AriaFlow – Data Privacy Agreement (Privacy Policy)
This policy gives the information required by Art. 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
1. Who is responsible
The controller for the processing described in this policy is:
AriaFlow GmbH, Große Bleiche 15, 55116 Mainz, Germany
Email and data protection officer: privacy@ariaflow.org
2. Scope and our two roles
2.1 This policy applies to the AriaFlow website and to both AriaFlow products: AriaFlow Express (single-user monthly subscription with the plans Starter, Pro and Expert) and AriaFlow Enterprise (company solution with role-based access). It covers the web application, the REST API, the MCP endpoints and the Office add-in (together the "Service"). Where a row in this policy applies to one product only, the product is named.
2.2 AriaFlow has two different roles:
| Role | Data | Rules that apply |
|---|---|---|
| Controller | Account data, billing data, usage and security logs, support requests, website data | This policy |
| Processor | Content that customers upload or generate in the Service (source documents, outputs, embeddings, run data, audit trail of the workspace) | The Data Protection Agreement (DPA) with the customer. The customer is the controller. |
2.3 If your employer or another organisation gave you access to the Service, this organisation decides how your content is used. Please contact its administrator first for questions about workspace content.
3. Data we process as controller
| Situation | Data | Purpose | Legal basis (GDPR) | Storage period |
|---|---|---|---|---|
| Account creation and login (Express: email and password; Enterprise: SSO) | Name, email address, organisation membership, role, authentication data (password hash or SSO identifier, MFA status), IP address | Create and secure the account, fraud prevention | Art. 6(1)(b); IP address: Art. 6(1)(f) | Term of the contract; then deleted, unless retention duties apply |
| Subscription (Express: Starter, Pro, Expert) | Name, company, address, VAT ID, selected plan, payment details (handled by the payment provider), invoices | Conclude and perform the contract, billing | Art. 6(1)(b); tax and commercial records: Art. 6(1)(c) | Term of the contract; invoices 10 years under German tax and commercial law |
| Usage and billing data | Subscription ID, number of documents generated, credit and token consumption by model, logins, upgrades and downgrades | Billing, plan limits, usage view for the customer | Art. 6(1)(b); further analysis: Art. 6(1)(f) | Term of the contract |
| Use provided by your organisation (Enterprise) | The data above, as far as it relates to you | Perform the contract with your organisation; share usage figures with its administrators | Art. 6(1)(f) | Term of the contract |
| Technical logs and error tracking | Date and time, browser and operating system, IP address, request data, error diagnostics | Stability, security and error analysis | Art. 6(1)(f) | 30 days |
| Audit trail (platform level) | Identity, timestamp, action, reason; API-token activity | Traceability, security, legal defence | Art. 6(1)(f) | Life of the organisation account |
| Support and sales requests | Name, email address, content of the request, ticket history | Answer the request, prepare or perform a contract | Art. 6(1)(b) | Duration of the business relationship, then statutory periods |
| Transactional email | Email address, message content (invitations, run notifications, approvals) | Operate the Service | Art. 6(1)(b) | 30 days at the email provider |
| Product information by email to existing customers | Email address | Information on new functions and Templates | Art. 6(1)(f) with Section 7(3) German Unfair Competition Act (UWG); you can object at any time | Until objection |
| Marketing newsletter | Email address | Offers and company news | Art. 6(1)(a) consent; you can withdraw it at any time | Until withdrawal |
| Security reports (responsible disclosure) | Contact data of the reporter, report content | Handle the report; acknowledgement within 5 business days | Art. 6(1)(f) | 3 years |
4. Cookies and similar technologies
4.1 The Service uses necessary cookies and local storage only: login session, security tokens, language and interface settings, and the cookie decision. The legal basis is Section 25(2) no. 2 TDDDG and Art. 6(1)(b) or (f) GDPR.
4.2 Analytics and marketing technologies are not used on the website or in the Service. If AriaFlow adds them later, they will run only with your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR, and this policy will list them.
4.3 Cloudflare routes the traffic between your browser and the Service for DNS, TLS termination and DDoS protection. Cloudflare processes connection data such as your IP address for this purpose. The legal basis is Art. 6(1)(f) GDPR.
5. Your content and AI models
5.1 Content that you upload or generate in the Service is processed only to provide the Service. It is not shared with other customers.
5.2 Your content is not used to train or improve any language model, ours or a vendor's. Zero data retention is enabled at the LLM gateway. Prompts and document excerpts are processed for a short time only and are not stored by the gateway or the model vendors.
5.3 Public research connectors (for example PubMed, ClinicalTrials.gov, openFDA, EMA) receive search queries only. They never receive your documents.
5.4 AriaFlow produces drafts for qualified human review. The Service makes no automated decisions with legal or similar effect on you (Art. 22 GDPR).
5.5 Upload content with personal data only if you have a legal basis for it. For business customers, the Data Protection Agreement (DPA) applies. Do not upload special categories of personal data, for example patient data with identifiers, unless a written handling model has been agreed with AriaFlow.
5.6 Standard retention of content: generation inputs 30 days; generation outputs 30 days after run completion; items in Trash 30 days; backups 30 days. Outputs that you save to your Resources library stay until you delete them. Deleted data is removed from all backups within 30 days at the latest.
6. Recipients
We use the following service providers. Each provider is bound by a data processing agreement and processes data only on our instructions.
| Provider | Purpose | Location | Transfer mechanism | Provider documentation |
|---|---|---|---|---|
| Microsoft (Azure) | Hosting of the EU instance; OCR (opt-in) | Poland Central (EU) | Processing in the EU; DPF and SCCs for support access from the US | microsoft.com/licensing/docs (Products and Services DPA) |
| Amazon Web Services | Hosting of the US instance (Enterprise only); OCR (opt-in) | us-east-1 (USA) | DPF and SCCs | aws.amazon.com/compliance/gdpr-center |
| Clerk, Inc. | Authentication and user directory; SSO/SAML/MFA (Enterprise) | USA | DPF (certified); SCCs as fallback | clerk.com/legal/dpa |
| OpenRouter, Inc. | Language model gateway, zero data retention | EU in-region routing | SCCs | openrouter.ai/privacy |
| Anthropic, PBC and OpenAI OpCo, LLC (via OpenRouter) | Language model inference, zero data retention | EU where routed; otherwise USA | Anthropic: DPF and SCCs; OpenAI: SCCs | anthropic.com/legal/privacy; openai.com/policies/data-processing-addendum |
| Google LLC and Llama inference providers (via OpenRouter; Enterprise only) | Language model inference, zero data retention | EU where routed; otherwise provider-dependent | Google: DPF and SCCs; Llama providers: OpenRouter DPA | cloud.google.com/terms/data-processing-addendum |
| Resend, Inc. | Transactional email | EU sending region; account data and logs in the USA | DPF (certified); SCCs as fallback | resend.com/legal/dpa |
| Functional Software, Inc. (Sentry) | Error tracking and performance monitoring | EU region | DPF (certified); SCCs as fallback | sentry.io/privacy |
| Arize AI, Inc. (Arize AX) | Observability of language model calls (traces) | EU region | SCCs | arize.com/privacy-policy |
| Cloudflare, Inc. | DNS, TLS termination, DDoS protection; connection metadata only, content is encrypted | Global network, EU entry point | DPF (certified) and SCCs | cloudflare.com/cloudflare-customer-dpa |
| Stripe Payments Europe, Ltd. | Payment for subscriptions and token recharges (Express). For fraud prevention and its own legal duties Stripe acts as an independent controller | Ireland; Stripe, Inc. (USA) for parts of the processing | DPF (certified) and SCCs | stripe.com/privacy |
The current list with a 30-day notice period for changes is published on our trust centre (Sub-processor List, TC-05). Our contracted partner G&L Scientific and its subsidiaries support service delivery and are bound by confidentiality. We disclose data to authorities only if the law requires it.
7. Storage location and international transfers
7.1 Workspace data is stored in the region of the instance: EU (Azure, Poland Central) or US (AWS, us-east-1). AriaFlow Express always runs on the EU instance; Enterprise customers choose the instance at onboarding. This includes the database, object storage, cache and backups. Data is not replicated between the instances.
7.2 Identity data is held by our identity provider in its EU region. This also applies to users of the US instance.
7.3 If a provider processes personal data outside the EU/EEA, we use the safeguards of Art. 44 to 49 GDPR: an adequacy decision, including the EU-U.S. Data Privacy Framework for certified providers, or the EU Standard Contractual Clauses. Additional safeguards are encryption in transit and at rest, and data minimisation in prompts. You can request a copy of the safeguards from the contact in section 1.
8. Data security
We protect your data with technical and organisational measures under Art. 32 GDPR. The main measures are:
- Tenant isolation enforced by the database (PostgreSQL Row-Level Security) on all organisation-scoped tables
- Six user roles, SSO via OAuth and SAML 2.0, and MFA
- TLS 1.2 or higher in transit; encryption at rest for databases, object storage and backups
- Secrets in managed key vaults; no credentials in code or images
- Append-only audit trail; modification and deletion are blocked for every role
- Nightly security scans (static analysis, dependency audits, secret scanning) and a published responsible-disclosure policy
We hold no third-party security certifications today. SOC 2 and ISO 27001 are planned for 2027/2028.
9. Your rights
You have the following rights under the GDPR:
| Right | Article |
|---|---|
| Access to your data and a copy | Art. 15 |
| Correction of wrong data | Art. 16 |
| Deletion | Art. 17 |
| Restriction of processing | Art. 18 |
| Data portability | Art. 20 |
| Objection to processing based on legitimate interests, and to direct marketing | Art. 21 |
| Withdrawal of consent with effect for the future | Art. 7(3) |
| Complaint to a supervisory authority | Art. 77 |
9.1 Functions in the Service: administrators can export the data of a single user and the whole workspace. Organisation owners can delete all workspace data permanently. This deletion requires a typed confirmation. Audit records are exempt from user-initiated deletion while the organisation exists, as far as legal compliance requires (Art. 17(3)(e) GDPR), and are removed when the organisation itself is deleted.
9.2 To use your rights, write to the contact in section 1. If AriaFlow acts as processor for your organisation, we forward your request to that organisation.
9.3 The supervisory authority responsible for AriaFlow is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Mainz. You can also contact the authority at your place of residence.
9.4 You are not obliged to provide personal data. Without account and billing data we cannot provide the Service.
10. Changes to this policy
We update this policy when the Service or the law changes. The current version is available in the Service and on our website. We inform account holders by email 30 days before a material change takes effect.
