Privacy Policy
Last updated: 21 April 2026.
AIGIUS B.V. ("AIGIUS", "we", "us") respects your privacy and handles personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch Implementing Act (UAVG).
1. Who we are
AIGIUS B.V., Roestuin 18, 3343 CV Hendrik-Ido-Ambacht, the Netherlands.
KvK: 97299545 · VAT: NL867991859B01.
For any privacy-related question you can reach our data protection contact at privacy@aigius.com.
2. When this policy applies
This policy describes how we process personal data when you visit aigius.com, contact us about our product, or evaluate AIGIUS in a pilot. A separate Data Processing Agreement (DPA) applies when AIGIUS acts as a processor for documents you feed into the platform.
3. Personal data we collect
3.1 Information you give us
- Contact details, name, business email, company, phone, when you request a demo, sign up for a trial, or correspond with us by email.
- Account data, login identifier and authentication credentials for customers with active deployments.
- Support content, anything you send us in a support conversation or attach to a ticket.
3.2 Information we collect automatically
- Server logs, IP address, user-agent, timestamps, requested URL. Retained for up to 30 days for security and abuse-prevention purposes.
- Product telemetry, aggregated, de-identified usage metrics from active deployments (queue depth, extraction latency, error rates). No document contents leave the customer's environment.
3.3 Information from third parties
We do not buy marketing lists. If you connect a mailbox via an OAuth integration, we only receive the scopes required to read the messages you have routed to AIGIUS.
4. Legal bases and purposes
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Responding to your demo / sales enquiry | Pre-contractual steps (art. 6(1)(b)) |
| Operating the platform under a signed contract | Performance of contract (art. 6(1)(b)) |
| Security, fraud prevention, audit logs | Legitimate interests (art. 6(1)(f)) |
| Invoicing, tax, statutory bookkeeping | Legal obligation (art. 6(1)(c)) |
| Product improvement from aggregated telemetry | Legitimate interests (art. 6(1)(f)) |
5. Where your data is processed
AIGIUS runs on dedicated hardware in certified datacenters in Germany and the Netherlands. Your documents and the AI processing that reads them stay inside the EU. We do not send document content to OpenAI, Anthropic, Google, AWS Bedrock, or any other hyperscaler AI API. No international transfer of your documents takes place as part of the core product.
Corporate communication tools (email, CRM) may involve sub-processors outside the EU under Standard Contractual Clauses. A current list is available on request.
6. Retention
- Sales and CRM contact data: up to 24 months after last contact.
- Server logs: 30 days.
- Customer production data: per the signed agreement and DPA.
- Statutory financial records: 7 years (Dutch fiscal law).
7. Your rights
Under GDPR you have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Send any request to privacy@aigius.com. We respond within 30 days.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
8. Security
Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, tenant-isolated databases, signed model updates, and a full audit trail for every extraction, validation, and ERP write. See the Security section of the main site for the architecture overview.
9. Changes
We update this policy when our processing changes. Material changes will be announced to active customers by email at least 30 days before they take effect.