01
Scope and operator
AAOE.ai is the controller of the limited personal information described in this notice. The public service provides read-only access to normalized government rates and related provenance. This notice covers the website, public API, operational logs, and messages sent to the project.
This notice does not govern a government agency’s website or API linked from AAOE, nor an enterprise customer’s ERP or travel-and-expense system. Those organizations apply their own notices and legal obligations.
02
Information the service handles
Network and request data
Cloudflare processes ordinary Internet request data needed to deliver and secure the service. This can include an IP address, user-agent, requested URL and query parameters, timestamp, protocol and device/network signals, response status, and security events.
For public rate limiting, the Worker creates a SHA-256 digest from the requesting IP address and a shortened user-agent string. The digest is scoped to an endpoint group and used by Cloudflare’s rate-limit binding. AAOE does not write the raw IP address, user-agent, or resulting digest to its D1 application database or R2 evidence store.
API parameters
Rate requests can include a rate type, country, category, effective date, fiscal year, and postal code. These parameters describe a government rate lookup. They may appear in the request URL and may be included in limited operational error logs. Do not place a person’s name, employee identifier, expense details, trip description, authentication credential, or other personal or confidential data in an AAOE URL.
Messages you send
If you email the project, AAOE receives the information you choose to provide, such as your name, business email, organization, role, technical requirements, and the content of your message. The site currently uses mail links rather than an embedded contact form.
Government source data
AAOE retrieves public government rate data and preserves source artifacts for provenance. These records are not intended to contain personal information. If unexpected personal information appears in a source artifact, it will be restricted, reviewed, and minimized or removed where doing so is consistent with legal and audit obligations.
03
Why the information is used
- Deliver the website and requested API response.
- Enforce reasonable request limits and defend the service from abuse.
- Diagnose errors, maintain availability, and investigate security events.
- Answer questions and evaluate requests for jurisdictions, higher limits, or enterprise access.
- Meet legal obligations and establish, exercise, or defend legal claims.
Where EU or UK data-protection law applies, these activities rely on AAOE’s legitimate interests in operating and securing the service, steps requested before entering a contract or performance of a contract, and legal obligations where applicable. AAOE does not use this information for advertising, data brokerage, cross-site tracking, or automated decisions about people.
04
Service providers and disclosure
Cloudflare provides DNS, network delivery and security, Workers compute, rate limiting, operational logging, D1 database storage, and R2 object storage. Cloudflare processes request and customer-log data under its own contractual and privacy terms.
Email providers process messages when you contact the project. Your organization’s mail provider and AAOE’s mailbox provider receive the routing and message data needed to deliver the email.
Government source systems receive only the lookup criteria needed for supported live connectors, such as country, category, postal code, or fiscal year. AAOE does not intentionally forward the caller’s IP address, user-agent, or identity to those sources.
Information may also be disclosed when required by law, to protect the service or others, or in connection with a reorganization or transfer of the project subject to appropriate notice and safeguards. AAOE does not sell personal information, share it for cross-context behavioral advertising, or disclose it to data brokers.
05
Retention and deletion
| Category | Current approach |
|---|---|
| Rate-limit digest | Used for the 60-second enforcement window and not copied into AAOE’s D1 or R2 stores. |
| Operational logs | Automatic per-invocation logs are disabled. Limited structured error and scheduled-operation logs may be sampled and retained by Cloudflare for no more than seven days. |
| Contact messages | Normally retained for up to 24 months after the last substantive interaction, then deleted unless an active contract, security matter, or legal obligation requires longer retention. |
| Government evidence | Source artifacts and audit records may carry a seven-year regulatory-source retention class. They are not intended to contain personal data. |
Backup copies and provider-level security records may age out on a different schedule. When exact deletion is technically impracticable, information is isolated from ordinary use until overwritten or expired.
07
Security and data minimization
Current controls include HTTPS, restrictive browser security headers, read-only public endpoints, input validation, rate limiting, private evidence storage, content-addressed source artifacts, append-only governed records, sanitized application errors, and reduced logging. No Internet service can promise absolute security.
Security concerns can be reported to security@aaoe.ai. Please do not include live credentials or unnecessary personal information in an initial report.
08
International processing
Cloudflare operates a global network, so requests can be processed outside the country where they originate. The public MVP does not promise country-specific data residency. Organizations requiring a data-processing addendum, regional processing boundary, custom retention, or other transfer safeguards should contact AAOE before production use.
09
Enterprise and ERP integrations
AAOE is intended to provide reference configuration data to an ERP or travel-and-expense system. It is not intended to receive an expense report, itinerary, employee profile, card transaction, patient information, or other regulated business record.
Send only the jurisdiction, rate category, and effective date needed to select a government rate. Keep employee-level matching and expense decisions inside your organization’s controlled systems.
Before an enterprise uses AAOE in production, the parties should document security contacts, service levels, change notification, retention, incident response, subprocessors, and any required data-processing terms. If future versions add accounts, API credentials tied to named users, billing, or customer-submitted data, this notice will be updated before that processing begins.
10
Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to appeal or complain to a privacy regulator. Because the public API does not create user accounts and AAOE does not store raw caller identifiers in its application data stores, the project may have little or no information that can be linked back to an API caller.
To make a request, email api@aaoe.ai. AAOE may need to verify the request and will respond as required by applicable law. Exercising a privacy right will not result in discriminatory treatment.
11
Changes to this notice
The effective date at the top identifies the current version. Material changes will be posted here before or when they take effect. If a change materially expands how personal information is used, AAOE will provide additional notice appropriate to the circumstances.
12
Contact
Privacy questions, rights requests, enterprise privacy requirements, and requests for a copy of relevant safeguards can be sent to api@aaoe.ai.
This notice describes the current public MVP. It is not a data-processing addendum, service-level agreement, or substitute for an enterprise contract.