Back to Home
APIR Intelligence · Legal

AI Privacy Policy

Last updated: May 24, 2026

Plain-English Summary

This page is the AI-specific addendum to our main Privacy Policy. It covers what data flows through our AI systems, where it goes, how long we keep it, and the rights you have over it under GDPR Articles 13 and 14.

The short version: we minimise what we send to AI providers, we never let them train on your content, we delete prompts and responses on a strict schedule, and you can opt out of every AI-assisted feature.

1.AI Data Collection (GDPR Art. 13)

Our AI data collection is feature-scoped, we only collect what a specific AI feature needs at the moment you invoke it, never speculatively. When you use an AI-assisted feature, the following data leaves APIR's systems and is sent to a third-party AI provider for inference. The processing happens under the legal bases documented in the rightmost column.

FeatureData SentRecipientLegal Basis
SENTINEL chatYour prompt text, your org_id (as a system tag), the last 10 turns of conversation context.Anthropic PBC (Claude API), USAContractual necessity (Art. 6(1)(b)), you initiated the chat.
Compliance AssessmentAgent metadata you registered (name, model provider, use case, system prompt), framework controls, no personal data of end users.Anthropic PBC, USAContractual necessity (Art. 6(1)(b)).
Regulatory RadarPublic regulatory source content (no customer data).Anthropic PBC, USALegitimate interest (Art. 6(1)(f)), operating a regulatory feed.
Company EnrichmentPublic company identifiers (name, domain) only. Never employee names, contact details, or financial data.Anthropic PBC, USALegitimate interest (Art. 6(1)(f)).
Ghost Audit narrativeAggregated audit event counts and severity tags. No raw agent inputs or outputs.Anthropic PBC, USAContractual necessity (Art. 6(1)(b)).

We do not send data to OpenAI, Google AI, or Mistral unless you have explicitly registered a BYOK (bring-your-own-key) credential for that provider in Settings → BYOK. In that case, the call routes through your key and the provider terms you accepted with them apply.

2.Data Provided When Collection Is Indirect (GDPR Art. 14)

If you appear in our system because your organisation registered you (e.g. a teammate invited you) and we've processed any of your data via an AI feature, you have the same Article 14 rights as anyone we collected from directly. The categories above are the only AI-mediated processing we do. You can request access, rectification, or erasure at privacy@apir.ai.

3.Third-party AI Providers | Contracts and Sub-processors

APIR relies on a small set of third-party AI providers to deliver intelligent features. Our primary provider is Anthropic PBC (USA). Fallback third-party AI providers are configured but inactive at time of writing: OpenAI, Google AI, Mistral, Groq. Any change to this list is notified to customers under section 8 below.

Our contract with Anthropic includes:

No training on our content. Anthropic's commercial API terms (effective at time of writing) state that inputs and outputs are not used to train models. We rely on this contractually and review it annually.

Zero data retention by request. Where Anthropic offers zero-retention processing, we have it enabled for the compliance and assessment endpoints, Anthropic deletes the request payload after the response is sent. SENTINEL chats use standard retention (30 days at the provider) for safety review purposes.

Standard Contractual Clauses (SCCs). Anthropic is US-based; transfers from EEA users rely on the European Commission's 2021 SCCs.

Sub-processor disclosure. Anthropic publishes their sub-processor list at anthropic.com/legal/subprocessors. Material changes there will be reflected here.

4.Retention

AI-related data lives on for the periods below, then is deleted.

Data TypeRetentionWhere
SENTINEL conversation logs90 daysAPIR PostgreSQL (Supabase EU-West)
AI-generated compliance findingsLifetime of your subscription + 30 daysAPIR PostgreSQL
Regulatory summariesIndefinite (public regulatory content, no PII)APIR PostgreSQL
Prompt / response at AnthropicZero retention for compliance + assessment endpoints; up to 30 days for SENTINEL (safety review)Anthropic, USA
Black box event hashes7 years (tamper-evident audit record)APIR PostgreSQL

5.Your Rights Over AI-Mediated Data

You have every right in the main Privacy Policy plus these AI-specific rights:

Right to opt out of AI features. SENTINEL, AI-drafted compliance findings, and AI enrichment can each be disabled at Settings → Notifications. Disabling does not delete prior outputs.

Right to human review. Any AI-generated finding or score can be challenged, request human review at privacy@apir.ai and a compliance team member responds within 48 business hours.

Right to explanation. For any AI output that meaningfully affects you, you can request the model used, prompt template, and decision logic. We'll provide that within 30 days under Art. 15.

Right to delete prompts. SENTINEL conversation history can be wiped per user from the chat panel. APIR-side deletion is immediate; provider-side deletion happens on the provider's schedule (zero-retention endpoints are immediate, others up to 30 days).

6.Opt-Out Mechanisms

You can disable APIR's AI features without losing access to the rest of the platform:

SENTINEL: close the chat panel; we don't open it on your behalf. To prevent it from being available at all for your org, contact your admin or email privacy@apir.ai.

AI-drafted findings: in your org settings, set Compliance > AI Drafting to off. Future findings will be skeleton templates that compliance staff fill in manually.

Enrichment: set Discovery > AI Enrichment to off in org settings. Existing enriched data stays unless you also request deletion.

All AI: if you need every AI feature off for compliance reasons, we can apply an org-wide AI block, email privacy@apir.ai with subject “Full AI opt-out”.

7.Children

APIR is not directed to anyone under 18. We do not knowingly collect data from children. AI features are not designed to process data about children, and any account discovered to be operated by or on behalf of a minor is removed.

8.Changes To This Policy

Material changes are notified by email at least 30 days before they take effect. Adding a new AI provider, changing retention periods, or changing legal basis all count as material.

9.Contact

Data Protection Officer: dpo@apir.ai

General AI privacy enquiries: privacy@apir.ai

Report an AI incident or harm: incidents@apir.ai