Return to AIHRIA Home
EU / GDPR Data Protection Policy

Privacy & Data Handling Notice

1. Data Controller

The data controller responsible for the processing of personal data on this website (aihria.eu) is:

DAETIS Foundry
Founder / Representative: David Mark
Email: contact@daetis.ai / contact@aihria.eu
Jurisdiction: European Union

2. Architectural Sovereignty & Hosting

This website is self-hosted on a dedicated Virtual Private Server (VPS) physically located within data centers in the European Union. Unlike standard corporate marketing setups, we do not employ external content delivery networks (CDNs) or US-based cloud middleware that route visitor IP addresses across non-EU jurisdictions.

3. Zero Third-Party Trackers & Cookies

We believe in structural privacy. Accordingly:

  • We do not utilize Google Analytics, Meta Pixel, Hotjar, or any commercial behavioral tracking suites.
  • We do not set persistent advertising, profiling, or tracking cookies on your device.
  • No cookie consent banner is needed because no non-essential cookies or tracker scripts are loaded.

4. Processing of Framing Inquiries

When you submit a request for a Phase I Framing call through our contact form, we collect:

  • Your name and business email address
  • Organization name and system domain context
  • Optional details describing your regulatory inquiry or system status

Legal Basis: Article 6(1)(b) GDPR (processing necessary for taking steps prior to entering into a contract upon your request).

Purpose & Retention: These details are used solely by the DAETIS Foundry team to schedule and conduct your framing discussion and produce your written framing memo. Inquiries that do not proceed to an engagement are purged after 12 months unless statutory retention duties apply.

5. Server Log Files

For the technical maintenance, stability, and security of our European server infrastructure, our web server software automatically records standard connection parameters:

  • IP address of the connecting terminal
  • Date, time, and timezone of the request
  • Specific resource requested and HTTP status code
  • User agent string (browser and operating system family)

Legal Basis: Article 6(1)(f) GDPR (legitimate interest in detecting malicious traffic, mitigating denial-of-service attempts, and verifying server integrity). Log files are kept in rotating archives and deleted automatically within 14 days.

6. Your Statutory Rights Under the GDPR

As an EU data subject, you hold full statutory rights under Chapter III of the GDPR:

  • Right of access (Art. 15 GDPR): Inquire whether and what personal data we hold about you.
  • Right to rectification (Art. 16 GDPR): Request correction of inaccurate information.
  • Right to erasure (Art. 17 GDPR): Request complete deletion of your data when retention criteria no longer apply.
  • Right to restriction (Art. 18 GDPR): Request restricted processing of your records.
  • Right to object (Art. 21 GDPR): Object to processing grounded in legitimate interests.

To exercise any of these rights, email us at contact@daetis.ai. You also have the statutory right to lodge a complaint with a supervisory data protection authority in your EU Member State.