All legal documents

Legal

Privacy Policy

Last updated: 2026-09-21

Last updated: 2026-09-21

This Privacy Policy explains how Resonix Labs (USA) Inc. (“Resonix,” “we,” “us”) collects, uses, discloses, and protects personal information when you visit resonixusa.com, contact us, or otherwise interact with us. It is written primarily under United States law (including the California Consumer Privacy Act / California Privacy Rights Act where applicable) and, where relevant, the EU/UK General Data Protection Regulation (GDPR).

Scope note. This Policy covers our websites and business interactions. Where Resonix software runs on your own systems, it is designed not to phone home or collect personal information unless a specific product or engagement says otherwise. Software license terms, if any, are separate from this Policy.

The Resonix group website at resonix.io is operated by a different Resonix entity and has its own privacy policy.

Cookie details are in our separate Cookie Policy.

1. Who we are (controller & contacts)

  • Data controller: Resonix Labs (USA) Inc., a Delaware corporation.
  • Contact: team@resonixusa.com

2. The personal information we collect

(a) Information you give us

  • Inquiries and correspondence: name, email, company, role, and anything you send by email or contact form.
  • Business / program discussions: information you choose to share about your organization, use case, or requirements when evaluating or engaging with Resonix.

(b) Information collected automatically

  • Access & security logs: IP address, browser user-agent, pages or resources accessed, and timestamps — for security, abuse prevention, and site operation.
  • Site analytics: aggregate usage and performance metrics via Vercel Analytics and Vercel Speed Insights.
  • Cookies / similar technologies: see our Cookie Policy.

This site does not offer user accounts or login. We do not collect passwords or maintain authenticated session accounts on resonixusa.com.

We do not intentionally collect sensitive personal information as a matter of course, and our sites are not directed to children under 16.

3. Why we use it (and GDPR legal bases where they apply)

PurposeExamplesGDPR legal basis (if GDPR applies)
Respond to you and run the businessreply to inquiries; discuss use cases, pilots, or contractsLegitimate interests; steps prior to a contract (Art. 6(1)(b))
Operate & secure the sitesecurity logs, abuse preventionLegitimate interests — security (Art. 6(1)(f))
Operate & improve the siteanalytics, performance, debuggingConsent (where required) or Legitimate interests
Comply with lawrecords, security, legal process, export-control / sanctions complianceLegal obligation (Art. 6(1)(c)); Legitimate interests

Where we rely on legitimate interests, we balance those interests against your rights; you may object (see §8).

4. Cookies & analytics

We may use cookies and similar technologies as described in our Cookie Policy, including analytics / performance tools such as Vercel Analytics and Speed Insights. Where consent is required (for example for certain EU/UK visitors), non-essential analytics will be used only with your consent. Details and controls are in the Cookie Policy.

5. How we share information

We do not sell your personal information. We share it only with:

  • Service providers who host and operate infrastructure under contract and our instructions, which may include:
  • Vercel — website hosting, analytics, performance;
  • Neon (hosted on AWS) — database, if used;
  • Cloudflare R2 — object storage, if used;
  • our email / messaging providers — transactional and business email.
  • Professional advisors (lawyers, accountants, auditors) under confidentiality.
  • Authorities where required by law, or to establish, exercise, or defend legal claims, or for export-control / sanctions compliance.
  • Corporate transactions — in connection with a merger, financing, reorganization, or sale, subject to confidentiality and this Policy.
  • Affiliated Resonix entities only as needed to respond to your request or deliver services (for example routing a technical question), under appropriate safeguards.

6. International transfers

We are based in the United States and use service providers that may process data in the United States and other countries. If personal data of EU/UK individuals is transferred outside the EEA/UK, we rely on an appropriate transfer mechanism (for example Standard Contractual Clauses, an adequacy decision, or the UK IDTA) where required.

7. How long we keep it (retention)

We keep personal information only as long as needed for the purposes above:

DataIndicative retention
Inquiry / correspondence24 months (or longer if needed for an active relationship or legal hold)
Access & security logs12–24 months
Analytics dataPer provider retention and our Cookie Policy

We then delete or irreversibly anonymize the data, unless a longer period is required by law.

8. Your rights

California (CCPA/CPRA) and other US state privacy laws (where applicable): you may have rights to know/access, delete, correct, and receive a portable copy of certain personal information, and to non-discrimination for exercising your rights. See §13.

GDPR / UK GDPR (if you are in the EU/UK): you may request access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests or to direct marketing. Where we rely on consent, you may withdraw it at any time. You may lodge a complaint with your supervisory authority.

To exercise a right, email team@resonixusa.com. We will respond within the timeframes required by law. We may need to verify your identity.

9. How we protect information

We use technical and organizational measures appropriate to the risk, which may include encrypted transport (HTTPS/TLS), access controls, audit logging, and least-privilege access. No method is 100% secure. We maintain processes to respond to incidents and will notify you and regulators of breaches where required by law.

10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

11. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date shows the latest version. Material changes will be notified as required by law.

12. Contact

Questions or requests: team@resonixusa.com

Resonix Labs (USA) Inc. A Delaware Corporation

13. Notice to California residents (CCPA/CPRA)

In the preceding 12 months we have collected the following categories of personal information (as defined by the CPRA), depending on how you interact with us:

CategoryExamples we may collectSold / Shared?
Identifiersname, email, company, IP addressNo
Commercial informationinquiry history, engagement related to products or servicesNo
Internet / network activitylog data, pages accessed, performance metricsNo
Professional / employment informationcompany, job title you provideNo

We do not sell and do not share personal information as “sell” and “share” are defined under the CPRA (including for cross-context behavioral advertising), and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit. Our purposes for collection are described in §3; we retain information per §7.

Your California rights: to know/access; delete; correct; opt out of sale/sharing (not applicable — we do neither); limit use of sensitive personal information (not applicable); and non-discrimination for exercising your rights. To exercise a right, contact team@resonixusa.com. We will verify your identity and may honor an authorized agent’s request with proof of authorization.

“Do Not Sell or Share My Personal Information”: because we do not sell or share personal information, no opt-out is required; this statement serves as our disclosure. We honor Global Privacy Control (GPC) browser signals as a valid opt-out of any future sale/sharing.