Privacy Policy

As of March 2026 ยท In accordance with EU GDPR (Regulation 2016/679)

Table of Contents
  1. Controller
  2. General Data Processing
  3. Legal Bases
  4. Hosting (IONOS)
  5. Backend Infrastructure (Supabase)
  6. Payment Processing (Stripe)
  7. AIGOY AI Governance Platform
  8. Local Data Storage
  9. Cookies & Technical Storage
  10. Email Communication
  11. Data Sharing with Third Parties
  12. Data Transfer to Third Countries
  13. Storage Duration
  14. Your Rights (GDPR)
  15. Right to Lodge a Complaint
  16. AI-Powered Risk Assessment
  17. Changes

๐Ÿข 1. Controller

Thomas Brandt
Sole proprietor operating under the brands AX1S and AIGOY

AX1S c/o Clevver ยท Winterhuder Weg 29, 7th Floor ยท 22085 Hamburg, Germany

Email: ยท Website: aigoy.io

๐Ÿ“‹ 2. General Data Processing

We process personal data only to the extent necessary for providing a functional AI Governance Platform as well as our content and services.

๐Ÿ”’ Privacy by Design: The AIGOY Platform was designed from the ground up with data minimization in mind. We use no tracking cookies, no Google Analytics, and no ad networks.

โš– 3. Legal Bases

๐ŸŒ 4. Hosting (IONOS)

This website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When visiting, the web server automatically captures IP address, timestamp, requested files, and referrer URL. This data is deleted after no more than 7 days.

Data Processing Agreement: Contract concluded with IONOS per Art. 28 GDPR.

๐Ÿ—„ 5. Backend Infrastructure (Supabase)

For authentication, data storage, and server-side logic, we use Supabase Inc. Our project is hosted in AWS eu-central-1 (Frankfurt) โ€” all data remains in the EU.

5.1 Data Processed

5.2 AI-Powered Processing (Edge Functions)

For risk assessment, we use Supabase Edge Functions that call Anthropic Claude. No personal data is transmitted โ€” only system name and use case. Anthropic contractually does not train its models on the transmitted data (no-training commitment); a data processing agreement (DPA) pursuant to Art. 28 GDPR is in place.

5.3 Security Measures

Encryption (TLS 1.2+ / AES-256), row-level security, regular EU backups, hosting with a SOC 2 Type II certified provider (Supabase).

๐Ÿ’ณ 6. Payment Processing (Stripe)

Paid licenses are processed via Stripe Payments Europe, Ltd. (Dublin, Ireland). Payment data is processed exclusively by Stripe and never stored on our servers.

Stripe Privacy Notice: stripe.com/en/privacy

๐Ÿ“Š 7. AIGOY AI Governance Platform

7.1 Registration

Email address, name, and password (encrypted) are processed for use.

7.2 AI System Inventory and Risk Assessment

We store master data, risk assessments, and AI suggestions for your AI systems. This processing is required for documentation per EU AI Act, NIS2, and DORA.

7.3 Competency Certificates

Upon training completion, internal competency certificates are issued. These are not state-recognized certificates.

๐Ÿ’พ 8. Local Data Storage

The application uses your browser's localStorage for language selection, AI system entries (cache), and session data. This data does not leave your computer.

๐Ÿช 9. Cookies & Technical Storage

โœ… No Cookie Banner Required: We use exclusively technically necessary cookies (login status, language selection). No tracking, no Google Analytics, no advertising cookies.

โœ‰ 10. Email Communication

Email inquiries are stored for processing. System notifications are sent via Supabase Auth.

๐Ÿ”„ 11. Data Sharing with Third Parties

Current data processors: IONOS SE (DE, hosting), Supabase Inc. (EU Frankfurt, backend), Stripe Payments Europe (IE, payment), Anthropic PBC (USA, AI service, Claude model โ€” transmitted data not used for training, DPA pursuant to Art. 28 GDPR).

๐ŸŒ 12. Data Transfer to Third Countries

All personal data is processed within the EU/EEA: IONOS (DE), Supabase (Frankfurt), Stripe (Dublin). For any access from third countries, Standard Contractual Clauses apply.

AI service (Anthropic): For AI-assisted analyses and the Compliance CoWorker โ€œFelixโ€ we use the Claude model from Anthropic PBC (San Francisco, USA). Anthropic contractually does not train its models on the data transmitted via the API (no-training commitment). For the transfer to the USA, Standard Contractual Clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR and the EU-U.S. Data Privacy Framework apply; a data processing agreement (DPA) pursuant to Art. 28 GDPR is in place. EU inference (e.g. via AWS Bedrock in Frankfurt) and customer-side model/key choice (BYOK) are in preparation.

โฑ 13. Storage Duration

๐Ÿ›ก 14. Your Rights (GDPR)

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), withdrawal of consent.

Contact: ยท Processing deadline: max. 1 month.

๐Ÿ“ฎ 15. Right to Lodge a Complaint

Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI)
Ludwig-Erhard-Str. 22, 7th Floor ยท 20459 Hamburg
Phone: +49 40 42854-4040 ยท [email protected]
datenschutz-hamburg.de

๐Ÿค– 16. AI-Powered Risk Assessment

The AIGOY Platform offers an AI-powered risk assessment as a guidance tool. It does not replace legal review. AIGOY assumes no liability for decisions based on AI-powered risk assessment.

๐Ÿ“ 17. Changes

We reserve the right to update this Privacy Policy. Material changes will be announced.