DRAFT — NOT APPROVED FOR PRODUCTION. Not legally binding until published and activated via the AIQOS admin legal-documents console.
# DRAFT — NOT APPROVED FOR PRODUCTION

**Status:** counsel/privacy/DPO-review draft only. Not published, not active. Facts
marked `[TO BE CONFIRMED]` come from `docs/compliance/*` and must be resolved before this
document is finalized — see `docs/specs/26-gdpr-readiness-and-legal-publication.md` §3, §10.

---

# AIQOS® · OneCraft — Privacy Notice

**Controller:** AIQOS B.V., BINK36, Binckhorstlaan 36, M4.17, 2516 BE The Hague,
Netherlands (KvK: 71140123)
**Contact for privacy questions:** alexandre.faber@aiqos.io
**Version:** 1.0-draft **Effective date:** [TO BE CONFIRMED — set on publication]

This Privacy Notice describes how AIQOS processes personal data in connection with
OneCraft (https://onecraft.aiqos.io). It is a notice, not itself a consent mechanism —
where consent is the legal basis for a specific activity (see §3), that consent is
collected separately and specifically.

If you access OneCraft as a member of a company Organization, your employer's own
Data Processing Addendum with AIQOS governs how your company's workspace content is
processed; this Notice covers what AIQOS itself controls (account, authentication,
security, billing, and service telemetry) and describes AIQOS's role as a processor for
company-workspace content.

## 1. What we collect

| Category | Examples |
|---|---|
| Account and identity | Email, name, profile image, locale |
| Authentication and session | Session state, sign-in method, last login |
| Legal-acceptance evidence | Document version accepted, timestamp, IP address (only where this deployment operates behind a trusted, configured reverse proxy), user agent |
| Billing (company workspaces) | Billing contact email, credit balances |
| Workspace content | Project files, prompts, chat messages, attachments you or your organization submit — see §2 for how this is processed |
| Feedback you submit | Description, category, severity, rating, and — only if you separately opt in — diagnostic detail, chat transcript, or a snapshot of your workspace files |
| Service telemetry | Token counts, cost, model/provider identifiers — **never the content of your prompts or responses** |
| Support communications | Messages you send to AIQOS support |

See `docs/compliance/data-inventory.md` for the full engineering-level inventory this
Notice is built from.

## 2. How we use it, and why

| Purpose | Lawful basis |
|---|---|
| Operate your account, authenticate you, and maintain your session | Necessary to provide the service you requested |
| Record your legal acceptance | Necessary to demonstrate you agreed to the current Beta User Terms and Acceptable Use Policy |
| Provision and manage your personal trial or company workspace | Necessary to provide the service |
| Prevent fraud, abuse, and security incidents | Our legitimate interest in a secure service |
| Bill and administer credits | Necessary to provide the service |
| Understand aggregate service cost and usage (never your prompt/response content) | Our legitimate interest in operating the service responsibly |
| Process feedback you submit | Your consent, given through the specific opt-in controls in the feedback form |
| Respond to support requests | Necessary to provide the service you requested |

For **company workspace content** (project files, prompts, chat messages your
organization's members submit), AIQOS generally acts as a **processor** on your
organization's instructions under a Data Processing Addendum; your organization is the
controller for that content and determines its own lawful basis with its own users.

## 3. AI processing

OneCraft uses third-party AI providers to generate and process content, including
`[TO BE CONFIRMED — final enabled-provider list per docs/compliance/subprocessor-register.md]`.
Prompts, relevant chat history, and project file content you or your organization submit
may be sent to these providers to generate a response. AIQOS uses paid API tiers for these
providers in production `[TO BE CONFIRMED]`, consistent with each provider's own terms
regarding whether free-tier usage may be used for their own model training.

## 4. Who else receives your data

| Recipient | Purpose |
|---|---|
| AI providers (see §3) | Generating responses to your requests |
| AIQOS `onestream-mcp` service | Validating and compiling OneStream artifacts you generate |
| Web-search provider (if enabled) | Answering questions that need current public information |
| Email delivery provider | Sending sign-in and notification emails |
| Bot-protection provider | Preventing automated abuse of sign-in |
| Identity providers (Google / Microsoft), if you use them to sign in | Authenticating you |
| Payment provider (if billing is active for your Organization) | Processing payments |
| Infrastructure/hosting providers | Running the service |

A complete, current list with regions and safeguard mechanisms is maintained in
`docs/compliance/subprocessor-register.md` and `docs/compliance/international-transfers.md`
`[TO BE CONFIRMED before this becomes the public subprocessor list — see spec 26 §3]`.

## 5. International transfers

Where any recipient in §4 is located outside the European Economic Area, AIQOS relies on
`[TO BE CONFIRMED — EU Commission adequacy decisions and/or Standard Contractual Clauses,
per docs/compliance/international-transfers.md]`.

## 6. How long we keep it

Retention periods are documented in `docs/compliance/retention-schedule.md` and summarized
here once approved `[TO BE CONFIRMED — periods pending human/DPO approval]`. In general:
soft-deleted projects are permanently removed after a defined retention window; feedback
workspace snapshots (only created if you opt in) expire and are purged automatically after
a defined retention window; legal-acceptance evidence is retained for as long as needed to
demonstrate your agreement.

## 7. Your rights

Subject to applicable law, you may request access to, export of, correction of,
restriction of, or objection to processing of your personal data, or deletion where
applicable. Submit a request at Settings → Privacy inside OneCraft, or email
alexandre.faber@aiqos.io. Requests concerning company-workspace content are generally
routed to your organization, since AIQOS is a processor for that content, not the
controller.

You also have the right to lodge a complaint with a supervisory authority, including the
Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

## 8. Cookies and local storage

See the OneCraft Cookie Notice for details on the cookies and browser storage OneCraft
uses.

## 9. Security

AIQOS applies technical and organizational measures appropriate to the risk, including
tenant-isolated authorization, encryption in transit, least-privilege storage credentials,
and audited administrative actions. No system is perfectly secure; report suspected
security issues to alexandre.faber@aiqos.io.

## 10. Changes to this Notice

AIQOS may update this Notice. Material changes will be reflected in a new version number
and effective date.

## 11. Contact

alexandre.faber@aiqos.io

---

**Outstanding items before publication** (see
`docs/specs/26-gdpr-readiness-and-legal-publication.md` §3): confirm production hosting
region, enabled AI providers, backup location/retention, and the approved retention
schedule; privacy counsel/DPO to confirm the controller/processor role table in
`docs/compliance/data-flow-and-role-map.md`; confirm whether a DPIA is required per
`docs/compliance/dpia-screening.md`.