Skip to main content
Legal & Privacy Policy

Privacy Policy

Effective Date: September 11, 2026 | Version 1.0 (Pre-Launch Operational Release)

Privacy Inquiries & Data Rights Requests: contact@aformix.comTerms of ServiceContact Team

Preamble & Scope

This Privacy Policy explains how Aforden (“Aforden,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects information when you register an organization workspace, access our field service management platform, interact with our dispatch APIs, use our technician interfaces, or visit our marketing properties (collectively, the “Service” or “Platform”).

[Data Controller / Processor Roles — TBD: In standard B2B SaaS operations, Aforden acts primarily as a data processor (or service provider) handling Customer Data, work orders, service locations, and CRM records on behalf of Customer organizations, and as a data controller for direct account registration credentials, billing records, and platform administrator profiles, subject to formal Data Processing Addenda upon commercial rollout.]

By accessing or using the Service, you acknowledge the collection and handling of your information as outlined in this Privacy Policy.

Section 1: Categories of Information We Collect

1.1 Account & Administrative Information: When you register a workspace or user account, we collect:

  • Full name, business email address, organizational job title, and company profile.
  • Authentication credentials: Passwords are protected using salted, one-way cryptographic hashing (bcrypt with a work factor of 12). Aforden never stores, transmits, or has access to plaintext passwords.
  • Assigned workspace membership roles (Owner, Administrator, Manager, Dispatcher, Technician, or Accountant per the Platform’s compile-time verified role-based access control matrix).

1.2 Operational Workspace Data: To deliver field service operations, Customer workspaces store:

  • Customer CRM profiles (contact names, business phone numbers, email addresses, and service notes).
  • Work order lifecycles (job descriptions, line-item tasks, equipment asset categories, priority levels, and completion statuses).
  • Invoices and commercial records (line-item parts, labor charges, payment terms, and status history).
  • Attachment and evidence storage (job site inspection photographs, diagnostic documents, and equipment manuals).

1.3 Operational Telemetry & Inbound Request Metadata: When interacting with the Platform or public REST APIs, we collect:

  • API endpoint request metadata: HTTP method, URI path, status code, response latency, and rate-limit consumption.
  • Client IP address: To maintain security and enforce rate limits without storing raw network locations, client IP addresses submitted to public endpoints are cryptographically hashed using SHA-256 (ipHash) before logging.
  • System diagnostic logs and unhandled error stack traces, attributed logically by workspace (workspaceId) and API credential (apiKeyId).

Section 2: Precise Geolocation & Location Tracking

Aforden treats precise geographic data as sensitive operational information subject to heightened architectural safeguards and strict purpose limitations.

2.1 Categories of Location Data Collected:

  • Customer Service Location Geocoordinates: Precise geographic coordinates (latitude and longitude) and physical street addresses associated with customer job sites and equipment assets (ServiceLocation.latitude, ServiceLocation.longitude), submitted by Customer to route technicians and schedule dispatch appointments.
  • Technician Travel & Service Area Data: Assigned operational zones (TechnicianServiceArea) and travel time entries (TechnicianTimeEntry with entry type TRAVEL), recording travel start and end timestamps, durations, and technician dispatch appointments.

2.2 Strict Purpose Limitation: Geolocation and travel telemetry are collected and processed solely for legitimate field service operations:

  • Calculating technician travel durations and routing efficiency.
  • Validating service area coverage and preventing schedule conflicts.
  • Establishing operational dispatch records and job arrival milestones.

2.3 Access Control & Tenant Isolation:

  • Precise location records are scoped strictly to Customer’s isolated workspace (workspaceId) at the application layer.
  • Access within a workspace is restricted by role-based access control: dispatchers, managers, and administrators may view job site coordinates to manage schedules, while field technicians only access job locations assigned to their active work orders.
  • Aforden does not sell, rent, monetize, or broker precise geolocation data to third parties, advertising exchanges, or unrelated tenant workspaces.

Section 3: Third-Party Service Providers & Subprocessors

Aforden does not share Customer Data with third parties except with verified infrastructure subprocessors necessary to operate the Platform. Below is the complete catalog of integrated third-party processors and the specific data categories transmitted to each:

3.1 Payment & Billing Gateways

  • Providers: Paddle (@paddle/paddle-node-sdk) and Stripe (stripe).
  • Data Categories Shared: Customer name, business email address, workspace ID, selected subscription plan tier, and transaction amounts.
  • Payment Card Data: Payment card numbers, expiration dates, and CVVs are collected and processed directly by our PCI-DSS compliant payment gateways through secure iframes/tokens. Aforden servers never store or process raw credit card numbers.

3.2 Transactional & Operational Email Delivery

  • Providers: Resend (resend) and Brevo (brevoAdapter).
  • Data Categories Shared: Recipient name, destination email address, transactional email subject, and notification content (e.g., account invitations, password reset verification tokens, and work order dispatch updates).

3.3 Operational SMS Messaging

  • Provider: Twilio (twilioAdapter).
  • Data Categories Shared: Destination phone numbers (in international E.164 format) and operational message text (e.g., appointment arrival notifications, urgent schedule changes).

3.4 Cloud Attachment Storage

  • Provider: Amazon Web Services (AWS S3) (awsS3Adapter).
  • Data Categories Shared: Binary image attachments (work order job photos), diagnostic PDF inspection evidence, and object storage keys scoped to Customer’s workspace.

3.5 Commercial Accounting Ledger Sync (Optional)

  • Provider: Intuit QuickBooks Online (quickBooksAdapter).
  • Data Categories Shared: Customer business names, billing addresses, invoice line-item descriptions, and payment totals, transmitted solely when a Workspace Owner explicitly connects their QuickBooks integration.

3.6 Technician Calendar Synchronization (Optional)

  • Provider: Google Calendar (googleCalendarAdapter).
  • Data Categories Shared: Dispatch appointment start/end timestamps, technician calendar identifiers, and work order summary titles, transmitted solely when calendar sync is authorized by the workspace.

3.7 Affirmative Disclosure: Zero Third-Party Advertising Trackers

  • Aforden does not install third-party advertising cookies, conversion trackers, behavioral tracking pixels, or third-party web analytics software (such as Google Analytics, Meta Pixel, PostHog, Segment, or Mixpanel).
  • We do not sell your personal data or share your personal data with third parties for cross-context behavioral advertising.

Section 4: Cookies & Local Storage

Aforden uses strictly necessary, functional cookies required to maintain user sessions, secure authentication states, and defend against security vulnerabilities:

Cookie NameProvider / ScopePurpose & ClassificationExpiration
__Secure-authjs.session-token /
authjs.session-token
Aforden (next-auth)Maintains authenticated session state for logged-in workspace members (httpOnly, secure, sameSite=lax).[Session Token Lifespan — TBD: e.g., 30 days sliding]
__Secure-authjs.callback-url /
authjs.callback-url
Aforden (next-auth)Stores redirect destination during authentication workflows (httpOnly, secure, sameSite=lax).Session
__Host-authjs.csrf-token /
authjs.csrf-token
Aforden (next-auth)Cryptographic anti-CSRF protection token preventing cross-site request forgery attacks (httpOnly, secure, sameSite=lax).Session

Because Aforden uses only strictly necessary operational cookies, tracking consent banners for advertising cookies are not required under applicable ePrivacy directives.

Section 5: Data Retention & Workspace Lifecycle

5.1 Active Subscription Retention: Aforden retains Customer Data and operational workspace records for as long as Customer maintains an active organizational subscription.

5.2 Post-Termination Retention: Upon subscription cancellation or workspace termination, customer data will be deleted within 30 days of account closure or termination, except where retention is required by law or for legitimate backup/audit purposes. During this 30-day window, Customer may request a data export.

5.3 Operational Log & Telemetry Retention: API request logs, cryptographically hashed IP addresses, and error stack traces are retained for system diagnostics and capacity planning for a period of [Log Retention Window — TBD: e.g., 90 days], after which they are automatically purged.

Section 6: Data Subject Rights & Manual Request Fulfillment

6.1 Your Privacy Rights: Depending on your jurisdiction (such as under the European General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA/CPRA)), you may have the following rights regarding personal data held by Aforden:

  • Right of Access: The right to request copies of the personal data we hold about you.
  • Right to Rectification: The right to request correction of inaccurate or incomplete records.
  • Right to Erasure (Deletion): The right to request deletion of personal data, subject to statutory recordkeeping requirements.
  • Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your statutory privacy rights.

6.2 Manual Fulfillment Process:

  • In this pre-launch operational release, Aforden does not provide automated self-service account deletion or export buttons. All privacy and data subject requests are processed manually by our platform administration team.
  • To exercise any of these rights, contact us electronically at contact@aformix.com with the subject line Data Privacy Request.
  • We will verify your identity (and organizational authority, if requesting workspace-level records) before processing the request. Verified requests will be fulfilled within [Statutory Response Window — TBD: e.g., 30 calendar days].

Section 7: Security Architecture & Safeguards

7.1 Application-Layer Tenant Isolation: As codified in our Terms of Service, all workspace data is logically siloed at the application layer by organizational workspace identifier (workspaceId). Cross-workspace data reads are blocked by software-level authorization filters.

7.2 Cryptographic Safeguards:

  • Passwords: Hashed with salted bcrypt (work factor 12) with constant-time verification.
  • Transport Security: All web and API traffic is served over encrypted HTTPS connections, enforced application-wide via HTTP Strict Transport Security (HSTS) headers with a 1-year max-age.
  • API Keys & Webhook Secrets: Developer API keys are never stored in plaintext; only cryptographically generated SHA-256 key hashes (keyHash) are persisted to the database. Webhook signing secrets and API credentials are restricted strictly to authorized workspace members via application-layer access controls.

7.3 Incident Notification: In the event of a confirmed security incident or data breach impacting Customer Data, Aforden will notify affected Workspace Owners via email within [Breach Notification Window — TBD: e.g., 72 hours] of confirmation, in compliance with applicable data protection laws.

Section 8: Corporate Governance & Legal Contact

8.1 Data Controller Identity:

  • Organization: Aforden
  • Corporate Registration & Postal Address: Deferred in this pre-launch release pending corporate milestones.
  • Data Protection Inquiries & DPO Contact: contact@aformix.com

8.2 Supervisory Authority & Dispute Escalation: If you are an individual located in the European Economic Area or United Kingdom and believe our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with your local supervisory authority [Supervisory Authority Reference — TBD].

8.3 Changes to this Policy: Aforden may periodically update this Privacy Policy to reflect platform evolution, legal requirements, or architectural updates. Material changes will be communicated via at least 30 days’ written notice (email to the account holder is sufficient) before any material change to this policy takes effect for existing customers.