Privacy Policy
GDPR Articles 13 and 14: information provided at collection.
Last updated:
AM8 SASU (“AM8”, “we”, “us”) is the data controller for personal data processed through am8-ai-governance.tech and the AM8 platform. We are a French société par actions simplifiée unipersonnelle (SASU), registered in France. This policy explains what we collect, the purposes of processing, our lawful basis, how long we keep data, and your rights.
Who we are and how to contact us
AM8 SASU is the controller for the personal data described in this policy. AM8 has assessed its obligations under Article 37 and is not required to designate a Data Protection Officer, so it has not designated one. Data protection is handled by our privacy team, who you can reach at privacy@am8-ai-governance.tech for any question about this policy or to exercise your rights.
What we process and the purposes of processing
We process account and profile details, organisation information, usage and security logs, support correspondence, and billing data. The purposes of processing are: to provide and secure the service, to administer your subscription, to provide support, and, only with your consent, to measure how the public website is used and to send product marketing. We do not sell personal data.
Lawful basis
Our lawful basis for processing is: performance of a contract (to deliver the service you have signed up for); our legitimate interests in operating, improving and securing the platform (balanced against your rights); consent for non-essential cookies, website analytics and marketing; and legal obligation for tax and accounting records.
Recipients and sub-processors
We share data with vetted sub-processors and other third parties strictly to deliver the service. Each is bound by a Data Processing Agreement. See the current sub-processor list. Our AI assistant is powered by Anthropic's Claude under Standard Contractual Clauses; Anthropic does not train on API data. Where you have turned analytics on, page views on the public website are measured by Vercel Web Analytics, which is cookieless: it stores nothing in your browser and sets no identifier that follows you between visits. Turn analytics off and the measurement code is never loaded.
International transfers
Some sub-processors are located outside the European Economic Area. Where we transfer personal data to a third country that is not covered by an adequacy decision, we rely on the EU Standard Contractual Clauses and additional safeguards.
Retention periods
We retain personal data only as long as necessary for the purposes above. Account data is kept for the life of your account and deleted (or anonymised) within 90 days of closure; billing and tax records are retained for 7 years to meet legal obligations; security logs are kept for up to 90 days.
Compliance evidence is an exception. AM8 is a compliance-monitoring platform, and the records that prove a control was tested (the audit log, control test results, and collected evidence) are retained after account closure under Article 17(3)(b), which permits retention where processing is necessary to comply with a legal obligation. These records are immutable by design: they cannot be altered or deleted, by you or by us, because a record that can be edited is not evidence.
How long. Control test results are kept for 7 years, then automatically deleted. All collected evidence, including the records supporting a conformity assessment, is kept for 10 years, because the EU AI Act (Article 18) requires technical and conformity documentation to remain available to authorities for ten years after a system is placed on the market, and the evidence is not separated by type. Both periods exceed the six-month minimum that Articles 19 and 26(6) set for automatically generated logs.
One category is different, and we say so rather than let the sentence above cover it: the record of how an AI-generated compliance verdict was reached is kept for as long as the evidence it supports, and is not on the automatic expiry sweep. It is what lets a decision be reconstructed years later, which is the point of keeping it.
A retained record contains the identifier of the closed workspace, which control was tested, the result, and when. It does not contain your name, your email address, or any credential. Where a record exists to prove that a person did something (signed an attestation, overrode an AI recommendation, reported an incident) it also holds that person's account identifier, and any free text they supplied is retained as part of the record. Once the workspace is deleted those identifiers no longer resolve to anyone, because the directory that gave them meaning is gone. To ask about a specific retained record, contact privacy@am8-ai-governance.tech.
Automated decision-making
ARIA produces AI-generated drafts and suggestions, but AM8 does not make decisions producing legal or similarly significant effects about you solely by automated decision-making or profiling within the meaning of Article 22. A qualified human reviews outputs before they are relied upon.
Your rights
You have the right to access (Article 15), rectification (Article 16), erasure (Article 17), restriction, data portability and objection. The right to erasure does not extend to the immutable compliance evidence described under Retention periods above, which is retained under Article 17(3)(b). To exercise any of these, contact privacy@am8-ai-governance.tech or use the tools in your account's privacy settings.
Complaints and supervisory authority
You have the right to lodge a complaint with your supervisory authority. AM8 is established in France, so our lead supervisory authority is the French CNIL (cnil.fr); you may also complain to the authority in your own country. As an EU-established controller, AM8 is not required to appoint an Article 27 EU representative.