Data controller What we process Legal basis Zero operator access Retention Data flow Security Your rights Fair use Contact

Data controller

The data controller for all personal data processed through Aileth is:

CompanyAileth
LocationApeldoorn, Netherlands
Emailprivacy@aileth.eu
JurisdictionEuropean Union — GDPR applies

What we process and why

Category Data Purpose
Account data Name, email address Authentication and account management (via Keycloak SSO)
Compliance documentation Policies, procedures, and evidence documents uploaded by you Analysing your ISO 27001 compliance posture. Documents are processed via Scaleway's EU-hosted AI infrastructure — never sent to US-based AI providers.
Usage data Timestamps of uploads, analyses, and logins Audit trail and service operation. No behavioural tracking or analytics.

We do not use your documentation for model training, benchmarking, or any purpose beyond delivering the service described in your subscription.

We process your data. We do not see it.

This is a deliberate architectural choice, not just a policy commitment. Aileth analyses your compliance documentation automatically — no human ever reads, reviews, or has access to what you upload.

What this means in practice
When you upload a policy document, it is encrypted with your own encryption password and processed by a language model via Scaleway's EU-hosted AI infrastructure. The analysis result is returned to your account. At no point does any Aileth employee have the ability to open, read, search, or export your documents or results. There is no support workflow, no admin dashboard, and no tooling through which staff could access tenant content.
  • No human review — document analysis is fully automated. Aileth staff do not read, annotate, or moderate your content.
  • No privileged access tooling — there is no internal admin interface that grants staff access to customer document content.
  • Client-controlled encryption — documents are encrypted with a password you set yourself on first login, along with a recovery key that only you hold. Aileth never has access to your encryption password. Even with full infrastructure access, the stored data cannot be decrypted without it.
  • Access logs contain no content — operational logs record timestamps and metadata (file size, document type) but never document contents.

If you contact support, we can see basic account metadata from the authentication system: whether your account exists, is active, and when you last logged in. We cannot see your documents, reports, or the number of files you have uploaded — those are stored encrypted in your tenant storage and are indistinguishable to us.

Data retention

Aileth applies a short and strict retention policy. We keep your data for as long as strictly necessary to deliver the service — and no longer.

Onboarding Day 0
Contract end ~Day 30
Deletion Day 60
All data gone
Active subscription Post-contract buffer Deleted
Data typeRetention periodDeletion method
Uploaded documents & analysis results Duration of subscription + 30 days Permanent deletion from object storage and vector database
Account data (name, email) Duration of subscription + 30 days User record removed from identity provider
Usage logs 90 days Automatic log rotation

You may request early deletion of all your data at any time by contacting privacy@aileth.eu. We will complete the deletion within 5 business days and confirm in writing.

How your data flows through the system

All processing happens within a single EU datacenter. The diagram below shows every stage a document passes through from upload to deletion.

Data flow — document lifecycle
Your browser
HTTPS / TLS 1.3
TLS
Ingress
K8s / nginx
Paris · EU
internal
API
FastAPI · auth
Paris · EU
internal
Storage
Object + vector DB
Paris · EU
internal
Scaleway AI
Paris · Scaleway API
Paris · EU
T+60d
Deleted
Permanent removal
EU-hosted node (Scaleway, Paris)
Permanent deletion at T+60 days
No external data transfer at any stage

Your documents are never sent to US-based AI providers (no OpenAI, no Anthropic, no Google). Analysis runs via Scaleway's generative AI infrastructure — EU-hosted, and subject to the same data residency commitments as the rest of the service.

Technical and organisational security measures

  • Encryption in transit — All communication is encrypted via TLS 1.3. No unencrypted HTTP is accepted.
  • Client-controlled encryption at rest — on first login you set a personal encryption password and receive a recovery key. Your documents are encrypted with that password before storage. Aileth never holds your encryption key — meaning the data cannot be decrypted even by us.
  • Tenant isolation — Each client's data is stored in a separate namespace in the vector database. Cross-tenant access is architecturally prevented at the API layer.
  • Authentication — All access requires authentication via Keycloak SSO. JSON Web Tokens are short-lived and validated on every request.
  • Network policy — The application cluster enforces Kubernetes NetworkPolicy: internal services are not reachable from the public internet except through the authenticated API.
  • EU-only infrastructure — No data is processed or stored outside the European Union. Infrastructure runs on Scaleway (Paris datacenter), a French cloud provider not subject to US CLOUD Act jurisdiction.

Your rights under GDPR

As a data subject under GDPR, you have the following rights. To exercise any of them, contact privacy@aileth.eu. We will respond within 30 days.

Right of access (Art. 15)
Request a copy of all personal data we hold about you.
Right to rectification (Art. 16)
Ask us to correct inaccurate or incomplete data.
Right to erasure (Art. 17)
Request deletion of your data before the standard retention period ends.
Right to portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to restriction (Art. 18)
Ask us to restrict processing while a dispute is being resolved.
Right to object (Art. 21)
Object to processing based on legitimate interests.

If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

Fair use policy

Aileth is a computationally intensive service. Each gap analysis involves AI processing of your documentation — a process that carries real infrastructure cost. Our subscription pricing reflects typical usage by an organisation conducting a genuine ISO 27001 audit preparation.

What constitutes excessive use
Systematically clearing your document library and re-uploading the same or equivalent documentation in order to trigger repeated full re-analyses within a short timeframe is considered excessive use. This includes scripted or automated bulk re-ingestion. Such usage is not covered by a standard subscription and may result in service throttling or suspension without refund.

Normal use includes uploading documentation as it is produced or updated, running analyses when your documentation set changes materially, and re-analysing individual controls as you address identified gaps.

If your organisation requires a higher processing volume — for example, managing multiple subsidiaries or running continuous compliance monitoring — please contact us at info@aileth.eu to discuss an appropriate arrangement.

We reserve the right to impose rate limits or suspend access for accounts showing patterns of systematic abuse. We will always notify an account holder before suspension except in cases of egregious abuse.

Contact for data matters

For all questions about this policy, data subject requests, or privacy concerns:

Emailprivacy@aileth.eu
Response timeWithin 5 business days for data requests; 30 days for formal GDPR requests

This policy was last updated in April 2026. We will notify active subscribers of any material changes at least 30 days before they take effect.