Privacy policy
How ADEXMA LLC collects, uses and protects personal data — on this website, in the free diagnostics, in the client platform, and in its own business development.
Last updated: 2026-08-16 · Version 1.0
1. Who we are and what this policy covers
ADEXMA LLC ("ADEXMA", "we") is an Ohio limited liability company that provides margin-architecture consulting and an AI-assisted client platform to manufacturers and their investors. Contact: clerouge@adexma.com · ADEXMA LLC — Ohio, United States.
This policy explains how we process personal data as a controller — for visitors to adexma.com, users of our free diagnostics, people we contact for business development, and holders of a portal account. Two things it does not cover: (1) the content our clients place in their platform workspaces (documents, operational data, questions to the AI advisors) — there we act as a processor on the client's instructions under a Data Processing Agreement, and the client's own privacy notice applies; (2) the consular activities of our managing member as Honorary Consul of France, which are governed by the French State's data-protection framework.
2. What we collect, why, and on what basis
| Situation | Data | Purpose | Legal basis (GDPR) · CCPA category |
|---|---|---|---|
| You visit adexma.com or the platform's public pages | Page path, referrer host, device class, a session-scoped identifier — no IP address is stored and no cookie is set by our own page-view beacon; on marketing pages, Vercel Web Analytics (cookieless) — not on client portal pages | Operate and improve the site; measure which content is read | Legitimate interests · Internet activity |
| You run a free diagnostic (Margin Scan, worksheet, Aerospace Readiness Index) or request a demo | Name, business email, company, role, your answers, the computed scores | Deliver your results; follow up on your request; qualify you as a prospect | Contract steps / consent · Identifiers, professional information |
| We reach out to you for business development | Name, employer, title, business email/phone, LinkedIn profile, professional context, our notes and scores, interaction history | Introduce our services to people likely to be interested; maintain professional relationships | Legitimate interests (B2B direct marketing) — you can object at any time · Identifiers, professional information |
| You hold a portal account (client or prospect seat) | Login email, name, engagement membership, role, seat expiry, sign-in timestamps, session identifiers, audit-trail entries, AI-interaction metadata (advisor, model, timing, token counts — not the text of your questions) | Authenticate you; grant and revoke access; keep an accountability record | Contract · Identifiers, internet activity |
| You correspond with us | Message content and metadata, attachments | Answer you; keep a record of the relationship | Legitimate interests / contract · Identifiers, professional information |
| You give us a business card | Card image and the details printed on it | Add you to our contacts (see business development) | Legitimate interests · Identifiers, professional information |
| We invoice or pay you | Billing contact and payment records | Contract performance; accounting and tax obligations | Contract; legal obligation · Commercial information |
We do not collect special categories of personal data, government identifiers, precise geolocation or biometric data through this website or the platform, and we ask clients not to place identity documents in the AI knowledge index.
3. Where personal data comes from
- Directly from you — forms, correspondence, meetings, business cards, your portal account.
- From your organisation — when your employer or a client grants you a portal seat or shares your details for an engagement.
- From public and professional sources — LinkedIn and Sales Navigator, company websites, event lists, public filings — for business development.
- Generated by us — scores, classifications, notes and audit entries.
4. Who receives personal data
We do not sell personal data, and we do not "share" it for cross-context behavioural advertising (in the CCPA sense). We disclose it only to: (a) service providers acting on our instructions — hosting, database, storage, email, model inference, error monitoring, connectors, payments and accounting — listed with their locations and transfer mechanisms on the Sub-processors page; (b) professional advisers (counsel, accountants) under confidentiality; (c) authorities where the law requires it — we tell you unless prohibited; (d) a successor in a merger or sale of the business, under this policy.
Where a language model processes your data (for example to classify a business contact or to answer a question in the platform), the provider processes it under commercial terms that prohibit training on our inputs and outputs; see AI transparency.
5. International transfers
ADEXMA is established in the United States, and most of its providers are US-headquartered. If you are in the EEA, the United Kingdom or Switzerland, your personal data will be processed in the United States. We rely on the Standard Contractual Clauses (Commission Decision 2021/914) with each provider, supplemented where available by the provider's certification under the EU-U.S. Data Privacy Framework, and we keep a transfer impact assessment on file (available on request). For client platform workspaces designated as EU-resident, documents and AI processing already run in France and the remaining components move to Paris on the schedule stated on the Sub-processors page.
6. How long we keep personal data
| Category | Retention |
|---|---|
| Business-development contacts and interaction history | 36 months after the last meaningful interaction, then deletion or anonymisation; objections are honoured immediately and kept on a suppression list |
| Free-diagnostic leads | 24 months after capture unless converted to a client or business-development relationship |
| Portal account data | Term of the seat + 30 days; sign-in logs 12 months; audit trail 7 years |
| Business-card images | 12 months after the details are extracted |
| Website page-view beacon | 400 days |
| Correspondence and contracts | Duration of the relationship + 3 years; accounting records 7 years |
Client workspace content is kept for the term of the engagement and deleted within 30 days of its end, or earlier on the client's instruction, as set out in the Data Processing Agreement.
7. Your rights
Everyone: you can ask what personal data we hold about you, have it corrected or deleted, and object to business-development contact at any time by writing to clerouge@adexma.com. We answer within one month (GDPR) or 45 days (CCPA), extendable once where the law allows; we may need to verify your identity, and an authorised agent may act for you with proof of authority. We never treat you differently for exercising a right.
If you are in the EEA, the UK or Switzerland (GDPR / UK GDPR / FADP): you also have the rights of restriction and portability, the right to withdraw consent where processing is based on it, and the right to lodge a complaint with a supervisory authority — in France the CNIL, in Belgium the APD/GBA, in the UK the ICO, in Switzerland the FDPIC — or with the authority of your habitual residence.
If you are a California resident (CCPA/CPRA): you have the rights to know, to delete, to correct, and to opt out of sale or sharing — we do not sell or share personal information and have not done so in the preceding twelve months — and to limit the use of sensitive personal information (we do not collect it). The categories we collect, their sources, purposes and recipients are described in sections 2 to 4; retention in section 6.
If your data is in a client's workspace: please contact that client (the controller); we will assist them in answering you.
9. Security
We maintain a written cybersecurity program aligned with the NIST Cybersecurity Framework 2.0. In practice: passwordless sign-in with one-time codes; per-engagement access that expires; row-level security on every database table; audited privileged operations; encryption in transit (TLS, HSTS) and at rest (AES-256); minimised error telemetry; independent assurance (SOC 2 / ISO 27001) from our infrastructure providers. Security researchers can reach us through the SECURITY.md disclosure policy in our platform repository.
10. Automated decisions and AI
The platform uses large language models to answer questions, draft analyses and extract text from documents. It does not make decisions with legal or similarly significant effects about you by automated means. Users are told when they are interacting with an AI system. Details of what the AI does, which providers run it and what it never does are on the AI transparency page.
11. Children
Our services are for businesses and their professionals. We do not knowingly collect personal data from anyone under 16.
12. Changes and contact
We will post any change here with a new "last updated" date; material changes affecting portal users are announced in the platform. Questions, requests and complaints: clerouge@adexma.com — ADEXMA LLC, Ohio, United States.