Privacy Policy
Last updated: September 2026
This privacy policy is available in English and German with the same content.
1. Who is responsible
Andreas Schadauer, sole trader
Viktorgasse 18/12a, 1040 Vienna, Austria
service@suveren.ai
For the website, registration, accounts and demo accounts, Suveren is the controller. During the first phase of an engagement, while Suveren hosts the Authority Server for a customer, Suveren processes that customer’s data on the customer’s behalf, under a data processing agreement with the customer. Once the customer runs the Authority Server on its own infrastructure, Suveren no longer receives that data, unless the customer sends it to us, for example for support. In demo accounts, only test data and the account data of the users may be entered (Terms, section 7).
2. What we collect
- Website visits: our hosting provider processes technical request data (IP address, browser, time, page requested) to deliver the site and keep it secure. We run no analytics.
- Registration: name, email address, company, company size, phone number (optional), what you want to use Suveren for, an optional note, and an invitation code if you have one.
- Booking the thirty minutes: if you book a slot, you enter your details on the booking page of cal.eu, which is embedded on our site. cal.eu processes them under its own privacy policy.
- Accounts: display name, email address, a hashed API key, team membership, roles and settings.
- Mandates: what an AI may do, for which purpose, within which limits, until when, and who issued it.
- Tickets: issued before an action runs. A ticket records the action type, the mandate and limits it falls under, the time, the signature, the person who authorised it, and a fingerprint (hash) of the content. For actions the AI takes on its own, the content itself is not stored.
- Approval requests: when a mandate says the AI must ask first, the proposed action, including its content (for example the text of an email), is stored so that the person approving can read it.
3. What we do not collect
- the content of actions the AI takes on its own: only a fingerprint,
- browsing behaviour, analytics or advertising data,
- source code or repository content,
- any information about how fast or how well a person works.
4. Why we process it, and on which legal basis
- Registration, arranging the conversation, demo accounts and the hosted Authority Server: to take steps before a contract and to provide the service (GDPR Art. 6(1)(b)).
- Transactional emails (confirming your address, activating your account): Art. 6(1)(b).
- Security, abuse prevention and technical logs: our legitimate interest in a secure service (Art. 6(1)(f)).
- Accounting and tax records for paid engagements: legal obligation (Art. 6(1)(c)).
5. Who receives data
- Vercel Inc. hosts the website and the application, in the Frankfurt region. Privacy policy
- Upstash Inc. provides the database, in the Frankfurt region. Privacy policy
- Brevo SAS (France) sends our transactional emails and receives your name and email address for that purpose. Privacy policy
- cal.eu handles bookings for the thirty-minute conversation, if you book one.
- Partners in an engagement receive customer data only as far as their part of the engagement needs it, and only under a written agreement.
We have data processing agreements with our processors. We do not sell data.
6. Transfers outside the EU
Our data is stored in the EU (Frankfurt). Vercel and Upstash are US companies, so access from the United States cannot be ruled out, for example for support or on a legal request. Such transfers are covered by the EU-U.S. Data Privacy Framework or by the EU Standard Contractual Clauses.
7. How long we keep it
- Registrations that do not lead to a demo account: deleted after 12 months.
- Rejected registrations: deleted within 90 days.
- Demo accounts, including their mandates, tickets and approval requests: deleted 90 days after the account is closed.
- Approval requests: kept until they are decided, at most 72 hours, and deleted 7 days after the decision.
- Deletion on request: within 30 days of your request.
- Hosted phase of an engagement: handed over to the customer or deleted when the customer moves to its own Authority Server, as set out in the data processing agreement.
- Accounting records: seven years, as Austrian tax law requires.
8. Cookies and browser storage
hap-session: keeps you signed in. It is strictly necessary and ends when you sign out, or after 24 hours (7 days after signing in through an email link, 30 days for a Gateway connection).NEXT_LOCALE: remembers the language you chose, for 30 days.- Local storage
theme: remembers light or dark mode on your device. It is never sent to us.
We use no tracking, advertising or analytics cookies. The embedded cal.eu booking page may set its own cookies; see its privacy policy.
9. The public ticket page
Anyone who has the link to a ticket can check it at suveren.ai/r/…. The page shows the action type, the time and the signature check. It shows the authorising person’s name only if their identity was verified, by Suveren or by an EU digital identity; otherwise it shows no name. It never shows the content of the action.
10. Security
Connections are encrypted. API keys are stored only as hashes. Tickets are signed. A change to their signed content can be detected by checking the signature with the matching public key.
11. Your rights
Under the GDPR you have the right to:
- Access your data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Complain to the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at)
Write to service@suveren.ai. We answer within one month.
12. Changes
We update this policy when our processing changes. We tell registered users about material changes by email. The date at the top shows the latest version.