In plain English
We collect the minimum needed to run the service and talk to you about it. We do not sell data, we do not run ad networks, and analytics only starts after you consent. Customer automation data stays in your chosen region and is never used to train models.
1. Who we are
AIInfraEngine B.V. ("we", "us") is the data controller for personal data processed through aiinfraengine.com and the AIInfraEngine platform. We are registered in the Netherlands and our registered office is Herengracht 182, 1016 BR Amsterdam.
For personal data you upload or generate inside your workspace, you are the controller and we act as your processor under the Data Processing Agreement that forms part of your contract.
2. What we collect
- Account data — name, work email, job title, company, and the workspace you belong to.
- Usage data — pages viewed, features used and execution counts. Collected only after you consent to analytics cookies.
- Support data — the content of tickets, chat sessions and any diagnostics you choose to attach.
- Marketing data — if you request a demo or subscribe to the newsletter, the details you provide and your engagement with our emails.
- Technical data — IP address, browser and device type, captured in server logs for security and abuse prevention.
- Customer content — the scripts, workflows, targets and execution results inside your workspace. We process these solely to provide the service.
3. Why we process it, and on what basis
- To provide the service — performance of the contract with you or your employer.
- To secure the service and prevent abuse — our legitimate interest in operating a safe platform.
- To respond to enquiries and support requests — performance of the contract, or legitimate interest for prospective customers.
- To send marketing — your consent, withdrawable at any time from any email or in your preferences.
- To improve the product using aggregate, non-identifying metrics — our legitimate interest, balanced against your privacy by using aggregation.
- To meet legal, tax and accounting obligations — compliance with a legal obligation.
4. AI processing
The AI Tools and Service Desk AI features send your prompt to a model provider for inference. Prompts and outputs are processed transiently and are not retained by us after the response is returned.
We contract with model providers on terms that prohibit training on customer data. If you require a specific provider, an air-gapped model server, or your own enterprise agreement with a provider, Enterprise plans support all three.
We never use customer content — scripts, workflows, execution data or ticket text — to train any model of ours or anyone else’s.
5. Who we share it with
We share personal data only with sub-processors who help us deliver the service: cloud hosting, email delivery, error monitoring, payment processing and AI inference. Each is bound by a data processing agreement and is listed in the sub-processor register available in your workspace.
We will disclose data if legally compelled, and we will notify you before doing so unless legally prohibited from notifying you.
We do not sell personal data, and we do not share it with advertising networks.
6. Where it lives
Cloud tenancies are available in the US, EU (Frankfurt), UK and Australia. Your chosen region is contractually binding for customer content — it does not move without your instruction.
Marketing and website data is processed in the EU. Transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses together with a transfer impact assessment.
7. How long we keep it
- Account data — for the life of the account, then 90 days after closure.
- Customer content — for your configured retention period; deleted within 30 days of workspace closure unless you request an export.
- Support tickets — 24 months from closure.
- Marketing data — until you unsubscribe, then 12 months to honour the suppression.
- Server and audit logs — 13 months.
8. Your rights
Under the GDPR and equivalent laws you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing that already happened.
Write to dpo@aiinfraengine.com. We respond within 30 days. If you are unhappy with our response you may complain to your supervisory authority — ours is the Autoriteit Persoonsgegevens in the Netherlands.
9. Security
We maintain an ISO 27001-certified information security management system and undergo annual SOC 2 Type II audits. Technical measures include encryption in transit and at rest, least-privilege access, mandatory MFA for staff, and continuous monitoring.
We will notify affected customers of a personal data breach without undue delay and within 72 hours of becoming aware, as required by law.
10. Changes
We will post material changes here and email account holders at least 30 days before they take effect. The effective date at the top of this page always reflects the current version, and previous versions are available on request.
Questions about this?
Write to legal@aiinfraengine.com, or our Data Protection Officer at dpo@aiinfraengine.com. Postal enquiries: AIInfraEngine, Herengracht 182, 1016 BR Amsterdam, Netherlands.