Sign InRequest Access

Privacy Policy

Effective: 23 May 2026 Version: 1.0 Applies to: aiia.run and the AIIA platform


AIIA orchestrates councils of specialised AI agents to produce institutional-grade analysis. Because that work involves processing documents and decisions that matter, we take the handling of personal data seriously. This policy explains, in plain terms, what we collect, why, on what legal basis, who we share it with, and the rights you can exercise.

It is written to comply with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the German Federal Data Protection Act (BDSG), the German Digitale-Dienste-Gesetz (DDG), and the relevant transparency obligations of the EU AI Act (Regulation (EU) 2024/1689).


1. Controller and contact

The controller responsible for the processing of personal data described in this policy, within the meaning of Art. 4(7) GDPR, is:

AIIA UG (haftungsbeschränkt) Kellinghusenstraße 8 20249 Hamburg Germany

Represented by the managing director: Alwin Brehde Registered with the Amtsgericht Hamburg, HRB 199065 VAT identification number (USt-IdNr.): A VAT identification number has not yet been issued.

Email: privacy@aiia.run General contact: hello@aiia.run Telephone: +49 40 35770823 Web: https://aiia.run

A formal Data Protection Officer (Datenschutzbeauftragter) has not been appointed because the statutory thresholds in § 38 BDSG are not met. Privacy enquiries are handled by the managing director directly via the address above.


2. Scope of this policy

This policy covers:

  • visitors to the public website at aiia.run and its sub-domains;
  • individuals who contact us, request a demo, or sign up for updates;
  • users with accounts on the AIIA platform, and personnel of customer organisations who are granted access;
  • third parties whose personal data is contained in documents or queries that customers submit to the platform.

It does not cover processing carried out by third parties on their own behalf — for example, when you follow a link to an external website. Where AIIA acts as a processor on behalf of a customer organisation (rather than as a controller), the customer's own privacy notice and the Data Processing Agreement (DPA) between us govern; the present policy then operates as a general transparency document.


3. What we collect, and when

3.1 When you visit the website

Each request to our web servers generates a short-lived technical log entry containing IP address, request timestamp, requested URL, referrer URL (if any), HTTP status code, transferred byte count, and User-Agent string. These logs are retained for up to 14 days for operations, security, and abuse defence, then deleted or aggregated into anonymised counters.

3.2 When you contact us, request a demo, or sign up for updates

We process the contact details you provide (typically name, work email, company, role) and the content of your message. If you book a demo via a scheduling tool, that tool's own data handling additionally applies (see Section 7).

3.3 When you create or use a platform account

Account authentication is handled by our identity provider, Clerk (see Section 7). Depending on the sign-in method, we receive: email address, name, profile image, organisation, role, the unique account identifier, authentication metadata (session timestamps, IP address at sign-in, device and user-agent), and security signals such as failed sign-in attempts.

Within the platform we store: workspace and organisation details; analysis configurations and run metadata; cost and usage data per analysis run; saved outputs and exports; preferences; audit trail entries (who did what, when).

3.4 Content you submit to the platform

To produce an analysis, you submit a query and, optionally, documents (PDFs, spreadsheets, text). These inputs may contain personal data — names of executives, deal counterparties, employees, customers, beneficial owners, advisors, and so on. We treat the entirety of submitted content as confidential customer data. See Section 6 for how it flows through the AI council.

3.5 Outputs and derived data

The analyses produced by AIIA (reports, structured artefacts, Glass Box transparency traces, cost breakdowns, per-model attributions) are stored against your account so that you can retrieve, export, and audit them. They may contain personal data drawn from your inputs and from publicly available research conducted by the platform.

3.6 Telemetry and error data

To keep the platform reliable, we collect application telemetry and error reports via Sentry (see Section 7). This includes stack traces, application state at the time of an error, request paths, user identifiers (where available), browser/OS identifiers, and breadcrumbs of preceding events. We configure Sentry to scrub common personal-data patterns from payloads at the SDK boundary, but residual personal data may still appear in error reports.

3.7 Communications

If you correspond with us by email, we retain the correspondence and the email headers for as long as needed to handle your matter and comply with retention obligations under German commercial and tax law (typically six to ten years for documents that qualify as commercial or tax-relevant records under § 257 HGB and § 147 AO).


4. Legal bases under Art. 6 GDPR

ProcessingLegal basis
Delivering the website, basic security logging, infrastructure operationsArt. 6(1)(f) GDPR — legitimate interest in operating and securing our services
Handling enquiries, demo requests, pre-contractual communicationsArt. 6(1)(b) GDPR — pre-contractual steps; Art. 6(1)(f) for general business communication
Account creation, authentication, providing the platform under a customer agreementArt. 6(1)(b) GDPR — performance of a contract
Processing customer content through the AI councilArt. 6(1)(b) GDPR and, where AIIA acts as processor, Art. 28 GDPR under the DPA
Billing, invoicing, accounting, statutory retentionArt. 6(1)(c) GDPR — legal obligation (HGB, AO, GwG where applicable)
Security monitoring, abuse defence, fraud prevention, error trackingArt. 6(1)(f) GDPR — legitimate interest in system integrity and availability
Improving and developing our services using aggregated, non-personal usage statisticsArt. 6(1)(f) GDPR — legitimate interest in service quality
Marketing emails or newsletters (if and when offered)Art. 6(1)(a) GDPR — consent; § 7(3) UWG for existing business contacts where its conditions are met
Establishing, exercising, or defending legal claimsArt. 6(1)(f) GDPR — legitimate interest in legal protection

Where we rely on legitimate interests, we have weighed those against the rights and freedoms of data subjects. You can object to processing on that basis at any time (see Section 13).


5. Purposes of processing

We process personal data only for purposes that are specified, explicit and legitimate:

  • providing the public website and the AIIA platform;
  • creating and managing user accounts and authenticating sessions;
  • running the analyses you request and delivering their outputs to you;
  • operating the multi-model AI council, including cross-examination, conflict detection, and Glass Box transparency artefacts;
  • billing, invoicing, accounting, and complying with German commercial and tax law;
  • communicating with you about your account, our services, and material changes to them;
  • monitoring service health, investigating incidents, and defending against abuse;
  • improving the platform via aggregated, non-personal usage metrics;
  • complying with applicable law and protecting our and your legal interests.

We do not sell personal data, we do not engage in cross-context behavioural advertising, and we do not use customer content to train AI models — neither our own (we operate no proprietary foundation model) nor those of our model providers, where their terms allow us to suppress training. See Section 6.


6. AI processing and your inputs

AIIA orchestrates a council of specialised AI agents across multiple model providers — currently Anthropic (Claude family), OpenAI (GPT family), Google (Gemini family), and Perplexity. A single analysis typically dispatches your inputs and our orchestration prompts to several of these providers in parallel and in sequence, including structured adversarial debate between agents.

6.1 What this means in practice

The content you submit and the intermediate reasoning produced by the council are transmitted to the model providers' APIs for the duration of an analysis. Each provider acts as our sub-processor under Art. 28 GDPR. We use the providers' enterprise API offerings (not consumer chat products), and we transmit data to API endpoints that are not used to train the providers' general models.

6.2 What we do not do

  • We do not use your inputs or outputs to train any model. We operate no proprietary foundation model.
  • We do not enable provider-side training opt-ins on enterprise endpoints, and our contracts with providers exclude such training in the configurations we use.
  • We do not share your inputs with other customers.
  • We do not use your inputs to enrich third-party marketing or advertising datasets.

6.3 Transparency under the EU AI Act

AIIA provides an AI system within the meaning of Regulation (EU) 2024/1689 ("EU AI Act") that incorporates third-party general-purpose AI models via enterprise APIs. In respect of the AIIA orchestration platform itself, AIIA may qualify as a provider of an AI system; in respect of the underlying third-party foundation models (Anthropic, OpenAI, Google, Perplexity), AIIA acts as a deployer and uses the model providers as sub-processors. AIIA does not develop or place general-purpose AI models on the market.

The platform produces analytical outputs, not legally binding recommendations. Outputs are labelled with the contributing models per decision (the Glass Box trace), and the platform is designed for human review: every output is intended as an input to a qualified human decision-maker, not a substitute for one. See also Section 12.

6.4 Research conducted by the platform

To answer some queries, the platform performs web research via Perplexity and other public sources. That research may surface personal data about identifiable third parties — for example, executives, deal participants, or board members of companies in scope. We process such data on the basis of legitimate interest (Art. 6(1)(f) GDPR) in producing the analysis you have requested, balanced against the limited and contextual nature of the data and its public origin.


7. Sub-processors and recipients

We engage the following categories of recipients and sub-processors. Each is bound to us by a written data processing agreement (DPA) under Art. 28 GDPR, by appropriate transfer safeguards where applicable, and by confidentiality obligations. A current, individually-named list is available to customers on request and is incorporated by reference into our DPA.

Sub-processorPurposeLocation of processingTransfer basis
Amazon Web Services EMEA SARLCloud hosting (compute, storage, database, cache, CDN)Frankfurt, Germany (eu-central-1)EU; AWS DPA + SCCs for any incidental US support access
Clerk, Inc.User authentication and session managementUnited StatesEU-US Data Privacy Framework; Standard Contractual Clauses (SCCs)
Anthropic, PBCAI model inference (Claude family)United StatesEU-US DPF; SCCs; enterprise API terms exclude training on inputs
OpenAI, L.L.C. / OpenAI Ireland LtdAI model inference (GPT family)United States; EU residency available for some endpointsEU-US DPF; SCCs; API DPA excludes training on inputs
Google LLCAI model inference (Gemini family)United States; certain endpoints may run in EU regionsEU-US DPF; SCCs
Perplexity AI, Inc.AI-mediated web research and retrievalUnited StatesEU-US DPF or SCCs as applicable
Functional Software, Inc. (Sentry)Application error tracking and performance monitoringUnited States (EU region available)EU-US DPF; SCCs; payload scrubbing configured at SDK
Temporal Technologies, Inc.Durable workflow orchestration of multi-step analysesUnited States or EU, depending on clusterEU-US DPF or EU residency; SCCs as applicable
GitHub, Inc.Source code and CI/CD; receives operational metadata only, not customer contentUnited StatesEU-US DPF; SCCs
Resend, Inc.Transactional email (waitlist notifications, applicant acknowledgements)United States (EU sending region in use)EU-US DPF; SCCs

Disclosure to authorities. We will disclose personal data to public authorities only where we are legally required to do so under EU or German law, and we will challenge requests that lack a clear legal basis. We do not voluntarily provide bulk access to customer data.


8. International data transfers

Our primary infrastructure (compute, storage, database) runs in the European Union, in AWS's Frankfurt region. However, several of the sub-processors listed in Section 7 are established in the United States, and processing therefore involves a transfer of personal data outside the European Economic Area within the meaning of Chapter V of the GDPR.

We rely on the following safeguards, in this order of priority:

  1. EU-US Data Privacy Framework (DPF). Where the recipient is certified under the DPF, we rely on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). You can verify a recipient's certification at https://www.dataprivacyframework.gov.
  2. EU Standard Contractual Clauses (SCCs). As a complementary or fallback safeguard, our DPAs incorporate the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 (Art. 46(2)(c) GDPR), supplemented by transfer impact assessments and additional technical measures (encryption in transit and at rest, access controls, pseudonymisation where feasible).
  3. Specific situations under Art. 49 GDPR are used only exceptionally — for example, when a transfer is necessary for the performance of a contract you have requested.

On request, we provide customers with a copy of the relevant SCCs and a description of supplementary measures for each sub-processor.


9. Retention

CategoryRetention
Web server logs (IP, request line, User-Agent)Up to 14 days, then deleted or aggregated
Contact and pre-contract correspondenceUp to 24 months from last contact, unless a contract follows
Account data and authentication recordsFor the lifetime of the account; deleted within 90 days of account closure unless retention is required
Customer content (inputs, outputs, traces)For the term of the customer agreement; deleted or returned within 30 days of contract end, subject to the customer's instructions in the DPA
Billing and accounting recordsUp to 10 years per § 257 HGB and § 147 AO
Error reports and telemetryUp to 90 days, then deleted or anonymised
Marketing data (where consent given)Until consent is withdrawn or after 24 months of inactivity
Records needed for legal claimsUntil the relevant limitation period expires

Where shorter retention is needed for a specific category and is technically feasible, we apply it.


10. Cookies and similar technologies

We use cookies and similar storage on your device only to the extent strictly necessary to deliver the service you have asked for — for example, to keep you signed in. These technically necessary uses do not require consent under § 25(2) No. 2 TDDDG (formerly TTDSG) and Art. 6(1)(f) GDPR.

We currently do not deploy analytics, advertising, or cross-site tracking technologies on the public website. If we introduce any non-essential cookies or similar in the future, we will request your prior, freely given, specific, informed and unambiguous consent via a consent banner that meets the requirements of § 25(1) TDDDG, Art. 7 GDPR, and the EDPB's guidelines on deceptive design patterns.

10.1 Local storage used by the platform

The signed-in platform uses local storage and similar mechanisms for session state, UI preferences, and security tokens. These are strictly necessary for the platform to function.

10.2 Fonts and external assets

Web fonts and similar static assets are served from infrastructure under our control or from compliant content delivery networks. We do not embed third-party font services that would transmit your IP address to providers outside our processor chain without consent.


11. Security

We implement technical and organisational measures (TOMs) appropriate to the risk under Art. 32 GDPR, including:

  • TLS 1.2+ encryption for all data in transit;
  • encryption at rest for primary databases and object storage;
  • least-privilege access control with multi-factor authentication for all administrative access;
  • environment isolation (production, staging, development);
  • secret management and key rotation;
  • logging and tamper-resistant audit trails;
  • vulnerability scanning, dependency monitoring, and timely patching;
  • infrastructure deployed as code under version control (Terraform);
  • vendor due diligence before onboarding new sub-processors.

A description of our TOMs is provided to customers as Annex 2 of the DPA. In the event of a personal data breach (Art. 4(12) GDPR) likely to result in a risk to the rights and freedoms of data subjects, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach (Art. 33 GDPR) and the affected data subjects without undue delay where the risk is high (Art. 34 GDPR).


12. Automated decisions and profiling

AIIA produces analytical outputs by automated means. We do not use these outputs to make decisions about you that produce legal or similarly significant effects within the meaning of Art. 22 GDPR. The platform is designed as a decision-support tool for qualified human decision-makers (analysts, partners, committee members), not as a fully automated decision-maker. Every analysis is presented with a Glass Box transparency trace so that the human in the loop can audit, challenge, and override its conclusions.

Where a customer chooses to use AIIA's outputs as part of their own automated decisioning, the customer is the controller of that decision and is responsible for complying with Art. 22 GDPR and the EU AI Act.


13. Your rights

Subject to the conditions and limits set out in the GDPR, you have the right to:

  • Access the personal data we hold about you and obtain a copy (Art. 15 GDPR);
  • Rectification of inaccurate or incomplete data (Art. 16 GDPR);
  • Erasure ("right to be forgotten") in the circumstances listed in Art. 17 GDPR;
  • Restriction of processing (Art. 18 GDPR);
  • Data portability for data you have provided to us, in a structured, commonly used, machine-readable format (Art. 20 GDPR);
  • Object to processing based on legitimate interests, including profiling (Art. 21 GDPR); in the case of direct marketing the objection is absolute;
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).

To exercise any of these rights, write to privacy@aiia.run. We may need to verify your identity to protect against unauthorised disclosure. We will respond without undue delay and in any event within one month of receipt, extendable by up to two further months for complex requests (Art. 12(3) GDPR).

Where AIIA acts as a processor on behalf of a customer organisation, requests concerning personal data we process for that customer should be addressed to the customer; we will forward such requests to the relevant customer and assist them in fulfilling their obligations.


14. Right to lodge a complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR). For AIIA, the competent lead authority is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI) Ludwig-Erhard-Straße 22, 7. OG 20459 Hamburg, Germany Web: https://datenschutz-hamburg.de Email: mailbox@datenschutz.hamburg.de


15. Children and minors

AIIA is a business-to-business service intended exclusively for professional users acting on behalf of an organisation. We do not knowingly process personal data of children. If you believe that we have inadvertently received such data, please contact us so we can delete it.


16. Changes to this policy

We will update this policy when our processing activities change or when the legal landscape requires it. The version number and effective date at the top reflect the current edition. For material changes, we will notify account holders by email or via an in-product notice with reasonable advance notice before the change takes effect. Previous versions are available on request.


17. Contact

Questions, requests, or concerns about this policy or your personal data:

  • Privacy: privacy@aiia.run
  • General contact: hello@aiia.run
  • Postal: see Section 1.
AIIA © 2026Auditable AI advisory for professional decision-makers.
PrivacyTermsLegal Notice