Privacy Policy — Battlement Systems
Legal

Privacy Policy.

The short version

  • This policy covers our website and business contacts. It does not cover data you place inside a Battlement vault — that is governed by your customer agreement, and we handle it as a processor, never for our own purposes. See customer data inside the vault.
  • We collect what you give us on the assessment form, plus ordinary server and campaign data. See information we collect.
  • We do not sell or share personal information for cross-context behavioural advertising, and we do not run ads on this site. See how we share information.
  • Non-essential cookies are off until you accept them, and you can at any time. See cookies and similar technologies.
  • You can ask us for a copy of your data, or ask us to delete it. See your rights.

01Who we are and what this covers

Battlement Systems, LLC (“Battlement”, “we”, “us”) provides sovereign AI data infrastructure to enterprise and public-sector organisations from facilities in the United States.

This policy explains how we handle personal information when you visit our website, submit an enterprise assessment request, read materials we publish, or otherwise correspond with us about our services. In this context Battlement is the controller of that information.

It does not apply to third-party sites we link to, or to any site or service that publishes its own privacy notice.

Who we market to

Battlement offers its services exclusively to organisations established in the United States. We do not direct marketing, advertising, or sales activity to individuals or organisations in the European Economic Area or the United Kingdom, we do not accept enquiries seeking deployment outside United States jurisdiction, and we do not monitor the behaviour of individuals located in those territories.

This site is reachable worldwide, as any website is, but mere accessibility is not the same as targeting a market. If you contact us from outside the United States we will respond to your enquiry, and we handle that correspondence as described in this policy.

02Customer data inside the vault

If your organisation is a Battlement customer, the data you place inside your vault is a different matter entirely and this policy does not govern it.

For that data we act as a processor (service provider) on your instructions, under the data processing terms in your customer agreement. We do not access it for our own purposes, we do not use it to train models, and we do not use it to build profiles of anyone. Access is limited to the personnel your agreement designates and is recorded in the tamper-evident audit trail described in your deployment documentation.

If you are an individual whose data an organisation has placed inside a Battlement vault, that organisation is the controller. Please direct access, correction, and deletion requests to them; we will assist them in responding, but we cannot act on their data without their instruction.

03Information we collect

Information you give us

When you submit an enterprise assessment request, we collect the fields on that form: your full name, work email address, organisation, job title or role, organisation size, and any description of your requirements you choose to add. The description field is free text — please do not enter sensitive personal information, credentials, or confidential technical detail there.

We also collect whatever you send us when you email, call, or meet with our team, including the contents and attachments of that correspondence.

Information collected automatically

  • Server and connection data — IP address, user agent, approximate region derived from the IP, referring URL, the pages requested, and timestamps. Our hosting provider records this to serve the site and to detect abuse.
  • Device and display data — screen size and browser capabilities, used to render the page correctly.
  • Cookie data — see section 6. Only the strictly necessary category operates before you make a choice.

Campaign and referral parameters

If you arrive from an advertisement, an email, or a partner link, the URL may carry campaign parameters — utm_source, utm_medium, utm_campaign, utm_content, and a Google click identifier (gclid) — along with the address of the page you landed on. If you then submit the assessment form, those values are attached to your submission so we can tell which campaigns produce genuine enquiries.

Information from other sources

We may supplement an enquiry with business information from public sources and reputable business-data providers — company size, sector, and publicly listed role — to route it to the right solutions architect. We do not buy consumer marketing lists.

We do not knowingly collect special category data (health, biometrics, religious or political views, and similar), and we ask that you not send it to us. We do not use or disclose Sensitive Personal Information for purposes other than those specified under California Civil Code Section 1798.121(a).

04How we use information

  • To respond to your enquiry — reviewing your requirements, preparing an architecture or compliance briefing, and arranging the follow-up our team promises within one business day.
  • To provide and administer our services — contracting, onboarding, support, billing, and the account relationship.
  • To secure our systems — detecting and investigating abuse, fraud, credential-stuffing, and other threats to the site and our infrastructure.
  • To meet legal and regulatory obligations — including export-control, sanctions, and record-keeping requirements applicable to the infrastructure we operate.
  • To measure and improve the site — understanding which material is read and which campaigns bring qualified enquiries. Where this requires non-essential cookies, it happens only with your consent.
  • To send relevant business communications — occasional updates about capabilities, compliance, and research, where you have asked for them or where permitted for existing business contacts. Every message carries an unsubscribe link.

We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not use website visitor data to train models.

05Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on the following bases:

PurposeLegal basis
Responding to an assessment requestSteps taken at your request prior to entering a contract (Art. 6(1)(b))
Providing and administering servicesPerformance of a contract (Art. 6(1)(b))
Security, abuse prevention, and site integrityLegitimate interests in protecting our systems and users (Art. 6(1)(f))
Business-to-business relationship management and campaign attributionLegitimate interests in operating and understanding our business (Art. 6(1)(f))
Non-essential cookies and marketing emailConsent (Art. 6(1)(a)), withdrawable at any time
Legal, regulatory, and export-control obligationsCompliance with a legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You may object to that processing — see section 11.

06Cookies and similar technologies

A cookie is a small file a site stores in your browser. We use as few as we can, in three categories:

Cookie categories used on this site.
Category Purpose Set before consent?
Strictly necessary Serving the site, protecting form submissions against abuse, load balancing, and remembering the cookie choice you make here. Yes — the site cannot function without them, and no consent is required
Analytics Aggregate measurement of which pages are read, how long they hold attention, and how visitors arrive. Used to improve the site, never to identify you. No
Marketing Connecting an enquiry to the campaign that prompted it, and enabling content embedded from third parties. No

Your choice

On your first visit we ask you to accept or deny non-essential cookies. Nothing in the analytics or marketing categories loads until you accept — denying is a single click, exactly as prominent as accepting, and denying does not degrade the site.

Your choice is stored in a strictly necessary cookie named bs_consent for six months, after which we ask again. You can change or withdraw it at any time:

Browser and platform controls

Every major browser lets you block or delete cookies in its settings. Blocking strictly necessary cookies may stop parts of the site working.

Global Privacy Control

If your browser sends a Global Privacy Control (GPC) signal — or a “Do Not Track” header — our site reads it and treats it as a denial. Analytics and marketing cookies are switched off automatically, the choice is recorded as though you had clicked Deny, and we do not show you a banner asking a question your browser has already answered. This is automatic and requires nothing from you.

You can override it: open the and switch a category on. A choice you make there is an explicit one, so it takes precedence over the signal until you change it again.

Separately, because we do not sell or share personal information for cross-context behavioural advertising, there is no sale or sharing for GPC to opt you out of in the first place — see how we share information.

Embedded content

Our white paper is embedded from Gamma, and that embed loads from Gamma's servers when the page renders it. Our explainer video is served from our own infrastructure, so watching it involves no third-party player or tracking. Web fonts used by our diagrams are requested from Google Fonts, which receives the requesting IP address as part of serving the file. Both providers are listed in how we share information.

07How we share information

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.

We disclose personal information only as follows:

Service providers

Vendors who process information on our behalf, under contract, for the purposes we specify and nothing else:

ProviderFunctionData involved
WebflowWebsite hosting and deliveryServer and connection data
HubSpotCustomer relationship managementAssessment form submissions, correspondence, campaign parameters
SalesforceCustomer relationship management (secondary route)Assessment form submissions
GammaHosting of the embedded white paperConnection data of readers who load the embed
Google FontsWeb font deliveryConnection data of visitors requesting a font file

Professional advisers

Lawyers, auditors, insurers, and accountants, bound by professional confidentiality obligations.

Legal and safety

Where we are required to by law, or where disclosure is necessary to establish or defend legal claims, to enforce our agreements, or to protect the rights and safety of our people, customers, or the public. Where a government or law-enforcement request reaches us, we require valid legal process, disclose the narrowest set of information that satisfies it, and notify the affected customer unless legally prohibited.

Corporate transactions

In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections. If personal information transfers to a different controller as a result, we will give notice before this policy stops applying to it.

08Data residency and transfers

Battlement operates within United States jurisdiction. Our production infrastructure and customer data reside in the United States, in facilities designated in the applicable customer agreement — currently Holmdel, New Jersey.

Website and business-contact information described in this policy is likewise processed in the United States. If you contact us from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) together with supplementary technical measures including encryption in transit and at rest. You can request a copy of the relevant transfer mechanism using the contact details in section 15.

09How long we keep information

InformationRetention
Assessment requests that do not become customers24 months from the last substantive contact
Customer contact and relationship recordsDuration of the relationship, then 7 years for contractual and tax records
Correspondence24 months, unless it forms part of a contract record
Server and security logs12 months, or longer where an active investigation requires it
Cookie consent record6 months, then we ask again
Marketing suppression listIndefinitely, and limited to the minimum needed to recognise you — an email address and the date you opted out, nothing else

When a period ends we delete the information or irreversibly de-identify it. Where a legal hold or regulatory obligation requires a longer period, that period governs.

The suppression list is the one entry that runs indefinitely, and it does so in order to comply with the US CAN-SPAM Act (15 U.S.C. § 7704(a)(4)) and Article 21 of the GDPR: both require that an opt-out be honoured on an ongoing basis, which is impossible if we forget who opted out. Keeping that minimal record is what stops you being re-added to a list you already left. It is never used to contact you, and you can ask us to erase it — though doing so removes the very thing preventing future messages.

10How we protect information

Security is the product, and we hold our own corporate systems to the standard we sell. Measures include encryption in transit (TLS 1.3) and at rest (AES-256-GCM), hardware-backed multi-factor authentication for staff, least-privilege and role-based access control, short-lived credentials, network segmentation, tamper-evident audit logging, background-checked personnel, vendor security review, and an incident response process with defined escalation.

Our infrastructure is assessed against SOC 2 Type II and ISO 27001 control frameworks with independent third-party audits.

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant supervisory authorities within the timeframes the law requires.

11Your privacy rights

Depending on where you live, you may have some or all of the following rights over the personal information we hold as a controller:

  • Access — a copy of the information we hold about you, and confirmation of how we use it.
  • Correction — to have inaccurate or incomplete information fixed.
  • Deletion — to have information erased, where no legal basis requires us to keep it.
  • Portability — to receive information you gave us in a structured, machine-readable format.
  • Restriction and objection — to limit processing, or object to processing based on legitimate interests. An objection to direct marketing is always honoured.
  • Withdrawal of consent — at any time, without affecting processing that already happened. For cookies, open the .
  • Non-discrimination — we will not deny you service, charge a different price, or provide a lesser standard because you exercised a privacy right.
  • Opt out of sale, sharing, or targeted advertisingwe do none of these, so there is nothing to opt out of. If that ever changes, we will update this policy and provide the mechanism before doing so.

How to exercise a right

Email privacy@battlementsystems.com and tell us which right you want to exercise. We will verify your identity in proportion to the sensitivity of the request — usually by confirming control of the email address on record, and for higher-risk requests by asking for additional matching information. We do not create accounts for the purpose of verification.

We respond within 30 days, or within 45 days where a US state law permits and the request is complex, in which case we will tell you before the first period expires. There is no charge unless a request is manifestly unfounded or excessive.

An authorised agent may submit a request on your behalf with written permission signed by you; we may contact you directly to confirm it.

If you are not satisfied

Contact us first and we will try to resolve it. You also have the right to appeal a refusal — reply to our decision with the word “appeal” and a different reviewer will consider it within 45 days. Beyond that, you may complain to your supervisory authority: in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office; in California, the California Privacy Protection Agency or the California Attorney General; and in other US states, your state Attorney General.

12Children

This is a business-to-business service. The site is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

13Region-specific disclosures

California, and other US state privacy laws

For residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws:

  • The categories of personal information we collect, the purposes, the sources, and the categories of recipients are described in sections 3, 4, and 7. In CCPA terms these are identifiers, professional or employment-related information, commercial information, and internet or network activity.
  • We do not collect or process Sensitive Personal Information for the purpose of inferring characteristics. We do not use or disclose Sensitive Personal Information for purposes other than those specified under California Civil Code Section 1798.121(a). Because our use falls entirely within those permitted purposes, the right to limit its use does not arise — but if that ever changes we will publish a “Limit the Use of My Sensitive Personal Information” control before it does.
  • We have not sold or shared personal information, and have not disclosed it for cross-context behavioural advertising, in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 16.
  • We disclose personal information to service providers for the business purposes listed in section 7.
  • Rights of access, correction, deletion, portability, and non-discrimination are exercised as described in section 11.

EEA, UK, and Switzerland

As set out in section 1, we offer our services exclusively to organisations established in the United States. We do not target the EEA or UK market and we do not monitor behaviour there, so Article 3(2) of the GDPR and UK GDPR does not extend to our processing, and we have accordingly not designated a representative under Article 27.

Where we do hold personal information about someone in the EEA, the UK, or Switzerland — because they contacted us, or because they are a contact at a US customer — we handle it on the legal bases in section 5, with the transfer safeguards in section 8, and we will honour the rights in section 11 on request regardless of whether we are strictly required to.

We have not appointed a statutory Data Protection Officer; privacy questions are handled by the contact in section 15.

Export controls

Our services are subject to US export control and sanctions law, including ITAR where applicable. We may process identity and organisation information for screening purposes as those regimes require.

14Changes to this policy

We update this policy when our practices or the law change. If a change materially affects how we use information you have already given us, we will give notice — by email to business contacts, or by a prominent notice on the site — before it takes effect, and where the law requires it we will ask for fresh consent.

Material changes also reset the cookie banner, so you will be asked to make your choice again.

15Contact us

For any question about this policy, or to exercise a privacy right:

Privacy enquiries
privacy@battlementsystems.com
Response within 30 days
Postal address
Battlement Systems, LLC
101 Crawfords Corner Rd, Suite 4-116
Bell Works Building
Holmdel, NJ 07733
United States