Legal
Privacy Policy
Last updated: March 2026
1. Introduction
EcoMetricx Inc. (“EcoMetricx,” “we,” “us,” or “our”) is committed to protecting the privacy of individuals who interact with our website and services. This Privacy Policy explains what data we collect, how we use it, and the choices you have regarding your information.
By using our website at ecometricx.click, submitting information through our forms, or interacting with EcoMetricx-hosted products and chatbot experiences, you agree to the practices described in this policy.
2. Data We Collect
We collect the following categories of information:
- Contact submissions: Name, email address, company, and the message you submit through our contact form.
- Whitepaper leads: Name, email address, and company name when you download a whitepaper or research resource.
- Authentication data: Email address and session tokens for administrators using our content management system. We do not collect passwords directly — authentication is managed via NextAuth.js.
- Usage data: Standard server logs including IP address, browser type, and pages visited. We do not use third-party analytics cookies unless explicitly noted.
- Hosted application and chatbot data: Configuration data, conversation content, application telemetry, uploaded files, and other business records required to operate EcoMetricx-hosted tools, AI assistants, and client-facing product experiences.
3. How We Use Your Data
We use the information we collect to:
- Respond to inquiries and provide requested services
- Send requested research materials and follow-up communications
- Maintain and secure our platform and content management system
- Comply with applicable legal obligations
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. AI and LLM Data Use Boundaries
EcoMetricx uses AI and large language model (LLM) technologies internally for certain analytical and operational tasks. We are committed to the following boundaries:
- No training on client data: Data you submit through our website — including contact form submissions, whitepaper lead information, and any client data shared with us for analytical engagements — is never used to train third-party AI or LLM models.
- No sharing with AI providers for training: We do not share client or user data with AI model providers (including OpenAI, Anthropic, or others) for training purposes.
- Internal AI usage: When AI tools are used internally to assist with research, drafting, or analysis, they operate under data processing agreements that prohibit use of submitted data for model training.
- Client engagement data: Any proprietary client data shared during a consulting engagement is governed by a separate Data Processing Agreement (DPA) and subject to confidentiality obligations. It is not submitted to any external AI system without explicit written authorization.
5. Subprocessors
We use the following third-party subprocessors to operate our platform. Each has been reviewed for data protection compliance:
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, database (DynamoDB), file storage (S3), compute (Lambda) | US East (N. Virginia) |
| NextAuth.js | Authentication session management for admin users | Self-hosted on AWS |
We will update this list when new subprocessors are added. Significant changes will be communicated via this page with an updated “Last updated” date.
6. Data Retention
We retain contact form submissions and whitepaper leads for up to 24 months from the date of submission, or until you request deletion, whichever is earlier. Authentication session data is retained for the duration of the active session. Server logs are retained for up to 90 days.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal data, subject to any legal retention obligations.
- Objection: Object to our processing of your data for certain purposes.
- Portability: Request your data in a structured, machine-readable format.
For residents of the European Union or United Kingdom, these rights are provided under the GDPR. For California residents, they are provided under the CCPA. To exercise any of these rights, contact us at the address below.
8. Security
We implement reasonable technical and organizational safeguards to protect personal data against unauthorized access, alteration, disclosure, or destruction. Our infrastructure runs on AWS with encryption at rest and in transit. Access to administrative systems is restricted to authenticated personnel.
Depending on the product or client deployment, EcoMetricx-hosted services may also operate in AWS, GCP, or Azure environments under customer-specific architectural and contractual requirements.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
9. Incident Response and Contact
In the event of a data security incident affecting your personal information, we will notify affected individuals and relevant authorities as required by applicable law.
For all privacy-related inquiries, data subject requests, or to report a security concern, please contact:
Privacy and Security Contact
EcoMetricx Inc.
Email: privacy@ecometricx.com
We aim to respond to all privacy inquiries within 5 business days.
10. Updates to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. We encourage you to review this page periodically. Continued use of our website after changes are posted constitutes your acceptance of the updated policy.