Who we are

Scorpiosys LLC, San Ramon, California, runs scorpiosys.ai and decides how the personal data described here is used. For any question about this notice, or to exercise a right described below, write to connect@scorpiosys.ai.

What we collect

When you send the contact form we receive your name, work email, company, the topic you chose and what you wrote.

To stop automated abuse of the form, we keep a salted hash of your IP address and of your email address as rate-limit counters, for up to two hours. The hashes cannot be read back without a secret key we hold. We also keep a short key that stops the same submission being sent twice, for up to 24 hours.

Our hosting provider keeps standard request logs, such as the page requested, the time and the IP address, for security and operation of the site.

What we do not collect

The site runs no analytics, no advertising or tracking cookies, no fingerprinting and no third-party scripts. Fonts are served from our own domain. The only cookie the site sets records that you have seen the cookie notice; see Cookie preferences.

Why we use it

We use what you send through the form to reply to you and to discuss the work you describe. Where the GDPR or UK GDPR applies, the lawful basis is our legitimate interest in answering an enquiry you chose to send, or taking steps at your request before a contract. Under the DPDP Act, we process it on the basis of the consent you give by submitting the form, for that purpose only.

We use the rate-limit counters and request logs to keep the site and the form secure.

Who processes it for us

Vercel hosts the site and runs the form endpoint. Resend delivers the form to our inbox. Upstash stores the rate-limit counters and duplicate-protection keys. Google Workspace holds our email. Each acts on our instructions under its own data processing terms.

We do not sell or share personal information, as those terms are defined in the CCPA and CPRA, and we do not use it for targeted advertising.

How long we keep it

Enquiry emails are kept for up to 24 months after our last contact with you, unless you become a client, in which case our client agreement governs retention. Rate-limit counters expire within two hours and duplicate-protection keys within 24 hours. Hosting logs are kept for the period our hosting provider sets for security purposes.

International transfers

Our processors store data in the United States. Where the GDPR or UK GDPR applies, transfers rely on the European Commission Standard Contractual Clauses and the UK addendum, as incorporated in each processor’s terms. Our engineering centre in Hyderabad, India may read an enquiry to prepare a reply.

Your rights

Under the GDPR and UK GDPR you may ask for access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest. You may also complain to your supervisory authority.

If you live in California, the CCPA and CPRA give you the right to know what we hold, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share, so there is nothing to opt out of. We will not treat you differently for using any of these rights.

Under India’s DPDP Act you may ask for a summary of your data and how it is processed, correction and erasure, withdraw consent, nominate another person to act for you, and raise a grievance with us before approaching the Data Protection Board of India.

To use any of these rights, email connect@scorpiosys.ai. We reply within 30 days and may need to confirm who you are first.

Children

The site is for business audiences and is not directed at children under 16. We do not knowingly collect their data.

Security

The site is served over HTTPS only. Form data travels encrypted to our processors, service keys are held server-side, and access to enquiry email is limited to the people who reply to it.

Changes to this notice

When this notice changes, the date at the top changes with it. Material changes will be stated on this page.