Privacy Policy
Last updated: 7 September 2026
1. Who we are, and in what capacity
Ayonix Corporation ("Ayonix", "we", "us", "our") builds computer vision and artificial intelligence software. This policy explains what we do with personal data, and it covers two relationships that data protection law treats very differently. Reading the right one matters, because the rights you have and the party you exercise them against depend on which applies.
- Ayonix as controller β this website and our own business
- When you visit ayonix.com, submit an enquiry, apply for a job, hold an account on our platforms, or deal with us as a customer, partner or supplier, Ayonix decides why and how your data is processed. We are the controller, and this policy is the notice for that processing. Requests go to infojp@ayonix.com.
- Ayonix as processor β biometric and video data in customer deployments
- When an organisation uses our software to process images, video, facial templates or embeddings, that organisation is the controller. It decides the purpose, the lawful basis and the retention period; we act only on its documented instructions under a data processing agreement. If your face has been processed by an Ayonix-powered system operated by someone else, your rights are exercised against that operator, not against us. Tell us and we will pass the request on where we can identify the customer, but we cannot answer it for them.
This website is not a biometric pipeline
ayonix.com holds no facial templates, embeddings, vectors or image buffers, and has no endpoint that accepts video for recognition. Nothing about visiting this site enrols you in any biometric system. Where our software processes biometric data it does so in deployments our customers run β commonly on their own premises, at the edge or in their own cloud tenancy, where we neither receive the data nor can retrieve it.
Where we act as controller, the establishment responsible is Ayonix Corporation, headquartered in Tokyo, Japan, with offices in Melbourne, Australia and Delaware, United States.
2. What we collect
Data you give us
| Where | What we store | Why |
|---|---|---|
| Contact and demonstration enquiries | Name, work email, company, phone, your message, and the solution type, deployment scale, industry and timeline you select | To answer you and to prepare a relevant response |
| Partnership applications | The same record as above, with partnership type, company website and region of interest recorded in the message | To assess and respond to the application |
| Job applications | Name, email, phone, LinkedIn URL, the position applied for, your cover letter, and your CV file | To assess your application and communicate with you about it |
| Platform accounts | Name, email, password hash, sign-in method, role, account timestamps, and β where you enable them β passkey credential identifiers, public keys and authenticator counters, or a TOTP secret | To create and secure your account and authenticate you |
Data we record automatically
| Category | What we store | Why |
|---|---|---|
| Authentication events | Email address attempted, IP address, browser user-agent string, whether the attempt succeeded, and the reason for failure | To detect credential-stuffing and brute-force attempts |
| Account lockouts | Email address, lockout time and expiry, reason, and the number of failed attempts | To enforce lockout after repeated failures |
| Security events | Account identifier, event type, IP address, user-agent, approximate location, severity and event metadata | To investigate suspicious activity and keep an audit trail |
| Network and delivery data | IP address and request metadata seen by Cloudflare as it serves and protects the site | To deliver the site and mitigate attacks |
| Site measurement | Page views and page-load timings, reported by Cloudflare Web Analytics | To understand which pages are used and how quickly they load |
We do not build advertising profiles, we run no third-party advertising or profiling trackers, and we do not attempt to identify individual visitors from technical data. The cookies and local storage this site uses are listed in full in our Cookie Policy.
Biometric and video data
Where our software processes images, video frames, facial landmark arrays, facial templates or embeddings, it does so on behalf of the customer operating the deployment. Ayonix does not harvest biometric data, does not sell it, and does not use biometric data processed on a customer's behalf to train, fine-tune, evaluate or otherwise improve our models, except where that customer has separately and specifically authorised it in writing.
In architectures where we host processing, frames are handled in memory for the time it takes to compute a result and are not written to durable storage as images. What persists is what the customer's configuration says should persist β typically a numerical template or embedding, held in the customer's own store under the customer's retention schedule.
3. Legal bases for processing
Where the GDPR or UK GDPR applies to processing for which we are the controller, we rely on the following bases under Article 6. Where we rely on legitimate interests, we have carried out a balancing assessment and will share it on request.
| Processing | Article 6 basis |
|---|---|
| Answering an enquiry or demonstration request | Steps at your request prior to entering a contract, Article 6(1)(b); legitimate interests in responding to business correspondence, Article 6(1)(f) |
| Assessing a job application | Steps at your request prior to entering a contract, Article 6(1)(b); legitimate interests in recruitment, Article 6(1)(f) |
| Operating an account and providing the Services | Performance of a contract, Article 6(1)(b) |
| Authentication logging, lockouts and security events | Legitimate interests in the security of our systems and our users' accounts, Article 6(1)(f); legal obligation where security incidents must be recorded, Article 6(1)(c) |
| Cookieless site measurement | Legitimate interests in understanding and improving the site, Article 6(1)(f) |
| Optional cookies and any future analytics cookies | Consent, Article 6(1)(a), withdrawable at any time |
| Responding to regulators, courts and law enforcement | Legal obligation, Article 6(1)(c) |
Special category data β Article 9
Biometric data processed for the purpose of uniquely identifying a person is a special category of data under Article 9. Where Ayonix processes it, we do so as a processor, and the Article 9 condition is the controller's to establish and document β most often explicit consent under Article 9(2)(a), or substantial public interest laid down in law under Article 9(2)(g). Our contracts require the customer to warrant that it holds that condition, together with every notice and consent that applicable law requires, before any biometric data is processed. We do not independently verify it, and in most deployments we cannot: we never see the data.
We do not ask for special category data on this website, and you should not send it to us through the enquiry form, the chat widget or email.
4. Retention and destruction
We keep personal data no longer than the purpose requires, and then delete it. Where a period below is expressed as a maximum, the data is deleted earlier once the purpose is satisfied.
| Data | Retention |
|---|---|
| Contact and partnership enquiries | Up to 24 months from the last exchange with you, then deleted |
| Job applications and CV files | Up to 12 months after the decision, unless you ask us to keep them on file for future roles or local law requires a different period |
| Account records | For the life of the account, and up to 90 days after closure to complete deletion across backups |
| Authentication attempts and lockouts | Up to 12 months, as a security record |
| Security events | Up to 24 months, or longer where an investigation or legal obligation requires it |
| Consent record | 182 days, held in a cookie on your own device |
Biometric data
Retention of biometric data in a deployment is set by the customer operating it, and that customer is responsible for publishing its schedule and honouring it. Where Ayonix processes biometric data on a customer's behalf, we apply the following commitments.
- Video frames and images submitted for recognition are processed in memory and are not retained as images once the result is returned.
- Facial templates and embeddings are retained only for the term of the customer's instruction, and are deleted or returned on termination of the agreement.
- Where Illinois BIPA applies, our standard is destruction on the earlier of the date the purpose for collection is satisfied and three years after the individual's last interaction with the controller β the outer limit BIPA sets β and sooner where the customer's own schedule is shorter.
- Deletion instructions from a customer are actioned across live systems promptly, and worked through backups within 90 days as those backups age out.
- Aggregate and statistical records that cannot be linked to an individual may be kept longer, because they are no longer personal data.
6. Subprocessors and international transfers
The services below are the ones this website and platform actually use. Each processes data on our instructions under a written agreement that includes the data protection terms the applicable law requires.
| Provider | Purpose | Data it can see |
|---|---|---|
| Cloudflare | Hosting, content delivery, security, the D1 database and R2 object storage | All data the site holds, plus request metadata and IP addresses |
| OpenAI | Generating replies in the website chat assistant | The text you type into the chat widget, and any file content you attach there |
| ElevenLabs | Speech synthesis for the voice assistant | The text to be spoken, and audio you submit for transcription |
| Resend | Delivering notification email when a form is submitted | The contents of the notification, including your name and email |
| Google, Apple, Microsoft | Federated sign-in, only if you choose to use it | The identity assertion exchanged during sign-in |
We do not use Amazon Web Services or Google Cloud Platform for this website or platform.
International transfers
Ayonix is headquartered in Japan and our providers operate globally, so personal data may be processed outside the country you are in, including in the United States and the European Union. Where data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one covers the destination β Japan holds an adequacy decision from the European Commission β and otherwise on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, supported by a transfer risk assessment and technical measures including encryption in transit.
For transfers from Japan, we obtain the consent the Act on the Protection of Personal Information requires for provision to a third party in a foreign country, or rely on an equivalent-standards framework where one applies. A copy of the transfer mechanism relied on for a specific transfer is available on request.
7. Your rights and how to exercise them
Subject to the conditions and exemptions in the law that applies to you, you have the following rights over personal data for which Ayonix is the controller.
- Access
- Confirmation of whether we process your data, a copy of it, and information about the purposes, recipients and retention period.
- Rectification
- Correction of inaccurate data and completion of incomplete data.
- Erasure
- Deletion where the data is no longer needed, where consent is withdrawn and no other basis applies, or where it has been processed unlawfully.
- Restriction and objection
- Restriction of processing while a dispute is resolved, and objection to processing based on legitimate interests, which we will stop unless we can demonstrate compelling grounds that override your interests.
- Portability
- A copy of data you provided to us, in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible.
- Withdrawal of consent
- Withdrawal at any time where processing is based on consent. It is as easy to withdraw as it was to give, and takes effect immediately, though it does not affect processing already carried out.
- CCPA and CPRA rights
- The right to know what is collected and disclosed, to delete it, to correct it, to limit the use of sensitive personal information, to opt out of sale or sharing β which does not arise, because we do neither β and not to be discriminated against for exercising any of them.
- Automated decisions
- The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions about you on this website.
Making a request
Write to infojp@ayonix.com with the request you are making and enough detail for us to find your data β typically the email address you used with us. We will acknowledge promptly and respond within 30 days, or within the period the applicable law sets, and will tell you if we need to extend that period and why. We may ask for information to verify your identity, used only for verification, and we will not charge for a request unless it is manifestly unfounded or excessive.
An authorised agent may make a request on your behalf with written authority we can verify. If we cannot identify you in our records from the information supplied, we will say so rather than ask for more data than the request needs.
If your data is in a customer's deployment
Where Ayonix is only the processor, we cannot action a request about that data ourselves β the operator of the system holds the relationship with you and decides the outcome. Write to us anyway: where we can identify the customer we will forward your request and tell you that we have.
If you are unhappy with our response, you may complain to your data protection authority: in the EEA or UK your national supervisory authority, in Japan the Personal Information Protection Commission, in Australia the Office of the Australian Information Commissioner. We would rather hear from you first, and we will try to resolve it.
8. How we protect data
We apply technical and organisational measures appropriate to the risk, including encryption in transit for all traffic to and from this site, password hashing, support for multi-factor authentication and passkeys on platform accounts, rate limiting and automatic lockout after repeated failed sign-in attempts, logging of security-relevant events, and access controls limiting staff access to what their role requires.
No system is perfectly secure, and we do not claim otherwise. Where a personal data breach is likely to result in a risk to people's rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the law requires, within 72 hours of becoming aware of it, and we will notify affected people where the risk is high. Where we are the processor, we notify the controller without undue delay so it can meet its own obligations.
To report a suspected vulnerability or a security incident, write to infojp@ayonix.com.
9. Children's privacy
The Services are directed to businesses and professionals. They are not directed to children, and we do not knowingly collect personal data from anyone under 16 β nor, for the purposes of the Children's Online Privacy Protection Act, from any child under 13. We do not create accounts for children and do not market to them.
If you believe a child has given us personal data, write to infojp@ayonix.com and we will delete it promptly. Where a customer's deployment involves children β a school, for example β that customer is the controller, and it is responsible for obtaining the parental or guardian consent the law requires.
10. Changes to this policy
We will update this policy when what we do with personal data changes, and the date at the top will change with it. Where a change materially affects your rights β a new purpose, a new category of data, or a new subprocessor that can see your data β we will give notice before it takes effect, by email to the account contact we hold or by prominent notice on the website, and will obtain consent where the law requires it.
11. Contact us
For any question about this policy, to exercise a right, or to raise a concern about how we handle personal data:
Ayonix Corporation
Privacy, data protection, legal and security: infojp@ayonix.com
Headquarters: Tokyo, Japan
Offices: Melbourne, Australia and Delaware, United States
Website: https://ayonix.com
