Privacy Policy — Platform
This privacy policy applies to the TrustTroiAI Platform, including the associated browser extension TrustTroiAI Inspector. It supplements the privacy policy of the marketing website trusttroiai.eu (/en/datenschutz). This document is specific to the Platform and prevails on overlapping topics. For the extension itself, a compact English version at /extension-privacy additionally addresses the requirements of the Chrome Web Store; that version refers to this policy as the main document.
Privacy at a glance
The TrustTroiAI Platform helps organisations identify, document and evidence their compliance obligations under EU regulation — in particular the AI Act, GDPR, Cyber Resilience Act and Data Act. In addition, we offer a browser extension and an integration with Atlassian Jira.
What we process: your account data, the contents of your compliance projects, your chat exchanges with our AI assistant and — where you connect the Jira integration — the contents of the Jira issues you select.
For what: to provide the Platform, to perform AI-assisted compliance analyses and to ensure smooth operation.
Where: on servers in Germany (Hetzner). AI analyses run at Mistral AI in France (EU). Transactional emails run via Resend (USA, safeguarded by Standard Contractual Clauses).
Your rights: access, rectification, erasure, restriction, data portability, objection and complaint to a supervisory authority. Details in Section 17.
Data protection contact: privacy@trusttroiai.eu.
Controller
The controller for data processing on this Platform is:
TrustTroiAI
Grünewalder Straße 29–31
coworkit (SG-Grünewald)
42657 Solingen
Germany
Contact for data protection matters:
Email: privacy@trusttroiai.eu
General contact: hallo@trusttroiai.eu
Data Protection Officer
We have not appointed a data protection officer. Under Section 38 of the German Federal Data Protection Act (BDSG), a data protection officer only needs to be appointed if, as a rule, at least 20 persons are permanently engaged in the automated processing of personal data. We do not reach this threshold. No obligation arises under Article 37 GDPR either, as we do not carry out regular and systematic monitoring of data subjects on a large scale and do not process special categories of personal data on a large scale. Please address data protection enquiries directly to privacy@trusttroiai.eu.
Hosting and server location
Description. Provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The application, the PostgreSQL database and all persisted content reside on a virtual server operated by Hetzner in Germany. When the application is accessed, the server processes technically necessary connection data.
Legal basis. Article 6(1)(f) GDPR (legitimate interest in a secure and efficient provision) and Article 6(1)(b) GDPR in the context of contract performance. A data processing agreement under Article 28 GDPR is in place with Hetzner.
Purpose. Operation, security and availability of the Platform.
Third-country transfer. No third-country transfer; the server and database location is Germany.
Server log files and application logs
Description. The web server automatically collects information that your browser transmits: browser type and version, operating system, referrer URL, hostname of the accessing computer, time of the server request and IP address. For error analysis and operational security, the application additionally logs technical events to the server's system journal. Before entries are written to the journal, potentially personal content is replaced by a redaction filter so that plaintext content from your projects and tickets does not appear in the logs.
Legal basis. Article 6(1)(f) GDPR.
Purpose. Technical provision, error analysis, defence against attacks.
Retention. Server log files: 14 days, after which they are automatically deleted or overwritten. Redacted application logs: 30 days.
Right to object. You may object to this processing under Article 21 GDPR. As the processing is essential for the provision and security of the Platform, an objection would exclude use of the Platform.
User account and authentication
Description. A user account is required to use the Platform. On registration we collect:
- First and last name — form of address, attribution of contributions and signatures
- Email address — login, verification, system notifications
- Company or organisation — assignment to organisation and projects
- Function or role — tailoring of compliance content to your role
- Country — determination of the applicable legal framework
- Password — authentication, stored exclusively as a bcrypt hash, never in plaintext
After registration we send you an email with a verification link. Without a confirmed email address, the account is not activated. On the email delivery service provider, see Section 13.
Legal basis. Article 6(1)(b) GDPR (performance of contract or pre-contractual measures).
Purpose. Provision of the user account, attribution of your contributions, communication.
Retention. For the duration of the contractual relationship; after termination, see Section 16.
Sessions and cookies
Description. Once you have signed in we set one strictly necessary cookie:
trusttroiai_session— contains a random session token. Attributes:HttpOnly,Secure,SameSite=None. Lifetime: 30 days.
SameSite=None is required so that the browser extension recognises you as signed in in the context of Jira. The cookie is not readable via JavaScript (HttpOnly) and is transmitted exclusively over HTTPS (Secure).
In our database we do not store the token itself but only its SHA-256 hash, together with expiry and revocation status. On sign-out the session is invalidated on the server. We additionally use a CSRF token to protect against attacks via forged requests.
We do not use non-essential cookies, tracking or marketing cookies.
Legal basis. Article 6(1)(b) GDPR and Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) — strictly necessary for the provision of the service you have expressly requested. No consent is required for these cookies.
Purpose. Maintenance of your session, protection against attacks.
Retention. Session token: 30 days. On sign-out the session is invalidated immediately.
Compliance projects, assessments and evidence
Description. The core purpose of the Platform is the documentation of your compliance work. In doing so we process the content you enter:
- Project data — project name, description, information about the AI system or product, deployment context, applicable regulations
- Assessment responses — your answers in the scoping and risk questionnaires and the resulting risk classification
- Obligation instances — which regulatory obligations apply to your undertaking and their processing status
- Evidence — texts, links, references to Git commits or Jira issues you have recorded, uploaded files and completed templates
- Signatures and version history — who released, revoked or replaced which evidence when, including previous versions
This content may contain personal data if you enter such data — for example the names of persons responsible in a record of processing activities. You decide what you enter.
Why we keep the history. Evidence keeping is the core of the product. If someone later asks who released a piece of evidence, that attribution must remain verifiable. Therefore evidence is not overwritten but versioned and marked as "replaced".
File uploads are stored on the server's file system and are accessible only via authenticated requests of your account.
Legal basis. Article 6(1)(b) GDPR. Where you enter personal data of third parties, you are the controller in that respect and we process this data on your behalf — see Section 14.
Purpose. Delivery of compliance documentation and evidence-keeping services.
Retention. For the duration of the contractual relationship; after termination, see Section 16.
Atlassian Jira integration (optional)
You can connect your Atlassian account to the Platform. The connection is optional and not required to use the Platform.
What happens on connection. The connection is established via OAuth 2.0 (3LO). We receive from Atlassian access and refresh tokens with the scopes read:jira-work, read:jira-user, write:jira-work, read:me, offline_access. We store your Atlassian account ID, the Cloud ID of your Jira instance, the scope of the granted permissions and the access and refresh tokens. The tokens are stored encrypted (Fernet, symmetric encryption with a key held only on the server).
Which Jira content is processed. For the issues you select we retrieve, via the Jira API: title, description, comments, status, assignments and attachments. This content may contain personal data — names of colleagues, customers, email addresses in free text.
As a rule we retrieve this data on demand and do not store it permanently. For performance and traceability reasons the following caches exist: the classification cache (result of the obligation assignment per issue), the attachment text cache (text extracted from PDF or Office attachments), the context delta (change state of an issue since the last analysis) and the compliance tasks (compliance tasks created or linked in Jira).
Disconnecting. You can disconnect the integration at any time in the settings, or revoke access in your Atlassian account. The stored tokens are then deleted.
Legal basis. Article 6(1)(b) GDPR (provision of the integration you have requested). Atlassian is not our processor in this respect but the source from which you make data available to us for processing.
Purpose. Obligation assignment at ticket level, evidence keeping in ticket context.
Retention. Caches: 90 days after last access. Compliance tasks: until you delete them in Jira or disconnect the integration. On disconnection, all caches relating to the affected issues are deleted.
AI-assisted processing
10.1 Provider used
For classification, assessment, text suggestions and the dialogue-based assistant, we use language models from Mistral AI SAS, 15 rue des Halles, 75001 Paris, France. Processing takes place on servers in the European Union. A data processing agreement under Article 28 GDPR is in place; a written exclusion of the use of your content for model training is part of the contractual arrangement.
No transmission to providers outside the EU takes place — in particular not to OpenAI, Google or Anthropic.
The following functions transmit data to Mistral: classification of issues by applicable obligations, assessment of recorded evidence, generation of evidence drafts and suggestion texts, prefilling of templates from existing context, questions and answers in the compliance assistant, and the conversion of your search and assistant queries into numeric representations (embeddings) for similarity search in the legal-text repository (see Section 10.7).
10.2 Pseudonymization before transmission
Before content is transmitted to the language model, it undergoes pseudonymization: detected personal identifiers — names, email addresses, phone numbers, account and customer numbers, account identifiers, technical resource identifiers — are replaced with placeholders such as [PERSON_A]. The model sees only the placeholders. In the response, placeholders are resolved back to the original values for display to you.
The mapping table placeholder–original exists exclusively in memory for the duration of the single request and is discarded afterwards. It is not stored. Additionally, we check the model's response for personal data it may have invented that did not appear in your input, and count such cases.
Pseudonymization before transmission currently applies to the following functions: evidence assessment, evidence drafting, template prefilling, suggestion texts, classification and champion-text generation.
10.3 Exception: compliance assistant (chat)
In the dialogue-based assistant, the text transmitted to the model is currently not pseudonymized. The reason is how the assistant works: during a conversation it autonomously calls tools that load further context; a mixture of placeholders and plaintext in the same dialogue leads to incorrect attributions and thereby to incorrect compliance statements. Instead, we transparently log which personal identifiers were included in a dialogue step and show this to you on every answer. Before your first use of the assistant, we explicitly point out this exception in a transparency dialog. An extension of pseudonymization to the assistant is in progress.
10.4 What we log about AI usage
Transparency log. For every AI call we store: the pseudonymized request text, the pseudonymized response, a list of the replaced categories with placeholder and count (without the original values), the number of invented personal identifiers in the response, and call metadata (user account, timestamp, model used). Legal basis: Article 6(1)(f) GDPR. Purpose: evidence keeping and internal quality control. Retention: 12 months.
Dialogue history. Your chat sessions, individual messages and the assistant's tool calls are stored in plaintext so that you can review and continue your history. This is a deliberate trade-off in favour of traceability; access to the database is restricted to operations. Retention: 18 months from the last activity in the session.
10.5 Legal basis
The legal basis for AI-assisted processing is Article 6(1)(b) GDPR (performance of contract), as the AI analysis constitutes the core service of the Platform and the Platform cannot fulfil its purpose without it. For the optional evaluation of Jira contexts (Section 9), your separate activation of this integration additionally applies, which you can withdraw at any time.
10.6 No automated decision-making in individual cases
The AI-assisted analyses produce proposals and assessments, not binding decisions. Each result is shown to you with a confidence value and the underlying legal source and must be confirmed by a human before it counts as evidence. No automated decision-making in the individual case, including profiling within the meaning of Article 22 GDPR, takes place.
10.7 Vector database and embeddings
For finding relevant legal texts we use a vector database (Qdrant) that runs in the process of our own application on the Hetzner server in Germany. No external provider is integrated for the database.
Only numeric representations (embeddings) of EU legal texts are persisted long-term in this database — in particular from the AI Act, GDPR, CRA and Data Act. Your account, project or evidence data is not stored in the vector database.
Your queries are also embedded, but not stored. To enable a similarity search between your query and the legal texts, the query text is converted into a numeric representation at the moment of processing by the embedding model of Mistral AI SAS (EU location). The pseudonymization described in Section 10.2 applies before this transmission to Mistral. The resulting query vector is used only for the single search and is discarded afterwards.
Browser extension TrustTroiAI Inspector
Description. The browser extension shows you, within a Jira issue, which EU compliance obligations apply to the work described in the issue and lets you record evidence against those obligations. It is an access channel to the Platform; an Inspector account is at the same time a Platform account. All processing described in Section 8 (compliance projects, assessments and evidence), Section 9 (Jira integration) and Section 10 (AI-assisted processing) applies accordingly when you use the extension.
In addition to central server storage, the extension stores in your browser's local extension storage: the session token (lifetime 30 days), your email address and the site name. This local storage remains on your device.
Legal basis, purpose and retention follow from the sections referenced above. You can disconnect the extension at any time via "Sign out" in the extension menu, which invalidates the session token immediately, and revoke access under "Connected apps" in your Atlassian account.
A compact English version of this policy, specifically addressing the requirements of the Chrome Web Store, is available at /extension-privacy.
Reach measurement and usage events
Description. To improve the Platform we collect usage events in our own database: page accessed, event type, referrer, browser identifier (user agent), a random session identifier, where applicable your user account ID and a hash of your IP address (SHA-256, truncated). The IP address itself is not stored.
Evaluation takes place exclusively on our own server. No data is transmitted to analytics providers such as Google Analytics and no cross-device profiles are created.
Legal basis. Article 6(1)(f) GDPR (legitimate interest in needs-based design of the service).
Purpose. Improvement of functionality and usability.
Retention. 12 months from the event, after which it is automatically deleted.
Right to object. You may object to this processing under Article 21 GDPR by sending a message to privacy@trusttroiai.eu.
Transactional emails
Description. For sending system emails — account verification, password reset, notifications, requests for expert review — we use Resend, Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA). Data transmitted: email address, name, content of the respective email. Data location: USA.
Legal basis. Article 6(1)(b) GDPR (performance of contract).
Purpose. Delivery of transactional messages you receive or trigger from the operation of the Platform.
Third-country transfer. The transfer is safeguarded by the Standard Contractual Clauses under Article 46(2)(c) GDPR. Additional technical and organisational measures by the provider apply.
Retention. Email contents are kept at Resend only as long as necessary for delivery and subsequent delivery-tracking purposes.
Processing on behalf of our customers
Insofar as you use the Platform as an organisation and thereby enter personal data of your staff, customers or third parties — including via the Jira integration — you are the controller in that respect within the meaning of the GDPR. We process this data on your behalf under Article 28 GDPR.
For this purpose we provide you with a data processing agreement, which also contains the list of sub-processors used. Enquiries to privacy@trusttroiai.eu.
Recipients and transfers to third countries
Recipients of personal data are exclusively the service providers named above:
- Hetzner Online GmbH, Gunzenhausen, Germany — server hosting and database. No third-country transfer.
- Mistral AI SAS, Paris, France — language models. No third-country transfer.
- Resend, Inc., USA — transactional emails. Third-country transfer, safeguarded by the Standard Contractual Clauses under Article 46(2)(c) GDPR.
Atlassian is not a sub-processor but the source from which you make data available to us for processing (see Section 9).
No transfer of your data to other third parties takes place unless we are legally required to do so or you have expressly consented.
Retention and deletion
We process personal data only for as long as is necessary for the respective purposes. The specific retention periods are stated with the individual processing operations in this policy. In summary:
- Account data, project, assessment and evidence data: for the duration of the contractual relationship
- Chat sessions and messages: 18 months from the last activity
- AI transparency log: 12 months
- Usage events: 12 months
- Jira caches: 90 days after last access
- Server log files: 14 days
- Application logs (redacted): 30 days
- Session token: 30 days; invalidated immediately on sign-out
After termination or a deletion request, your personal data is deleted within 30 days. Excluded is data for which statutory retention obligations apply — in particular commercial and tax retention periods of six or ten years pursuant to Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO).
On the deletion process. We delete your record in two stages. Immediately upon your request, all identifiers relating to you — email address, first and last name, account identifiers — are removed from your user record and your sessions are revoked. This removes the personal reference within the meaning of Article 4(1) GDPR. The technical links to your evidence and releases initially remain, so that the auditability of already granted compliance releases is not destroyed for the projects of your organisation that continue to exist. At the latest 30 days after your deletion request, these records are also deleted permanently.
Your rights
Under the GDPR you have the following rights against us:
- Access (Article 15 GDPR) — which data we process about you
- Rectification (Article 16 GDPR) — correction of inaccurate data
- Erasure (Article 17 GDPR) — see Section 16
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR) — release of the data you provided in a commonly used, machine-readable format. Release is currently made on request by email; a self-service export is in progress.
- Objection (Article 21 GDPR) — against processing based on our legitimate interest
- Withdrawal of consent given (Article 7(3) GDPR) — with effect for the future. The lawfulness of processing carried out until the withdrawal remains unaffected.
Account closure and deletion are currently carried out on request by email to privacy@trusttroiai.eu. We respond to your requests without undue delay and at the latest within one month.
Right to lodge a complaint with a supervisory authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Article 77 GDPR), in particular in the Member State of your residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
www.ldi.nrw.de
Data security
We take technical and organisational measures to protect your data, in particular:
- Transport encryption of all connections (TLS/HTTPS)
- Passwords stored exclusively as bcrypt hashes
- Session tokens stored only as hash values in the database; cookies with
HttpOnlyandSecure - Encrypted storage of access tokens for third-party systems (Fernet)
- Pseudonymization of personal identifiers before transmission to the language model (Section 10.2)
- Redaction of personal content before writing to system logs
- Restriction of administrative functions to an explicitly maintained list of authorised accounts
- Limitation of AI usage per account and day as abuse protection
- Server location Germany
Changes to this privacy policy
We update this privacy policy when the legal situation or our processing changes. The current version is available on this page. Material changes are announced in advance.