← Back to Home
Effective Date: September 2026 • Document Version: 1.1
LEGAL // PRIVACY & COOKIE COMPLIANCE

Privacy Policy & Cookie Disclosure

Transparent disclosure of technical data processing, storage, and privacy practices for the antivirus.airageo.com website and the Aira Antivirus WordPress plugin.

SCOPE 01 // WEBSITE PRIVACY & COOKIES

Scope 1: Website (antivirus.airageo.com)

This scope applies exclusively to visits and interactions with the website at antivirus.airageo.com.

1. Server Technical Logging

When connecting to this website, standard technical HTTP request metadata is processed by the hosting web server infrastructure as necessary to deliver requested resources and maintain basic connection integrity.

Technical connection processing is operated directly by the hosting environment under its standard operational configurations. The site does not perform user profiling, behavioral analysis, or marketing tracking based on server logs.

2. Cookies & Client-Side Storage Audit

We strictly adhere to the EU ePrivacy Directive (Directive 2002/58/EC as amended, Art. 5(3)) and data minimization principles:

  • HTTP Cookies: This website sets and reads ZERO (0) cookies. No session cookies, persistent cookies, or third-party cookies are created.
  • Client Storage (localStorage): We use a single persistent client-side entry: aira_antivirus_lang (values: "en" or "ru"). Purpose: remembering your chosen interface language. This storage is strictly functional and technical, is never transmitted to external servers, and is exempt from consent requirements under ePrivacy Art. 5(3) as strictly necessary to deliver a service explicitly chosen by the user.
  • Cookie Consent Banner: Because this site uses zero cookies and zero non-essential storage or trackers, displaying a cookie consent banner is neither legally required nor appropriate under ePrivacy and GDPR rules.

3. Zero Third-Party Trackers & Self-Hosted Assets

The website contains no Google Analytics, no Meta/Facebook Pixel, no tag managers, no social embeds, and no telemetry beacons. All font assets (Plus Jakarta Sans and JetBrains Mono) are self-hosted directly on our server in WOFF2 format. No requests or IP addresses are transmitted to Google Fonts or third-party CDNs.

4. Direct Downloads & No Data Collection Forms

There are no registration forms, contact forms, or newsletter subscriptions on this website. The plugin download link provides a direct static ZIP archive (aira-antivirus.zip) without requiring email capture, account creation, or payment credentials.

SCOPE 02 // SOFTWARE & AI GATEWAY

Scope 2: Aira Antivirus WordPress Plugin & AI Gateway

This scope details data handling during operation of the Aira Antivirus WordPress plugin and its advisory AI Gateway queries.

1. Local Server-Side Triage

Core inspection routines run locally on your WordPress host server. File scanning evaluates file integrity on-server without uploading your site file tree.

2. AI Request Architecture & Data Boundaries

When local analysis flags an ambiguous or suspicious finding requiring AI advisory evaluation, an API request is transmitted to the Aira AI Gateway. The transmitted request strictly contains:

  • Whitelisted finding context: detection rule identifier, finding category, relative file path, and relevant line numbers.
  • Maximum 8,192 bytes of the relevant file: a bounded slice extracted from the flagged file (capped at 8,192 bytes).
  • Provisioning & auth metadata: origin site URL, installation ID, authentication token, request timestamp, and origin IP.

3. Full-Site Content & Database Exclusion

Full-site content and the website database are not uploaded in the AI request. The plugin does not transmit WordPress SQL tables (users, passwords, customer orders, posts) or full site archives to the AI Gateway.

4. Notice on User Code Content

User code potentially may itself contain personal data or secrets (e.g. hardcoded API keys, internal credentials, personal names, or developer comments present inside the inspected file). If such data exists within the bounded 8,192-byte file slice, it will be included in the AI request payload. Automatic exclusion of embedded personal data within user-authored executable code is not guaranteed.

COMPLIANCE // GDPR TRANSPARENCY

GDPR Transparency Framework

Summary of processing purposes, legal bases, retention criteria, and data subject rights under Regulation (EU) 2016/679 (GDPR).

Project & Privacy Contact
Aira Antivirus is an independent project developed within the airageo.com ecosystem. For privacy inquiries and data-related requests, please use the official contact channel at airageo.com.
Purposes & Processing Scope
1) Functional interface language persistence via client localStorage (strictly necessary functional storage).
2) Technical web server connectivity for resource delivery.
3) Advisory threat analysis of submitted bounded code snippets (maximum 8,192 bytes) for plugin users.
Processors & Infrastructure
Hosting infrastructure providers (server execution); cloud AI inference providers (OpenAI API under API zero-data-retention terms for threat triage). Fonts and frontend assets are strictly self-hosted.
Retention Periods
Language setting: stored client-side in browser localStorage until cleared by user. Server technical logging: subject to hosting infrastructure operational policies. AI Gateway requests: transient processing during request execution.
Your Rights (Articles 15–22 GDPR)
You have the right to request access to, rectification of, or erasure of your personal data, restriction of processing, and the right to object to processing based on legitimate interests. Contact: airageo.com.
Right to Lodge a Complaint
Under Article 77 GDPR, you have the right to lodge a complaint with an EU/EEA supervisory authority in your country of residence if you consider that processing of personal data infringes GDPR.