Privacy Policy
Last updated: June 2026
aissurance is committed to protecting your personal data in compliance with the GDPR and the EU AI Act.
Data We Collect
- Account data: Name, email, company name, role
- AI system data: Model metadata, endpoint configurations, risk classifications
- Evidence data: Uploaded files, text evidence, verification records
- Usage data: API access logs, feature usage metrics
How We Use Your Data
- Providing compliance classification services
- Generating regulatory documents
- Maintaining encrypted evidence storage
- Platform operation and security
Data Encryption
All tenant data is encrypted using hierarchical envelope encryption (Master Key → Tenant Key → Data Encryption Key). Data at rest is stored on local POSIX filesystems. We cannot read your encrypted data without your tenant key.
Data Retention
- Active account data: Retained for the duration of your subscription
- Post-withdrawal retention: 10 years for compliance evidence (as required by EU AI Act)
- Audit logs: Retained for regulatory proof
Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (via crypto-shredding)
- Port your data (JSON/CSV export)
- Object to processing
Crypto-Shredding
Upon account deletion, we destroy your tenant encryption key, making all stored data permanently unreadable. This satisfies GDPR Article 17 (right to erasure).
Contact
For privacy inquiries: info@aissurance.eu