Our GDPR Commitments
GDPR
How Aturno complies with the General Data Protection Regulation.
Last updated: September 2026
Contents
Request our DPA
Our Data Processing Agreement is available on request. Contact us at legal@aturno.ai.
Who We Are
Aethelon s.r.o. is the data controller for personal data processed through the Aturno platform (aturno.ai). We are registered in the Czech Republic and operate exclusively under Czech and EU law. As a legal AI platform serving legal professionals, we treat data protection not as a compliance exercise but as a core product requirement.
Legal Bases for Processing
We process personal data only where a valid legal basis under Article 6 GDPR exists. The following table summarises our processing activities and their legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account registration and authentication | Art. 6(1)(b): Contract performance |
| Delivering AI research and drafting features | Art. 6(1)(b): Contract performance |
| Payment processing and billing | Art. 6(1)(b): Contract performance |
| Security monitoring and fraud prevention | Art. 6(1)(f): Legitimate interests |
| Compliance with Czech accounting and tax law | Art. 6(1)(c): Legal obligation |
| Marketing communications (optional) | Art. 6(1)(a): Consent |
Your Rights
As a data subject under GDPR, you have the following rights. All requests are handled free of charge within 30 days.
Right of Access (Art. 15)
Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your data where there is no compelling reason for continued processing.
Right to Restriction (Art. 18)
Ask us to restrict processing of your data in certain circumstances.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests.
Right to Withdraw Consent (Art. 7)
Withdraw consent at any time where processing is based on consent, without affecting prior processing.
To exercise any of these rights, contact us at privacy@aturno.ai. We will acknowledge your request within 72 hours and respond in full within 30 days.
Data Transfers
Our storage and database run in EU regions. Some subprocessors process data in the United States; every such transfer relies on a Chapter V GDPR safeguard:
- Standard Contractual Clauses (SCCs): where any subprocessor operates outside the EEA, we use the EU Commission's approved SCCs as the transfer mechanism.
- Adequacy decisions: for transfers to countries with an EU adequacy decision, no additional safeguards are required.
- AI model processing currently runs on OpenAI infrastructure in the United States under the EU SCCs incorporated in our executed Data Processing Addendum with OpenAI Ireland Ltd, with a contractual prohibition on training on your data. Under OpenAI's standard API policy, inputs and outputs are retained for up to 30 days solely for abuse monitoring and then deleted. We have requested EU-region processing and zero data retention from OpenAI and will move AI processing fully in-region once approved.
Subprocessors
We use a small number of trusted subprocessors, each bound by a data processing agreement consistent with GDPR. The location column states where processing takes place; US processing is covered by the EU Standard Contractual Clauses:
| Subprocessor | Purpose | Location |
|---|---|---|
| WorkOS, Inc. | Authentication and identity management | US (EU SCCs) |
| Convex, Inc. | Serverless database and backend: chat history and account data | EU region (US entity, EU SCCs) |
| Cloudflare, Inc. (R2) | Encrypted file storage | EU region (US entity, EU SCCs) |
| Stripe Payments Europe, Ltd. | Payment processing (PCI-DSS Level 1) | EU (Ireland) |
| OpenAI Ireland Ltd | AI model provider: no training on your data, zero data retention requested | US processing under EU SCCs; EU residency in progress |
| LanceDB, Inc. | Vector search over the public legal corpus | US (EU SCCs) |
| Perplexity AI, Inc. | Web search, only when you use web search mode | US (EU SCCs) |
| Vercel Inc. | Web hosting and frontend delivery | US (EU SCCs) |
| PostHog, Inc. | Product analytics, enabled only with your cookie consent | EU region (US entity, EU SCCs) |
We will notify you at least 30 days before adding a new subprocessor. You may object to any new subprocessor by contacting us at privacy@aturno.ai.
Data Processing Agreement
If you use Aturno on behalf of an organisation and are required to have a Data Processing Agreement (DPA) in place, we are happy to provide one. Our DPA covers the full GDPR processor/controller framework, including subprocessor management, data subject rights assistance, breach notification procedures, and data deletion commitments. Request our DPA at legal@aturno.ai.
Security Measures
We implement appropriate technical and organisational measures under Art. 32 GDPR to protect your personal data:
- Encryption at rest: AES-256 for all files stored on Cloudflare R2.
- Encryption in transit: TLS 1.2 minimum for all connections.
- Access controls: role-based access with audit logging and least-privilege principles.
- Data minimisation: we collect only the data necessary to provide the service.
- Breach response: 72-hour notification to ÚOOÚ, prompt notification to affected users.
Supervisory Authority
You have the right to lodge a complaint with the competent supervisory authority at any time. For users in the Czech Republic, the supervisory authority is:
Úřad pro ochranu osobních údajů (ÚOOÚ)
You may also contact the supervisory authority in your country of residence if you are not based in the Czech Republic.
Contact
For all GDPR-related enquiries, data subject requests, or to request our Data Processing Agreement:
