Privacy Policy

How aissurance handles your personal data.

Privacy Policy

Last updated: June 2026

aissurance is committed to protecting your personal data in compliance with the GDPR and the EU AI Act.

Data We Collect

  • Account data: Name, email, company name, role
  • AI system data: Model metadata, endpoint configurations, risk classifications
  • Evidence data: Uploaded files, text evidence, verification records
  • Usage data: API access logs, feature usage metrics

How We Use Your Data

  • Providing compliance classification services
  • Generating regulatory documents
  • Maintaining encrypted evidence storage
  • Platform operation and security

Data Encryption

All tenant data is encrypted using hierarchical envelope encryption (Master Key → Tenant Key → Data Encryption Key). Data at rest is stored on local POSIX filesystems. We cannot read your encrypted data without your tenant key.

Data Retention

  • Active account data: Retained for the duration of your subscription
  • Post-withdrawal retention: 10 years for compliance evidence (as required by EU AI Act)
  • Audit logs: Retained for regulatory proof

Your Rights

Under GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data (via crypto-shredding)
  • Port your data (JSON/CSV export)
  • Object to processing

Crypto-Shredding

Upon account deletion, we destroy your tenant encryption key, making all stored data permanently unreadable. This satisfies GDPR Article 17 (right to erasure).

Contact

For privacy inquiries: info@aissurance.eu