ACCOUNT DATA CONTROLS
Account & Privacy
Version privacy-2026-08-14 · Controlled preproduction pilot
Approval status: preproduction draft requiring the applicable organization and Legal/Privacy owners to confirm roles, retention, subprocessors, region, and request procedures before production.
Information processed
- Account identifiers such as Cognito subject, email, role, MFA and session-security signals.
- Organization, shop, project, inspection, component, evidence, measurement, review, and audit metadata your organization authorizes.
- Operational records such as timestamps, request IDs, errors, security events, configuration versions, and policy acceptance.
Why it is processed
ARIA uses this information to authenticate users, enforce tenant and role boundaries, operate inspection workflows, generate advisory AI drafts, preserve evidence provenance, prevent abuse, investigate incidents, recover service, support users, and demonstrate controlled-pilot performance.
Service providers and AI processing
Authorized information may be processed by the configured cloud, identity, monitoring, and AI providers under the deployment and organizational agreements. Only the current organization/shop inspection context may enter inference. See the AI-use notice.
No implied training permission
Accepting this notice does not authorize customer evidence for model training, global learning, cross-customer reuse, marketing, or sale. Training or broader reuse requires a separate documented data-use approval and technical gate.
Retention and protection
Data is encrypted in transit and at rest where configured, access is logged, and tenant scope is server-derived. Retention, legal hold, correction, export, and deletion follow the approved organization policy and applicable contract. No system can promise absolute security.
Your choices and requests
Contact your organization or shop administrator to correct account attributes, review access, request an authorized export/deletion, revoke sessions, or raise a privacy concern. Some inspection and audit records may be retained when required by quality, security, legal-hold, or contractual controls.
Policy changes
ARIA records acceptance of this exact version. A material change requires renewed acceptance before inspection-data access resumes.