Privacy Policy
1. Who we are
This site (aernd.ua) is operated by Autonomous Engineering R&D Ukraine ("AE R&D", "we", "us"), an engineering company developing autonomous unmanned systems. We are the data controller for personal data we collect through this website. For details about our legal entity, registered address and contact information, see the Contacts page or the bottom of this Policy.
2. What data we collect
We collect personal data only when you actively submit it through one of two forms, plus minimal technical data automatically. 2.1. Partner access request form (intro modal on the homepage). When you request partner-portal access, we collect: full name, email address, phone number (optional), company name, description of your interest, date and time of submission, your IP address (for spam protection only; not stored long-term in human-readable form), and confirmation that you consented to this Privacy Policy. 2.2. Vacancy application form (on each /careers/[position] page). When you apply for an open position, we collect: full name, email address, phone number (optional), cover letter (optional), CV / resume file in PDF or Word format (optional, up to 5 MB), the specific vacancy you applied to, date and time of submission, your IP address (for spam protection only), and confirmation that you consented to this Privacy Policy. 2.3. Authentication data (only for partner-portal users). If you have an active partner-portal account, additional data exists in your account: full name, email, company, partner tier, optional bio / phone. 2.4. Technical data collected automatically. Your locale preference, stored in a cookie named `ae_locale` (essential for site functioning; no personal data). Authentication session tokens, stored in cookies (only if you sign in to the partner portal). Anonymized page-view data and Web Vitals performance metrics, collected by Vercel Analytics and Vercel Speed Insights — see Section 7. We do not use third-party advertising trackers, conversion pixels, social-media trackers, or cross-site tracking technologies.
3. Why we collect it (legal basis)
We process your data for the following purposes and legal bases: • Partner access request — to review your request, verify your interest, and contact you to grant or refuse access. Legal basis: pre-contractual measures (Art. 6(1)(b) GDPR) and your consent (Art. 6(1)(a)). • Vacancy application — to evaluate your candidacy and contact you about next steps. Legal basis: pre-contractual measures (Art. 6(1)(b)) and your consent (Art. 6(1)(a)). • Partner account data — to provide partner-portal services, generate offers, and manage access. Legal basis: performance of contract (Art. 6(1)(b)). • Cookies (essential) — for site functionality (locale, authentication). Legal basis: legitimate interest (Art. 6(1)(f)). • Cookieless analytics (Vercel) — to monitor performance and detect outages. Legal basis: legitimate interest (Art. 6(1)(f)). • IP address (rate-limiting) — to prevent spam, abuse, and automated submissions. Legal basis: legitimate interest (Art. 6(1)(f)). For Ukrainian law, the corresponding bases are consent and contract performance under Articles 6 and 11 of Law of Ukraine "On Personal Data Protection" (No. 2297-VI).
4. Where your data is stored
We use the following data processors. Each is contractually obligated to handle your data according to applicable data protection law. • Supabase Inc. — database, authentication, encrypted file storage (CVs). Hosted in EU (Frankfurt) or AWS-EU regions. CV files are stored in a private bucket; access requires expiring signed URLs. • Resend, Inc. — transactional email delivery. Located in the USA, with Standard Contractual Clauses (SCCs) for EU transfers. Email contents include your submitted name, email and request details — necessary to notify our team. • Vercel, Inc. — hosting, Vercel Analytics, Vercel Speed Insights. Global edge network with EU data residency for site assets. Analytics and Speed Insights are cookieless and do not link to identifiable persons. Where data is transferred outside Ukraine or the EEA, the transfer is protected by Standard Contractual Clauses (SCCs) or equivalent safeguards.
5. How long we keep your data
Retention periods by category: • Partner access request — pending or rejected: up to 12 months from submission, then deleted. • Partner access request — approved: for the duration of the partner relationship + 3 years afterwards. • Active partner account: while the account is active. After deactivation: 3 years (for accounting / legal purposes). • Vacancy application — not selected: up to 6 months after the position is closed, then deleted (unless you consent to longer retention for future vacancies). • Vacancy application — selected, hired: becomes part of your employee file; retained per labor law. • Server logs containing IP addresses: up to 30 days. • Vercel anonymized analytics: per Vercel's retention policy (currently rolling 30-day window for raw events).
6. Who we share your data with
We do not sell your personal data. We do not share it with third parties for marketing purposes. We do not transfer it to advertising networks. We share data only with: • Our internal team (HR, sales, engineering — strictly on a need-to-know basis). • The processors listed in Section 4 (under data-processing agreements). • Government authorities when legally required (court order, legitimate request from competent authorities).
7. Cookies
This site uses only strictly necessary cookies. We do not use cookies for marketing, advertising or cross-site tracking, so we do not display a cookie consent banner. • `ae_locale` — stores your language preference (EN / UA). Duration: 1 year. Type: essential, set by us. • `sb-*` (Supabase) — authentication session for partner-portal users. Duration: session / 1 hour for refresh tokens. Type: essential, set by Supabase on sign-in. Vercel Analytics and Vercel Speed Insights, which we use to monitor site performance, do not use cookies. They generate an anonymized session ID per visit that cannot be linked back to you.
8. Your rights
Under GDPR (if you are in the EEA) and the Law of Ukraine "On Personal Data Protection", you have the following rights: • Right of access — to know whether we process your personal data and obtain a copy. • Right of rectification — to correct inaccurate data. • Right to erasure ("right to be forgotten") — to have your data deleted. • Right to restriction of processing — to limit how we process your data. • Right to data portability — to receive your data in a machine-readable format. • Right to object — to object to processing based on our legitimate interest. • Right to withdraw consent — at any time, where consent is the legal basis (does not affect prior lawful processing). • Right to lodge a complaint with a supervisory authority. In Ukraine, the Verkhovna Rada Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини) is the supervisory authority. To exercise any of these rights, contact us at info@aernd.com. We will respond within 30 days.
9. Security
We implement technical and organizational measures to protect your data, including: • TLS/HTTPS for all data in transit (HSTS enabled). • Encrypted storage at rest (Supabase encryption). • CV files stored in a private storage bucket; access requires short-lived signed URLs. • Role-based access control with row-level security policies in our database. • HTML escaping of user-submitted content in outbound emails (XSS protection). • Rate limiting on public forms to prevent abuse. • Regular review and patching of dependencies. No method of transmission over the Internet is 100% secure. We commit to industry-standard safeguards but cannot guarantee absolute security.
10. International transfers
Some of our processors (notably Resend) are located outside Ukraine and the EEA. Where this is the case, transfers are protected by Standard Contractual Clauses (SCCs) under Article 46 GDPR or equivalent safeguards.
11. Children
This site is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted personal data, please contact us so we can delete it.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on the site. The "Last updated" date at the top of this page reflects the date of the most recent change.
13. Contact
For any privacy-related questions or to exercise your rights, contact us at info@aernd.com. If you are not satisfied with our response, you may contact the Verkhovna Rada Commissioner for Human Rights of Ukraine, the supervisory authority for personal data protection in Ukraine.
AE R&D · Autonomous Engineering R&D Ukraine