Which document applies to you. If AIK runs on your own server, you are the controller and the processor both: we never receive your data, and this agreement does not apply — see the security brief instead. This document is for clients whose install we host, where you decide what is processed and we process it for you.
Controller: the client organisation named in the service order. Processor: Alexander Krastev, trading as AIK Automation, Bulgaria (EU) — contact support@aikautomation.com.
We process personal data only on the controller's documented instructions, which are: the configuration made in the platform by the controller's own users, the service order, and any written instruction sent to the contact address above.
| Category | What it is |
|---|---|
| Account data | Name, e-mail address, hashed password, sign-in times, 2FA secret. |
| Configuration | Agents, workflows, assistants, schedules, and API keys the controller adds (stored encrypted). |
| Content | Files uploaded to the sandbox, documents processed, chat messages, extracted fields, e-mails and calls the platform is configured to handle. |
| Records | Run logs (what ran, when, at what cost) and the tamper-evident activity log. |
| Technical | IP addresses, used for rate limiting and security, and in web-server logs. |
Data subjects are the controller's own staff and whoever appears in the content they choose to process — for example the people named on an invoice or the caller on a phone line.
Purpose and duration: to provide the platform, for as long as the service order is in force.
All hosted data is stored in the European Union: the application and its PostgreSQL database on a server in Oracle Cloud's EU region, and backups in Backblaze B2's EU region.
There is no transfer outside the EU by the platform itself, with one exception the controller creates: when the controller configures a non-EU AI provider (OpenAI, Anthropic, Google, xAI and so on), the text and files sent to that provider leave the EU under that provider's own terms. This is a controller decision — the platform runs equally on EU-hosted or entirely local models, and which provider is used is set by the controller.
| Who | What for | Where |
|---|---|---|
| Oracle Cloud Infrastructure | Server hosting | EU |
| Backblaze B2 | Encrypted off-site backups | EU |
| Zoho Mail | Platform e-mail (notifications, support) | EU |
| Stripe, PayPal | Payments (they receive billing data, not content) | EU / US, own SCCs |
| AI providers chosen by the controller | Model calls | Depends on the provider chosen |
We give 30 days' written notice before adding or replacing a sub-processor, and the controller may object; if the objection cannot be resolved, the controller may terminate the hosted service for the affected part.
A fuller description for an IT department is in the security brief, including what we do not claim.
One person — the processor — administers the hosted service, and has technical access to the server and database in order to operate, back up and repair it. There are no other staff. Access is used only to run the service or on the controller's instruction, and administrative actions are recorded in the activity log.
A full restore is whole-server; a single-client restore is a re-import. Backups are a complete dump of the hosted platform, so restoring it takes every account back to that point. For one client we instead keep a nightly export of each account and read it back into that account alone. That recovers what they created — agents, workflows, projects, document types, assistants, saved facts and files — as copies, switched off, for you to check. It does not recover stored API keys (deliberately excluded from every export so a backup cannot leak them), anything owned by another account, or platform history such as run logs and the audit trail.
No 24/7 monitored operations. The service is administered by one person in European time. There is no on-call rota and no uptime guarantee unless one is written into the service order.
No certification. We hold no ISO 27001 or SOC 2 certification. The measures above are real and described honestly; they are not audited by a third party.
Data is kept while the service order is in force. On termination, the controller may export their data through the platform; 30 days after termination the account and its data are deleted from the live system, and from backups as those age out of the 14-day retention window.
Two records survive an account deletion with the person's identity removed: run history and the activity log. The activity log is a hash chain — deleting a row would break the proof for every later entry — so the link to the person is dropped instead of the record.
This agreement supplements the Terms of Service and Privacy Policy and prevails over them for hosted processing. It is governed by Bulgarian law and the GDPR. If a term is found invalid, the rest stands.
This document is provided in good faith and is not legal advice. A client's own counsel should review it before signature; we will sign a client's own DPA where its terms match the facts described here.