Privacy Policy
Last updated: October 9, 2026 · Company opened: October 1, 2026
1. Scope and responsibility
This Privacy Policy explains how Corten Mechanism handles personal information in connection with its website, business communications and AI automation services. It applies to people who visit the website, contact the company, request a proposal or participate in a client project. Corten Mechanism began operating on October 1, 2026. This policy was last updated on October 9, 2026.
The website introduces services and packages. It does not require a visitor account, collect payment-card information through the project form or provide an automated checkout for automation projects. A separate written agreement defines the scope of any paid engagement.
2. Information you provide
If you contact us directly, we may receive your name, business email address, company name, telephone number, chosen service, descriptions of business processes and the contents of your correspondence. During a project, you may also provide workflow specifications, sample records, integration requirements, account-access instructions and other information necessary to perform the agreed work.
Please provide only information relevant to the enquiry or project. Do not place passwords, API keys, payment-card numbers, government identification numbers, medical information or other sensitive records in the website form. Any project requiring access credentials or sensitive business data must use a separately agreed method and appropriate access controls.
3. How the website form works
The project form in this website implementation validates entries and displays an acknowledgement and a reference code inside your browser. The form does not transmit its entries to Corten Mechanism, create a server-side enquiry record, send an email or save the entries in browser local storage. The reference code is generated locally and is not a server receipt or evidence of delivery.
After the local acknowledgement appears, the form fields are cleared. Information typed before completion remains in the visible form until you clear it, complete the local interaction or leave the page. To communicate an enquiry to the company, use the contact details at the end of this policy through your own communication service. Information sent that way is handled as direct correspondence.
4. Hosting and technical information
The website is intended to run on Shopify. Hosting, content delivery, security and platform functions may involve technical information such as an IP address, browser type, device information, request time and requested resources. The platform and any installed store applications control their own technical processing.
The supplied custom sections do not include analytics pixels, advertising trackers, customer profiling scripts or a newsletter subscription service. Typography is loaded from Google Fonts, which involves requests to a third-party font service. The supplied images are intended to be uploaded to Shopify and served through its content-delivery infrastructure. Store-owner additions may change these practices and require a corresponding policy update.
5. Purposes of processing
We use information received through direct communications to understand requests, prepare proposals, arrange project discussions, provide agreed services, support delivered workflows and maintain appropriate business records. We may also use relevant information to handle complaints, resolve disputes, prevent misuse and meet applicable legal obligations.
Where a legal basis is required, the relevant basis may include taking requested steps before a contract, performing a contract, complying with legal obligations or pursuing legitimate business interests that are balanced against individual rights. When a particular activity requires consent, that activity should occur only after the necessary consent is obtained. Contacting us does not automatically enrol you in marketing.
6. Client data and AI services
Some projects involve configuring tools that process a client's customer, lead, employee or operational data. The client remains responsible for deciding what data its workflow may use and for having the authority and notices necessary for that use. Our role, instructions and responsibilities for project data must be defined in the project agreement and, where appropriate, a data-processing agreement.
An integration may send selected information to an AI provider, CRM, automation platform or another service chosen for the project. Provider retention, training settings, access controls and processing locations should be reviewed before production use. This policy does not claim that every AI provider uses the same settings or that client data is automatically excluded from provider training.
7. Sharing and retention
Information may be shared with service providers where needed for agreed communication, project delivery, administration, professional advice or security. We may also disclose information when required by law or reasonably necessary to protect rights and address misuse. We do not include a data-sale or advertising-audience programme in the supplied website.
We retain direct correspondence and project records for periods appropriate to the purpose, contractual obligations, accounting requirements and potential disputes. There is no single retention period suitable for every record. Data that is no longer needed should be deleted, returned or appropriately minimised, subject to obligations to retain specific records.
8. Security, location and individual requests
Security measures should reflect the nature of the information and the project, including limited access, appropriate authentication and careful handling of credentials. No website, email service or connected platform can guarantee absolute security. A suspected security incident should be reported promptly using the contact details below.
Information may be processed in the United States and in other locations used by the relevant service providers. Where applicable law requires a transfer mechanism or additional safeguards, these must be addressed for the particular processing. Depending on the law that applies, you may request access, correction, deletion, restriction, portability or withdrawal of consent. We may need to verify your identity and may retain information where a lawful exception applies.
9. Children, external services and changes
The services are intended for business users and are not directed to children under 13. We do not seek children's information through the project form. If you believe a child's information has been provided through direct correspondence, contact us so the matter can be reviewed.
This policy does not control websites, applications or services operated by third parties. A material change to the website's actual collection or use of information should be reflected in an updated policy and, where required, an appropriate notice or consent process. The update date at the top identifies the current version.
Email: projects@cortenmechanism.com
Address: 726 Harvard Dr, Owensboro, KY 42301
Phone: +16067771098
