Bonterms-derivative. This Privacy Notice substantially follows the Bonterms Privacy Notice framework with adaptations for ElasticD3M, LLC's services, U.S. operations, GDPR for EU/UK/Swiss data subjects, CCPA/CPRA and other comprehensive U.S. state privacy laws, and the technical scope of the SCADA AI™ platform (configuration metadata, not regulated payloads).
1. Scope
This Privacy Notice describes how ElasticD3M, LLC ("we", "us") collects, uses, and discloses Personal Information when you visit ai4scada.ai, purchase a SCADA/OT Security Readiness & Gap Analysis, subscribe to an SCADA AI™ tier, or otherwise interact with our Services. For data we process on Customer's behalf as a Processor under enterprise agreements, the Data Processing Addendum governs.
This Notice applies to all visitors and customers. EU, UK, and Swiss data subjects have additional rights under GDPR / UK GDPR / Swiss FADP described in Section 5. California and other U.S. state residents have additional rights under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and analogous comprehensive privacy laws described in Section 6.
2. Controller and Processor Roles
For Personal Information processed when you interact with our marketing site, purchase the analysis, or correspond with us, ElasticD3M, LLC is the Controller (or "Business" under CCPA/CPRA).
For Personal Data processed on Customer's behalf when the SCADA AI™ Services generate the readiness analysis from the intake answers Customer submits, ElasticD3M, LLC is the Processor (or "Service Provider"). Customer is the Controller. The DPA governs those processing activities.
3. Information We Collect
We collect the following categories of Personal Information:
- Identity and contact information: name, business email address, phone number, company name, business address, job title, provided at intake, checkout, or via direct correspondence.
- Intake answers: the 15 answers Customer gives about how its control environment connects, who reaches it remotely, how changes are approved, and how it would recover, plus any organization or site detail Customer chooses to include in them.
- Nothing read from Customer systems: the Services use no connectors, agents, scanners, credentials, or network access of any kind. We read nothing from Customer's environment and nothing from Customer's control network. The analysis is generated from the intake answers alone, so we never receive regulated payload contents (PHI, cardholder data, GDPR Article 9 special categories) or operational process data.
- Billing information: limited payment metadata (last 4 of card, billing zip, expiration) provided to us by Stripe. We do not store full payment card numbers; Stripe is our payment processor and is PCI-DSS Level 1 compliant.
- Technical information: IP address, browser type, device type, referrer, pages visited, timestamps, collected automatically via server logs and Cloudflare Web Analytics. Cloudflare Web Analytics does not use cookies and does not track users across sites.
- Communications: emails you send to agents@ai4scada.ai or other ai4scada.ai addresses, including the content and attachments.
We do not use behavioral tracking pixels in outbound emails, cross-site advertising cookies, or session-replay tools. We do not sell Personal Information.
4. How We Use Information
We use Personal Information to:
- Provide, maintain, and improve the Services, including generating SCADA/OT Security Readiness & Gap Analysis reports.
- Process payments through Stripe and send transactional emails (the welcome email with the intake link, and the delivery email with the analysis).
- Respond to support requests and other communications.
- Comply with legal obligations, enforce our Terms of Service, and protect against fraud or misuse.
- Send service updates and infrequent product communications. You may opt out of non-essential communications at any time by clicking the unsubscribe link in any such message or emailing privacy@elasticd3m.com.
5. GDPR Rights (EU, UK, Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights regarding your Personal Data:
- Access, you may request a copy of the Personal Data we hold about you.
- Rectification, you may request correction of inaccurate or incomplete Personal Data.
- Erasure ("right to be forgotten"), you may request deletion subject to legal-retention obligations.
- Restriction, you may request that we limit Processing in specified circumstances.
- Portability, you may request export of your Personal Data in a structured, commonly used, machine-readable format.
- Objection, you may object to Processing based on legitimate interests, including direct marketing.
- Withdrawal of consent, where Processing is based on consent, you may withdraw consent at any time without affecting prior lawful Processing.
- Right to lodge a complaint, with your local Supervisory Authority.
Our lawful bases for Processing include: (i) performance of a contract; (ii) compliance with legal obligations; (iii) legitimate interests in operating, securing, and improving our Services; and (iv) consent where required. For international transfers, see Section 9. To exercise any GDPR right, email privacy@elasticd3m.com; we respond within thirty (30) days.
6. CCPA/CPRA Rights (California) and Other U.S. State Rights
California residents have the right to: (i) know what Personal Information we collect, (ii) request deletion of Personal Information, (iii) request correction of inaccurate information, (iv) opt out of sale or sharing of Personal Information (we do not sell or share), and (v) limit use of "sensitive Personal Information" (we do not knowingly process sensitive PI as defined under CPRA). To exercise any right, email privacy@elasticd3m.com. We respond within forty-five (45) days. We will not retaliate against you for exercising these rights.
If you are a resident of another U.S. state with comprehensive privacy law (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as enacted), you have substantially similar rights and may submit a request through the same channel.
7. Disclosure to Third Parties
We disclose Personal Information to:
- Subprocessors, third-party service providers acting on our instructions. The full list with each provider's purpose, data scope, and location is published at /subprocessors and updated at least quarterly.
- Legal authorities when required by valid subpoena, court order, or other legal process. We notify Customer of the request unless legally prohibited.
- Successors in connection with a merger, acquisition, or sale of substantially all assets, subject to confidentiality protections consistent with this Notice.
We do not disclose Personal Information to advertising networks, data brokers, or other parties for marketing purposes. We do not engage in "cross-context behavioral advertising" as defined by CCPA/CPRA.
8. Data Retention
We keep the records below for as long as the customer relationship lasts and afterward for as long as needed to answer questions about a delivered analysis, resolve disputes, and meet legal obligations. We do not currently delete these records automatically on a fixed schedule. You may ask us to delete your data at any time at privacy@elasticd3m.com; we delete it within thirty (30) days, except where the law requires us to keep it.
| Category | Retention period |
|---|---|
| Purchase record, identity and contact | Until you ask us to delete it |
| Intake answers you submit | Until you ask us to delete them |
| Delivered analysis (your SCADA/OT readiness analysis PDF) | Until you ask us to delete it |
| Billing and tax records | 7 years (legal obligation) |
| Email correspondence | Until you ask us to delete it |
| Server logs and site analytics | Set by the hosting and analytics providers (Railway, Cloudflare) |
9. International Data Transfers
Our Services are operated from the United States, and every provider on the Subprocessors List is a United States company. Provider stores customer data (the purchase record, the intake answers, and the analysis) in a United States region. Model inference by Anthropic, PBC may run outside the United States under Anthropic's default routing, which Provider does not currently restrict; the Subprocessors List says so against that provider. For EU/UK/Swiss data subjects, transfers to the United States are made pursuant to Standard Contractual Clauses (Module 2: Controller to Processor) and the UK International Data Transfer Addendum, available on request to privacy@elasticd3m.com. Where applicable, we conduct transfer-impact assessments consistent with EDPB guidance.
10. Security
We maintain industry-standard administrative, physical, and technical safeguards to protect Personal Information. Specifics include: TLS 1.2+ in transit on every public endpoint, AES-GCM encryption of fields the platform classifies as sensitive (such as stored credentials) before they are written, production access limited to named individuals, and a recorded human approval before any analysis is sent. We notify Customer of any confirmed Personal Data Breach within seventy-two (72) hours.
11. Children's Data
The Services are intended for business use by adults representing organizations. We do not knowingly collect Personal Information from anyone under the age of eighteen (18). If we discover we have collected such information, we will delete it promptly.
12. Changes to This Notice
We may update this Privacy Notice from time to time. For material changes, we will give at least thirty (30) days' advance notice via email or platform notice before the change becomes effective. The "Effective Date" at the bottom of this page indicates when the most recent version took effect.
13. Contact
Privacy questions, data subject requests, or general inquiries: privacy@elasticd3m.com
Postal address:
ElasticD3M, LLC
Attn: Privacy
7700 Broadway St, Ste 104 PMB1083
San Antonio, TX 78209, United States
Effective Date: October 7, 2026 · Version: 2.1 (Bonterms-derivative)
Replaces all prior versions of the Privacy Policy published at ai4scada.ai before this date.