This Privacy Policy explains how [Euridium legal entity name] (“Euridium”, “we”), established at [registered address, Brussels, Belgium] and acting as data controller, processes personal data when you use the Euridium platform (the “Service”). For any privacy question you can contact us at [privacy@euridium.eu][, and our Data Protection Officer at [dpo@euridium.eu]].
| Category | Examples | Source |
|---|---|---|
| Account data | First and last name, email, country, date of birth, organisation, password (stored hashed by our authentication provider) | You, at sign-up |
| Profile & preferences | Organisation details, theme, marketing opt-in, terms-acceptance timestamp | You |
| Compliance content | Systems, assessments, obligations, contracts, vendors, incidents, certifications, remediation notes, and any documents/evidence you upload | You |
| Technical data | Session tokens, and limited local-storage values (theme, remembered email) | Automatically |
We do not knowingly collect special-category data. Please do not upload personal data of third parties as “evidence” unless you have a lawful basis to do so.
We rely on the following processors. A current list is available on request.
| Processor | Purpose | Location / safeguards |
|---|---|---|
| Supabase | Database, authentication and file storage | [Region]; [SCCs / adequacy as applicable] |
| Microsoft Azure OpenAI | AI features (copilot, drafting, clause extraction). Content you submit to these features is sent for processing. | [Region]; processed and not used to train foundation models per the provider's terms — [confirm] |
| [Hosting / CDN, e.g. Netlify] | Static front-end delivery | [Region] |
Where personal data is transferred outside the EEA, we rely on appropriate safeguards (such as European Commission Standard Contractual Clauses or an adequacy decision). Details: [describe transfer mechanism].
We keep account and compliance data for as long as your account is active, and for [X] after closure unless a longer period is required by law. You can delete your account at any time from Settings → Account, which removes your associated data subject to legal retention obligations.
Access to your data is restricted to your account through database row-level security. Data is encrypted in transit (TLS). [Describe encryption at rest, backups, access controls, and any audits/certifications — e.g. ISO 27001/SOC 2 status.]
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to certain processing, and withdraw consent at any time. You can exercise several of these directly in Settings → Account (export and deletion). To make any other request, contact [privacy@euridium.eu]. You also have the right to lodge a complaint with your supervisory authority (in Belgium, the Autorité de protection des données / Gegevensbeschermingsautoriteit).
We do not use advertising cookies. We use strictly necessary browser storage for your session, your theme preference, and (only if you choose “Remember my email”) your email address.
We may update this policy; material changes will be notified in-app or by email. The “last updated” date reflects the current version.