AriaFlow – Data Privacy Agreement (Privacy Policy)

Document ID
LG-01
Version
1.0
Date
2026-09-22
Owner
AriaFlow GmbH

This policy gives the information required by Art. 13 and 14 of Regulation (EU) 2016/679 ("GDPR").

1. Who is responsible

The controller for the processing described in this policy is:

AriaFlow GmbH, Große Bleiche 15, 55116 Mainz, Germany

Email and data protection officer: privacy@ariaflow.org

2. Scope and our two roles

2.1 This policy applies to the AriaFlow website and to both AriaFlow products: AriaFlow Express (single-user monthly subscription with the plans Starter, Pro and Expert) and AriaFlow Enterprise (company solution with role-based access). It covers the web application, the REST API, the MCP endpoints and the Office add-in (together the "Service"). Where a row in this policy applies to one product only, the product is named.

2.2 AriaFlow has two different roles:

RoleDataRules that apply
ControllerAccount data, billing data, usage and security logs, support requests, website dataThis policy
ProcessorContent that customers upload or generate in the Service (source documents, outputs, embeddings, run data, audit trail of the workspace)The Data Protection Agreement (DPA) with the customer. The customer is the controller.

2.3 If your employer or another organisation gave you access to the Service, this organisation decides how your content is used. Please contact its administrator first for questions about workspace content.

3. Data we process as controller

SituationDataPurposeLegal basis (GDPR)Storage period
Account creation and login (Express: email and password; Enterprise: SSO)Name, email address, organisation membership, role, authentication data (password hash or SSO identifier, MFA status), IP addressCreate and secure the account, fraud preventionArt. 6(1)(b); IP address: Art. 6(1)(f)Term of the contract; then deleted, unless retention duties apply
Subscription (Express: Starter, Pro, Expert)Name, company, address, VAT ID, selected plan, payment details (handled by the payment provider), invoicesConclude and perform the contract, billingArt. 6(1)(b); tax and commercial records: Art. 6(1)(c)Term of the contract; invoices 10 years under German tax and commercial law
Usage and billing dataSubscription ID, number of documents generated, credit and token consumption by model, logins, upgrades and downgradesBilling, plan limits, usage view for the customerArt. 6(1)(b); further analysis: Art. 6(1)(f)Term of the contract
Use provided by your organisation (Enterprise)The data above, as far as it relates to youPerform the contract with your organisation; share usage figures with its administratorsArt. 6(1)(f)Term of the contract
Technical logs and error trackingDate and time, browser and operating system, IP address, request data, error diagnosticsStability, security and error analysisArt. 6(1)(f)30 days
Audit trail (platform level)Identity, timestamp, action, reason; API-token activityTraceability, security, legal defenceArt. 6(1)(f)Life of the organisation account
Support and sales requestsName, email address, content of the request, ticket historyAnswer the request, prepare or perform a contractArt. 6(1)(b)Duration of the business relationship, then statutory periods
Transactional emailEmail address, message content (invitations, run notifications, approvals)Operate the ServiceArt. 6(1)(b)30 days at the email provider
Product information by email to existing customersEmail addressInformation on new functions and TemplatesArt. 6(1)(f) with Section 7(3) German Unfair Competition Act (UWG); you can object at any timeUntil objection
Marketing newsletterEmail addressOffers and company newsArt. 6(1)(a) consent; you can withdraw it at any timeUntil withdrawal
Security reports (responsible disclosure)Contact data of the reporter, report contentHandle the report; acknowledgement within 5 business daysArt. 6(1)(f)3 years

4. Cookies and similar technologies

4.1 The Service uses necessary cookies and local storage only: login session, security tokens, language and interface settings, and the cookie decision. The legal basis is Section 25(2) no. 2 TDDDG and Art. 6(1)(b) or (f) GDPR.

4.2 Analytics and marketing technologies are not used on the website or in the Service. If AriaFlow adds them later, they will run only with your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR, and this policy will list them.

4.3 Cloudflare routes the traffic between your browser and the Service for DNS, TLS termination and DDoS protection. Cloudflare processes connection data such as your IP address for this purpose. The legal basis is Art. 6(1)(f) GDPR.

5. Your content and AI models

5.1 Content that you upload or generate in the Service is processed only to provide the Service. It is not shared with other customers.

5.2 Your content is not used to train or improve any language model, ours or a vendor's. Zero data retention is enabled at the LLM gateway. Prompts and document excerpts are processed for a short time only and are not stored by the gateway or the model vendors.

5.3 Public research connectors (for example PubMed, ClinicalTrials.gov, openFDA, EMA) receive search queries only. They never receive your documents.

5.4 AriaFlow produces drafts for qualified human review. The Service makes no automated decisions with legal or similar effect on you (Art. 22 GDPR).

5.5 Upload content with personal data only if you have a legal basis for it. For business customers, the Data Protection Agreement (DPA) applies. Do not upload special categories of personal data, for example patient data with identifiers, unless a written handling model has been agreed with AriaFlow.

5.6 Standard retention of content: generation inputs 30 days; generation outputs 30 days after run completion; items in Trash 30 days; backups 30 days. Outputs that you save to your Resources library stay until you delete them. Deleted data is removed from all backups within 30 days at the latest.

6. Recipients

We use the following service providers. Each provider is bound by a data processing agreement and processes data only on our instructions.

ProviderPurposeLocationTransfer mechanismProvider documentation
Microsoft (Azure)Hosting of the EU instance; OCR (opt-in)Poland Central (EU)Processing in the EU; DPF and SCCs for support access from the USmicrosoft.com/licensing/docs (Products and Services DPA)
Amazon Web ServicesHosting of the US instance (Enterprise only); OCR (opt-in)us-east-1 (USA)DPF and SCCsaws.amazon.com/compliance/gdpr-center
Clerk, Inc.Authentication and user directory; SSO/SAML/MFA (Enterprise)USADPF (certified); SCCs as fallbackclerk.com/legal/dpa
OpenRouter, Inc.Language model gateway, zero data retentionEU in-region routingSCCsopenrouter.ai/privacy
Anthropic, PBC and OpenAI OpCo, LLC (via OpenRouter)Language model inference, zero data retentionEU where routed; otherwise USAAnthropic: DPF and SCCs; OpenAI: SCCsanthropic.com/legal/privacy; openai.com/policies/data-processing-addendum
Google LLC and Llama inference providers (via OpenRouter; Enterprise only)Language model inference, zero data retentionEU where routed; otherwise provider-dependentGoogle: DPF and SCCs; Llama providers: OpenRouter DPAcloud.google.com/terms/data-processing-addendum
Resend, Inc.Transactional emailEU sending region; account data and logs in the USADPF (certified); SCCs as fallbackresend.com/legal/dpa
Functional Software, Inc. (Sentry)Error tracking and performance monitoringEU regionDPF (certified); SCCs as fallbacksentry.io/privacy
Arize AI, Inc. (Arize AX)Observability of language model calls (traces)EU regionSCCsarize.com/privacy-policy
Cloudflare, Inc.DNS, TLS termination, DDoS protection; connection metadata only, content is encryptedGlobal network, EU entry pointDPF (certified) and SCCscloudflare.com/cloudflare-customer-dpa
Stripe Payments Europe, Ltd.Payment for subscriptions and token recharges (Express). For fraud prevention and its own legal duties Stripe acts as an independent controllerIreland; Stripe, Inc. (USA) for parts of the processingDPF (certified) and SCCsstripe.com/privacy

The current list with a 30-day notice period for changes is published on our trust centre (Sub-processor List, TC-05). Our contracted partner G&L Scientific and its subsidiaries support service delivery and are bound by confidentiality. We disclose data to authorities only if the law requires it.

7. Storage location and international transfers

7.1 Workspace data is stored in the region of the instance: EU (Azure, Poland Central) or US (AWS, us-east-1). AriaFlow Express always runs on the EU instance; Enterprise customers choose the instance at onboarding. This includes the database, object storage, cache and backups. Data is not replicated between the instances.

7.2 Identity data is held by our identity provider in its EU region. This also applies to users of the US instance.

7.3 If a provider processes personal data outside the EU/EEA, we use the safeguards of Art. 44 to 49 GDPR: an adequacy decision, including the EU-U.S. Data Privacy Framework for certified providers, or the EU Standard Contractual Clauses. Additional safeguards are encryption in transit and at rest, and data minimisation in prompts. You can request a copy of the safeguards from the contact in section 1.

8. Data security

We protect your data with technical and organisational measures under Art. 32 GDPR. The main measures are:

  • Tenant isolation enforced by the database (PostgreSQL Row-Level Security) on all organisation-scoped tables
  • Six user roles, SSO via OAuth and SAML 2.0, and MFA
  • TLS 1.2 or higher in transit; encryption at rest for databases, object storage and backups
  • Secrets in managed key vaults; no credentials in code or images
  • Append-only audit trail; modification and deletion are blocked for every role
  • Nightly security scans (static analysis, dependency audits, secret scanning) and a published responsible-disclosure policy

We hold no third-party security certifications today. SOC 2 and ISO 27001 are planned for 2027/2028.

9. Your rights

You have the following rights under the GDPR:

RightArticle
Access to your data and a copyArt. 15
Correction of wrong dataArt. 16
DeletionArt. 17
Restriction of processingArt. 18
Data portabilityArt. 20
Objection to processing based on legitimate interests, and to direct marketingArt. 21
Withdrawal of consent with effect for the futureArt. 7(3)
Complaint to a supervisory authorityArt. 77

9.1 Functions in the Service: administrators can export the data of a single user and the whole workspace. Organisation owners can delete all workspace data permanently. This deletion requires a typed confirmation. Audit records are exempt from user-initiated deletion while the organisation exists, as far as legal compliance requires (Art. 17(3)(e) GDPR), and are removed when the organisation itself is deleted.

9.2 To use your rights, write to the contact in section 1. If AriaFlow acts as processor for your organisation, we forward your request to that organisation.

9.3 The supervisory authority responsible for AriaFlow is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Mainz. You can also contact the authority at your place of residence.

9.4 You are not obliged to provide personal data. Without account and billing data we cannot provide the Service.

10. Changes to this policy

We update this policy when the Service or the law changes. The current version is available in the Service and on our website. We inform account holders by email 30 days before a material change takes effect.