Legal
Privacy Policy
Last updated: 2026-01-15
This Privacy Policy explains how AIBRAI (“we”, “us”) processes personal data on aibrai.com. We comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP / nFADP).
1. Data controller
AIBRAI · info@aibrai.com · Headquartered in Bern, Switzerland with a branch in Vienna, Austria. Contact us at any time at info@aibrai.com.
2. What we collect and why
- AI Bias Registry submissions — only what you choose to enter. You may submit anonymously. We do not require an email address. Submissions are stored to support research, regulatory intelligence and public accountability.
- Contact form — name, email, organisation and message you send us, used only to respond to your enquiry.
- Newsletter — your email address, used solely to send the AIBRAI briefing. Unsubscribe at any time.
- Abuse-prevention signals — a salted hash of your IP address and a Cloudflare Turnstile result are stored for up to 48 hours to block automated abuse.
- Server logs — minimal request logs kept for security and operations.
3. Legal basis (GDPR Art. 6)
- Consent — newsletter, optional registry fields.
- Legitimate interest — public accountability research, abuse prevention, security.
- Contract / pre-contract — responding to enquiries and engagements.
4. Sharing and processors
We do not sell personal data. Limited categories of sub-processors operate our infrastructure under data-processing agreements: Supabase (database and authentication), Cloudflare (network, bot mitigation) and our transactional email provider. Aggregated, anonymised registry statistics may be published.
5. International transfers
Data may be transferred outside Switzerland and the EEA under appropriate safeguards (Standard Contractual Clauses or equivalent).
6. Retention
Registry submissions are retained as long as needed for research and public-interest accountability. Excel exports generated for internal review are deleted automatically after 30 days. Email-send logs are purged after 90 days. Abuse signals are purged after 48 hours.
7. Your rights
You may request access, rectification, deletion, restriction, objection, portability and to withdraw consent at any time. See the dedicated data-request (DSAR) page for the full process, response times and identity checks. For anonymous registry submissions, use your reference code at /registry/delete. You may also complain to a supervisory authority (e.g. the Swiss FDPIC).
8. Cookies and consent
We use only strictly necessary cookies and local storage entries required to run the site (authentication session, cookie preference). Optional analytics and marketing categories are exposed in the cookie banner and are off by default. You can change your choice at any time from the "Cookie preferences" link in the footer. We do not use advertising or cross-site tracking cookies.
9. Security
Encryption in transit (HTTPS), row-level access policies, salted IP hashing, CAPTCHA verification, rate limiting and HIBP-leaked-password checks on sign-up.
10. Changes
We will post any updates to this page and update the “last updated” date above.
