This privacy policy applies to the TrustTroiAI Platform, including the associated browser extension TrustTroiAI Inspector. It supplements the privacy policy of the marketing website trusttroiai.eu (/en/datenschutz). This document is specific to the Platform and prevails on overlapping topics. For the extension itself, a compact English version at /extension-privacy additionally addresses the requirements of the Chrome Web Store; that version refers to this policy as the main document.
The TrustTroiAI Platform helps organisations identify, document and evidence their compliance obligations under EU regulation — in particular the AI Act, GDPR, Cyber Resilience Act and Data Act. In addition, we offer a browser extension and an integration with Atlassian Jira.
What we process: your account data, the contents of your compliance projects, your chat exchanges with our AI assistant and — where you connect the Jira integration — the contents of the Jira issues you select.
For what: to provide the Platform, to perform AI-assisted compliance analyses and to ensure smooth operation.
Where: on servers in Germany (Hetzner). AI analyses run at Mistral AI in France (EU). Transactional emails run via Resend (USA, safeguarded by Standard Contractual Clauses).
Your rights: access, rectification, erasure, restriction, data portability, objection and complaint to a supervisory authority. Details in Section 17.
Data protection contact: [email protected].
The controller for data processing on this Platform is:
TrustTroiAI
Grünewalder Straße 29–31
coworkit (SG-Grünewald)
42657 Solingen
Germany
Contact for data protection matters:
Email: [email protected]
General contact: [email protected]
We have not appointed a data protection officer. Under Section 38 of the German Federal Data Protection Act (BDSG), a data protection officer only needs to be appointed if, as a rule, at least 20 persons are permanently engaged in the automated processing of personal data. We do not reach this threshold. No obligation arises under Article 37 GDPR either, as we do not carry out regular and systematic monitoring of data subjects on a large scale and do not process special categories of personal data on a large scale. Please address data protection enquiries directly to [email protected].
Description. Provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The application, the PostgreSQL database and all persisted content reside on a virtual server operated by Hetzner in Germany. When the application is accessed, the server processes technically necessary connection data.
Legal basis. Article 6(1)(f) GDPR (legitimate interest in a secure and efficient provision) and Article 6(1)(b) GDPR in the context of contract performance. A data processing agreement under Article 28 GDPR is in place with Hetzner.
Purpose. Operation, security and availability of the Platform.
Third-country transfer. No third-country transfer; the server and database location is Germany.
Description. The web server automatically collects information that your browser transmits: browser type and version, operating system, referrer URL, hostname of the accessing computer, time of the server request and IP address. For error analysis and operational security, the application additionally logs technical events to the server's system journal. Before entries are written to the journal, potentially personal content is replaced by a redaction filter so that plaintext content from your projects and tickets does not appear in the logs.
Legal basis. Article 6(1)(f) GDPR.
Purpose. Technical provision, error analysis, defence against attacks.
Retention. Server log files: 14 days, after which they are automatically deleted or overwritten. Redacted application logs: 30 days.
Right to object. You may object to this processing under Article 21 GDPR. As the processing is essential for the provision and security of the Platform, an objection would exclude use of the Platform.
Description. A user account is required to use the Platform. On registration we collect:
After registration we send you an email with a verification link. Without a confirmed email address, the account is not activated. On the email delivery service provider, see Section 13.
Legal basis. Article 6(1)(b) GDPR (performance of contract or pre-contractual measures).
Purpose. Provision of the user account, attribution of your contributions, communication.
Retention. For the duration of the contractual relationship; after termination, see Section 16.
Description. Once you have signed in we set one strictly necessary cookie:
trusttroiai_session — contains a random session token. Attributes: HttpOnly, Secure, SameSite=None. Lifetime: 30 days.SameSite=None is required so that the browser extension recognises you as signed in in the context of Jira. The cookie is not readable via JavaScript (HttpOnly) and is transmitted exclusively over HTTPS (Secure).
In our database we do not store the token itself but only its SHA-256 hash, together with expiry and revocation status. On sign-out the session is invalidated on the server. We additionally use a CSRF token to protect against attacks via forged requests.
We do not use non-essential cookies, tracking or marketing cookies.
Legal basis. Article 6(1)(b) GDPR and Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) — strictly necessary for the provision of the service you have expressly requested. No consent is required for these cookies.
Purpose. Maintenance of your session, protection against attacks.
Retention. Session token: 30 days. On sign-out the session is invalidated immediately.
Description. The core purpose of the Platform is the documentation of your compliance work. In doing so we process the content you enter:
This content may contain personal data if you enter such data — for example the names of persons responsible in a record of processing activities. You decide what you enter.
Why we keep the history. Evidence keeping is the core of the product. If someone later asks who released a piece of evidence, that attribution must remain verifiable. Therefore evidence is not overwritten but versioned and marked as "replaced".
File uploads are stored on the server's file system and are accessible only via authenticated requests of your account.
Legal basis. Article 6(1)(b) GDPR. Where you enter personal data of third parties, you are the controller in that respect and we process this data on your behalf — see Section 14.
Purpose. Delivery of compliance documentation and evidence-keeping services.
Retention. For the duration of the contractual relationship; after termination, see Section 16.
You can connect your Atlassian account to the Platform. The connection is optional and not required to use the Platform.
What happens on connection. The connection is established via OAuth 2.0 (3LO). We receive from Atlassian access and refresh tokens with the scopes read:jira-work, read:jira-user, write:jira-work, read:me, offline_access. We store your Atlassian account ID, the Cloud ID of your Jira instance, the scope of the granted permissions and the access and refresh tokens. The tokens are stored encrypted (Fernet, symmetric encryption with a key held only on the server).
Which Jira content is processed. For the issues you select we retrieve, via the Jira API: title, description, comments, status, assignments and attachments. This content may contain personal data — names of colleagues, customers, email addresses in free text.
As a rule we retrieve this data on demand and do not store it permanently. For performance and traceability reasons the following caches exist: the classification cache (result of the obligation assignment per issue), the attachment text cache (text extracted from PDF or Office attachments), the context delta (change state of an issue since the last analysis) and the compliance tasks (compliance tasks created or linked in Jira).
Disconnecting. You can disconnect the integration at any time in the settings, or revoke access in your Atlassian account. The stored tokens are then deleted.
Legal basis. Article 6(1)(b) GDPR (provision of the integration you have requested). Atlassian is not our processor in this respect but the source from which you make data available to us for processing.
Purpose. Obligation assignment at ticket level, evidence keeping in ticket context.
Retention. Caches: 90 days after last access. Compliance tasks: until you delete them in Jira or disconnect the integration. On disconnection, all caches relating to the affected issues are deleted.
For classification, assessment, text suggestions and the dialogue-based assistant, we use language models from Mistral AI SAS, 15 rue des Halles, 75001 Paris, France. Processing takes place on servers in the European Union. A data processing agreement under Article 28 GDPR is in place; a written exclusion of the use of your content for model training is part of the contractual arrangement.
No transmission to providers outside the EU takes place — in particular not to OpenAI, Google or Anthropic.
The following functions transmit data to Mistral: classification of issues by applicable obligations, assessment of recorded evidence, generation of evidence drafts and suggestion texts, prefilling of templates from existing context, questions and answers in the compliance assistant, and the conversion of your search and assistant queries into numeric representations (embeddings) for similarity search in the legal-text repository (see Section 10.7).
Before content is transmitted to the language model, it undergoes pseudonymization: detected personal identifiers — names, email addresses, phone numbers, account and customer numbers, account identifiers, technical resource identifiers — are replaced with placeholders such as [PERSON_A]. The model sees only the placeholders. In the response, placeholders are resolved back to the original values for display to you.
The mapping table placeholder–original exists exclusively in memory for the duration of the single request and is discarded afterwards. It is not stored. Additionally, we check the model's response for personal data it may have invented that did not appear in your input, and count such cases.
Pseudonymization before transmission currently applies to the following functions: evidence assessment, evidence drafting, template prefilling, suggestion texts, classification and champion-text generation.
In the dialogue-based assistant, the text transmitted to the model is currently not pseudonymized. The reason is how the assistant works: during a conversation it autonomously calls tools that load further context; a mixture of placeholders and plaintext in the same dialogue leads to incorrect attributions and thereby to incorrect compliance statements. Instead, we transparently log which personal identifiers were included in a dialogue step and show this to you on every answer. Before your first use of the assistant, we explicitly point out this exception in a transparency dialog. An extension of pseudonymization to the assistant is in progress.
Transparency log. For every AI call we store: the pseudonymized request text, the pseudonymized response, a list of the replaced categories with placeholder and count (without the original values), the number of invented personal identifiers in the response, and call metadata (user account, timestamp, model used). Legal basis: Article 6(1)(f) GDPR. Purpose: evidence keeping and internal quality control. Retention: 12 months.
Dialogue history. Your chat sessions, individual messages and the assistant's tool calls are stored in plaintext so that you can review and continue your history. This is a deliberate trade-off in favour of traceability; access to the database is restricted to operations. Retention: 18 months from the last activity in the session.
The legal basis for AI-assisted processing is Article 6(1)(b) GDPR (performance of contract), as the AI analysis constitutes the core service of the Platform and the Platform cannot fulfil its purpose without it. For the optional evaluation of Jira contexts (Section 9), your separate activation of this integration additionally applies, which you can withdraw at any time.
The AI-assisted analyses produce proposals and assessments, not binding decisions. Each result is shown to you with a confidence value and the underlying legal source and must be confirmed by a human before it counts as evidence. No automated decision-making in the individual case, including profiling within the meaning of Article 22 GDPR, takes place.
For finding relevant legal texts we use a vector database (Qdrant) that runs in the process of our own application on the Hetzner server in Germany. No external provider is integrated for the database.
Only numeric representations (embeddings) of EU legal texts are persisted long-term in this database — in particular from the AI Act, GDPR, CRA and Data Act. Your account, project or evidence data is not stored in the vector database.
Your queries are also embedded, but not stored. To enable a similarity search between your query and the legal texts, the query text is converted into a numeric representation at the moment of processing by the embedding model of Mistral AI SAS (EU location). The pseudonymization described in Section 10.2 applies before this transmission to Mistral. The resulting query vector is used only for the single search and is discarded afterwards.
Description. The browser extension shows you, within a Jira issue, which EU compliance obligations apply to the work described in the issue and lets you record evidence against those obligations. It is an access channel to the Platform; an Inspector account is at the same time a Platform account. All processing described in Section 8 (compliance projects, assessments and evidence), Section 9 (Jira integration) and Section 10 (AI-assisted processing) applies accordingly when you use the extension.
In addition to central server storage, the extension stores in your browser's local extension storage: the session token (lifetime 30 days), your email address and the site name. This local storage remains on your device.
Legal basis, purpose and retention follow from the sections referenced above. You can disconnect the extension at any time via "Sign out" in the extension menu, which invalidates the session token immediately, and revoke access under "Connected apps" in your Atlassian account.
A compact English version of this policy, specifically addressing the requirements of the Chrome Web Store, is available at /extension-privacy.
Description. To improve the Platform we collect usage events in our own database: page accessed, event type, referrer, browser identifier (user agent), a random session identifier, where applicable your user account ID and a hash of your IP address (SHA-256, truncated). The IP address itself is not stored.
Evaluation takes place exclusively on our own server. No data is transmitted to analytics providers such as Google Analytics and no cross-device profiles are created.
Legal basis. Article 6(1)(f) GDPR (legitimate interest in needs-based design of the service).
Purpose. Improvement of functionality and usability.
Retention. 12 months from the event, after which it is automatically deleted.
Right to object. You may object to this processing under Article 21 GDPR by sending a message to [email protected].
Description. For sending system emails — account verification, password reset, notifications, requests for expert review — we use Resend, Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA). Data transmitted: email address, name, content of the respective email. Data location: USA.
Legal basis. Article 6(1)(b) GDPR (performance of contract).
Purpose. Delivery of transactional messages you receive or trigger from the operation of the Platform.
Third-country transfer. The transfer is safeguarded by the Standard Contractual Clauses under Article 46(2)(c) GDPR. Additional technical and organisational measures by the provider apply.
Retention. Email contents are kept at Resend only as long as necessary for delivery and subsequent delivery-tracking purposes.
Insofar as you use the Platform as an organisation and thereby enter personal data of your staff, customers or third parties — including via the Jira integration — you are the controller in that respect within the meaning of the GDPR. We process this data on your behalf under Article 28 GDPR.
For this purpose we provide you with a data processing agreement, which also contains the list of sub-processors used. Enquiries to [email protected].
Recipients of personal data are exclusively the service providers named above:
Atlassian is not a sub-processor but the source from which you make data available to us for processing (see Section 9).
No transfer of your data to other third parties takes place unless we are legally required to do so or you have expressly consented.
We process personal data only for as long as is necessary for the respective purposes. The specific retention periods are stated with the individual processing operations in this policy. In summary:
After termination or a deletion request, your personal data is deleted within 30 days. Excluded is data for which statutory retention obligations apply — in particular commercial and tax retention periods of six or ten years pursuant to Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO).
On the deletion process. We delete your record in two stages. Immediately upon your request, all identifiers relating to you — email address, first and last name, account identifiers — are removed from your user record and your sessions are revoked. This removes the personal reference within the meaning of Article 4(1) GDPR. The technical links to your evidence and releases initially remain, so that the auditability of already granted compliance releases is not destroyed for the projects of your organisation that continue to exist. At the latest 30 days after your deletion request, these records are also deleted permanently.
Under the GDPR you have the following rights against us:
Account closure and deletion are currently carried out on request by email to [email protected]. We respond to your requests without undue delay and at the latest within one month.
Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Article 77 GDPR), in particular in the Member State of your residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
www.ldi.nrw.de
We take technical and organisational measures to protect your data, in particular:
HttpOnly and SecureWe update this privacy policy when the legal situation or our processing changes. The current version is available on this page. Material changes are announced in advance.
This website uses only strictly necessary cookies and privacy-friendly, cookieless analytics. Privacy