Skip to content

Privacy Policy

Last updated: 7 September 2026

1. Who we are, and in what capacity

Ayonix Corporation ("Ayonix", "we", "us", "our") builds computer vision and artificial intelligence software. This policy explains what we do with personal data, and it covers two relationships that data protection law treats very differently. Reading the right one matters, because the rights you have and the party you exercise them against depend on which applies.

Ayonix as controller β€” this website and our own business
When you visit ayonix.com, submit an enquiry, apply for a job, hold an account on our platforms, or deal with us as a customer, partner or supplier, Ayonix decides why and how your data is processed. We are the controller, and this policy is the notice for that processing. Requests go to infojp@ayonix.com.
Ayonix as processor β€” biometric and video data in customer deployments
When an organisation uses our software to process images, video, facial templates or embeddings, that organisation is the controller. It decides the purpose, the lawful basis and the retention period; we act only on its documented instructions under a data processing agreement. If your face has been processed by an Ayonix-powered system operated by someone else, your rights are exercised against that operator, not against us. Tell us and we will pass the request on where we can identify the customer, but we cannot answer it for them.

This website is not a biometric pipeline

ayonix.com holds no facial templates, embeddings, vectors or image buffers, and has no endpoint that accepts video for recognition. Nothing about visiting this site enrols you in any biometric system. Where our software processes biometric data it does so in deployments our customers run β€” commonly on their own premises, at the edge or in their own cloud tenancy, where we neither receive the data nor can retrieve it.

Where we act as controller, the establishment responsible is Ayonix Corporation, headquartered in Tokyo, Japan, with offices in Melbourne, Australia and Delaware, United States.

2. What we collect

Data you give us

WhereWhat we storeWhy
Contact and demonstration enquiriesName, work email, company, phone, your message, and the solution type, deployment scale, industry and timeline you selectTo answer you and to prepare a relevant response
Partnership applicationsThe same record as above, with partnership type, company website and region of interest recorded in the messageTo assess and respond to the application
Job applicationsName, email, phone, LinkedIn URL, the position applied for, your cover letter, and your CV fileTo assess your application and communicate with you about it
Platform accountsName, email, password hash, sign-in method, role, account timestamps, and β€” where you enable them β€” passkey credential identifiers, public keys and authenticator counters, or a TOTP secretTo create and secure your account and authenticate you
Passwords are stored as a hash, never in readable form. CV files are held in Cloudflare R2 object storage rather than in the database record.

Data we record automatically

CategoryWhat we storeWhy
Authentication eventsEmail address attempted, IP address, browser user-agent string, whether the attempt succeeded, and the reason for failureTo detect credential-stuffing and brute-force attempts
Account lockoutsEmail address, lockout time and expiry, reason, and the number of failed attemptsTo enforce lockout after repeated failures
Security eventsAccount identifier, event type, IP address, user-agent, approximate location, severity and event metadataTo investigate suspicious activity and keep an audit trail
Network and delivery dataIP address and request metadata seen by Cloudflare as it serves and protects the siteTo deliver the site and mitigate attacks
Site measurementPage views and page-load timings, reported by Cloudflare Web AnalyticsTo understand which pages are used and how quickly they load
Cloudflare Web Analytics is cookieless: it stores nothing on your device, reads nothing stored there, and does not fingerprint your browser. The Cookie Policy sets out the detail.

We do not build advertising profiles, we run no third-party advertising or profiling trackers, and we do not attempt to identify individual visitors from technical data. The cookies and local storage this site uses are listed in full in our Cookie Policy.

Biometric and video data

Where our software processes images, video frames, facial landmark arrays, facial templates or embeddings, it does so on behalf of the customer operating the deployment. Ayonix does not harvest biometric data, does not sell it, and does not use biometric data processed on a customer's behalf to train, fine-tune, evaluate or otherwise improve our models, except where that customer has separately and specifically authorised it in writing.

In architectures where we host processing, frames are handled in memory for the time it takes to compute a result and are not written to durable storage as images. What persists is what the customer's configuration says should persist β€” typically a numerical template or embedding, held in the customer's own store under the customer's retention schedule.

4. Retention and destruction

We keep personal data no longer than the purpose requires, and then delete it. Where a period below is expressed as a maximum, the data is deleted earlier once the purpose is satisfied.

DataRetention
Contact and partnership enquiriesUp to 24 months from the last exchange with you, then deleted
Job applications and CV filesUp to 12 months after the decision, unless you ask us to keep them on file for future roles or local law requires a different period
Account recordsFor the life of the account, and up to 90 days after closure to complete deletion across backups
Authentication attempts and lockoutsUp to 12 months, as a security record
Security eventsUp to 24 months, or longer where an investigation or legal obligation requires it
Consent record182 days, held in a cookie on your own device

Biometric data

Retention of biometric data in a deployment is set by the customer operating it, and that customer is responsible for publishing its schedule and honouring it. Where Ayonix processes biometric data on a customer's behalf, we apply the following commitments.

  • Video frames and images submitted for recognition are processed in memory and are not retained as images once the result is returned.
  • Facial templates and embeddings are retained only for the term of the customer's instruction, and are deleted or returned on termination of the agreement.
  • Where Illinois BIPA applies, our standard is destruction on the earlier of the date the purpose for collection is satisfied and three years after the individual's last interaction with the controller β€” the outer limit BIPA sets β€” and sooner where the customer's own schedule is shorter.
  • Deletion instructions from a customer are actioned across live systems promptly, and worked through backups within 90 days as those backups age out.
  • Aggregate and statistical records that cannot be linked to an individual may be kept longer, because they are no longer personal data.

5. Sharing and disclosure

We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. Because no such sale or sharing takes place, there is no β€œDo Not Sell or Share My Personal Information” mechanism to operate: the answer is already no for every person. We have not sold or shared personal information in the preceding twelve months.

We disclose personal data only in these circumstances:

  • To the subprocessors listed in the next section, which process it on our documented instructions and under contract.
  • To professional advisers β€” lawyers, auditors, accountants β€” bound by duties of confidentiality.
  • Where a law, regulation, court order or binding request from a public authority requires it. We assess each request, disclose only what is required, and tell the affected person unless legally prohibited from doing so.
  • To protect the rights, safety or property of Ayonix, our customers or the public, including to investigate fraud or a security incident.
  • In connection with a merger, acquisition, financing or sale of assets, under confidentiality obligations and with notice where the law requires it.

6. Subprocessors and international transfers

The services below are the ones this website and platform actually use. Each processes data on our instructions under a written agreement that includes the data protection terms the applicable law requires.

ProviderPurposeData it can see
CloudflareHosting, content delivery, security, the D1 database and R2 object storageAll data the site holds, plus request metadata and IP addresses
OpenAIGenerating replies in the website chat assistantThe text you type into the chat widget, and any file content you attach there
ElevenLabsSpeech synthesis for the voice assistantThe text to be spoken, and audio you submit for transcription
ResendDelivering notification email when a form is submittedThe contents of the notification, including your name and email
Google, Apple, MicrosoftFederated sign-in, only if you choose to use itThe identity assertion exchanged during sign-in
The website chat assistant is not local. What you type into it is sent to OpenAI to generate a reply, so please do not enter confidential information, personal data about other people, or special category data.

We do not use Amazon Web Services or Google Cloud Platform for this website or platform.

International transfers

Ayonix is headquartered in Japan and our providers operate globally, so personal data may be processed outside the country you are in, including in the United States and the European Union. Where data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one covers the destination β€” Japan holds an adequacy decision from the European Commission β€” and otherwise on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, supported by a transfer risk assessment and technical measures including encryption in transit.

For transfers from Japan, we obtain the consent the Act on the Protection of Personal Information requires for provision to a third party in a foreign country, or rely on an equivalent-standards framework where one applies. A copy of the transfer mechanism relied on for a specific transfer is available on request.

7. Your rights and how to exercise them

Subject to the conditions and exemptions in the law that applies to you, you have the following rights over personal data for which Ayonix is the controller.

Access
Confirmation of whether we process your data, a copy of it, and information about the purposes, recipients and retention period.
Rectification
Correction of inaccurate data and completion of incomplete data.
Erasure
Deletion where the data is no longer needed, where consent is withdrawn and no other basis applies, or where it has been processed unlawfully.
Restriction and objection
Restriction of processing while a dispute is resolved, and objection to processing based on legitimate interests, which we will stop unless we can demonstrate compelling grounds that override your interests.
Portability
A copy of data you provided to us, in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible.
Withdrawal of consent
Withdrawal at any time where processing is based on consent. It is as easy to withdraw as it was to give, and takes effect immediately, though it does not affect processing already carried out.
CCPA and CPRA rights
The right to know what is collected and disclosed, to delete it, to correct it, to limit the use of sensitive personal information, to opt out of sale or sharing β€” which does not arise, because we do neither β€” and not to be discriminated against for exercising any of them.
Automated decisions
The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions about you on this website.

Making a request

Write to infojp@ayonix.com with the request you are making and enough detail for us to find your data β€” typically the email address you used with us. We will acknowledge promptly and respond within 30 days, or within the period the applicable law sets, and will tell you if we need to extend that period and why. We may ask for information to verify your identity, used only for verification, and we will not charge for a request unless it is manifestly unfounded or excessive.

An authorised agent may make a request on your behalf with written authority we can verify. If we cannot identify you in our records from the information supplied, we will say so rather than ask for more data than the request needs.

If your data is in a customer's deployment

Where Ayonix is only the processor, we cannot action a request about that data ourselves β€” the operator of the system holds the relationship with you and decides the outcome. Write to us anyway: where we can identify the customer we will forward your request and tell you that we have.

If you are unhappy with our response, you may complain to your data protection authority: in the EEA or UK your national supervisory authority, in Japan the Personal Information Protection Commission, in Australia the Office of the Australian Information Commissioner. We would rather hear from you first, and we will try to resolve it.

8. How we protect data

We apply technical and organisational measures appropriate to the risk, including encryption in transit for all traffic to and from this site, password hashing, support for multi-factor authentication and passkeys on platform accounts, rate limiting and automatic lockout after repeated failed sign-in attempts, logging of security-relevant events, and access controls limiting staff access to what their role requires.

No system is perfectly secure, and we do not claim otherwise. Where a personal data breach is likely to result in a risk to people's rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the law requires, within 72 hours of becoming aware of it, and we will notify affected people where the risk is high. Where we are the processor, we notify the controller without undue delay so it can meet its own obligations.

To report a suspected vulnerability or a security incident, write to infojp@ayonix.com.

9. Children's privacy

The Services are directed to businesses and professionals. They are not directed to children, and we do not knowingly collect personal data from anyone under 16 β€” nor, for the purposes of the Children's Online Privacy Protection Act, from any child under 13. We do not create accounts for children and do not market to them.

If you believe a child has given us personal data, write to infojp@ayonix.com and we will delete it promptly. Where a customer's deployment involves children β€” a school, for example β€” that customer is the controller, and it is responsible for obtaining the parental or guardian consent the law requires.

10. Changes to this policy

We will update this policy when what we do with personal data changes, and the date at the top will change with it. Where a change materially affects your rights β€” a new purpose, a new category of data, or a new subprocessor that can see your data β€” we will give notice before it takes effect, by email to the account contact we hold or by prominent notice on the website, and will obtain consent where the law requires it.

11. Contact us

For any question about this policy, to exercise a right, or to raise a concern about how we handle personal data:

Ayonix Corporation

Privacy, data protection, legal and security: infojp@ayonix.com

Headquarters: Tokyo, Japan

Offices: Melbourne, Australia and Delaware, United States

Website: https://ayonix.com