Aixy·
GDPR EU AI Act Security Subprocessors Privacy

Privacy & trust

Privacy notice

How Aixy uses personal data across its website, dashboard, customer relationships and LLM gateway service.

Last reviewed
26 August 2026
Status
Publication draft
Not a public compliance claim yet.

This material is prepared for review, but Aixy has not enabled the GDPR compliance claim. The remaining evidence and approval gates are listed on the GDPR transparency page.

1. Who is responsible

Controller: Aixy (registered operator details pending approval)

Country: Spain

Privacy contact: [email protected]

The approved identity of the individual operator or entity, tax/registration number and postal address must be completed before this notice is approved for publication.

2. Scope and roles

This notice covers aixy-gateway.com, the Aixy dashboard, direct sales and support interactions, and personal data for which Aixy decides the purposes and means.

When a customer sends prompts, responses or workload metadata through the gateway, the customer normally acts as controller and Aixy acts as processor. Those activities are governed by the customer's agreement and the Data Processing Addendum.

3. Data we process

  • Account and organization data: name, business email, organization, role, project and team memberships.
  • Authentication data: password hashes, session-token hashes, passkey public-key metadata, login and security events. Aixy does not store passkey private keys or biometric data.
  • Service metadata: project, API key and user identifiers, selected provider and model, timestamps, tokens, cost, latency, routing and policy outcomes, error information, IP address and bounded user agent where required for security or audit.
  • Customer content: prompts and responses only when an authorized customer administrator explicitly enables encrypted content capture. Content capture is disabled by default.
  • Billing data: plan, subscription identifiers, invoice and payment status. Payment-card data is handled by the payment provider when billing is enabled.
  • Communications: business correspondence, support requests and transactional email delivery metadata.
  • Website and security data: request metadata processed by the hosting and edge-security provider. The public website does not use advertising or audience-measurement cookies.

4. Purposes and legal bases

PurposeLegal basis
Create accounts, authenticate users and deliver the servicePerformance of a contract or steps requested before entering a contract
Secure the service, prevent abuse, investigate incidents and preserve audit evidenceLegitimate interests in security and legal obligations where applicable
Billing, accounting and subscription administrationContract performance and legal obligations
Respond to sales, support and privacy requestsRequested pre-contractual steps, contract performance or legitimate interests in business communication
Send optional marketing communicationsConsent, where used; communications include an unsubscribe method

Aixy does not use customer prompts or responses to train its own models or for advertising. When Aixy acts as processor, the legal basis is determined by the customer controller.

5. Recipients and international transfers

Aixy uses infrastructure, edge delivery, operational monitoring, transactional email and payment suppliers as needed to provide the service. The current processing chain and review status are documented on the subprocessor page.

Aixy-operated regional infrastructure is based in AWS Europe (Frankfurt). A customer's selected model provider may process a request in another location. Before non-EEA transfers are enabled, Aixy and the customer must identify an applicable adequacy decision or appropriate safeguards such as Standard Contractual Clauses and assess any necessary supplementary measures.

6. Retention

  • Operational analytics: Free 7 days; Starter 30 days; Enterprise 90 days.
  • Optional encrypted prompt/response capture: 1 day, 3 days, 7 days, 30 days, 90 days, selected by an authorized customer administrator.
  • Browser sessions: 12 hours by default and invalidated on logout, password reset or administrative revocation.
  • Cloud service logs: generally 14 days where controlled by Aixy infrastructure configuration.
  • Account and tenant data: for the active relationship. A scheduled deletion pauses access and remains recoverable for at least 30 days. Whole-tenant permanent purge is allowed no earlier than day 97 so that the longest 90-day live-store retention and seven-day database-backup window can expire.
  • Billing and legal records: for the applicable statutory period.

A narrowly scoped billing, dispute, security, privacy-request or legal hold may delay deletion of data that must be preserved. Every hold needs a recorded reason and release condition. The public compliance claim remains disabled until the purge workflow, backup expiry and connected-vendor deletion are operationally verified.

7. Your rights

You may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent where processing relies on consent. You may also object to decisions based solely on automated processing; Aixy does not make such decisions about website visitors or account users.

Send requests to [email protected]. Aixy will verify identity proportionately and respond without undue delay, normally within one month. You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.

8. Security and changes

Aixy applies access control, encryption, tenant isolation, bounded retention, audit evidence and incident procedures described in its technical and organizational measures. No internet service can promise absolute security.

Material changes will be reflected on this page. Where required, Aixy will provide additional notice through the service or by email.

Aixy·
Privacy Cookies Legal notice DPA EU AI Act Compliance contact