Privacy notice
Last updated 30 September 2026. This notice covers the FairAudit app and the fairaudit.ai website.
In short
- Controller: Inclusive Data SL, stela@fairaudit.ai.
- Purpose: give you access to the private beta and answer your questions; answer your early-access application and hold a call you book; product updates only if you tick the box.
- Legal basis: steps before a contract and our legitimate interest in running a gated service; your consent for updates.
- Recipients: the processors listed below, some in the US.
- Your rights: access, correction, deletion, restriction, objection, portability, and withdrawing consent. Write to stela@fairaudit.ai.
What we collect, and why
Applying for early access on this website. Your name, work email, role and company if you give them, what you are applying for, and anything you write. Purpose: to answer your application. Basis: the steps needed before entering into an agreement with you (GDPR Art. 6(1)(b)). The form is handled by Formspree; see the processors and transfers below.
Booking a call. If you book a demo or a feedback call, the booking goes through Google Calendar, part of Google Workspace, which already handles our email. Google receives the name and email you enter and the time you choose. Purpose: to hold the call. Basis: the steps needed before entering into an agreement with you (GDPR Art. 6(1)(b)).
Signing in. Your email address, used to send you a sign-in link through Supabase. We keep a sign-in record: your email, when you first and last tried to sign in, and how many attempts were made. Purpose: to run an invite-only beta, grant or refuse access, and enforce per-person usage limits. Basis: the steps needed before entering into an agreement with you, and our legitimate interest in running a gated service securely (GDPR Art. 6(1)(b) and (f)). Your email is needed to sign in; you can ask us for an access code instead. The first time you sign in, an alert with your address goes to the operator through Google Workspace so access can be granted. Once access is granted, we email you through Google Workspace to say it is ready.
Product updates (optional). At sign-in, and on the early-access form, you can tick a box to receive occasional product updates. It is unticked by default and not a condition of access. We store your choice, the wording you saw, and the time. Basis: your consent (GDPR Art. 6(1)(a); LSSI Art. 21). Withdraw it at any time by replying to any update email or writing to stela@fairaudit.ai; we record the withdrawal with its date.
Using the assistant. The questions you ask and the answers you receive are sent to AI model providers to generate the answer. We do not store your conversations: they are held in server memory only while you use them, under a random identifier, and are gone when the server restarts or a new version is deployed; your browser keeps them for the tab only. We record usage and cost per person per day, to enforce spend limits. Our server logs hold technical data only: your IP address, the time, the address requested and its status, timings, which passages of the law were retrieved, token counts and cost, a pseudonymous reference to your account, and errors. They don’t contain the content of your questions or the answers, and email addresses are masked. A conversation or report leaves the system only when you click Export. Basis: providing the service you asked for (GDPR Art. 6(1)(b)). Please don’t paste personal data about other people into the assistant.
No tracking. No advertising cookies or pixels. The app stores your access code and session in your browser only to keep you signed in. This website counts visits in aggregate, without identifying you.
No automated decisions about you. We don’t make decisions with legal or similarly significant effects about you by automated means. Access is granted by a person.
Who processes it for us
Supabase (sign-in), Vercel (hosting of the app and of this website), Fly.io (the API; our servers run in Amsterdam), Google Workspace (access emails and call bookings), Formspree (the early-access form on this website), and the AI model providers reached through OpenRouter, plus Mistral as a direct fallback. Each acts on our instructions under a data processing agreement.
Transfers outside the EU
Some of these providers are US companies. The safeguard for each:
- Vercel: certified under the EU-US Data Privacy Framework, plus standard contractual clauses in its DPA.
- Supabase: sign-in data is stored in the EU (Ireland); Supabase is a US company, so its DPA includes standard contractual clauses for any access from outside the EU.
- Fly.io: our servers run in the EU (Amsterdam); Fly.io’s data processing agreement, signed with us, includes the EU standard contractual clauses, and Fly.io is certified under the EU-US Data Privacy Framework.
- Google Workspace: Google LLC is certified under the EU-US Data Privacy Framework, and Google’s Cloud Data Processing Addendum relies on that certification for transfers to the US; the EU standard contractual clauses apply if Google stops relying on it.
- OpenRouter and the model providers behind it: OpenRouter is not certified under the Data Privacy Framework; its data processing agreement, part of its terms for business use, incorporates the EU standard contractual clauses (controller to processor). OpenRouter must bind the model providers it uses to data protection terms no less protective than its own.
- Formspree: a US company; the form data is hosted on Amazon Web Services in the United States. Formspree states that it relies on the EU standard contractual clauses as a data processor (its published security information).
- Mistral: based in the EU, no transfer.
How long we keep it
- Early-access applications: deleted 6 months after our last contact about your application. These are deleted by hand, not by the daily run below.
- Sign-in requests that are never granted: deleted 30 days after your first attempt, or sooner if we dismiss them.
- Sign-in records of authorised users: kept while you have access, deleted 6 months after your access ends.
- Usage and cost records: deleted after 90 days.
- Product-update consent: kept while you’re subscribed. After you withdraw, we keep the record for 3 years, only as proof of what you agreed to, because Spanish data protection law allows an infringement of this kind to be pursued for 3 years; then it is deleted. If you left the box unticked, that answer is deleted with your sign-in record.
- Server logs: our own log file is overwritten as it fills and wiped whenever a new version is deployed; Fly.io’s log search keeps them for 7 days.
- Conversations: not stored.
Deletion runs automatically every day. Everything else is deleted on request, except what the law requires us to keep.
Your rights
You can ask to see, correct or delete what we hold, restrict or object to its use, receive a copy, and withdraw consent at any time without affecting what came before. One email does it: stela@fairaudit.ai. We answer within one month. You can also complain to the Spanish data protection authority (AEPD, aepd.es) or the authority where you live.
We also mark and sign what the assistant generates, as the EU AI Act requires: transparency.