PRIVACY · DATENSCHUTZ · CONFIDENTIALITÉ
This notice explains what personal data we process when you use AI Safety Check, why, on what legal basis, and who else is involved. Controller: Aisthetic Lab (see Impressum). Contact: the address in the Impressum.
Readiness check and policy draft: the company name, your work email, the industry, the team size, the AI tools you list, and the data categories you indicate. Purpose: to generate your draft AI usage policy and send it to you. Legal basis: performance of a contract or steps prior to entering one (Art. 6(1)(b) GDPR); for the free draft by a business contact, our legitimate interest in answering your request (Art. 6(1)(f)).
Account and training data (Passport / Training / Business): user name, work email, role, training progress, module test scores, attempts, timestamps, completion records and completion record identifiers, and whatever you enter in the tool registry and incident log. Purpose: to provide the service and to produce the documented evidence it is bought for.
Payment and invoicing: company details, address, order data and, where provided, a VAT identification number. Purpose: invoicing and bookkeeping. Legal basis: contract and legal obligations (Art. 6(1)(b) and (c) GDPR). We do not process card data — invoices are settled by bank transfer.
Technical data: server logs (IP address, time, requested page, user agent) for security and operation.
The draft AI usage policy is not produced by an external AI model. It is assembled by our own software from curated, pre-written clauses according to deterministic rules and the details you enter — text is selected and filled in, not generated by a third-party language model, and no input is sent to OpenAI, Anthropic, Mistral or any comparable provider. There is no profiling and no automated decision-making within the meaning of Art. 22 GDPR. The result is a template, not legal advice: see the terms of service. Should a language-model provider be used for this or another feature later, it will be named in this notice as a processor with its location and the legal basis for any transfer, before that feature goes live.
Hosting and database: the application runs on the Higgsfield platform (Cloudflare Workers with D1 database, EU region). Higgsfield is our contractual platform partner; Cloudflare provides the underlying infrastructure. Media and images are delivered through the CloudFront content delivery network operated by Amazon Web Services.
Email: the service does not currently send automated emails. The contact address hello@aistheticlab.com is hosted by Namecheap Private Email, which processes the correspondence you send us (and the invoices we send by email). If a transactional email service is added later, it will be named here before it goes live. Our agreements with these service providers are available on request.
We do not sell personal data and we do not share it with advertisers. Data is disclosed only to the processors above, to professional advisers where necessary, or where we are legally obliged to disclose it.
Hosting and database run in the European Union; individual service providers may process data in the United States. In particular, media and images are delivered through the CloudFront content delivery network of Amazon Web Services and transactional emails are sent through our email service provider — both may process data in the USA. Where that happens, transfers are covered by the EU–US Data Privacy Framework and/or the European Commission's standard contractual clauses, together with the technical measures described in this notice. Details are available on request.
Draft policies and readiness-check entries: as long as needed to provide them, and then deleted unless you become a customer. Training and completion records: for the term of the agreement plus at least 12 months, so the evidence remains available — they are yours and exportable at any time. Invoices: for the statutory retention periods under German commercial and tax law (up to 10 years). Server logs: a short operational period, normally up to 30 days.
You have the rights under Arts. 15–21 GDPR: access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw it at any time with effect for the future. You may also lodge a complaint with a supervisory authority — for us, the competent authority for Hesse (Hessischer Beauftragter für Datenschutz und Informationsfreiheit).
When a company invites its employees to the training, that company is the controller and we are the processor (Art. 28 GDPR). We then process names, work email addresses, progress and test results on the company's documented instructions. A data processing agreement (AVV/DPA) is available and can be requested at any time — see the DPA page.
We use a session cookie that is technically necessary to keep you signed in. We do not use advertising or analytics cookies and we do not build marketing profiles. There is no newsletter and no marketing email list.
Access is protected by password hashing and session authentication; each company's data is scoped to that company. If this notice changes, we update the date below and, for material changes, inform customers.
Last updated: 2026-09-25