AIGIUSAIGIUS

Privacy Policy

Draft for legal review. This document is a working draft. It may be updated after review by Dutch counsel and our DPO. Please contact us for the signed version applicable to your agreement.

Last updated: 21 April 2026.

AIGIUS B.V. ("AIGIUS", "we", "us") respects your privacy and handles personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch Implementing Act (UAVG).

1. Who we are

AIGIUS B.V., Roestuin 18, 3343 CV Hendrik-Ido-Ambacht, the Netherlands.
KvK: 97299545 · VAT: NL867991859B01.

For any privacy-related question you can reach our data protection contact at privacy@aigius.com.

2. When this policy applies

This policy describes how we process personal data when you visit aigius.com, contact us about our product, or evaluate AIGIUS in a pilot. A separate Data Processing Agreement (DPA) applies when AIGIUS acts as a processor for documents you feed into the platform.

3. Personal data we collect

3.1 Information you give us

  • Contact details, name, business email, company, phone, when you request a demo, sign up for a trial, or correspond with us by email.
  • Account data, login identifier and authentication credentials for customers with active deployments.
  • Support content, anything you send us in a support conversation or attach to a ticket.

3.2 Information we collect automatically

  • Server logs, IP address, user-agent, timestamps, requested URL. Retained for up to 30 days for security and abuse-prevention purposes.
  • Product telemetry, aggregated, de-identified usage metrics from active deployments (queue depth, extraction latency, error rates). No document contents leave the customer's environment.

3.3 Information from third parties

We do not buy marketing lists. If you connect a mailbox via an OAuth integration, we only receive the scopes required to read the messages you have routed to AIGIUS.

4. Legal bases and purposes

PurposeLegal basis (GDPR art. 6)
Responding to your demo / sales enquiryPre-contractual steps (art. 6(1)(b))
Operating the platform under a signed contractPerformance of contract (art. 6(1)(b))
Security, fraud prevention, audit logsLegitimate interests (art. 6(1)(f))
Invoicing, tax, statutory bookkeepingLegal obligation (art. 6(1)(c))
Product improvement from aggregated telemetryLegitimate interests (art. 6(1)(f))

5. Where your data is processed

AIGIUS runs on dedicated hardware in certified datacenters in Germany and the Netherlands. Your documents and the AI processing that reads them stay inside the EU. We do not send document content to OpenAI, Anthropic, Google, AWS Bedrock, or any other hyperscaler AI API. No international transfer of your documents takes place as part of the core product.

Corporate communication tools (email, CRM) may involve sub-processors outside the EU under Standard Contractual Clauses. A current list is available on request.

6. Retention

  • Sales and CRM contact data: up to 24 months after last contact.
  • Server logs: 30 days.
  • Customer production data: per the signed agreement and DPA.
  • Statutory financial records: 7 years (Dutch fiscal law).

7. Your rights

Under GDPR you have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Send any request to privacy@aigius.com. We respond within 30 days.

You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

8. Security

Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, tenant-isolated databases, signed model updates, and a full audit trail for every extraction, validation, and ERP write. See the Security section of the main site for the architecture overview.

9. Changes

We update this policy when our processing changes. Material changes will be announced to active customers by email at least 30 days before they take effect.