GDPR Compliance Statement

Last updated: March 27, 2026

1. Purpose

This statement describes how The AI Check ("AIC," "we," "us," or "our") complies with the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"). It is intended for users, enterprise customers, data protection officers, and supervisory authorities who need to understand our data protection posture.

This document should be read alongside our Privacy Policy, Sub-Processor List, and Terms of Service.

2. Data Controller

ControllerGreg Monzar (or AIC legal entity once incorporated)
Contact Email[email protected]
Data Protection OfficerNot required at current scale. AIC will appoint a DPO when its core processing activities meet the "large scale" criteria defined by GDPR Article 37 and European Data Protection Board (EDPB) guidelines — specifically, regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data. This assessment is reviewed periodically as AIC's user base grows.
EU Representative (Art. 27)Required under Article 27 if AIC processes EU personal data on more than an occasional basis without an EU establishment. AIC will appoint an EU Representative before actively marketing to EU users. Appointment details will be published here and in our Privacy Policy when finalized.

3. Lawful Bases for Processing

AIC processes personal data under the following lawful bases:

Processing ActivityLawful BasisGDPR Article
Account creation and authenticationPerformance of contractArt. 6(1)(b)
Encrypted vault storage and retrievalPerformance of contractArt. 6(1)(b)
Billing and subscription managementPerformance of contractArt. 6(1)(b)
Security monitoring and fraud preventionLegitimate interestArt. 6(1)(f)
Analytics — anonymized, no PII (Plausible)Legitimate interestArt. 6(1)(f)
Marketing to existing customers (product updates)Legitimate interest (soft opt-in) + opt-out requiredArt. 6(1)(f)
Marketing to new subscribers (newsletter)ConsentArt. 6(1)(a)

4. Special Categories of Data (Article 9)

AIC does not intentionally process special category data (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, sexual orientation, etc.).

Encrypted vault content is stored as ciphertext. Under current European Data Protection Board (EDPB) guidance, strongly encrypted data is still legally considered personal data if a decryption key exists — even if that key is held exclusively by the user and is inaccessible to AIC. AIC therefore treats vault ciphertext as personal data for GDPR compliance purposes. However, AIC's technical inability to decrypt vault content means that the risks associated with processing data that may include special categories are mitigated to near zero — AIC cannot access, read, classify, or use the data regardless of its nature.

5. Zero-Knowledge Architecture and GDPR

AIC's zero-knowledge encryption model (the "Zurich Protocol") has specific implications for GDPR compliance:

  • Data minimization (Art. 5(1)(c)): AIC stores the minimum data necessary. Vault content is stored as ciphertext only — AIC cannot access or use it beyond storage and retrieval at the user's direction.
  • Data protection by design (Art. 25): Client-side AES-GCM-256 encryption with per-conversation envelope encryption is built into the architecture from the ground up, not bolted on as an afterthought.
  • Security of processing (Art. 32): Encryption at rest (ciphertext in database), encryption in transit (TLS), access controls via Supabase Row Level Security, PBKDF2 key derivation, unique IV per encryption operation.
  • Breach impact reduction: In the event of a data breach, compromised vault data consists of ciphertext that is computationally infeasible to decrypt without the user's master key, which AIC does not hold. This materially reduces the risk to data subjects.

6. Data Subject Rights

AIC supports the exercise of all GDPR data subject rights:

RightGDPR ArticleHow to ExerciseResponse Time
AccessArt. 15Dashboard data export (self-service) or email [email protected]Self-service: immediate. Email: 30 days.
RectificationArt. 16Dashboard settings (self-service)Immediate
ErasureArt. 17Dashboard account deletion (self-service). Cryptographic erasure is immediate; account metadata rows deleted within 30 days.Immediate (crypto); 30 days (metadata)
PortabilityArt. 20Dashboard export in JSON — a structured, commonly used, and machine-readable format (self-service)Immediate
ObjectArt. 21Email [email protected]. Users may opt out of analytics and marketing communications.30 days
RestrictionArt. 18Email [email protected]30 days
ComplaintArt. 77Contact your national supervisory authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany). You may also contact AIC first and we will attempt to resolve the matter.N/A (supervisory authority sets timeline)

Zero-knowledge limitation: AIC can provide access to, export, or delete account metadata and encrypted vault data. However, AIC cannot provide vault content in plaintext — only the user holds the decryption key. Data subject access requests for vault content must be fulfilled by the user themselves via the self-service export and decrypt features.

7. International Data Transfers

AIC is operated from Canada. The European Commission has recognized Canada as providing an adequate level of data protection under its Personal Information Protection and Electronic Documents Act (PIPEDA). The initial transfer of personal data from the EEA to AIC therefore benefits from this adequacy decision.

AIC's primary infrastructure is hosted in the United States via Supabase (Amazon Web Services) and Vercel (AWS / Google Cloud Platform). For onward transfers of personal data from AIC to these US-based sub-processors, AIC relies on:

  • Standard Contractual Clauses (SCCs) as adopted by the European Commission (Module 2: controller to processor), incorporated into our agreements with sub-processors where available.
  • EU-U.S. Data Privacy Framework (DPF) certification, where the sub-processor is actively certified.

UK-specific transfer mechanisms: Post-Brexit, the United Kingdom operates under the UK GDPR. Transfers of personal data from the UK to US-based sub-processors rely on the UK Addendum to the EU Standard Contractual Clauses and, where applicable, the UK Extension to the EU-U.S. Data Privacy Framework.

The transfer of encrypted vault content carries significantly reduced risk because the data is ciphertext — even if intercepted or accessed by an unauthorized party, it is computationally infeasible to decrypt without the user's master key.

Enterprise customers subject to GDPR may request EU data residency for their Supabase database instance. See our Sub-Processor List for details.

8. Data Breach Notification (Articles 33 and 34)

AIC will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to the rights and freedoms of data subjects, as required by Article 33.

Where the breach is likely to result in a high risk to affected individuals, AIC will also notify the affected data subjects without undue delay, as required by Article 34.

Zero-knowledge impact on breach severity: A breach of AIC's database would expose encrypted vault content as ciphertext only. Without each user's individual master key (which AIC does not hold), the vault data is meaningless to an attacker. This materially reduces the severity assessment under Article 33(1) for vault content. However, unencrypted account metadata (email addresses, billing references, sync logs) is subject to standard breach notification obligations.

9. Records of Processing Activities (Article 30)

AIC maintains internal Records of Processing Activities (ROPA) as required by Article 30. The ROPA includes:

  • Categories of data subjects (registered users, enterprise workspace members, website visitors)
  • Categories of personal data processed (account data, encrypted vault content, billing data, analytics)
  • Processing purposes (authentication, encrypted storage, billing, product improvement)
  • Categories of recipients and sub-processors (see Sub-Processor List)
  • Third-country transfers and transfer mechanisms (SCCs, DPF)
  • Retention periods (see Privacy Policy Section 7)
  • Technical and organizational security measures (client-side encryption, RLS, TLS, PBKDF2)

The ROPA is an internal document and is not published. It is available to supervisory authorities on request.

10. Data Processing Agreements

Enterprise customers who use AIC as a data processor on behalf of their organization may request a Data Processing Agreement (DPA) that complies with GDPR Article 28. The DPA covers:

  • Processing instructions and scope
  • Confidentiality obligations
  • Technical and organizational security measures (Article 32)
  • Sub-processor authorization and notification
  • Assistance with data subject rights requests
  • Data deletion or return on termination
  • Audit rights
  • International transfer mechanisms (SCCs, Module 2: controller to processor)

To request a DPA, contact [email protected].

11. Technical and Organizational Security Measures (Article 32)

AIC implements the following measures to ensure a level of security appropriate to the risk:

  • Encryption at rest: All vault content encrypted with AES-GCM-256 using per-conversation envelope encryption. Unique initialization vector (IV) per encryption operation — IV reuse is treated as a critical vulnerability.
  • Encryption in transit: All connections use TLS 1.2 or higher.
  • Zero-knowledge design: AIC never possesses, transmits, or stores plaintext vault content or user API keys. Decryption occurs exclusively on the user's device.
  • Access controls: Supabase Row Level Security (RLS) enforced on all database tables with no exceptions. Users can only access their own data.
  • Authentication: Supabase Auth with hashed passwords. PKCE flow for OAuth.
  • Principle of least privilege: Service accounts and API keys scoped to minimum required permissions.
  • No plaintext logging: AIC does not log vault content, encryption keys, or API keys in application logs, error reports, or monitoring systems.

12. Automated Decision-Making and Profiling (Article 22)

AIC does not engage in automated decision-making or profiling as defined by GDPR Article 22. AIC does not build user profiles, does not make automated decisions that produce legal effects or similarly significant effects concerning users, and does not use personal data for targeted advertising or behavioural analysis.

13. Children and Age of Consent (Article 8)

GDPR Article 8 governs the conditions applicable to a child's consent in relation to information society services. AIC complies with Article 8 by requiring all users to be at least 18 years of age to create an account or use the Service. This minimum age is set above the thresholds in Article 8 (16 years, or as low as 13 in certain Member States) to provide a clear compliance margin and to align with the contractual capacity requirements in our Terms of Service.

AIC does not knowingly collect personal data from children under 18. If we become aware that a user is under 18, their account will be terminated and their data deleted. If you believe a child under 18 has created an AIC account, please contact [email protected].

14. Contact

For GDPR-related inquiries, data subject rights requests, or to report a data protection concern, contact us at [email protected].

You also have the right to lodge a complaint with your national data protection supervisory authority at any time.

This document was last updated on March 27, 2026. It is a pre-launch draft and will be reviewed by legal counsel before becoming effective.