Enaloris · Legal
Privacy Policy
Effective date: September 20, 2026 · Last updated: September 20, 2026
This Privacy Policy describes how Enaloris LLC (“Enaloris,” “we,” “us,” or “our”), a Colorado limited liability company based in Denver, Colorado, United States, treats information in connection with the public website at https://enaloris.com/ (the “Site”).
The Site is a company card: it explains who we are, the kind of software work we do, and selected products we develop, including aioral.ru and aioraly.com. The Site does not include a contact form, a checkout, an account login for the public, or a newsletter signup. We designed it that way on purpose. This Policy is written to match that design, not a generic shop or SaaS dashboard.
By using the Site you acknowledge this Policy. If you do not agree, do not use the Site. Product-specific privacy practices for Aioral properties are governed by those properties’ own notices when you visit them.
1. Who is responsible
Enaloris LLC is the operator of the Site. We are located in Denver, Colorado, USA. The Site is hosted on infrastructure provided by a commercial hosting provider (currently Hostinger). We do not operate a public inbox on this Site. Correspondence about this Policy may be sent by postal mail addressed to Enaloris LLC, Denver, Colorado, United States, with the subject “Privacy.”
This Policy covers only the Site. It does not automatically cover every system we design or operate for a client, and it does not replace the privacy notice of aioral.ru or aioraly.com.
2. What this Site is — and is not
The Site publishes informational pages: a landing page, this Privacy Policy, Terms of Use, and an Accessibility statement. It is not a marketplace, not a patient or customer portal, and not a place where we ask you to create a profile.
- We do not run a public contact form on the Site.
- We do not ask you to register an account to read the Site.
- We do not sell goods through the Site.
- We do not display a public email address or telephone number on the Site.
- Outbound links to aioral.ru and aioraly.com leave this Site. Those destinations have their own operators’ pages, cookies, and notices.
If you never submit information to us, the only data we are likely to see is the technical data that any website receives when a browser requests a page.
3. Information we may process
3.1 Information you choose to send
Because the Site has no form, we do not collect names, emails, phone numbers, or messages through on-page fields. If you still write to us by postal mail, we will process whatever you put in that letter (for example your name, return address, and the content of the request) solely to understand and respond to it.
3.2 Information collected automatically
When your browser or an automated client requests a page, standard server and security logs may include:
- Internet Protocol (IP) address and approximate network location derived from it;
- date and time of the request, requested URL, referrer, and user-agent string;
- whether the response was served from cache;
- security events (for example repeated failed attempts to reach the WordPress login URL, which is not advertised on the Site).
This data is generated by the hosting stack, the content management system (WordPress), the page cache (LiteSpeed Cache), and security software (including Wordfence and Sucuri Scanner) that we run to keep the Site available and to reduce abuse. We do not use it to build a marketing profile of you.
3.3 Information we do not seek
We do not intentionally collect special categories of personal data (health, biometrics, precise geolocation, payment card numbers, Social Security numbers, or children’s data) through the Site. Do not send such information to us unsolicited.
4. Cookies, local storage, and similar technology
A cookie is a small file or similar identifier that a site may store in your browser. This Site uses a short list of technically necessary items. We do not run a cookie-consent banner that implies optional advertising cookies, because we do not operate advertising pixels or a marketing tag manager on the Site.
Depending on your browser and whether you are only reading pages or (if you are a site administrator) signing in, the following may appear:
- WordPress session cookies — used if someone authenticates to the administration area. Public visitors who never log in should not receive a WordPress logged-in cookie.
- Cache and performance cookies or headers — LiteSpeed and the CDN in front of the host may use cache keys so that anonymous pages can be served quickly. These are operational, not advertising identifiers.
- Security cookies — security plugins may set cookies to distinguish browsers during brute-force or firewall evaluation.
- Preference cookies — none are set by the public landing for language or marketing.
You can instruct your browser to refuse cookies. If you do, the public pages should still render. Administration of the Site may not work without cookies. Blocking cookies does not stop the server from seeing your IP address on each request.
We do not currently load Google Analytics, Meta Pixel, TikTok Pixel, or similar third-party advertising SDKs on the Site. If that changes, we will update this Policy before those tools go live.
5. How we use information
We use Site-related information only for:
- delivering the pages you request and keeping them cached;
- securing the Site (rate limiting, malware scanning, blocking abusive automation);
- diagnosing faults, measuring availability, and restoring from backup;
- complying with law, court order, or a valid legal process;
- establishing, exercising, or defending legal claims;
- responding to a written request you send us about this Policy.
We do not use Site logs to send you promotional email. We do not sell, rent, or barter personal information from the Site for money. We do not use the Site to make automated decisions that produce legal or similarly significant effects about you.
6. Legal bases (EEA, UK, and similar regimes)
If you access the Site from a jurisdiction that requires a “legal basis” for processing, we rely on:
- Legitimate interests — operating a public informational website, keeping it secure, and preventing fraud or abuse, in a way that does not override your interests;
- Legal obligation — where we must retain logs or disclose information because the law requires it;
- Consent — only if we later introduce an optional tool that actually needs consent (we do not currently);
- Contract — only if you later enter a separate written agreement with us; visiting the Site alone is not that contract.
7. Sharing
We share information only as needed to run the Site:
- Hosting and infrastructure — Hostinger and related content-delivery nodes process requests in order to serve HTML, CSS, images, and to apply cache and TLS;
- Security vendors — Wordfence, Sucuri, and similar scanners may receive technical telemetry that their products need to detect attacks;
- Backup processors — UpdraftPlus stores backups in a private directory on the same account, off the public webroot;
- Professional advisers and authorities — if we are legally required or if it is necessary to protect the Site, our rights, or the rights of others;
- Business transfer — if Enaloris LLC is involved in a merger, acquisition, or sale of assets, Site records would transfer under this Policy’s restrictions.
We do not share Site data with data brokers. We do not authorize third parties to serve interest-based ads on the Site.
When you follow a link to aioral.ru or aioraly.com, those sites may set their own cookies and collect their own data. Read their notices. Enaloris develops those products; this Policy still applies only to enaloris.com unless a product notice says otherwise.
8. Retention
Server and security logs are kept for a limited operational window — typically weeks to a few months — unless an incident, claim, or legal hold requires longer. Backups rotate on a fortnightly schedule with a small number of retained copies. Postal correspondence is kept as long as needed to handle the request and any related legal obligation, then securely destroyed. We do not keep a marketing list from this Site because the Site does not collect one.
9. Security
We apply layered controls that match a small public WordPress site: TLS in transit, a hidden administration URL, XML-RPC disabled for the public, REST user listing locked down, security scanners, file-edit disabled in the application, backups stored outside the webroot, and a single page cache (LiteSpeed) rather than stacked caches. No method of transmission or storage is perfectly secure. You use the Site at your own risk as to residual vulnerabilities.
Do not send passwords, payment data, or health information to us through unofficial channels. We will never ask you for a password to this Site by email.
10. International transfers
Enaloris is a United States company. The host may store or process data in the United States or in other regions where the host operates. If you visit from outside the United States, you understand that your technical data may be processed in the U.S., which may have different data-protection rules than your country. Where a transfer tool is required, we rely on the host’s published transfer mechanisms and on the fact that the Site is a publicly available informational resource.
11. Children
The Site is written for a professional audience. It is not directed at children under 16 (or under 13 where that is the relevant U.S. COPPA threshold). We do not knowingly collect personal information from children via the Site. If you believe a child has sent us personal information, write to us at the postal address in Section 1 and we will delete it when we can identify it.
12. Your choices and rights
Because the Site does not maintain customer accounts or marketing lists, many “access / delete my profile” workflows do not apply. You can still:
- stop using the Site;
- clear cookies and site data in your browser;
- use tracking-prevention or a VPN — noting that we still receive an IP address on each request;
- ask, by postal mail, whether we hold any correspondence or logs that identify you, and request deletion or correction where the law gives you that right and we can locate the records.
Depending on where you live, you may have rights under the EU/UK GDPR, the Colorado Privacy Act, the California Consumer Privacy Act (as amended by CPRA), or similar state laws. Those statutes often apply only when a business meets revenue, volume, or “sale/share” thresholds. We do not sell personal information as those laws define a sale. We do not share personal information for cross-context behavioral advertising. If a rights request is made and the law applies to us, we will not discriminate against you for exercising it.
Authorized agents may submit a request if they provide proof of authority that we can reasonably verify. We may need enough information to confirm you are who you say you are; we will not collect extra data beyond that need.
Colorado residents may also contact the Colorado Attorney General with a complaint. California residents may contact the California Privacy Protection Agency or the California Attorney General. EEA/UK residents may lodge a complaint with their local supervisory authority. We would rather hear from you first.
13. Do Not Track and global privacy controls
The Site does not change its behavior in response to a browser’s “Do Not Track” signal, because we do not run third-party ad tracking on the Site. A Global Privacy Control signal, if present, is consistent with our practice of not selling or sharing personal information for advertising.
14. Third-party pages and embedded content
The Site may link to third-party websites. We are not responsible for their content, cookies, or policies. Opening aioral.ru or aioraly.com is a navigation to a different property. Do not assume this Policy travels with you.
We do not embed third-party comment widgets, maps that phone home with your location, or social share buttons that load tracker scripts on the landing page.
15. Automated access
Search engines and other bona fide crawlers may fetch public pages, including robots.txt, sitemap_index.xml, and llms.txt. Aggressive scraping, credential stuffing, or attempts to reach non-public administration endpoints are abuse. We may block IP addresses or user-agents engaged in that activity and may retain related logs longer than ordinary traffic logs.
16. Changes
We may update this Policy when the Site, our vendors, or the law changes. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of the Site after an update means you accept the revised Policy. If we ever introduce a contact form, analytics, or advertising cookies, that is a material change and this Policy will be revised before those features go live.
17. No additional contracts
This Policy explains privacy practices for a public website. It is not a master services agreement, a business-associate agreement, a data-processing agreement, or a promise that any particular product we develop will process personal data in a stated way. Those terms, if any, are written in a separate contract.
18. Contact
Enaloris LLC
Denver, Colorado
United States of America
This Site does not publish an email address and does not host a contact form. For privacy questions about enaloris.com, send postal mail to the company at the city above, marked “Privacy.” For questions about Aioral products, use the notices on aioral.ru or aioraly.com as applicable.