Our GDPR Commitments

GDPR

How Aturno complies with the General Data Protection Regulation.

Last updated: September 2026

01

Who We Are

Aethelon s.r.o. is the data controller for personal data processed through the Aturno platform (aturno.ai). We are registered in the Czech Republic and operate exclusively under Czech and EU law. As a legal AI platform serving legal professionals, we treat data protection not as a compliance exercise but as a core product requirement.

02

Legal Bases for Processing

We process personal data only where a valid legal basis under Article 6 GDPR exists. The following table summarises our processing activities and their legal bases:

Processing ActivityLegal Basis
Account registration and authenticationArt. 6(1)(b): Contract performance
Delivering AI research and drafting featuresArt. 6(1)(b): Contract performance
Payment processing and billingArt. 6(1)(b): Contract performance
Security monitoring and fraud preventionArt. 6(1)(f): Legitimate interests
Compliance with Czech accounting and tax lawArt. 6(1)(c): Legal obligation
Marketing communications (optional)Art. 6(1)(a): Consent
03

Your Rights

As a data subject under GDPR, you have the following rights. All requests are handled free of charge within 30 days.

Right of Access (Art. 15)

Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

Request deletion of your data where there is no compelling reason for continued processing.

Right to Restriction (Art. 18)

Ask us to restrict processing of your data in certain circumstances.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests.

Right to Withdraw Consent (Art. 7)

Withdraw consent at any time where processing is based on consent, without affecting prior processing.

To exercise any of these rights, contact us at privacy@aturno.ai. We will acknowledge your request within 72 hours and respond in full within 30 days.

04

Data Transfers

Our storage and database run in EU regions. Some subprocessors process data in the United States; every such transfer relies on a Chapter V GDPR safeguard:

  • Standard Contractual Clauses (SCCs): where any subprocessor operates outside the EEA, we use the EU Commission's approved SCCs as the transfer mechanism.
  • Adequacy decisions: for transfers to countries with an EU adequacy decision, no additional safeguards are required.
  • AI model processing currently runs on OpenAI infrastructure in the United States under the EU SCCs incorporated in our executed Data Processing Addendum with OpenAI Ireland Ltd, with a contractual prohibition on training on your data. Under OpenAI's standard API policy, inputs and outputs are retained for up to 30 days solely for abuse monitoring and then deleted. We have requested EU-region processing and zero data retention from OpenAI and will move AI processing fully in-region once approved.
05

Subprocessors

We use a small number of trusted subprocessors, each bound by a data processing agreement consistent with GDPR. The location column states where processing takes place; US processing is covered by the EU Standard Contractual Clauses:

SubprocessorPurposeLocation
WorkOS, Inc.Authentication and identity managementUS (EU SCCs)
Convex, Inc.Serverless database and backend: chat history and account dataEU region (US entity, EU SCCs)
Cloudflare, Inc. (R2)Encrypted file storageEU region (US entity, EU SCCs)
Stripe Payments Europe, Ltd.Payment processing (PCI-DSS Level 1)EU (Ireland)
OpenAI Ireland LtdAI model provider: no training on your data, zero data retention requestedUS processing under EU SCCs; EU residency in progress
LanceDB, Inc.Vector search over the public legal corpusUS (EU SCCs)
Perplexity AI, Inc.Web search, only when you use web search modeUS (EU SCCs)
Vercel Inc.Web hosting and frontend deliveryUS (EU SCCs)
PostHog, Inc.Product analytics, enabled only with your cookie consentEU region (US entity, EU SCCs)

We will notify you at least 30 days before adding a new subprocessor. You may object to any new subprocessor by contacting us at privacy@aturno.ai.

06

Data Processing Agreement

If you use Aturno on behalf of an organisation and are required to have a Data Processing Agreement (DPA) in place, we are happy to provide one. Our DPA covers the full GDPR processor/controller framework, including subprocessor management, data subject rights assistance, breach notification procedures, and data deletion commitments. Request our DPA at legal@aturno.ai.

07

Security Measures

We implement appropriate technical and organisational measures under Art. 32 GDPR to protect your personal data:

  • Encryption at rest: AES-256 for all files stored on Cloudflare R2.
  • Encryption in transit: TLS 1.2 minimum for all connections.
  • Access controls: role-based access with audit logging and least-privilege principles.
  • Data minimisation: we collect only the data necessary to provide the service.
  • Breach response: 72-hour notification to ÚOOÚ, prompt notification to affected users.
08

Supervisory Authority

You have the right to lodge a complaint with the competent supervisory authority at any time. For users in the Czech Republic, the supervisory authority is:

Úřad pro ochranu osobních údajů (ÚOOÚ)

Pplk. Sochora 27, 170 00 Praha 7, Czech Republic

www.uoou.cz

+420 234 514 111

You may also contact the supervisory authority in your country of residence if you are not based in the Czech Republic.

09

Contact

For all GDPR-related enquiries, data subject requests, or to request our Data Processing Agreement:

privacy@aturno.ai

Aethelon s.r.o., Czech Republic

Start free today.

No credit card required to begin.