Trust, Compliance & Governance

Legal, Privacy & Security

A unified transparency center governing how Achtrex secures automotive systems, delivers enterprise software platforms, and upholds international privacy standards.

Effective Date: January 1, 2026 • Version 3.2
Legal Framework

Terms of Service

1. Agreement to Terms

These Terms of Service ("Terms") constitute a legally binding agreement between you (whether individually or on behalf of an enterprise entity, "Customer", "you", or "your") and Achtrex ("Company", "we", "us", or "our"), governing your access to and use of Achtrex automotive software builds, cognitive AI platforms, consultation advisory services, cloud platforms, and related documentation (collectively, the "Services").

By accessing, querying, integrating, or utilizing the Services, you acknowledge that you have read, understood, and agreed to be bound by all of these Terms. If you do not agree with all of these Terms, you are prohibited from using the Services.

2. Enterprise Licensing & Software Access

Subject to your full compliance with these Terms and payment of applicable platform subscriptions, Achtrex grants you a limited, non-exclusive, non-transferable, revocable license to access our custom software builds, cognitive AI tools, and consulting deliverables solely for internal operational workflows, application enrichment, or authorized dealer platform syndication.

  • Platform Credentials: You are strictly responsible for maintaining the confidentiality of platform credentials, client secrets, and authentication bearer tokens. Any query or action initiated via your credentials is deemed authorized by your organization.
  • Rate Limits & Fair Use: You agree to conform with published rate-limiting tiers (measured in requests per second and monthly quota limits). Scripted circumvention of rate limit controls constitutes an immediate breach.
  • No Unauthorized Reverse Engineering: Automated extraction, reverse compilation, bulk offline mirroring, or unauthorized sub-licensing of proprietary Achtrex code or AI models without express written authorization is strictly prohibited.

3. Service Level Commitments & Reliability

For production tier enterprise accounts, Achtrex provides a standard 99.9% Platform Uptime Commitment calculated on a calendar month basis, excluding scheduled maintenance windows notified at least 72 hours in advance. Target response latencies are maintained via redundant edge nodes.

4. Intellectual Property & Neutral Infrastructure

All patents, copyrights, database rights, trademarks, algorithmic classification models, taxonomy structures, and software codebases comprising the Achtrex platform remain the exclusive property of Achtrex. Nothing in these Terms transfers proprietary ownership to Customer. Customer retains all rights and ownership over Customer proprietary data ingested into the system.

5. Payment, Invoicing & Billing

Fees for Services are billed in advance on an annual or monthly subscription schedule as specified in your Enterprise Master Services Agreement (MSA) or order schedule. All fees are non-refundable except where required by law or as expressly set forth in an SLA rebate provision. Late balances accrue interest at 1.5% per month or the legal statutory ceiling.

6. Limitation of Liability & Indemnification

To the maximum extent permitted by applicable law, neither party shall be liable for indirect, incidental, consequential, punitive, or exemplary damages, including lost profits or business disruption. The aggregate liability of Achtrex under any claim arising from or related to the Services shall not exceed the total fees paid by Customer to Achtrex in the twelve (12) months preceding the incident.

7. Governing Law & Dispute Resolution

These Terms are governed by and construed in accordance with the laws of the United Arab Emirates as applicable in the Emirate of Dubai. Any dispute, controversy, or claim arising out of or in connection with these Terms shall be resolved via binding commercial arbitration or the competent courts of Dubai.

Data Protection

Privacy Policy

1. Our Privacy Commitment

Achtrex respects the privacy of our website visitors, platform clients, enterprise partners, and authorized users. This Privacy Policy details how we collect, process, store, and safeguard personal and operational information across our platform, in full alignment with the UAE Federal Decree-Law No. 45/2021 on Personal Data Protection, the General Data Protection Regulation (GDPR), and other applicable global standards.

2. Categories of Information Collected

  • Account & Contact Data: Name, work email address, company affiliation, telephone number, job title, and billing records provided during partner enrollment, contact inquiries, or meeting bookings.
  • Technical & System Logs: Request timestamps, originating IP addresses, user agent headers, session parameters, and latency metrics recorded automatically when interacting with Achtrex software platforms.
  • Vehicular & Diagnostic Metadata: Vehicle equipment codes, diagnostic trouble codes (DTC), and parts identifiers processed through diagnostic and workshop interfaces. Note: Mechanical vehicle identifiers do not contain personal individual identity data.

3. Purpose and Legal Grounds for Processing

We process collected data exclusively under the following legal bases:

  • Contractual Performance: Fulfilling our service obligations, provisioning platform access, maintaining uptime, and delivering software engineering deliverables.
  • Legitimate Interests: Preventing unauthorized access, ensuring system cybersecurity, and optimizing software performance.
  • Legal Compliance: Meeting corporate, taxation, and statutory audit obligations under UAE law.

4. Data Sharing & Sub-Processors

Achtrex does not sell, rent, or monetize personal information. We share information only with strictly audited infrastructure sub-processors (such as ISO-certified cloud hosting providers and payment processors) bound by comprehensive Data Processing Agreements (DPAs) and confidentiality safeguards.

5. Global Data Subject Rights

Regardless of geographic residency, Achtrex affords users full control over their personal records:

Right of Access & Rectification

Request a verified extract of your stored records or request correction of inaccuracies.

Right to Erasure ("Forget Me")

Direct our compliance team to delete personal identifiers from active data stores.

To exercise any data rights, submit your request to privacy@achtrex.com. We respond to all formal requests within 30 days.

6. Data Retention & Anonymization

Account profiles are maintained throughout the active contractual lifecycle. Operational platform telemetry logs are pseudonymized and archived for 90 days for security analysis before automatic purged retention.

Infrastructure Security

Security Architecture & Data Perimeter

1. Security by Design & Defense in Depth

At Achtrex, security is not an afterthought; it is built into every architectural layer of our automotive data pipeline. We implement a zero-trust model across all development environments, microservices, and client communication interfaces.

End-to-End Encryption

All data in transit is protected via TLS 1.3 with strict HSTS enforcement. Data at rest is encrypted using military-grade AES-256 with automated HSM key rotation.

Zero-Trust & MFA

All administrative platform access requires mandatory hardware token MFA, short-lived session grants, and continuous role-based least-privilege enforcement.

Isolated Multi-Tenant Clusters

Customer data partitions are logically and cryptographically segmented. No customer queries or DMS inventory feeds bleed across enterprise tenant boundaries.

DDoS & Edge Shielding

Global Anycast edge networks block Layer 3/4 and Layer 7 volumetric attacks before they reach backend processing clusters, guaranteeing uninterrupted uptime.

2. Business Continuity & Disaster Recovery

Achtrex maintains real-time active-active database replication across geographically distributed Tier IV data center facilities. We maintain:

  • Recovery Point Objective (RPO): < 15 minutes across core automotive repositories.
  • Recovery Time Objective (RTO): < 60 minutes for instantaneous failover orchestration.
  • Automated Daily Backups: Immutable snapshots stored offsite with air-gapped cryptographic integrity validation.

3. Incident Management & Breach Notification SLA

Our Security Operations Center (SOC) operates 24/7/365 automated anomaly detection. In the event of a verified data breach affecting customer data, Achtrex will notify impacted customers within 72 hours of formal confirmation in accordance with applicable statutory standards.

4. Responsible Disclosure & Vulnerability Submissions

We welcome responsible vulnerability disclosures from certified security researchers. If you identify a potential vulnerability in our software or web infrastructure, please report it immediately to security@achtrex.com with proof-of-concept replication steps.