Privacy Policy
Last updated: 2026-09-17
Not legal advice
This tool provides general information about EU AI Act compliance. It is not legal advice, and using it does not create an attorney-client or other professional relationship. We do not guarantee the completeness, accuracy, or currency of any classification or report generated. Consult qualified legal counsel before relying on this content for a regulatory filing, audit defense, or other formal purpose.
1. What data we collect
- Your answers to the risk-classification wizard (sector, function, affected population, provider/deployer role, autonomy/oversight level, and related questions).
- A session identifier used to resume a wizard session and, after purchase, to retrieve your report.
- Payment confirmation metadata from our hosted checkout provider (e.g. amount, timestamp, order reference) — we never receive or store your full card number.
- Basic technical logs (IP address, timestamps, user agent) kept for security and fraud prevention.
2. Why we process it
Wizard answers are processed to generate your classification result and, if purchased, your gap report (performance of the contract you enter into by using the tool / making a purchase). Technical logs are processed under our legitimate interest in keeping the service secure and reliable.
3. Where your data is hosted
The application is hosted on infrastructure pinned to the Frankfurt (fra1) region, and any database used to store wizard sessions or purchased reports is hosted in an EU region. Your data does not leave the EU as part of normal operation of this service.
4. Retention and deletion
Wizard session answers, for sessions that are never purchased, are retained for 90 days from your last activity to let you resume where you left off, then permanently deleted.
Once a report is purchased, the underlying wizard answers and the report itself are retained for 36 months from purchase, so you can re-download the report and use it for audit-defense purposes, then permanently deleted unless a longer retention is required by law (for example, financial records kept for tax/invoicing purposes).
You may request deletion of your data at any time by contacting us; we will action the request within 30 days, subject to any legal retention obligations that apply to financial records.
5. Your rights (GDPR)
Subject to applicable law, you have the right to access, correct, delete, restrict, or port your data, and to object to certain processing. Contact us to exercise any of these rights.
6. Third parties
We share data with the minimum necessary third parties to run the service: our hosting provider, our EU-region database provider, and our hosted checkout / payment provider. None of these parties may use your data for their own purposes.
7. Changes to this policy
We may update this policy from time to time; the "last updated" date above reflects the most recent revision.
8. Contact
Questions about this policy, or to exercise a data-protection right: privacy@aiactaudit.ai
Draft pending qualified legal counsel review — see the launch-gate task before public launch.