Privacy Policy
Effective Date: August 8, 2026
This Privacy Policy explains how AndonEAM Inc. ("AndonEAM," "we," "us," or "our") handles personal information when you visit our website, communicate with us, or use an AndonEAM workspace. A customer order form, data processing addendum (DPA), or other written agreement may contain additional terms and controls if your organization uses the service.
1. Information we collect
Depending on how you interact with AndonEAM, we may collect:
- Account and contact information, such as your name, work email, organization, job role, and authentication-provider identifiers.
- Customer Content, such as asset records, maintenance information, engineering documents, prompts, comments, approvals, and other material submitted to a workspace, together with outputs generated from that material.
- Usage and device information, such as IP address, browser and device type, timestamps, page and feature interactions, diagnostic logs, and cookie or similar-technology data.
- Commercial and support information, such as demo requests, order and billing contacts, support messages, and records of our communications.
Your organization decides what Customer Content it submits. It is responsible for having an appropriate legal basis and providing any notices required for personal information included in that content.
2. How we use information
We use information as reasonably necessary to:
- provide, secure, administer, and support the website and service;
- authenticate users and manage workspace permissions;
- process Customer Content and generate requested analyses or workflow suggestions;
- diagnose faults, monitor performance, and improve product usability and reliability;
- respond to inquiries, deliver service notices, and manage customer relationships;
- prevent fraud, abuse, and security incidents; and
- comply with law and enforce our agreements.
Where applicable law requires a legal basis, that basis may be performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, or consent where we specifically request it.
3. Customer Content and organizational accounts
When we process personal information in Customer Content on behalf of an organization, that organization generally determines the purpose and means of processing and AndonEAM acts as its service provider or processor. Your organization's administrators may access, manage, export, restrict, or delete information in its workspace. Questions about that processing should usually be directed to the organization first. Our DPA, if applicable, governs processing instructions, assistance, and deletion obligations.
4. AI-assisted processing
Some features use AI-assisted systems to organize submitted material and propose analyses, explanations, or workflow actions. To provide those features, relevant portions of Customer Content may be processed by AndonEAM infrastructure and by service providers enabled for the applicable deployment. The precise providers, data flows, and retention settings may vary by product configuration and customer agreement. AI-assisted results can be incomplete or incorrect and should be reviewed by qualified people before they inform maintenance, safety, financial, or operational decisions.
5. When we disclose information
We may disclose information in the following circumstances:
- Service providers and subprocessors. Vendors may support hosting, authentication, communications, monitoring, analytics, payment administration, support, and AI-assisted features. They receive information only as needed for their role and subject to applicable contractual restrictions.
- Your organization and integrations. Workspace administrators, authorized users, and third-party integrations selected by the customer may receive information according to configured permissions.
- Legal, safety, and security reasons. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate misuse, or secure the service.
- Corporate transactions. Information may be disclosed in connection with due diligence, financing, reorganization, merger, acquisition, or sale of assets, subject to appropriate confidentiality protections.
- Professional advisers. Auditors, lawyers, insurers, and similar advisers may receive information where necessary for their services.
We do not use Customer Content to target third-party advertising. Subprocessor details and any customer-specific approval or notice rights are governed by the applicable DPA or other written agreement.
6. Cookies and analytics
We may use essential cookies or local storage for authentication, preferences, and security, and limited analytics technologies to understand website and product usage. Browser settings can restrict some technologies, although doing so may affect service functionality. Where consent is required, non-essential technologies will be used in accordance with the choices presented to you.
7. Retention and deletion
We retain personal information for as long as reasonably necessary for the purposes described above, including to provide the service, follow customer instructions, meet contractual and legal obligations, resolve disputes, and maintain security records. Customer-specific retention and return or deletion terms may be stated in an order form or DPA. Deleted information may remain in protected backups until those backups cycle out, unless a longer period is required by law.
8. Security
We use administrative, technical, and organizational safeguards intended to protect information against unauthorized access, loss, alteration, or disclosure. No system is completely secure, and controls may differ by deployment, integration, and contract. Security commitments in a signed customer agreement take precedence over general website descriptions. Please avoid sending credentials or confidential operational data through ordinary email or public website forms.
9. International data transfers
AndonEAM and its service providers may process information in countries other than the country where it was collected. Where required, we use contractual or other recognized safeguards for cross-border transfers. Customer-specific hosting or transfer terms, if any, are stated in the applicable written agreement.
10. Your privacy choices and rights
Depending on your location and relationship with AndonEAM, you may have rights to ask for access, correction, deletion, restriction, objection, or portability, or to withdraw consent. These rights can be subject to verification, legal exceptions, and an organization's control of its workspace. We may direct a workspace-related request to the relevant customer administrator. You may also complain to the privacy regulator available in your jurisdiction.
11. Children
AndonEAM is a business service and is not directed to children. We do not knowingly request personal information from anyone who is not legally able to enter into a binding business-services agreement.
12. Changes and contact
We may update this policy as our services or legal obligations change. We will post the revised policy with a new effective date and provide additional notice when required. For privacy questions or requests, email info@andoneam.com. Please do not include passwords, confidential asset data, or other sensitive operational material in email.
Copyright © 2026 AndonEAM Inc. All rights reserved.