1. Our Guiding Privacy Principles
Consistent with our Information Security Management System (ISMS) and Quality Management System (QMS), we apply the following principles to everything we do with personal data:
- We do not sell personal information to any third party, under any circumstances.
- We collect the minimum personal information necessary to operate, secure, and improve our website and Services (data minimization).
- We use our website's automatically collected technical data solely to understand usage, maintain security, and improve the site — never to build advertising profiles or to sell to data brokers.
- All personal information we hold is encrypted both in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
- Access to personal information is restricted on a least privilege, need-to-know basis and is logged and monitored under our secure data protection management system.
- We retain personal information only as long as necessary for the purpose it was collected, or as required by law.
2. Information We Collect
2.1 Information You Provide Voluntarily
We only collect personal information that you choose to give us. The most common example is our email subscription / newsletter sign-up, where we collect:
- Your name and email address;
- Your company name and job title, if you choose to provide them; and
- Any additional information you voluntarily include in a form, inquiry, registration, survey, or contest entry.
Providing this information is entirely optional. If you do not subscribe or submit a form, we do not collect this category of information about you.
2.2 Information Collected Automatically
When you visit our website, certain technical information is captured automatically by standard web servers and security logging processes, including:
- Browser type and version;
- IP address;
- Device and operating system information;
- Pages visited, referring/exit pages, and approximate session timestamps; and
- Cookies and similar technologies (see Section 5).
This automatically collected information is used only to operate, secure, and enhance the website — for example, to detect and prevent abuse, diagnose technical issues, and understand aggregate usage trends. We do not use this data to identify individuals for marketing purposes unless it is voluntarily linked to information you provided under Section 2.1.
2.3 Information We Do Not Collect
Our website is not designed to collect sensitive categories of personal data (such as health, financial account, government identification, or biometric data). Where our software or AI products process such data on behalf of a customer, that processing is governed by the applicable customer agreement and the customer’s own privacy notice, not this Policy.
3. How We Use Your Information
We use personal information only for the following legitimate business purposes:
- To respond to your inquiries, registrations, and requests;
- To send you information about MaxisAI products and services, where you have consented to receive marketing communications;
- To operate, maintain, secure, and improve our website and Services;
- To conduct internal audits, information security monitoring, and compliance activities consistent with Quality and Information security standards; and
- To comply with applicable laws, regulations, and lawful requests from public authorities.
We do not use automated means to analyze or predict your personal characteristics, behavior, health, or preferences for our own purposes (see Section 12, “Automated Decisions and Profiling”).
4. Legal Basis for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases to process personal information:
- Consent — for example, when you subscribe to marketing emails.
- Legitimate interests — for example, to secure our website, prevent fraud, and improve our Services, balanced against your rights and interests.
- Contractual necessity — to respond to inquiries or provide information you have requested.
- Legal obligation — where processing is required to comply with applicable law.
You may withdraw consent at any time as described in Section 14, “Your Choices,” without affecting the lawfulness of processing carried out before withdrawal.
5. Cookies and Similar Technologies
We use cookies and similar technologies to recognize your browser, remember preferences, and understand how our website is used. Categories of cookies we may use include strictly necessary, performance/analytics, and functionality cookies. We do not use cookies to sell your information or to share it with third-party advertising networks.
You can control cookies through your browser settings, including choosing to block or delete cookies. If you reject cookies, some areas or features of our website may not function as intended.
6. No Sale of Personal Information
MaxisAI does not sell, rent, or trade personal information to any third party for monetary or other valuable consideration, and we do not permit third parties to use information collected through our website for their own independent marketing purposes.
7. How We Share Information
We do not share your personal information with third parties for their own independent use without your express consent, except as described below:
- Sub-processors and service providers who support our operations (e.g., hosting, email delivery, security monitoring) under contracts that restrict their use of your data solely to providing services to us;
- Where required by law, regulation, court order, or lawful request from a public authority;
- To protect the rights, property, or safety of MaxisAI, our users, or others; and
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
8. Data Security
Consistent with our Information Security Management System and our SOC 2 Type II attestation, we maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption of personal information both in transit and at rest;
- Role-based access controls and the principle of least privilege;
- Continuous security monitoring, logging, and periodic vulnerability assessments;
- Formal incident response and breach notification procedures; and
- Regular internal and external audits performed for our QMS and ISMS.
No method of transmission or storage is 100% secure. If we become aware of a security incident affecting personal information, we will notify affected individuals and/or applicable regulators in accordance with applicable law and our incident response procedures.
9. Data Retention and Minimization
We retain personal information only for as long as necessary to fulfill the purpose for which it was collected — for example, for as long as you remain subscribed to our communications — or as required by applicable law, after which it is securely deleted or anonymized. We do not retain website technical/log data beyond what is needed for security and operational purposes.
10. Data Hosting and International Transfers
MaxisAI may host and otherwise process personal information in the United States and India. Regardless of location, we apply consistent privacy and security protections to personal information. Where personal information is transferred from the European Union or other jurisdictions with data transfer restrictions, MaxisAI relies on appropriate safeguards, such as Standard Contractual Clauses, to enable the transfer. Contact our privacy office for more information at privacy@maxisai.com.
11. AI Product Data Practices
For our AI-enabled products, we apply additional safeguards appropriate to the clinical and life sciences context in which they are used:
- Customer data processed by our AI products is used solely to deliver the contracted service to that customer and is not used to train shared or third-party AI models without the customer's prior written consent.
- Access to data used in connection with AI product functionality is subject to the same encryption, access control, and logging safeguards described in Section 8.
- AI-generated outputs within regulated clinical and life sciences workflows are intended to support, not replace, qualified human review, consistent with applicable GxP validation and quality requirements.
- We do not use AI to make automated decisions that produce legal or similarly significant effects concerning individuals (see Section 12).
Customers deploying our AI products remain responsible for validating output in accordance with their own regulatory obligations and internal quality procedures.
12. Automated Decisions and Profiling
We do not make decisions about you, whether automated or otherwise, and we do not attempt to analyze or predict your behavior, preferences, interests, health, or other personal characteristics for our own purposes. Where our software or AI products carry out automated processing on the instructions of a customer, that processing is governed by the agreement between MaxisAI and that customer. For more information about automated processing of personal information on behalf of a customer, please contact that customer directly.
13. Children’s Privacy
Our website is a general-audience site and is not directed to children. We do not knowingly collect personal information from children 16 years of age or younger. If we learn that we have inadvertently collected personal information from a child, we will take steps to delete it promptly.
14. Your Choices
You may opt out of marketing communications at any time by using the unsubscribe / opt-out link included in any marketing message, or by sending a request to privacy@maxisai.com.
15. Your Rights
Depending on the laws that apply to you, you may have the right to:
- Confirm whether we hold personal information about you, and access that information;
- Request correction of inaccurate or incomplete personal information;
- Request erasure of your personal information (“right to be forgotten”);
- Request restriction of, or object to, certain processing;
- Request a portable copy of personal information you provided to us; and
- Understand where your personal information has been stored, processed, or transferred, and the safeguards applied.
To exercise any of these rights, email privacy@maxisai.com. We will respond without undue delay and, in any event, within 30 days. MaxisAI reserves the right to take reasonable steps to verify your identity before granting access or making changes. If your personal information was collected on behalf of a customer, we may refer your request to that customer, and applicable law may limit what MaxisAI itself can do directly.
If you are not satisfied with our response, you may lodge a complaint with a supervisory authority — for example, the Data Protection Authority in your EU member state, the Privacy Commissioner of Canada (or your Province), or the U.S. Federal Trade Commission.
16. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, MaxisAI will notify affected individuals and/or the relevant supervisory authority in accordance with applicable law (including, where relevant, the GDPR’s 72-hour notification requirement to supervisory authorities) and our documented incident response procedures.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post any updated policies on this page with a new effective date and will provide extra notice for any significant changes.
18. Contact Us
If you have questions, suggestions, or complaints regarding this Policy or our handling of personal data, please contact our Data Protection Officer:
Email: privacy@maxisai.com
MaxisAI
510 Thornall Street, Suite 180, Edison, NJ 08837, USA
