AEGYS Privacy Notice
Operator: A & S INFORMATION SOLUTIONS OPC Product: AEGYS Corporate website: https://www.aandssolutions.com Product: https://aandssolutions.com/aegys DPO: Atty. Janine Rose G. Lumanag · dpo@aandssolutions.com General support: hello@aandssolutions.com Effective: 19 August 2026 Version: privacy-2026-08-19-v1 NPC / Seal: This Notice does not claim that A & S or AEGYS is NPC-registered, NPC-certified, or entitled to display an NPC Seal or Certificate of Registration.
This Notice describes how AEGYS processes personal data. It is A & S’s transparency/privacy notice. It does not, by describing processing, create additional contractual warranties. The Data Processing Addendum governs A & S’s processing of Customer Personal Data as Personal Information Processor.
A & S does not sell personal data. Consent is not the universal lawful basis for processing, for sensitive personal information, or for cross-border cloud processing.
AEGYS is the full commercial production system. This Notice does not describe a pilot, controlled-launch, or reduced product.
Roles (PIC and PIP)
A & S is not exclusively PIC or exclusively PIP.
| Role | When | Examples |
|---|---|---|
| A & S as PIC | A & S determines purposes for its own business/platform | Subscription/account administration; customer administrative/contact details A & S maintains; licensing/payment/refund records; legal-acceptance records (when enabled); A & S operator audit; security/compliance records; DPO/DSAR records; incident/breach records; legal-hold and deletion/offboarding evidence; support records; other A & S corporate/regulatory records |
| A & S as PIP | The subscribing law firm determines purposes; A & S hosts/processes under documented instructions | Clients; matters/cases; pleadings/files; legal-workflow information; billing/ledger; SOAs/ARs; scheduling; notarial workspace records; staff/workspace data; client correspondence; information collected through client-facing portal/token/link functions; other law-firm practice data |
For PIP processing, see the Data Processing Addendum.
Customer = the subscribing law firm. Authorized User = authorized law-firm personnel with authenticated workspace access. Client / data subject (workspace) = a person whose information the firm processes. Clients are not AEGYS customers or Authorized Users. Portal / Link Recipient = a person permitted to use a limited client-facing function without a workspace login.
Data-subject requests about A & S PIC records may be sent to dpo@aandssolutions.com. Requests about law-firm workspace data should generally be directed to the subscribing law firm as PIC; A & S will assist that firm as PIP.
1. Who this applies to
- People who create or administer an AEGYS trial or subscription (firm administrators and staff — Authorized Users).
- People whose information a Customer stores in its workspace (clients and related persons).
- Portal/Link Recipients, to the limited extent the Customer causes AEGYS to process their information through a client-facing function.
2. Personal data A & S collects for its own account (PIC)
| Category | Source | Purpose | Lawful basis (general) |
|---|---|---|---|
| Administrator Google name/email | Google sign-in (openid, email, profile) | Create and authenticate the firm | Contract / legitimate interest in operating the service |
| Firm name and registry status | Onboarding / A & S operator records | Trial, activation, expiry, cancellation, reactivation records | Contract |
| Licence payment / refund records | A & S operator after you pay | Record that AEGYS was paid; tax/accounting | Contract / legal obligation (tax) |
| Payment-notification contents | You, if you use Notify payment | Tell A & S that payment was sent | Contract |
| Legal acceptance (when enabled) | Checkbox at onboarding | Evidence you accepted Terms and this Notice | Contract / legal claims |
| Rate-limit keys including IP | Connection to the service | Abuse prevention | Legitimate interest in security |
| Support emails | You | Support and billing | Contract / legitimate interest |
| Operator audit | A & S operator actions | Security and operational accountability | Legitimate interest / legal claims |
| Incident / DSAR / DPO records | Operators / DPO | Security, privacy compliance, legal claims | Legal obligation / legitimate interest / legal claims |
Lawful bases are stated at a general level. Consent is not the default basis. If a particular activity independently requires consent under applicable law, that requirement remains.
3. Tenant law-firm workspace data (PIP)
Processed on the Customer’s instructions because the Customer entered, generated, or caused it to be collected in AEGYS:
Client identities and contacts; matter/case fields; opposing/collaborating counsel; court fields; tasks, events, hearings, filings; billing/ledger; SOA and acknowledgment receipts; uploads; generated PDFs; logos/letterheads; staff roster and professional identifiers; firm address and sender identity; optional firm PayMongo keys if the firm stores them; walk-ins, notarization, correspondence, reports; and other firm-domain records.
Sensitive personal information (SPI) and privileged information. AEGYS does not require unnecessary SPI or privileged information for ordinary platform operation. Subscribing law firms may process such information through AEGYS where it is necessary and supported by an applicable lawful basis or authority. The law firm, as PIC, determines necessity, lawful basis, purpose, proportionality, and professional use. A & S, as PIP, retains confidentiality, security, tenant-isolation, and processing obligations. AEGYS promotes data minimization but will not prohibit legitimate legal-practice information, automatically inspect case content, or disable existing functionality merely because SPI or privileged information may be processed.
Portal, upload, payment, and consultation links are time-limited signed/scoped tokens. Anyone who has a valid URL may use that limited function until it expires or is revoked. That does not grant workspace dashboard access.
4. How we collect it
Google OAuth (openid, email, profile). Forms in AEGYS. Files you upload. Information a Client or recipient submits because the firm requested it through a client-facing function. Payment notices you send. A & S operator recording of licence payments. Transactional email events when mail is sent.
We do not require a payment card to start a trial.
5. Cookies / session
AEGYS uses an HTTP-only session cookie (NextAuth JWT) to keep Authorized Users signed in. We do not operate a separate advertising cookie program in the product.
6. Recipients and subprocessors
AEGYS uses third-party cloud and infrastructure providers. Personal data may therefore be processed or stored outside the Philippines. A & S uses contractual and other legally sufficient safeguards appropriate to those relationships and sufficient for A & S to meet its applicable PIP obligations. Philippine privacy and accountability obligations continue to apply. Cross-border processing is not a waiver of the Data Privacy Act.
A & S does not operate its own exclusive physical data center. A & S does not promise Philippine-only data residency.
Current production processors (as of 19 August 2026, based on production/account evidence):
| Provider | Why | Tenant personal data? | Location |
|---|---|---|---|
| Vercel | Application hosting, serverless, deployment, logs | Yes, in requests and logs | Cloud processing across Vercel’s infrastructure; a single exclusive country is not verified. The production object store used for AEGYS files is in Singapore (sin1) |
| Neon | PostgreSQL / database | Yes | AWS ap-southeast-1 (Singapore) — verified |
| Vercel Blob | PDFs, uploads, brand assets | Yes | Singapore (sin1) — verified for the production store |
| OAuth sign-in (openid/email/profile) | Account identity of Authorized Users; not client files via OAuth scopes | Google’s global infrastructure. Google acts as independent PIC of the Google Account | |
| Resend | Transactional email | Yes, when SOA/AR/mail is sent. From: documents@notifications.aandssolutions.com; Reply-To from the firm’s settings when set | Cloud email infrastructure; a single exclusive country is not verified from A & S account evidence |
| Vercel KV | Rate limiting | IP in keys; not document bodies | Cloud key-value infrastructure used through Vercel; a single exclusive country is not verified |
PayMongo is not used to collect A & S licence fees. A firm may store its own PayMongo keys for client payments. That is the firm’s processor relationship.
Sentry is not listed as an active subprocessor. Production environment names currently do not include a Sentry DSN.
Optional Google Drive / OneDrive connectors, if a firm enables them, are the Customer’s processors for files sent there. They are not the default AEGYS file store.
Where an available provider arrangement cannot provide the legally required protections for the affected processing, A & S will not represent that provider as acceptable merely because stronger terms are unavailable. Unresolved provider-contract facts are kept for owner/provider resolution and are not published as if they were verified.
A & S may use or take guidance from NPC Advisory No. 2024-01 Model Contractual Clauses where appropriate; A & S does not represent that every provider has executed those model clauses.
Material new or replacement subprocessors. Where reasonably practicable, A & S will give Customers at least fifteen (15) calendar days’ advance notice before a new or replacement Material Subprocessor begins processing their tenant personal data, identifying provider, function, general nature of processing, geography where verified and appropriate, and effective date. Notice may be by email to the registered administrative address, an AEGYS administrative notice, a maintained list plus direct notice of material changes, or another reasonable written electronic method. Manual/email notice is sufficient.
A Customer may object during the notice period on reasonable documented data-protection or information-security grounds. Preference for another vendor, branding, pricing unrelated to privacy/security, a demand for Customer-selected infrastructure, or a demand for Philippine-only hosting (which AEGYS has not contracted to provide) is not an unrestricted veto. A & S will review in good faith. If a reasonable objection cannot be resolved and A & S cannot avoid using the proposed Material Subprocessor for that Customer, the Customer may terminate the affected service before the change takes effect without that termination being treated as Customer breach, with unused prepaid subscription (not an already-earned setup fee) refunded under the refund policy. Urgent security, legal, provider-failure, or service-continuity changes may occur on shorter notice, with notice as soon as reasonably practicable.
Existing Material Subprocessors disclosed when the Customer accepts the DPA are covered by the Customer’s general authorization. A separate click-to-approve is not required for every already-disclosed provider.
7. Cross-border processing
Personal data may be transferred or processed outside the Philippines because A & S uses cloud/service providers whose infrastructure or processing locations may be outside the Philippines.
Verified locations: Neon production database on AWS ap-southeast-1 (Singapore); production Vercel Blob store in sin1 (Singapore). Other providers process on cloud/global infrastructure rather than a single verified country.
Safeguards: contractual or other legally sufficient provider arrangements where in place and sufficient for A & S’s PIP obligations; organizational access control (A & S operator allowlist, tenant isolation, row-level security); technical measures in Section 8.
Cross-border cloud processing is not automatically or universally based on individual consent. The Customer as PIC remains responsible for having the applicable lawful basis or authority, and for providing required transparency, for its processing. A & S remains responsible for its PIP obligations and for appropriate subprocessor safeguards. Cross-border processing does not remove those obligations and is not a waiver of the Data Privacy Act.
8. Storage and security (non-exploitative)
Workspace rows are stored per firm with database row-level security for AEGYS tenant queries. Licence payments, legal-acceptance, retention/hold/deletion-audit tables are platform tables, not granted to the tenant role.
Files are stored in a private Vercel Blob store and, in some fallback cases, as database-hosted file bytes. Application file download is authorized per firm. Direct object URLs are not a public download path. This is not a marketing claim of “private cloud” or “your information never leaves our servers.”
Passwords are not stored.
This is not a claim of perfect security, SOC 2, ISO, or NPC certification of AEGYS.
9. Confidentiality and privilege
A & S treats tenant workspace information as confidential and processes it subject to applicable security, confidentiality, and data-protection obligations.
Legal privilege is different. Information processed through AEGYS may include confidential or legally privileged information belonging to or controlled by the subscribing law firm. Whether particular information is protected by attorney-client privilege or another legal privilege depends on the applicable lawyer-client relationship, the nature and circumstances of the information or communication, and applicable law. Use of AEGYS does not itself create or determine legal privilege. A & S does not waive privilege by operating the platform.
10. Personal data breach
A & S distinguishes ordinary service incidents, internal security incidents, and personal data breaches. Not every application error is a reportable breach.
For Customer Personal Data, A & S as PIP notifies the subscribing law firm as PIC without undue delay and, where reasonably practicable, within 24 hours of awareness or reasonable belief that a personal data breach affecting that tenant has occurred. That 24-hour period is an AEGYS operational/contractual target, not a universal NPC statutory deadline. The PIC remains primarily responsible for applicable NPC and data-subject notices. The current legal baseline for mandatory notification, where it applies, is generally 72 hours upon knowledge or reasonable belief by the PIC or PIP, subject to applicable rules. A & S does not automatically file NPC notices for every Customer. For A & S PIC records, A & S’s DPO assesses and, where required, notifies.
NPC filings, where required, are presently made through DBNMS as an operational/DPO process. Incident records are retained generally 5 years after closure. Current recording is mailbox/DPO/manual. See the incident procedure.
11. Retention
See the Retention & Disposal Schedule.
PIP tenant workspace
- Active paid workspace: retained while subscription/authorized use remains active.
- Unconverted trial: access locks at trial expiry; content retained up to 90 days from trial expiration, then deletion-eligible unless a lawful hold applies.
- Paid cancellation/termination/lapse: ordinary service ends as of the effective date; content retained up to 90 days from that date, then deletion-eligible unless a lawful hold applies.
- Legal hold suspends deletion. Removing a hold does not automatically create a fresh 90-day period if the original deadline has passed.
- Early deletion is a controlled, verified process — not a customer one-click.
- Application deletion removes active tenant data/files. Provider recovery copies may remain until those windows expire (Neon Instant Restore currently approximately 6 hours; restore not tested). Not instantaneous destruction of all backup history. Not a daily or long-term backup. Independent Blob restore is not a verified AEGYS backup service.
A & S PIC records are not automatically deleted by the tenant-workspace job and are not a 10-year copy of the deleted workspace. Category periods:
- Contract / legal-acceptance / minimal account-deletion tombstone: generally 10 years after termination/deletion (or longer while a related claim/legal hold remains).
- Accounting/tax-supporting records: applicable Philippine tax/accounting law; BIR baseline currently 5 years, subject to statutory reckoning and any longer period required in a particular case. Not “all payment records are deleted after five years.”
- Routine A & S operator / security audit logs: generally 2 years, unless investigation, incident, litigation, or law requires longer.
- Routine support: generally 2 years after the matter is closed, unless a longer category applies.
- Material incident/breach records: generally 5 years after closure.
- DSAR/DPO compliance records: generally 5 years after final resolution/closure.
- Legal hold or other law may extend relevant records.
- After workspace deletion, only a minimal tombstone (identifiers, dates, high-level deletion facts) is kept — not client files, pleadings, matter narratives, uploads, full client rosters, or practice billing ledgers.
Scheduled destructive deletion of deletion-eligible workspaces remains off until A & S expressly authorizes it.
If a cancelled firm is later reactivated before deletion of the original workspace, A & S restores the same firm and retained tenant data. The cancellation-based 90-day deletion clock does not continue while the firm is active. After actual deletion, the old workspace is not restored.
12. Your choices and rights
Firm administrators can correct much workspace data in the product while they have access.
For A & S PIC records: email dpo@aandssolutions.com. A & S will handle applicable data-subject rights for those records through its DPO.
For client/matter (PIP) data: contact the subscribing law firm as PIC. A & S will not automatically disclose or delete tenant data on a direct request from an unidentified third party. A & S will ordinarily refer such requests to the relevant PIC and will assist a verified PIC request without undue delay, targeting assistance or a substantive status update within five (5) business days. That target is an AEGYS operating standard, not a universal statutory DSAR completion deadline.
Cross-border processing is not a reason to deny otherwise applicable data-subject rights.
13. Children
AEGYS is for law-firm operations, not directed at children.
14. Changes
Material changes will be posted on /privacy with a new version identifier. Existing firms will not be silently marked as having accepted a version they never accepted.
15. Contact
A & S INFORMATION SOLUTIONS OPC DPO: Atty. Janine Rose G. Lumanag · dpo@aandssolutions.com Support: hello@aandssolutions.com https://www.aandssolutions.com