Privacy notice

Last updated: 2026-07-09

1. Who is the controller

The data controller for GAAI Cloud is DigiPulse. Full legal details are available in the Imprint.

  • VAT / BCE : BE1000.838.278 (establishment 2.350.182.613)
  • Email for privacy requests : privacy@gaai.cloud
  • Postal address : Rue Mazy 118/022 bus 2A, 5100 Jambes (Namur), Belgium

2. What data we process

GAAI Cloud is a governance layer for AI agents. We deliberately keep the data we process narrow.

Account & billing

  • Email address (for sign-in, transactional email, billing receipts).
  • Name and country (for VAT compliance), collected by our payment processor Paddle.
  • Subscription state (tier, period, status) — necessary to provide the service.

Workspace governance entries

  • The decisions, memory entries, and acceptance criteria you (or your AI agent on your behalf) write into your workspace. Treat these as you would a private project notebook.
  • An append-only audit log of every governance action, HMAC-pseudonymised so user identifiers cannot be reversed without the per-organisation key.
  • Workspace routing identifiers appear in audit rows and in per-call routing records. These constitute pseudonymous personal data under Art. 4(5) GDPR: they cannot identify a natural person without your account record, which is held separately and never included in the audit chain. They are protected by the same HMAC-SHA256 per-organisation pseudonymisation key.

Cross-workspace fan-out (Art. 13(1)(c))

When your agent session has access to multiple workspaces, the service may performcross-workspace fan-out reads — retrieving governance entries from each workspace in parallel in response to a single tool call. The scope of this processing is bounded exclusively to workspaces where you hold an active membership. Results are returned directly to your agent session and are not stored, merged, or aggregated server-side (Art. 25 data minimisation: the server returns raw per-workspace rows; your agent synthesises them client-side). No fan-out is performed outside your membership boundary.

What we do not store

  • Model-provider credentials. GAAI Cloud does not ask for, store, proxy, or manage the credentials used by your connected AI tools and agents.
  • Prompts, completions, or LLM tokens. LLM inference is client-side per design ; we capture only the governance side-effects (memory writes, decisions, audit events) that you explicitly persist.
  • Source code from your repos. The agent reads your files locally ; we receive only the content you actively store as a memory entry or artefact.

Who can access your workspace content

Your workspace content is encrypted at rest (AES-256) and isolated per workspace — no other customer can ever access yours. Because GAAI Cloud runs on managed infrastructure (Cloudflare platform encryption) rather than client-held encryption keys, we — DigiPulse, as operator — retain technical access to the content you store. We access it only to operate the service, to provide support at your request, to investigate a security or abuse incident, or where the law requires it. We never access it otherwise, and we never use it to train any model.

3. Lawful bases (GDPR Art.6)

  • Performance of contract for account, billing, and core workspace functionality.
  • Legitimate interest for security audit logs and abuse prevention, balanced against data-minimisation via the HMAC pseudonymisation noted above.
  • Legitimate interest (Art. 6(1)(f)) for measuring how our website is used. This analytics is cookieless: PostHog derives a short-lived, non-reversible statistical identifier on its EU servers and stores nothing on your device. We have weighed this limited, privacy-preserving measurement against your interests and consider that it does not override your rights ; you may object at any time (§7) or send a Do-Not-Track signal, which we honour.
  • Legal obligation for accounting. Customer invoices and EU VAT records are issued and retained by our merchant-of-record, Paddle (§4), undertheir statutory obligation — not ours. On our side we keep only our own non-personal payout and reconciliation records (Belgian accounting law, 7-year retention), which carry no per-customer billing identifiers.

4. Sub-processors

We use the following sub-processors. Each has a contract that mirrors GDPR obligations.

  • Cloudflare — Workers, Durable Objects (EU jurisdiction pinned), D1, R2, Vectorize. Hosting + storage + audit archive.
  • Paddle — Merchant-of-record for EU VAT compliance, payment processing. Receives email, name, country, payment method (no card data hits us).
  • Resend — Transactional email (sender domainsend.gaai.cloud, reply-to support@gaai.cloud).
  • PostHog (EU project) — cookieless product analytics via our EU reverse proxy (v.gaai.cloudeu.i.posthog.com). No analytics cookies ; the source IP is used only in transit to derive an aggregate measure and is then discarded, never stored on your device.
  • AI model providers — only where your connected tools or agents use them independently. GAAI Cloud does not proxy model requests or receive model-provider credentials.

5. Where your data is stored

Your data is split across multiple Cloudflare services, each with its own data-residency posture. We classify them by what can and cannot be pinned to a specific jurisdiction on Cloudflare's platform today.

5.1 — Services intended for EU jurisdiction

The following Cloudflare services support EU jurisdictional pinning and hold your workspace content :

  • Durable Objects (workspace SQLite stores) — workspace state, governance memory entries, audit log records. EU jurisdiction is being progressively enforced ; until full enforcement, instances are placed on a best-effort basis in EU datacenters.
  • R2 (audit archives, KB artefacts) — audit log storage with 13-month compliance retention. Migration to EU-jurisdictional R2 buckets is in progress.
  • D1 (platform records) — organizations, users, memberships, OAuth sessions metadata. Migration to EU-jurisdictional D1 databases is in progress.

5.2 — Services without EU-only option (Cloudflare platform limitations)

Cloudflare does not currently offer jurisdictional restrictions for the following services (see Cloudflare Data Localization compatibility table) :

  • Vectorize (memory embeddings) — vector representations of your governance memory used for semantic search. Cloudflare Vectorize is a globally distributed service ; no jurisdictional restriction is available today. Embeddings are mathematical representations, not raw text, but may preserve semantic information ; we treat them as personal data under GDPR Recital 26 and apply the same retention rules as workspace content.
  • Workers KV (short-lived caches) — OAuth access tokens (≤15-minute TTL), session JWTs (≤1-hour TTL), rate-limit counters (≤1-minute TTL). Cloudflare KV does not support jurisdictional storage today. No workspace governance content is ever stored in KV.

5.3 — Cloudflare control-plane exception (transparency disclosure)

Per Cloudflare's official Durable Objects documentation, "a DurableObjectId will be logged outside of the specified jurisdiction for billing and debugging purposes"(source). This is a platform-level Cloudflare constraint we cannot opt out of without leaving Cloudflare. The Durable Object identifier is an opaque internal handle — it does not contain workspace content, account information, email, or any payload data.

Sub-processors (§4) operate under their own data-processing agreements ; details on request.

6. How long we keep it

  • Workspace governance entries : while your account is active, plus a 30-day grace period after deletion request (recoverable on user demand).
  • Audit log : personal data in audit records is retained for 13 months, after which the pseudonymisation keys are destroyed, rendering identities irreversible. The tamper-evident audit chain is kept for security and accountability under legitimate interest, but holds no re-identifiable personal data beyond 13 months. R2 compliance archives are retained for 13 months. (The 7-year retention below applies to accounting records only, not to audit logs.)
  • Billing & VAT records : invoices are held by Paddle (merchant-of-record) for the statutory period — we do not retain customer invoices. Your subscription record in our database is deleted when your organisation is erased. We keep only non-personal payout / reconciliation data for our own accounting (7 years, Belgian law).
  • Analytics : 12 months retention on PostHog EU project, automatic purge.

7. Your rights (GDPR Art.15-22)

You have the right to:

  • Access — receive a copy of the data we hold about you.
  • Rectification — correct anything inaccurate.
  • Erasure — Art.17 hard-delete is implemented end-to-end: workspace entries (Durable Object storage, embeddings, R2 objects) are destroyed; organisation, membership and subscription records are removed from our database; audit logs are pseudonymised via superseding records. Invoices already issued remain with Paddle (merchant-of-record) under its own legal-retention obligation, not ours.
  • Portability — Art.20 export of your workspace data as a ZIP archive containing SQLite tables + R2 binaries.
  • Objection / restriction — restrict processing for analytics or governance legitimate-interest entries.
  • Lodge a complaint with the Belgian Data Protection Authority (APD-GBA) atwww.dataprotectionauthority.be.

Send any request to privacy@gaai.cloud. We respond within 30 days. No fee unless the request is manifestly excessive.

Business customers who act as data controllers for the content they store in their workspace can request a Data Processing Agreement (GDPR Art. 28) atprivacy@gaai.cloud.

8. Cookies & tracking

Our website uses no analytics or advertising cookies and shows no cookie banner, because it stores nothing on your device for those purposes. Product analytics (PostHog EU) runs in cookieless mode: usage is measured with a short-lived, non-reversible hash derived from a daily-rotating salt on PostHog's EU servers, with the source IP discarded after processing — nothing is stored on or read from your device, so no consent is required under the ePrivacy Directive (Art. 5(3)).

The only cookies or local storage you may encounter are strictly necessary ones, which are exempt from consent: an anti-abuse challenge (Cloudflare Turnstile) on our forms ; cookies set by our payment provider (Paddle) if and when you begin a checkout ; and the sign-in session and security cookies of the authenticated app (app.gaai.cloud). None of these are used to track you. You can object to analytics at any time (§7) or send a Do-Not-Track browser signal, which we honour.

9. Changes

We update this notice when our practices change. TheLast updated date at the top tracks revisions. Material changes are announced by email to active subscribers at least 30 days in advance.