TrustTroiAI Platform
This policy applies to the TrustTroiAI platform. It describes which data we process, for which purposes, and to whom it is disclosed.
A separate, more specific policy applies to the TrustTroiAI Inspector browser extension at trusttroiai.com/extension-privacy. The more specific policy always takes precedence.
The controller for data processing on this website is:
TrustTroiAI · Owner: Earwin Wilfried Tchebtchou Tsobeng · Grünewalder Straße 29-31 · coworkit (SG-Grünewald) · 42657 Solingen · Germany
Contact: Phone: +49 176 29572844 · Email (privacy): privacy@trusttroiai.com · Email (support): support@trusttroiai.com
When you register on our platform, we collect the following data:
Mandatory: – email address (for authentication and communication) – function/role (e.g. “Product Manager”, “CTO”) – company/organisation – country
Optional: – first name – last name – further contact details
Technical data: – password (stored encrypted as a bcrypt hash) – plan type (adventure, starter, bundle, essentials, professional, business, it_partner) – assessments counter (for quota enforcement) – user role (user, expert, admin)
When you run a compliance assessment, we record:
Project data: – project name – project description (free text) – client (optional) – location – industry – chosen regulation (AI Act, GDPR, etc.)
Assessment results: – answers to assessment questions – scope classification – role (provider/deployer) – risk class – identified obligations – system requirements
Clarification workflow: – your answers to AI-generated follow-up questions
Collected automatically: – IP address (stored only as a SHA256 hash; no reconstruction of the plain-text IP is possible) – browser type / user agent (max. 500 characters) – session ID (UUID) – access time – CSRF token (technically necessary)
Important: We do not store plain-text IP addresses, only SHA256 hashes (privacy by design, Art. 25 GDPR).
Our platform uses only strictly necessary cookies required to operate the website:
No cookie banner required: because we use no tracking or marketing cookies, no cookie banner is necessary under § 25 TTDSG.
We process your data to perform the usage contract:
For the following processing we obtain your explicit consent:
AI-assisted analyses: – processing of your project descriptions by Mistral AI (Paris, France) – generation of assessment results via AI agents – Finn AI assistant (knowledge assistant + situation assistant) – template generation via Mistral AI Large
Important: You can withdraw your consent at any time in the settings. This does not affect the lawfulness of processing carried out before withdrawal.
On the basis of our legitimate interest we process data for:
You can object to processing based on legitimate interest at any time (see section 9).
The Finn AI assistant helps you with compliance questions through source-based answers.
Two modes: – Knowledge assistant (Cool Mode): general regulatory questions – Situation assistant (from Professional): individual compliance guidance
Data processed: – your questions/prompts (free text) – conversation history (for context) – sources/articles used
Conversation history: We store your queries and Finn's answers for 90 days, to keep context in follow-up questions and to improve the service.
Quota system: Adventure users can make 2 queries per month. Paid users have unlimited access.
AI tool: Mistral AI (Paris, FR) – see section 5.2
Legal basis: Consent (Art. 6(1)(a) GDPR)
We let you generate compliance-specific templates. For this we record your answers to questions about certain articles of the relevant regulation.
Data processed: – your answers to template questions (structured) – free-text input (may contain personal or business-critical data) – generated documents (DOCX format, stored as JSON)
AI tool: Mistral AI Large (Paris, FR) processes your template answers to generate a structured document. Processing is based on the same consent as for assessments.
Storage: Generated templates are stored in our database in JSON format and are available for you to download at any time.
Purpose: Creating compliance templates to implement regulatory requirements
Legal bases: – performance of a contract (Art. 6(1)(b) GDPR) – consent for AI processing (Art. 6(1)(a) GDPR)
Retention: – template answers: until account deletion + 30 days – generated templates (JSON): until account deletion + 30 days
Depending on your plan, you can have your assessment results validated by external compliance experts.
Data processed: – complete assessment results – project descriptions – all your answers – risk classification and identified obligations
Data experts create: – comments and notes – validation decisions – signed compliance roadmaps
Recipients: External compliance experts (independent processors under Art. 28 GDPR). We conclude data processing agreements (DPAs) with all experts before they gain access to your data.
Locations: Worldwide (all under a DPA)
Access logging: We log every expert access to your data (who, when, which assessment) for 12 months.
Purpose: Professional review and validation of your compliance analyses
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR)
Retention: – expert comments: until account deletion + 30 days – signed roadmaps: 12 months after generation – access logs: 12 months
From the Professional plan you can invite team members to work on projects together.
Data processed: – team members' email addresses – access management (who sees which projects) – team assignments
Responsibility: TrustTroiAI remains the controller under the GDPR for all processed data, including data of team members. The team administrator is an authorised user, not a separate controller.
Access control: Team members only see the projects explicitly assigned to them. An overview of all access rights is available in the team dashboard.
Purpose: Shared use of projects and assessments
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR)
Retention: Until account deletion + 30 days
To improve the platform we collect anonymised usage statistics.
Data collected:
Table: page_events (retention: 12 months) – session ID (UUID) – user ID (only for logged-in users) – event type (e.g. “scope_check_start”, “assessment_complete”) – page visited – referrer URL – user agent (max. 500 characters) – IP hash (SHA256, first 32 characters only) – no reconstruction of the plain-text IP is possible – metadata (industry, role, risk class, token count, estimated cost)
Table: usage_logs (retention: 24 months) – user ID – request type (e.g. “AI-Act assessment”, “Finn knowledge”) – agent name (which AI agent) – regulation (EU_AI_ACT, GDPR, etc.) – input/output tokens (count) – estimated cost (USD) – AI model (e.g. “mistral-large-latest”) – success/error – response time (milliseconds)
Error logs (retention: 30 days) – user ID – error message – timestamp
Anonymisation: – usage statistics are aggregated and stored without a direct personal reference – IP addresses are stored solely as a SHA256 hash (privacy by design) – error logs are automatically deleted after 30 days
Purpose: – platform improvement and feature analysis – cost transparency (API usage) – debugging and error analysis
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
Right to object: You can object to the anonymised use of data at any time in the settings. Error logs continue to be stored for 30 days (technically necessary for debugging).
We only pass your data to the following recipients where this is necessary to perform the contract or on another legal basis:
Hetzner Online GmbH · Purpose: hosting of the production server and database · Location: Nuremberg, Germany (EU) · Legal basis: processing under Art. 28 GDPR · DPA: concluded
Mistral AI · Purpose: AI-assisted analyses (assessments, Finn assistant, template generation) · Location: Paris, France (EU) · Legal basis: processing under Art. 28 GDPR + consent (Art. 6(1)(a) GDPR) · DPA: being requested · Data transferred: project descriptions, Finn queries, template answers
Important: Under its terms, Mistral AI does not store your data permanently.
Qdrant Cloud · Purpose: vector database for RAG-based answers (Finn assistant) · Location: EU · Legal basis: processing under Art. 28 GDPR · DPA: being requested · Data transferred: regulatory texts only (EU AI Act, GDPR, etc.), no user data
Stripe Payments Europe Ltd. · Purpose: payment processing · Location: Dublin, Ireland (EU) + USA (Data Privacy Framework) · Legal basis: processing under Art. 28 GDPR · DPA: Stripe Data Processing Agreement active · Data transferred: email, payment data, billing address
US transfer: Stripe is certified under the EU-US Data Privacy Framework. Payment data is additionally processed by Stripe in the USA.
Resend Inc. · Purpose: sending transactional emails (registration, password reset, order confirmations) · Location: USA · Legal basis: processing under Art. 28 GDPR + Standard Contractual Clauses (SCCs) under Art. 46 GDPR · DPA: being requested (SCCs already in place) · Data transferred: email address, name (optional), email content
Third-country transfer: Resend is based in the USA. The transfer is based on the EU Commission's Standard Contractual Clauses (SCCs).
Plausible Analytics · Purpose: anonymous web analytics (only on the website trusttroiai.eu) · Location: EU · Legal basis: legitimate interest (Art. 6(1)(f) GDPR) · Note: no cookies, no IP storage, GDPR-compliant
Important: Plausible Analytics is not used in the web app (trusttroiai.com).
External compliance specialists (independent) · Purpose: expert validation of assessments · Locations: worldwide · Legal basis: processing under Art. 28 GDPR · DPA: concluded with every expert before data access · Data transferred: complete assessment results, project descriptions
Qualifications: – lawyers specialising in IT law, data protection or compliance – certified data protection officers – advisors with proven regulatory expertise
We only store your data for as long as necessary for the respective purposes:
| Datenart | Speicherdauer |
|---|---|
| Pflichtdaten (E-Mail, Funktion, etc.) | Bis Kontolöschung + 30 Tage |
| Optionale Daten (Name, etc.) | Bis Kontolöschung + 30 Tage |
| Passwort-Hash | Bis Kontolöschung (sofort gelöscht) |
| Plan-Typ, Assessments-Zähler | Bis Kontolöschung + 30 Tage |
| Datenart | Speicherdauer |
|---|---|
| Assessment-Ergebnisse | 12 Monate nach letztem Zugriff |
| Projekte (inaktiv) | 24 Monate nach letzter Änderung |
| Datenart | Speicherdauer |
|---|---|
| Template-Antworten | Bis Kontolöschung + 30 Tage |
| Generierte Templates (JSON) | Bis Kontolöschung + 30 Tage |
| Datenart | Speicherdauer |
|---|---|
| Finn-Anfragen (Prompts) | 90 Tage |
| Finn-Antworten | 90 Tage |
| Datenart | Speicherdauer |
|---|---|
| Expert-Kommentare | Bis Kontolöschung + 30 Tage |
| Signierte Roadmaps | 12 Monate nach Generierung |
| Expert Access-Logs | 12 Monate |
| Datenart | Speicherdauer |
|---|---|
| page_events | 12 Monate |
| usage_logs | 24 Monate |
| Error-Logs | 30 Tage |
| Aggregierte Statistiken (anonym) | Unbegrenzt (kein Personenbezug) |
| Datenart | Speicherdauer | Grund |
|---|---|---|
| Rechnungen | 10 Jahre | § 147 AO (Abgabenordnung) |
| Verträge | 6 Jahre | § 257 HGB |
| Stripe Customer ID | Bis Kontolöschung + 10 Jahre | Buchhaltung |
Important: After the retention periods expire, your data is deleted automatically and irreversibly.
You can delete your account yourself at any time in the settings.
Deletion period: 30 days
What is deleted: – all account data – all projects and assessments – all templates – Finn conversation history – team assignments
What remains (statutory retention): – invoices (10 years) – contracts (6 years) – Stripe customer ID (anonymised after 30 days, kept for invoice reference for 10 years)
During the 30-day period: – your account is deactivated (no login possible) – you can revoke the deletion (email to support@trusttroiai.com)
After 30 days: – permanent, irreversible deletion of all data (except statutory retention obligations)
We use technical and organisational measures to protect your data from unauthorised access, loss or manipulation:
You have the following rights regarding your personal data:
You can request information about the data we process at any time: – which data is stored – for which purposes – to which recipients it was transferred – how long it is stored
Contact: privacy@trusttroiai.com
You can correct inaccurate data at any time in your account settings or contact us.
You can request erasure of your data where: – the data is no longer needed for the original purposes – you have withdrawn your consent – you have objected and there are no overriding grounds for processing – the data was processed unlawfully
Exceptions: – statutory retention obligations (invoices: 10 years, contracts: 6 years) – establishment, exercise or defence of legal claims
To delete: Settings → “Delete account”
You can request restriction of processing where: – the accuracy of the data is contested – processing is unlawful but you do not want erasure – we no longer need the data but you need it for legal claims
You have the right to receive your data in a structured, common and machine-readable format.
Currently: export by email request to privacy@trusttroiai.com · Planned: automatic export function (Q3 2026)
Exportable data: – assessment results (JSON/PDF) – projects – templates – Finn conversation history (optional)
You can object at any time to the processing of your data based on legitimate interest (Art. 6(1)(f) GDPR):
Concerns: – anonymised usage analysis (page_events, usage_logs)
To object: Settings → “Disable usage analysis”
Exception: Error logs continue to be stored for 30 days (technically necessary for debugging).
You can withdraw your consent to AI processing at any time:
Concerns: – Mistral AI processing (assessments, Finn, templates)
To withdraw: Settings → “Disable AI processing”
Consequences: – assessments, Finn and templates no longer work – data already processed remains lawfully stored – you can consent again at any time
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data infringes the GDPR.
Competent supervisory authority:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW) · Kavalleriestraße 2-4 · 40213 Düsseldorf · Germany
Phone: +49 211 38424-0 · Email: poststelle@ldi.nrw.de · Website: https://www.ldi.nrw.de
Your data is generally processed within the EU/EEA.
Exceptions with appropriate safeguards:
Resend (USA): – legal basis: Standard Contractual Clauses (SCCs) under Art. 46 GDPR – data transferred: email address, name (optional), email content – purpose: transactional emails
Stripe (US portion): – legal basis: Data Privacy Framework (DPF) – data transferred: payment data, customer ID – purpose: payment processing
All other subprocessors (Hetzner, Mistral AI, Qdrant, Plausible Analytics, experts) process data exclusively within the EU/EEA.
We do not use any fully automated decision-making (including profiling) within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
AI-assisted analyses: Our AI agents (Mistral AI) produce suggestions for risk classes and obligations. These suggestions serve as a basis for decisions but are not adopted automatically. You can correct results at any time or have them validated by an expert.
In principle we do not process any special categories of personal data within the meaning of Art. 9 GDPR (e.g. health data, biometric data, political opinions, etc.).
If you accidentally enter sensitive data in your free-text input (project descriptions, Finn queries), you should delete it immediately or contact us.
Our platform is intended exclusively for companies and business customers. Use by persons under 16 is not intended.
If you discover that a minor has created an account without the consent of a parent or guardian, please contact us immediately at support@trusttroiai.com.
We reserve the right to update this privacy policy to reflect changes to our services or legal requirements.
Notice: Material changes will be communicated to you by email at least 30 days before they take effect.
Current version: The current version is available at: trusttroiai.com/datenschutz
Last updated: 4 August 2026
For questions about data protection or to exercise your rights, contact us:
Data protection: Email: privacy@trusttroiai.com
Support: Email: support@trusttroiai.com · Phone: +49 176 29572844
Address: TrustTroiAI · Earwin Wilfried Tchebtchou Tsobeng · Grünewalder Straße 29-31, coworkit · 42657 Solingen · Germany
This website uses only strictly necessary cookies and privacy-friendly, cookieless analytics. Privacy