Privacy Policy
Who we are
The AI Use Evidence platform and this website are operated by Elkhan Guliyev, an individual entrepreneur registered in the Republic of Azerbaijan.
For any question about this policy or about your personal data, write to support@aiuseevidence.com. We answer data subject requests at that address.
The two roles we act in
This distinction determines who you should contact, so it comes first.
We are the controller for personal data about visitors to this website, about people who contact us, and about the administrators and consultants who hold accounts with us. We decide why and how that data is processed, and this policy describes it.
We are a processor for personal data about the employees of a client organisation — the people who receive policy acknowledgement requests and training assignments. That data is entered by the client organisation or by the consulting firm acting for it, and we process it only on their documented instructions. The client organisation is the controller and decides why the data is there and how long it stays.
If you are an employee who received an email from us about your employer's AI policy or training, your employer decides what happens to your data. Contact your employer first. If you contact us, we will pass your request to them and help them answer it.
What we collect and why
When you visit this website
Our servers and our network provider record the request: IP address, the page requested, the time, the referring page, and browser and device information. We use this to serve the site, to keep it secure, and to detect abuse. This site sets no analytics or advertising cookies.
When you contact us
We keep your name, email address, and the content of the correspondence, so that we can answer and keep a record of what was agreed.
When you hold an account
Name, work email address, organisation, role and permissions, language preference, authentication records including sign-in times and the devices used, and — on paid plans — billing contact details and subscription history. We use this to give you access, to secure the account, to bill you, and to send service messages about the platform.
Because the platform produces audit evidence, actions taken inside it are recorded in an audit trail: who did what, to which record, and when. The audit trail cannot be edited or selectively deleted, which is the point of it.
On behalf of a client organisation
Employee name, work email address, job title, department, role, language, time zone, start date, and the governance records that follow from these: which policy version a person acknowledged and when, which training they were assigned and completed, their assessment results, and the AI tools associated with their account when a discovery connection is used. We act as processor for all of it.
Our legal bases
Where the GDPR applies, we rely on the following as controller:
| Purpose | Legal basis |
|---|---|
| Providing the platform to an account holder | Performance of a contract |
| Billing, invoicing, accounting records | Contract; legal obligation |
| Service email about the platform (outages, changes, security) | Legitimate interests — you need to know |
| Site security, abuse detection, server logs | Legitimate interests — protecting the service |
| Answering correspondence | Legitimate interests; contract where you are a customer |
As processor for employee data, the legal basis is chosen by the client organisation, not by us.
Who processes data on our behalf
We keep the list of sub-processors short deliberately. The database, cache, and file storage run on our own servers rather than on managed third-party services.
| Sub-processor | Purpose | Established in |
|---|---|---|
| Contabo GmbH | Server hosting | Germany |
| Cloudflare, Inc. | DNS, TLS, content delivery, protection against attack | United States |
| Mailgun Technologies (Sinch) | Sending platform email, EU sending region | United States / EU infrastructure |
| Dodo Payments | Payment processing as merchant of record | See their own privacy notice |
| Infomaniak Network SA | Our business mailbox, used for correspondence with us | Switzerland |
We do not sell personal data, we do not share it with advertising networks, and we do not use it to train machine learning models. We disclose data to anyone else only where the law requires it, and we will tell the affected customer unless we are prohibited from doing so.
Client organisations are notified before we add a sub-processor that will handle employee data, so that they can object.
International transfers
We state this plainly because our customers are asked about it in their own audits: we are established in the Republic of Azerbaijan, which is not covered by a European Commission adequacy decision. Where we process personal data originating in the European Economic Area, we do so under the European Commission's standard contractual clauses, together with the technical measures described in §8.
Application data is stored on servers we operate, and their location is set out in the data processing agreement. Our sub-processors are listed in §5 with their place of establishment; each transfer to them relies on standard contractual clauses or another transfer mechanism permitted under Chapter V of the GDPR.
How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 30 days for export, then deleted or anonymised |
| Employee data held for a client organisation | The period that organisation configures; deleted or pseudonymised at their instruction |
| Audit trail | Kept for the evidentiary period the client organisation sets — its value depends on it not being editable |
| Billing and tax records | As long as tax law requires |
| Web server and application logs | Short operational period, then rotated out |
| Encrypted backups | 14 days, then overwritten |
Deleting a record removes it from the live system immediately. Because backups are snapshots, a deleted record can persist in an encrypted backup for up to 14 more days before it is overwritten. Backups are used only to restore the service after a failure.
How we protect it
- Isolation between customers is enforced by the database, not by application code. Every tenant-scoped table has row-level security applied without exception, so a query that forgets a filter returns nothing rather than another customer's data.
- All traffic to the platform is encrypted in transit with TLS.
- Files uploaded to the platform are scanned for malware and are not served to anyone until the scan has passed.
- Actions are written to an append-only audit trail that cannot be edited or selectively deleted.
- Backups are encrypted, and the decryption key is held outside the servers being backed up.
- Credentials and API keys exist only on the production server, never in source control.
- Access to production is limited to the operator of the service and is logged.
No system is perfectly secure. If a personal data breach occurs, we will notify affected controllers without undue delay so that they can meet their own notification deadlines, and we will notify regulators and individuals where we are required to.
Your rights
Subject to the conditions in applicable law, you may ask us to give you access to your personal data, correct it, delete it, restrict how we use it, or provide it in a portable format. You may object to processing we base on legitimate interests, and you may withdraw consent where we relied on it, without affecting what happened before.
Write to support@aiuseevidence.com. We reply within one month; if a request is complex we may extend that and will tell you why. We do not charge for this, and we may need to verify your identity before acting.
If we hold your data as processor for your employer, we will forward your request to them, because the decision is theirs to make.
You may also complain to a data protection authority — in the EEA, the supervisory authority of your country of residence or workplace.
Cookies
This website sets no cookies and runs no analytics or advertising scripts. That is why you are not being asked to dismiss a consent banner.
The platform itself sets only the cookies needed to keep you signed in and to protect the session against cross-site request forgery. These are strictly necessary and cannot be switched off without breaking sign-in.
Children
The platform is a business service. It is not directed at children and we do not knowingly collect data about anyone under 18. If you believe we have, tell us and we will delete it.
Changes to this policy
We will update this page when our processing changes and will move the version and effective date at the top. If a change materially affects how we handle your personal data, we will notify account administrators by email before it takes effect.