Privacy Policy
Last updated 20 September 2026 · Applies to optimus-gen3order.us
Who we are and what this policy covers
This Privacy Policy explains how Optimus Robotics ("we", "us", "our") handles personal information collected through the website optimus-gen3order.us and through the reservation and enquiry forms published on it. Optimus Robotics is the controller of that information.
It does not cover third-party websites that we link to, nor the separate contractual arrangements that apply once you become a customer. Those arrangements are set out in the agreement signed at that time, and where they conflict with this policy in respect of customer data, the signed agreement prevails.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
Information we collect
We collect only what we need in order to answer an enquiry and prepare a quotation. There are three categories.
Information you give us directly
- Your name and work email address.
- The organisation you represent and the country of intended deployment.
- The configuration you selected, the number of units you are considering, and your target allocation window.
- Anything you choose to write in the free-text notes field.
- Your consent choices, including whether you opted in to the quarterly programme update.
The reservation form does not ask for a telephone number, a postal address or any payment details, and you should not enter them. If you include such details in the free-text field we will remove them from our records unless they are necessary to answer your question.
Information collected automatically
- Standard server log data: IP address, browser user agent, referring page, and the date and time of the request.
- The single consent preference stored in your browser, described in the Cookie Policy.
Information we do not collect
- Special category data such as health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation.
- Government identifiers, financial account numbers or payment card data.
- Information about children. This site is directed at organisations and is not intended for anyone under 18.
Why we use your information and our legal basis
Where the EU or UK General Data Protection Regulation applies, we rely on the legal bases set out below.
| Purpose | Information used | Legal basis |
|---|---|---|
| Responding to a reservation request and issuing a written quotation | Name, email, organisation, country, configuration, notes | Steps taken at your request prior to entering a contract |
| Answering a general enquiry | Name, email, message content | Legitimate interests — responding to people who contact us |
| Sending the quarterly programme update | Name, email | Consent, withdrawable at any time |
| Keeping the site secure and preventing abuse | Server log data | Legitimate interests — network and information security |
| Meeting legal, tax and accounting obligations | Enquiry and transaction records | Compliance with a legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating and protecting the site does not override your rights and freedoms. You may object to that processing at any time using the contact address at the foot of this page.
How long we keep it
- Enquiries that do not become a quotation — 12 months from the last message exchanged, then deleted.
- Reservation requests that lead to a quotation — 24 months from the date of the quotation, unless a contract is signed, in which case the retention period in that contract applies.
- Marketing consent records — for as long as you remain subscribed, plus 24 months so that we can evidence the consent.
- Server logs — 90 days.
- Records required for tax or accounting purposes — for the period required by the applicable law, typically six to seven years.
At the end of a retention period, records are deleted or irreversibly anonymised. Anonymised aggregate statistics may be kept indefinitely because they no longer identify anyone.
Who we share it with
We share personal information only where it is necessary, and only with the following categories of recipient.
- Hosting and email providers that operate the infrastructure this site and our correspondence run on, acting as processors under written instructions.
- Professional advisers such as lawyers, auditors and insurers, where they need the information to advise us.
- Authorities, where we are required to disclose information by law, court order or a valid regulatory request. Where we are lawfully permitted to tell you about such a request, we will.
- A successor entity, if the business or the relevant part of it is reorganised, merged or acquired. You would be notified before your information became subject to a different policy.
Our processors are bound by contract to process personal information only on our instructions, to keep it confidential, and to apply appropriate technical and organisational security measures.
International transfers
Our infrastructure providers may process data in the United States and in the European Economic Area. Where personal information is transferred out of the EEA or the United Kingdom, we rely on one of the following safeguards:
- An adequacy decision issued by the European Commission or the UK government covering the destination country.
- The European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer is from the United Kingdom.
- A transfer risk assessment, with supplementary measures such as encryption in transit and at rest where the assessment indicates they are needed.
You may request a copy of the relevant safeguard by writing to us. We will provide it with commercially confidential terms redacted.
Your rights
Subject to the law that applies to you, you have the following rights. Exercising them is free of charge, and we will not treat you differently for doing so.
- Access — a copy of the personal information we hold about you.
- Rectification — correction of information that is inaccurate or incomplete.
- Erasure — deletion where we no longer have a lawful reason to keep it.
- Restriction — a pause on processing while a dispute about accuracy or legal basis is resolved.
- Portability — a machine-readable copy of information you gave us, where processing is based on consent or contract.
- Objection — to processing based on legitimate interests, and at any time to direct marketing.
- Withdrawal of consent — at any time, without affecting processing already carried out.
If you are a California resident
Under the California Consumer Privacy Act as amended, you may request disclosure of the categories and specific pieces of personal information collected, the categories of sources, the business purpose, and the categories of third parties to whom it was disclosed. You may request deletion and correction, and you may direct us not to sell or share your personal information. We do not sell or share personal information as those terms are defined by that Act, and we do not use or disclose sensitive personal information for purposes that would require an opt-out. You may use an authorised agent, and we will verify the request through the email address on file.
How to make a request
Write to [email protected] from the address you used to contact us, and state which right you wish to exercise. We respond within 30 days, or within 45 days where the CCPA applies, and we will tell you if we need an extension and why. If we cannot verify your identity from the information available, we will ask for additional confirmation before acting.
Security
We apply technical and organisational measures proportionate to the information involved, including encryption of data in transit over TLS, encryption at rest for stored records, access control on a need-to-know basis, multi-factor authentication for administrative accounts, and periodic review of who holds access.
No method of transmission or storage is completely secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will notify you directly where the law requires it.
Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects on the basis of automated processing alone, and we do not carry out profiling for that purpose. Quotations are prepared and reviewed by a person.
Complaints
If you are dissatisfied with how we have handled your personal information, please raise it with us first — most concerns are resolved quickly. You also have the right to lodge a complaint with a supervisory authority in the country where you live or work, or where you believe the issue occurred. Complaining to us first is not a precondition of exercising that right.
Changes to this policy
If we make a material change to this policy, we will update the date at the top of the page and, where the change affects how we use information you have already given us, we will contact you directly at the email address we hold. Earlier versions are retained and available on request.
Questions about this document?
Write to [email protected]. We answer written enquiries within five business days. Please include the name of this document and the section number you are asking about.