How We Handle Your Information
This policy explains what data we collect, why we collect it, and exactly what happens to it. No legalese. No hidden clauses. Straight answers.
01
Information We Collect
We collect only the information you voluntarily provide when you interact with our site or services. This includes:
- Contact details: your name, email address, and company name submitted through our contact form
- Inquiry details: your CTO situation, company stage, service tier interest, and the description of your technology needs
- Communication records: email correspondence and notes from strategy calls related to consulting engagements
- Technical data: anonymized browser type, device category, and page visit data collected through analytics
We do not collect sensitive personal data such as financial information, government identifiers, or health records through this website.
02
How We Use Your Information
Every piece of data we collect serves a specific, legitimate purpose:
- Respond to inquiries: to reply personally to your contact form submissions and schedule strategy calls
- Deliver consulting services: to understand your technology challenges, prepare for calls, and provide relevant recommendations
- Improve our site: to understand which pages and content are most useful, and to optimize the experience for future visitors
- Follow up on engagements: to send proposals, contracts, and deliverables related to active consulting relationships
We will never use your data for purposes beyond those listed here without your explicit consent.
03
Data Storage and Security
Your data is protected with enterprise-grade security practices:
- Infrastructure: our website is hosted on a proprietary global edge network with built-in DDoS protection, Web Application Firewall (WAF), and zero-trust architecture
- Encryption: all data transmitted to and from our site is protected with AES-256-bit TLS encryption. Data at rest is encrypted using AES-256 encryption on hardened infrastructure
- Access control: access to client data is limited strictly to Alastair Monte Carlo and is protected by multi-factor authentication with hardware security keys
- Retention: contact form submissions are retained for the duration of the business relationship. You may request deletion at any time, and all data will be permanently destroyed within 30 days of your request
- Zero-knowledge: we operate on a zero-knowledge principle wherever possible. Your sensitive data is encrypted in a way that even our infrastructure providers cannot access it
04
Third-Party Sharing
We do not sell, rent, or trade your personal information. Period. Your data is never shared with third parties for marketing purposes.
We may use the following trusted services in the course of operating our site:
- Proprietary edge infrastructure: website hosting, security, and performance optimization via our global edge network
- Edge compute workers: secure contact form processing and submission handling on our distributed infrastructure
- Analytics providers: anonymized, aggregate website usage data to understand traffic patterns and improve user experience
Each of these providers is bound by their own privacy policies and data protection obligations. We select partners that meet or exceed industry-standard security practices.
05
Cookies and Tracking
We take a minimal approach to cookies. Our site uses:
- Essential cookies: required for basic site functionality, security features, and edge network performance optimization
- Analytics cookies: anonymized tracking to understand page visits, session duration, and navigation patterns. No personally identifiable information is stored in these cookies
We do not use advertising cookies, social media tracking pixels, or retargeting technologies. Your browsing activity on our site is never shared with advertisers.
06
Your Rights
You have full control over your personal data. At any time, you may request:
- Access: receive a complete copy of all personal data we hold about you
- Correction: update or correct any inaccurate information in our records
- Deletion: permanently remove all your personal data from our systems
- Portability: receive your data in a standard, machine-readable format
- Restriction: limit how we process your data while a concern is being resolved
To exercise any of these rights, contact us at
sterling@aamc.ai.
We will respond to all requests within 72 hours.
07
Confidentiality and NDA
We understand that technology strategy discussions often involve sensitive intellectual property, trade secrets, and proprietary business information. Confidentiality is not optional. It is foundational to every engagement.
- NDA by default: a mutual Non-Disclosure Agreement (NDA) is executed before any sensitive discussions begin. We routinely execute NDAs with clients across regulated industries including fintech, healthcare, defense, and government technology
- No data retention: upon engagement completion, all client data, documents, and communications are permanently destroyed within 30 days unless otherwise agreed in writing
- Zero third-party exposure: your data is never shared with, sold to, or accessed by any third party. Period
Contact sterling@aamc.ai to request an NDA prior to your initial conversation, or reach us via WhatsApp for end-to-end encrypted messaging.
08
Secure Communications
Client communications are treated with the same rigor as the technology we build. Every channel is encrypted, every conversation is confidential.
- End-to-end encrypted messaging: available via WhatsApp for clients who require maximum communication security
- Encrypted email: all email communications are transmitted over TLS-encrypted channels
- Video calls: strategy sessions are conducted over encrypted video platforms with no recording unless explicitly authorized by the client
- Document sharing: all documents, proposals, and deliverables are transmitted through encrypted channels. Sensitive materials are password-protected with AES-256 encryption
09
Changes to This Policy
We may update this privacy policy to reflect changes in our practices or applicable regulations. When we do, the effective date at the top of this page will be revised. For material changes that affect how your data is processed, we will provide notice through our website or direct communication.