Aixy·
GDPR EU AI Act Security Subprocessors Privacy

Privacy & trust

GDPR transparency

How Aixy handles personal data, supports customers acting as controllers, and documents its privacy controls.

Last reviewed
26 August 2026
Status
Publication draft
Not a public compliance claim yet.

This material is prepared for review, but Aixy has not enabled the GDPR compliance claim. The remaining evidence and approval gates are listed on the GDPR transparency page.

GDPR Readiness programme In progress

A documented path to a defensible GDPR claim

Aixy does not present this badge as an Article 42 certification or a regulator endorsement. It links to the controls, contractual terms and operational evidence behind the statement.

Our roles

Controller

Aixy determines the purposes and means for account administration, authentication, billing, support, service security and its direct business relationships.

Processor

For prompts, responses and workload metadata submitted by a customer, Aixy processes personal data on the customer's documented instructions and under a Data Processing Addendum.

Product privacy controls

  • Content capture is disabled by default. Prompts and responses are excluded from logs, metrics, traces, analytics and audit events.
  • Optional capture is explicit and scoped. An authorized administrator can enable prompt or response capture for an organization or project.
  • Captured content is encrypted. The gateway encrypts the bounded value with AES-256-GCM before it enters the asynchronous storage queue.
  • Retention is bounded. Available content retention presets are 1 day, 3 days, 7 days, 30 days, 90 days. Operational analytics are retained for Free: 7 days; Starter: 30 days; Enterprise: 90 days.
  • Tenant deletion fails closed. Access is paused during a recoverable period. Permanent whole-tenant purge is gated until bounded stores and backups can expire, and is blocked by an active legal, billing, dispute, security or privacy-request hold.
  • Primary regional infrastructure is in Frankfurt. Aixy-operated AWS services remain in eu-central-1. The destination of a model request also depends on the provider and region selected by the customer.
  • Access is tenant scoped. Organization and project permissions, encrypted provider credentials, project API keys and audit evidence restrict and record control-plane access.

Documents available

Privacy noticeController processing, legal bases, retention and rights. Data Processing AddendumArticle 28 terms for customer data. Technical and organizational measuresSecurity and privacy safeguards implemented in the service. Subprocessor transparencyProcessing purpose, location and transfer review. Cookie noticeMarketing-site and dashboard storage technologies.

Publication gate

The stronger “GDPR compliance programme” wording remains disabled until every item below has an owner, approval and retained evidence.

  • Approved controller identity (individual operator or entity), tax/registration number, and postal address
  • Verified production subprocessor list and signed data-processing terms
  • Completed transfer assessments for non-EEA vendors and customer-selected model providers
  • Founder/operator approval of the DPA, ROPA, DPIA, LIAs, and privacy procedures
  • Production evidence for tenant purge, backup expiry, security controls, and browser requests

What the badge does not mean

GDPR compliance is a continuing legal and operational responsibility. The badge does not mean that Aixy has been certified under Articles 42 and 43, that a supervisory authority has approved the service, or that every customer use case automatically complies with the GDPR.

Customers remain responsible for their own purposes, legal bases, notices, instructions, data minimization and choice of model providers. Aixy supplies controls and information to support that work.

Official references

General Data Protection Regulation · EDPB accountability guidance · EDPB certification guidance

Aixy·
Privacy Cookies Legal notice DPA EU AI Act Compliance contact