Privacy Policy

Effective Date: November 1, 2025 | Last Updated: November 1, 2025

1. Introduction

This Privacy Policy describes how awRAG.io ("awRAG," "we," "us," or "our") collects, uses, and protects your personal information when you use our universal RAG-as-a-Service platform.

awRAG is operated by Muhammed Alp, located in Gelderblomstr 73, 47138 Duisburg, Germany. We are committed to protecting your privacy and ensuring the security of your data in compliance with the General Data Protection Regulation (GDPR).

Contact Information:
awRAG.io - Owned and operated By Muhammed Alp
Gelderblomstr 73, 47138 Duisburg, Germany
Email: contact@awrag.io

2. Data Controller

The data controller responsible for your personal data is:

Muhammed Alp
awRAG.io
Gelderblomstr 73, 47138 Duisburg, Germany
Email: contact@awrag.io

3. What Data We Collect

We collect the following types of personal data when you use our platform:

  • Account Information: Email address, name (if provided), and password (encrypted)
  • Document Data: Files and documents you upload to our platform for RAG processing
  • Usage Data: Information about how you interact with our platform, including query history, document processing logs, and feature usage
  • Technical Data: IP address, browser type, device information, and access logs
  • Payment Information: Processed securely through our third-party payment provider (we do not store full payment card details)
  • Communication Data: Messages you send us through contact forms or support requests

4. How We Use Your Data

We process your personal data for the following purposes:

  • Service Provision: To provide, maintain, and improve our RAG-as-a-Service platform
  • Document Processing: To generate embeddings, perform vector searches, and enable AI-powered document querying
  • Account Management: To create and manage your user account, authenticate access, and manage subscriptions
  • Customer Support: To respond to your inquiries, provide technical support, and communicate important updates
  • Platform Security: To detect and prevent fraud, abuse, and security threats
  • Legal Compliance: To comply with applicable laws, regulations, and legal obligations
  • Service Improvement: To analyze usage patterns and improve our platform features (anonymized data only)

5. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Contractual Necessity: Processing necessary to perform our service contract with you (account management, document processing, subscription services)
  • Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our platform, ensuring security, and preventing fraud (balanced against your rights)
  • Legal Obligation: Processing required to comply with legal and regulatory requirements
  • Consent: For specific processing activities where we obtain your explicit consent (you can withdraw consent at any time)

6. European Data Storage & Security

🇪🇺 All Your Data Storage in Europe

At awRAG, data security comes first. That's why we don't just use SOC 2-certified infrastructure for storing customer data; the awRAG application itself is built strictly according to SOC 2 principles.

We prioritize data security and GDPR compliance by storing all your data exclusively within the European Union. While some AI processing occurs temporarily outside the EU (see Section 10: International Data Transfers), all storage remains in the EU:

  • Database Storage: EU data centers (Switzerland 🇨🇭)
  • Application Hosting: EU data centers (Finland 🇫🇮)
  • File Storage: EU data centers (Switzerland 🇨🇭)

Security Measures:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using SSL/TLS protocols
  • Encryption at Rest: Your documents and data are encrypted when stored in our databases and file storage
  • Access Controls: Strict Row Level Security (RLS) policies ensure your data is isolated and accessible only to you
  • Authentication: Secure user authentication with encrypted password storage
  • Regular Backups: Automated backups ensure data resilience and disaster recovery
  • Security Monitoring: Continuous monitoring for security threats and anomalous activity

7. Third-Party Service Providers

We work with trusted third-party service providers to deliver our platform. These providers have access to your data only to perform specific tasks on our behalf and are obligated to protect your information:

  • Cloud Infrastructure Providers: Enterprise-grade EU-based hosting and database services with GDPR compliance
  • AI Processing Services (100% GDPR Compliant): Vector embeddings and reranking services provided by third-party AI providers with full GDPR Data Processing Agreement (DPA), EU-approved Standard Contractual Clauses (SCCs), SOC 2 Type 2 certification, and Transfer Impact Assessments
  • Payment Processor: Secure payment processing (specific provider details in Terms of Service)

We maintain 100% GDPR compliance by ensuring all third-party processors have binding Data Processing Agreements (DPAs) with EU-approved Standard Contractual Clauses (SCCs) where required. All processors undergo regular security audits and compliance assessments.

8. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account Data: Retained while your account is active and for up to 90 days after account deletion (to prevent accidental data loss)
  • Document Data: Retained while your account is active or until you delete specific documents
  • Usage Logs: Retained for up to 12 months for security and troubleshooting purposes
  • Legal Records: Retained as required by applicable laws and regulations

After the retention period expires, we securely delete or anonymize your personal data.

9. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

  • Right of Access: You can request a copy of all personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data
  • Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data under certain circumstances
  • Right to Restriction of Processing: You can request that we limit how we use your personal data
  • Right to Data Portability: You can request your data in a structured, machine-readable format for transfer to another service
  • Right to Object: You can object to certain types of data processing, including processing based on legitimate interests
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time
  • Right to Lodge a Complaint: You can file a complaint with your local data protection authority if you believe your rights have been violated

To exercise any of these rights, please contact us at contact@awrag.io. We will respond to your request within 30 days as required by GDPR.

10. International Data Transfers

All your data is stored within the European Union (EU). However, we do transfer document content outside the EU for temporary processing in the following cases:

  • AI Embedding Generation (Third-Party AI Service - 100% GDPR Compliant): When you upload documents, the text content is temporarily sent to our third-party AI processing partner to generate vector embeddings. The embeddings are then stored in our EU database (Switzerland). Our AI partner processes the data temporarily and does not retain it. This transfer is fully GDPR-compliant and protected by Data Processing Agreements (DPA) with Standard Contractual Clauses (SCCs) approved by the European Commission. Our AI partner is SOC 2 Type 2 certified and conducts Transfer Impact Assessments (TIA) to ensure EU data protection standards are maintained.
  • User-Initiated AI Queries: When you explicitly connect third-party AI models (e.g., OpenAI, Google Gemini) via MCP protocol, data transfer is initiated by you and subject to the third party's privacy policy
  • Legal Requirements: Where required by law or to protect our legal rights

Important Distinction: While document processing may temporarily occur outside the EU, all data storage (documents, embeddings, user data, backups) remains exclusively within the European Union. We maintain 100% GDPR compliance by ensuring all non-EU processors have binding Data Processing Agreements (DPAs) with EU-approved Standard Contractual Clauses (SCCs) and undergo regular Transfer Impact Assessments.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to provide and improve our platform. For detailed information about our use of cookies, please refer to our Cookie Policy.

We only use essential cookies required for platform functionality (authentication, session management). We do not use analytics or marketing cookies without your explicit consent.

12. Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR)
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Provide information about the nature of the breach, likely consequences, and measures taken to address it

13. Children's Privacy

Our platform is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete such information promptly.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email or through a prominent notice on our platform
  • Give you the opportunity to review the changes before they take effect (for material changes)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

awRAG.io - Data Controller
Muhammed Alp
Gelderblomstr 73, 47138 Duisburg, Germany
Email: contact@awrag.io

We are committed to resolving any privacy concerns you may have and will respond to your inquiries within a reasonable timeframe.

16. Data Protection Authority

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local data protection authority or the lead supervisory authority in the EU.

Last Updated: November 1, 2025 | Terms of Service | Cookie Policy | Security & Compliance