process information in ways that require additional explanation. Their product-specific privacy policies supplement this Policy.
If a product-specific privacy policy conflicts with this Policy, the product-specific policy controls for that product and subject matter. This General Privacy Policy continues to apply to shared services such as Ackaia ID, corporate websites, account security, billing, legal compliance, and cross-service administration unless the product policy expressly states otherwise.
For example, CipherDrive™ has a separate Privacy Policy describing encrypted storage, file metadata, public sharing, local key storage, transfer accounting, and its Risk Assessment Engine.
5. Definitions#
“Personal Information” or “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an individual or household, as defined by applicable law.
“Processing” means collecting, using, storing, organizing, transmitting, disclosing, securing, deleting, or otherwise handling personal information.
“Service” or “Services” means an Ackaia-operated website, application, account system, product, API, interface, feature, or related service.
“Sensitive Personal Information” means categories given additional protection under applicable law, which may include authentication secrets, precise location, government identifiers, financial information, health information, biometric information, or information revealing certain protected characteristics.
“Service Provider” means a vendor, contractor, processor, or other organization that processes information to help Ackaia operate.
6. Categories of Information We Process#
The categories below describe information Ackaia may process. The actual categories depend on which Services you use, your settings, your location, your plan, and your interactions with Ackaia.
6.1 Account and Identity Information#
We may process:
- name and display name;
- email address and verified-contact status;
- Ackaia ID and other internal identifiers;
- username, profile information, and avatar;
- account creation date, status, type, and settings;
- organization, role, team, or membership information;
- age or eligibility confirmation where necessary;
- country, region, language, and time zone;
- information used for account recovery or verification.
6.2 Authentication and Security Information#
We may process:
- password hashes and passkey-related public information;
- multifactor-authentication configuration;
- session, token, and credential identifiers;
- login, logout, recovery, verification, and revocation events;
- IP addresses;
- approximate location inferred from an IP address;
- device, browser, operating-system, and user-agent information;
- failed-login and security-challenge records;
- suspicious-activity, fraud, abuse, and risk indicators;
- authorization decisions, policy evaluations, and security audit events;
- records associated with trusted or remembered devices.
Ackaia does not store plaintext passwords. Product-specific cryptographic secrets and local key material are handled as described in the applicable product documentation.
6.3 Subscription and Billing Information#
If you use a paid Service, trial, promotion, or offer, we may process:
- selected plan, billing interval, and entitlements;
- subscription, renewal, cancellation, and grace-period status;
- transaction, invoice, order, offer, and promotion identifiers;
- billing name, email, address, and tax information;
- payment status and fraud indicators;
- limited payment-method metadata provided by a processor, such as card brand, last digits, expiration information, or a processor token;
- credits, discounts, and redemption history.
Payment processors generally process full payment-card details directly. Ackaia does not intend to store full card numbers when a payment processor performs that function.
6.4 Government and Tax Identifiers#
Where required for billing, tax, compliance, identity, or account purposes, Ackaia may process a government or tax identifier supplied by you, such as a CPF, SSN, NIF, or equivalent identifier.
Unless a separate notice states otherwise, structural or mathematical validation does not mean Ackaia verified the identifier with a government agency or confirmed that it belongs to the person who supplied it.
6.5 Service and Usage Information#
We may process:
- Services and features accessed;
- page, screen, endpoint, or action events;
- request dates, timestamps, durations, and status codes;
- usage, quota, entitlement, and rate-limit records;
- feature preferences and configuration;
- API client, integration, and application identifiers;
- diagnostic, crash, reliability, and performance information;
- service region and routing information;
- records of administrative or organizational actions;
- non-content telemetry needed to operate and improve the Services.
6.6 Device, Network, and Website Information#
When you visit or use Ackaia websites and applications, we may process:
- IP address and approximate IP-derived region;
- browser, device type, and operating system;
- referring and destination pages;
- timestamps and navigation events;
- cookie, local-storage, session-storage, or similar identifiers;
- consent and preference records;
- security, bot-detection, and anti-fraud signals;
- performance and error telemetry.
6.7 Communications, Support, and Feedback#
If you communicate with Ackaia, we may process:
- your name, email address, and Account identifiers;
- the content and metadata of the communication;
- attachments, screenshots, logs, or files you choose to provide;
- support, complaint, appeal, and resolution history;
- survey responses and feedback;
- call or meeting information where notice and consent requirements are satisfied.
Do not send passwords, private keys, recovery phrases, illegal material, or unrelated sensitive information through ordinary support channels.
6.8 User Content#
Some Services allow you to submit, store, publish, transmit, or share User Content. Ackaia processes that content as necessary to provide the relevant Service and for the purposes described in applicable Product Terms.
Product architecture matters. For a supported zero-knowledge or end-to-end encrypted feature, Ackaia may store encrypted content without possessing the cryptographic material required to decrypt it. Other Services, support submissions, public pages, or communications may provide content to Ackaia in plaintext.
A general privacy statement does not override the specific technical boundaries described for a product.
6.9 Security, Trust, Safety, and Abuse Information#
We may process:
- authentication and authorization events;
- security alerts, audit logs, and incident records;
- fraud, spam, malware, phishing, or abuse indicators;
- public-link, endpoint, account, or integration risk signals;
- reports submitted by users, researchers, claimants, or authorities;
- vulnerability reports and remediation communications;
- hashes, fingerprints, or other technical indicators described in a Product Policy;
- enforcement, appeal, preservation, and legal-compliance records.
6.10 Information from Integrations and Third Parties#
We may receive information from:
- payment processors;
- identity, authentication, or verification providers you choose to use;
- organizational administrators;
- integrations you authorize;
- infrastructure, security, email, monitoring, or support providers;
- abuse reporters, copyright claimants, researchers, or law-enforcement authorities;
- public sources where collection and use are lawful;
- transaction, fraud-prevention, or sanctions-screening partners where applicable.
The categories received depend on the third party, your choices, and the purpose of the integration.
6.11 Ackaia ID Identity and Credential Verification Information#
When an authorized Ackaia staff member initiates a verification request for a sensitive support, privacy, security, legal, account, or credential-related matter, we may process:
- a verification-request identifier, status, creation and expiration dates, completion progress, and the verification methods requested;
- the reason for the request, document instructions, accepted document types, and an optional support-case reference, which are displayed to the signed-in Account holder and authorized Ackaia personnel;
- your response to the request, including whether you complete a step or report that you do not recognize the request;
- for an MFA step, the current one-time code you submit, the validation result, attempt count, timestamps, and limited security information used for rate limiting and short-lived replay prevention. The submitted one-time code is used transiently and is not stored as part of the verification record;
- for a document step, the document or credential you submit, which may include a government-issued identity document, passport, driver’s license, press credential, student credential, or another document specifically described in the request;
- information visible in the submitted document, which may include your name, portrait, date of birth, nationality, signature, document or credential number, issuer, affiliation, eligibility status, and issue or expiration date, depending on the document and purpose;
- limited file and security metadata, such as the original filename, media type, file size, integrity information, submission time, and destruction time;
- the reviewer’s identity, review decision, public review note, and review timestamps; and
- security and audit information associated with creating, viewing, completing, declining, cancelling, expiring, or reviewing the request, such as relevant Account identifiers, IP address, user agent, and event timestamps.
Please submit only the document, pages, and information reasonably requested. Avoid including unrelated sensitive information.
The current Ackaia ID verification feature uses human review for submitted documents. It does not use facial recognition or automated biometric matching. A document portrait remains personal information and may incidentally reveal sensitive characteristics. We do not use those characteristics to infer protected traits or for an unrelated purpose. If Ackaia later introduces biometric processing, we will provide additional notice and establish an appropriate legal basis, including consent where required, before that processing begins.
7. Sources of Personal Information#
Ackaia may collect personal information:
- directly from you;
- automatically from your device, browser, or use of a Service;
- from an organization or administrator that provides access to you;
- from Service Providers and integrations;
- from another user when they invite, share, or interact with you;
- from security researchers, abuse reporters, legal claimants, or authorities;
- from public sources where permitted by law;
- by deriving operational or security information from other data.
8. How We Use Personal Information#
8.1 Provide and Operate the Services#
We use information to:
- create and maintain Accounts;
- authenticate users and authorize actions;
- deliver product features and requested transactions;
- maintain settings, entitlements, quotas, and organization membership;
- route requests and operate infrastructure;
- provide support and resolve technical problems;
- enable integrations and exports you request.
8.2 Secure Accounts, Users, and Infrastructure#
We use information to:
- prevent unauthorized access and account takeover;
- detect suspicious activity, fraud, malware, abuse, and policy violations;
- enforce authentication, authorization, rate, and security controls;
- investigate and respond to incidents;
- protect cryptographic and key-management workflows;
- preserve service integrity and availability;
- maintain security and audit records.
8.3 Process Payments and Manage Entitlements#
We use information to:
- process transactions and renewals;
- issue invoices and receipts;
- apply plans, promotions, credits, and quotas;
- prevent payment fraud;
- manage cancellations, disputes, and refunds;
- meet accounting and tax obligations.
8.4 Communicate With You#
We use information to:
- send authentication, security, billing, and service notices;
- respond to support, privacy, legal, and security requests;
- provide policy and product updates;
- request feedback;
- send optional marketing communications where permitted.
8.5 Maintain, Analyze, and Improve#
We use operational information to:
- debug errors and investigate failures;
- measure reliability, performance, and capacity;
- understand feature adoption and usability;
- improve accessibility and localization;
- develop and evaluate Services;
- prevent outages and reduce operational risk.
Where feasible, Ackaia may aggregate, de-identify, minimize, or pseudonymize information used for these purposes.
8.6 Enforce Terms and Protect Rights#
We use information to:
- investigate suspected violations;
- prevent harm to users, victims, Ackaia, or third parties;
- enforce contracts, policies, and legal rights;
- manage complaints, appeals, and disputes;
- preserve evidence and establish, exercise, or defend legal claims.
8.7 Comply With Law#
We may use or disclose information to:
- comply with legal and regulatory obligations;
- respond to valid legal process;
- meet tax, accounting, consumer-protection, and data-protection requirements;
- report suspected child exploitation or other serious illegal activity where required or appropriate;
- respond to emergencies and credible threats of severe harm.
Our approach to legal process is described in the Ackaia Corporation Legal Request Response Policy.
8.8 Verify Identity or Credentials for Sensitive Requests#
We use verification information only as reasonably necessary to:
- confirm that a person controls the relevant Ackaia ID or is the person to whom the request or Account relates;
- authenticate a person before responding to a sensitive support, privacy, security, legal, or Account request;
- confirm a credential or eligibility status when the verification request clearly identifies that purpose;
- prevent impersonation, unauthorized disclosure, Account takeover, fraud, and abuse;
- allow authorized personnel to review a submitted document and communicate the result;
- investigate an unrecognized verification request; and
- maintain proportionate security, compliance, and decision records.
We do not use submitted verification documents or MFA codes for advertising, marketing, unrelated product analytics, or automated profiling.
9. Legal Bases for Processing#
Where law requires a legal basis, Ackaia may rely on:
9.1 Contract#
Processing necessary to enter into or perform a contract with you, such as creating an Account, authenticating you, providing a Service, processing a subscription, or responding to a support request.
9.2 Legitimate Interests#
Processing necessary for legitimate interests, including security, fraud and abuse prevention, service reliability, product improvement, customer support, business administration, legal claims, and protection of users, provided those interests are not overridden by applicable rights and freedoms.
9.3 Legal Obligation#
Processing necessary to comply with applicable law, legal process, tax, accounting, reporting, child-safety, consumer-protection, or data-protection obligations.
9.4 Consent#
Processing based on consent where required, including certain optional communications, cookies, integrations, or features. You may withdraw consent at any time, without affecting processing already lawfully performed.
9.5 Vital Interests and Public Interest#
Limited processing necessary to protect life, prevent serious harm, protect children or victims, respond to an emergency, or perform a task in the public interest where applicable law permits.
9.6 Identity and Credential Verification#
The legal basis for a verification depends on why it was requested. Ackaia may process verification information as necessary to perform or administer a contract, respond to your request, pursue legitimate interests in Account security and fraud prevention, or comply with a legal obligation. Where a verification is used to authenticate a statutory privacy-rights request, information collected for that verification is limited to identity verification, request security, required recordkeeping, and handling the request.
If applicable law requires consent or another additional condition for a particular category of verification information, Ackaia will establish that condition before processing the affected information.
10. How We Disclose Personal Information#
Ackaia may disclose personal information in the following circumstances.
10.1 Service Providers#
We may engage providers for:
- cloud hosting and storage;
- network delivery and infrastructure;
- payment processing and billing;
- email and communications;
- security, logging, fraud prevention, and monitoring;
- customer support and ticketing;
- analytics and performance measurement;
- professional legal, accounting, insurance, and audit services;
- abuse prevention and child-safety functions;
- other operational services.
Providers are authorized to process information only for defined purposes and are subject to contractual, legal, and technical safeguards as appropriate to their role.
10.2 Organizational Customers and Administrators#
If an organization controls your Account or access, Ackaia may disclose relevant account, membership, administrative, security, entitlement, and usage information to authorized administrators, subject to the Service design and applicable agreements.
10.3 Integrations and Your Direction#
We disclose information when you direct us to do so, including when you:
- enable an integration;
- use a shared or public feature;
- invite another user;
- export information;
- request support involving a third party.
10.4 Security, Safety, and Legal Compliance#
We may disclose information to authorities, reporting bodies, child-protection organizations, security partners, affected organizations, or other appropriate recipients where reasonably necessary and legally permitted to:
- comply with law or valid legal process;
- prevent fraud, abuse, exploitation, malware, or severe harm;
- protect users, victims, Ackaia, or third parties;
- investigate or respond to a security incident;
- establish, exercise, or defend legal claims;
- enforce applicable agreements.
10.5 Business Transactions#
Information may be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate confidentiality and privacy safeguards.
10.6 Public Information#
Information you intentionally publish through a public profile, repository, page, comment, link, or sharing feature may be visible to others and may be copied or redistributed outside Ackaia’s control.
10.7 Access to Identity Verification Information#
Submitted verification documents are available only to authorized Ackaia personnel whose role requires access to review or administer the request. Access to a document is controlled and logged. The Account holder can view the reason, case reference, instructions, status, progress, and applicable public review note for their request.
Infrastructure and storage providers may process encrypted document data and related operational metadata as Service Providers under the safeguards described in Section 10.1. Ackaia does not sell verification information, share it for cross-context behavioral advertising, or disclose a submitted verification document for an unrelated commercial purpose.
11. Sale and Sharing of Personal Information#
Ackaia does not sell personal information for money.
Ackaia does not share personal information for cross-context behavioral advertising and does not use encrypted CipherDrive™ file contents for advertising.
If Ackaia introduces a practice treated as a “sale” or “sharing” under applicable law, we will update this Policy and provide required notices and opt-out mechanisms before or when the practice begins.
Disclosures to Service Providers, disclosures you direct, and disclosures for security or legal purposes are not treated as sales where applicable law excludes them from that definition.
12. Cookies and Similar Technologies#
Ackaia may use cookies, local storage, session storage, IndexedDB, and similar technologies for:
- authentication and session management;
- account and security controls;
- user preferences and accessibility;
- fraud and abuse prevention;
- performance, diagnostics, and basic usage measurement;
- consent and communication preferences;
- product-specific local cryptographic state as separately disclosed.
Where required, Ackaia will request consent for non-essential technologies. You can use browser or device settings to control these technologies, but disabling essential storage may prevent a Service from working.
13. International Data Transfers#
Ackaia is based in the United States and may use infrastructure and Service Providers in multiple countries. Personal information may therefore be processed outside the country where you live.
Where required, Ackaia uses recognized transfer mechanisms and safeguards, which may include:
- adequacy decisions;
- standard contractual clauses;
- contractual and organizational protections;
- transfer risk assessments;
- another mechanism permitted by applicable law.
Product-specific region placement or storage architecture may be described separately and does not necessarily mean all account, security, or support information remains in that region.
14. Data Retention#
Ackaia retains personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, protect security, meet legal obligations, resolve disputes, and enforce agreements.
Retention depends on factors such as:
- the Service and type of information;
- whether the Account or subscription remains active;
- user settings and deletion actions;
- security, fraud, abuse, and incident requirements;
- tax, accounting, contractual, and legal obligations;
- backup and disaster-recovery cycles;
- litigation holds and valid preservation requests;
- whether information can be safely aggregated or de-identified.
Deletion from active systems may not immediately remove information from encrypted backups, immutable security records, or legally required archives. Such information remains protected and is removed or overwritten according to applicable lifecycle processes.
Identity-verification documents follow a shorter, purpose-specific lifecycle. A submitted document is retained only while it awaits an authorized review. The document is permanently and cryptographically destroyed as soon as an approval or rejection decision is recorded, or earlier if the Account holder marks the request as unrecognized, Ackaia cancels the request, or the request expires. Ackaia deletes the stored ciphertext and irreversibly clears the document-encryption key and content-integrity value. If physical deletion of a residual storage object cannot be completed immediately, clearing the key renders that ciphertext unrecoverable by Ackaia. The document image or PDF is not retained in accessible form as part of the completed review record.
The one-time MFA code submitted for a verification is not retained in the verification record. A short-lived non-reversible replay-prevention value may be held for approximately two minutes, and rate-limiting information may be held temporarily to protect the verification endpoint.
After a verification closes, Ackaia currently retains limited request, step, decision, and document metadata for up to 90 days to show the outcome, resolve errors or disputes, and protect the integrity of the process. After that period, sensitive operational metadata—including the written reason, support-case reference, document instructions and types, rejection or review notes, original filename, and media type—is deleted or redacted. Minimal audit events may be retained longer where reasonably necessary for security, abuse prevention, legal obligations, or legal claims, but those events do not contain the submitted document or MFA code. A valid legal preservation obligation may delay deletion of eligible records, but cannot restore a document that has already been cryptographically destroyed.
15. Security#
Ackaia maintains technical, administrative, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
Safeguards may include:
- access control and least privilege;
- multifactor authentication for sensitive access;
- encryption in transit and at rest where appropriate;
- secure development and change management;
- logging, monitoring, and incident response;
- vulnerability management and responsible disclosure;
- backups and continuity controls;
- personnel and provider safeguards;
- data minimization and retention controls.
For Ackaia ID document verification, the file is encrypted before it reaches persistent storage using a unique document-encryption key protected separately from the stored ciphertext. Only authorized personnel can request a controlled review stream, and each document-view event is logged. Review responses are delivered with controls intended to prevent browser or intermediary caching. Recording a review decision deletes the stored ciphertext and irreversibly clears the cryptographic material required to recover it.
Details are provided in the Ackaia Corporation Information Security Policy. No security program eliminates all risk, and you are responsible for protecting your credentials, devices, sessions, and recovery information.
16. Automated Systems#
Ackaia may use automated systems to:
- authenticate and authorize actions;
- detect account compromise, fraud, abuse, malware, or suspicious activity;
- enforce rate, quota, payment, and security controls;
- route support or operational events;
- generate product-specific risk signals described in applicable Product Policies.
Automated systems may block or restrict an action or Account. Where required by law and reasonably feasible, Ackaia provides a way to request review or appeal a significant automated enforcement action.
Ackaia does not intend to make solely automated decisions that produce legal or similarly significant effects about individuals unless the processing is permitted by law and appropriate notice and safeguards are provided.
17. Your Privacy Rights#
Depending on where you live and the context, you may have the right to:
- know whether Ackaia processes your personal information;
- access or receive a copy of personal information;
- correct inaccurate or incomplete information;
- delete information;
- restrict or object to processing;
- withdraw consent;
- receive portable information in a structured format;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit certain uses of sensitive personal information;
- appeal a denied privacy request;
- lodge a complaint with a data-protection authority;
- receive equal service and not be discriminated against for exercising a right.
These rights are not absolute. Exceptions may apply for security, fraud prevention, legal obligations, freedom of expression, protection of others, contractual necessity, or legal claims.
18. Rights in the European Economic Area and European Union#
Where the General Data Protection Regulation applies, you may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.
You may object to processing based on legitimate interests. Ackaia will stop the affected processing unless it demonstrates compelling legitimate grounds or the processing is needed for legal claims.
Where processing is based on consent, withdrawal does not affect the lawfulness of processing performed before withdrawal.
19. Rights in the United Kingdom#
Where the United Kingdom General Data Protection Regulation and Data Protection Act 2018 apply, you may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and safeguards relating to automated decision-making.
You may complain to the UK Information Commissioner’s Office or another competent authority. Ackaia encourages you to contact privacy@ackaia.com first so we can try to resolve the concern.
20. Rights in Brazil#
Where the Lei Geral de Proteção de Dados Pessoais (“LGPD”) applies, you may have rights to:
- confirm processing;
- access personal data;
- correct incomplete, inaccurate, or outdated data;
- request anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data;
- request portability where regulated and applicable;
- obtain information about recipients and consequences of refusing consent;
- withdraw consent;
- request review of certain automated decisions;
- petition the Autoridade Nacional de Proteção de Dados or consumer-protection bodies.
For LGPD purposes, Ackaia may act as controlador or operador depending on the processing context.
21. Rights in California#
Where the California Consumer Privacy Act, as amended, applies, California residents may have rights to:
- know the categories and specific pieces of personal information collected;
- know the categories of sources, purposes, and recipients;
- request deletion;
- request correction;
- opt out of sale or sharing;
- limit certain uses or disclosures of sensitive personal information;
- receive non-discriminatory treatment for exercising a right.
Ackaia does not sell personal information or share it for cross-context behavioral advertising as described in Section 11.
You may use an authorized agent where permitted by law. Ackaia may verify your identity and the agent’s authority before completing a request.
22. Exercising Your Rights#
To submit a privacy request, contact privacy@ackaia.com or use privacy controls made available in the relevant Service.
Please identify:
- the right you wish to exercise;
- the relevant Ackaia Service;
- the Account or email involved;
- your jurisdiction, if relevant;
- sufficient detail for us to understand the request.
Ackaia may verify your identity and authority using information reasonably related to the request. We will not ask for more information than necessary. For sensitive or high-risk requests, additional verification may be required to protect the Account and other people.
When Ackaia uses the Ackaia ID verification feature, the request will identify why verification is needed, the required method or methods, any document instructions, and when the request expires. MFA can be requested only if it is already enabled on the Account. You may complete the requested steps separately, report that you do not recognize the request, or contact privacy@ackaia.com if you need to discuss an alternative verification method.
If we cannot reasonably verify your identity or authority, we may defer or decline the affected sensitive request to prevent unauthorized disclosure or Account action. This does not waive your privacy rights. Where required by law, we will explain the decision and provide an available alternative or appeal process.
If Ackaia cannot fulfill a request, we will explain the reason where required by law and describe any available appeal process.
23. Organizational Accounts#
If your Account is provided or controlled by an organization, the organization may be responsible for responding to requests concerning information it controls.
Ackaia may direct your request to that organization or assist it as a processor. Requests concerning Ackaia-controlled Account, billing, security, or corporate information may remain Ackaia’s responsibility.
24. Children’s Privacy#
The Services are not directed to children under 13, and Ackaia does not knowingly collect personal information from a child under 13 without authorization required by law.
Where local law establishes a higher age for independent consent, a parent or legal guardian may need to authorize processing. If you believe a child provided information contrary to this Policy, contact privacy@ackaia.com.
Ackaia may process limited information to assess age or eligibility where necessary and lawful. We seek to minimize that information and do not use it for unrelated advertising.
25. Data Breaches and Incident Notification#
Ackaia maintains incident-response processes designed to identify, contain, investigate, remediate, and learn from security incidents.
If an incident involving personal information triggers a legal notification obligation, Ackaia will notify affected individuals, customers, regulators, or other parties within the time and in the manner required by applicable law.
Notification may be delayed where authorized or required by law enforcement, necessary to avoid increasing harm, or otherwise permitted by applicable law.
26. De-Identified and Aggregated Information#
Ackaia may create and use aggregated or de-identified information for security, reliability, analytics, research, capacity planning, and product improvement.
Where information is maintained as de-identified, Ackaia will not attempt to re-identify it except where permitted to test the effectiveness of de-identification or required by law.
27. Do Not Track and Global Privacy Control#
Because there is no uniform industry standard for browser “Do Not Track” signals, Ackaia may not respond to those signals in a consistent manner.
Where applicable law requires recognition of a valid opt-out preference signal, such as Global Privacy Control, Ackaia will process the signal for the browser or device from which it is received. Because Ackaia does not currently sell personal information or share it for cross-context behavioral advertising, such a signal may not change current practices.
28. Changes to This Policy#
Ackaia may update this Policy to reflect changes in law, Services, technology, security, operations, or data practices.
The revision history and effective date identify the current version. For material changes, Ackaia will provide notice where reasonably required through email, an Account notice, the affected Service, or the Legal Repository.
If a change requires consent under applicable law, Ackaia will request consent before applying the change to the affected processing.
29. Complaints#
If you have a privacy concern, contact privacy@ackaia.com. We will review and respond within the period required by applicable law.
You may also submit a complaint to the competent privacy, data-protection, consumer-protection, or regulatory authority in your jurisdiction.
30. Contact#
Ackaia Corp. Privacy: privacy@ackaia.com
Legal: legal@ackaia.com
Security: security@ackaia.com
Abuse: abuse@ackaia.com
Website: www.ackaia.com
Address: 1233 York Avenue, Apt. 301, New York, NY 10065, United States of America
---
End of General Privacy Policy
