Privacy Policy
Effective date: 2026-09-25
Last updated: 2026-09-25
1. Who we are and how to contact us
This Privacy Policy explains how AIMLGov, s.r.o., company ID 29742188, with its registered office at Příčná 1892/4, Nové Město, 110 00 Praha 1, Czech Republic ("AIMLGov", "we", "us", "Provider") processes personal data in connection with the AIGov platform available at govbase.dev (the "Service").
Contact for privacy and legal matters: legal@govbase.dev (not a substitute for formal legal notices). Postal correspondence: AIMLGov, s.r.o., at the registered office above.
For most processing described in this Policy, AIMLGov acts as a controller. Where AIMLGov processes personal data on behalf of a Customer as part of the Customer's use of the Service (in particular, Customer Data submitted into the Service), AIMLGov acts as a processor, and that processing is governed by the Data Processing Agreement (the "DPA") between AIMLGov and the relevant Customer.
This Policy should be read together with the Cookie Policy (https://govbase.dev/cookies), which addresses cookies, browser storage and measurement technologies in more detail, and with the Terms of Service and DPA, which govern the contractual relationship with Customers.
2. Scope
This Policy applies to:
- visitors to our public website and marketing pages;
- prospects who contact us or request a demo;
- individuals who sign up for, administer, or are added as Authorized Users of a Customer's AIGov account;
- individuals whose data we process for billing, support, or account administration purposes; and
- Individual and Corporate Contributors under our Contributor License Agreements, to the extent personal data is processed in that context.
It does not govern how a Customer, as controller, processes personal data using the Service (e.g., personal data a Customer chooses to record about its own personnel, AI systems, or governance processes inside AIGov). That processing is the Customer's responsibility as controller, and AIMLGov's role as processor is governed by the DPA. If you are an individual whose data has been submitted into AIGov by one of our Customers and you have a question or request, please contact that Customer directly; AIMLGov will support the Customer in responding as required under the DPA.
3. Categories of personal data we process
Depending on how you interact with us, we may process:
a) Account and identity data — name, work email address, password (hashed), job title, company/organization, team/tenant assignment, role and permissions within the Service, profile information you choose to add.
b) Billing and subscription data — billing contact name and email, billing address, VAT/company identification numbers, subscription plan, invoices, payment status, and transaction identifiers. Full card/payment details are collected and processed directly by our payment processor, Stripe; AIMLGov does not store full card numbers.
c) Technical logs and telemetry — IP address, device and browser information, authentication and session events, API request logs, error logs, security and audit logs, timestamps, and similar operational data generated by use of the Application.
d) Analytics data — aggregate, cookieless traffic and performance data collected via Vercel Web Analytics and Vercel Speed Insights (route/URL, referrer, coarse device/browser category, approximate country-level location derived from the request, timing/Web Vitals metrics). See the Cookie Policy for details of the technologies used.
e) Support and communications data — content of support requests, emails, and other communications you send us, together with associated metadata (sender, timestamps, attachments).
f) Customer Data you or your organization submit into the Service — where you are an Authorized User acting on behalf of a Customer, information you enter into AIGov (e.g., names of responsible persons, reviewer/approver identities, comments, uploaded documents) is Customer Data processed by AIMLGov as processor on the Customer's instructions.
g) Legal acceptance records — the version of each legal document (Terms of Service, this Privacy Policy, the DPA) you accepted, a SHA-256 hash of the exact text accepted, the timestamp of acceptance, and associated technical metadata.
h) Contributor data — where you accept an Individual or Corporate Contributor License Agreement, we process your name, email address, GitHub/GitLab username or other contributor identifier, organization (if applicable), acceptance records, and related audit metadata.
We do not intentionally collect special categories of personal data (Art. 9 GDPR) about Service users and ask that none be submitted as Customer Data unless strictly necessary for a Customer's own lawful purposes, in which case the Customer remains responsible as controller for the relevant legal basis.
4. Sources of personal data
We obtain personal data:
- directly from you (e.g., when you register, contact us, or use the Service);
- from the Customer organization that added you as an Authorized User, or from an administrator within that organization;
- automatically, through your use of the Service (technical logs, analytics, cookies as described in the Cookie Policy);
- from our payment processor, Stripe, in connection with billing events; and
- from publicly available sources or business contact data, where you interact with us as a prospect and we have a legitimate reason to collect such data (e.g., a business email address used to request a demo).
Where a Customer or another third party (e.g., a colleague who invites you) provides us with your personal data, that party is responsible for ensuring it had a lawful basis and, where required, gave you appropriate notice before doing so.
5. Purposes and legal bases
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Providing and operating the Service | Account creation, authentication, tenant/team management, core Application functionality | Performance of a contract (Art. 6(1)(b)) or legitimate interests (Art. 6(1)(f)) |
| Billing and subscription management | Invoicing, processing payments via Stripe, dunning | Performance of a contract (Art. 6(1)(b)); legal obligation for accounting/tax records (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention and abuse monitoring | Authentication logs, rate limiting, anomaly detection, access control | Legitimate interests (Art. 6(1)(f)) — securing the Service and our Customers' data |
| Product analytics and performance monitoring | Vercel Web Analytics, Speed Insights | Legitimate interests (Art. 6(1)(f)) — understanding and improving the Service; processing is cookieless and limited to aggregate technical data |
| Customer support | Responding to support requests, troubleshooting | Performance of a contract (Art. 6(1)(b)); legitimate interests where you are not the contracting party |
| Legal acceptance and compliance records | Recording acceptance of Terms, this Policy, the DPA | Legal obligation and legitimate interests (Art. 6(1)(c), (f)) — evidencing agreement and compliance |
| Marketing communications (where applicable) | Responding to demo requests, sending product updates you opted into | Consent (Art. 6(1)(a)) or legitimate interests for existing business contacts, subject to opt-out |
| Legal claims, audits and regulatory compliance | Responding to legal process, enforcing our Terms, defending claims | Legal obligation and legitimate interests (Art. 6(1)(c), (f)) |
| Contributor licensing administration | Recording acceptance and scope of CLAs | Performance of a contract / legitimate interests (Art. 6(1)(b), (f)) |
We do not use your personal data for any automated decision-making that produces legal or similarly significant effects on you, and we do not perform profiling for advertising purposes.
6. Recipients and disclosures
We disclose personal data only as necessary and to the following categories of recipients:
- Sub-processors and service providers engaged to help operate the Service (hosting, database, DNS/proxy, payment processing, transactional email) — see Section 8 and the published Subprocessor List;
- Professional advisors (legal, accounting, auditors) where necessary;
- Purchasers or successors in the context of a merger, acquisition, financing, or sale of assets, subject to confidentiality and, where required, notice to affected individuals;
- Public authorities or regulators, where required by law, a valid legal process, or to protect the rights, property, or safety of AIMLGov, our Customers, or others; and
- A Customer organization, where you are an Authorized User of that Customer and account/administration data needs to be shared with the Customer's administrators as part of normal Service operation.
We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.
7. International data transfers
Some of the infrastructure used to provide the Service is located, or may process data, outside the European Economic Area ("EEA") — in particular in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses ("SCCs") and, where relevant, the UK International Data Transfer Addendum, as implemented through our sub-processors' own data processing agreements. Where a sub-processor participates in the EU–U.S. Data Privacy Framework, that may provide an additional or alternative basis for the relevant transfer.
We keep the transfer mechanisms used by our sub-processors under review as part of our vendor management process. A summary of the transfer mechanism relied upon for each sub-processor is maintained together with the Subprocessor List referenced in Section 8. You may request further information about the safeguards applicable to a specific transfer by contacting legal@govbase.dev.
8. Sub-processors
We use a limited number of carefully selected sub-processors to provide the Service. Categories currently in use include: cloud application hosting, database hosting, DNS/proxy and network services, payment processing, and transactional email delivery.
An up-to-date list of sub-processors, including the service each provides, its general processing location, and its role, is published at https://govbase.dev/subprocessors (or, until that page is published, is available on request at legal@govbase.dev). Material changes to this list are notified in accordance with the mechanism described in the DPA.
9. Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, taking into account:
- the duration of your (or your organization's) contractual relationship with us;
- legal, tax, and accounting retention requirements under Czech and EU law;
- the need to maintain audit trails, security logs, and legal acceptance records for compliance and evidentiary purposes; and
- applicable limitation periods for legal claims.
Indicative retention periods:
| Category | Typical retention |
|---|---|
| Active account and identity data | Duration of the account, plus a limited period after closure for reactivation/support purposes |
| Billing and invoicing records | As required by applicable tax/accounting law |
| Technical/security logs | Retained only for as long as necessary for the operational and security purpose for which they were generated, on a rolling basis |
| Analytics data | Retained in aggregate/technical form; not linked to an identified individual account |
| Support communications | Duration of the relationship plus a reasonable period for quality and dispute-resolution purposes |
| Legal acceptance records | Duration of the relationship plus the applicable limitation period |
10. Your rights
Subject to applicable law and the exceptions described above, you may have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, including direct marketing;
- data portability, where processing is based on consent or contract and carried out by automated means; and
- withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact legal@govbase.dev. We may need to verify your identity before responding, and may decline or limit requests to the extent permitted by law (for example, where fulfilling a request would adversely affect the rights of others or conflict with a legal retention obligation).
If your personal data was submitted into AIGov by a Customer as Customer Data, please also contact that Customer directly, as it is the controller for that data; AIMLGov will assist the Customer in responding as required under the DPA.
Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority. In the Czech Republic, the competent authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz. You may also contact the supervisory authority in your own EU member state of residence or habitual work.
11. Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure, proportionate to the risk.
12. Children
The Service is intended for business use by adults acting on behalf of an organization. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 16.
13. Relationship to the Cookie Policy
This Policy addresses our processing of personal data generally. Cookies, browser storage, and similar measurement technologies used within the Service are described in detail in the separate Cookie Policy (https://govbase.dev/cookies), which forms part of our overall privacy documentation. Where there is any inconsistency between the two documents regarding cookies specifically, the Cookie Policy prevails; for all other personal data processing, this Policy applies.
14. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our sub-processors, or legal requirements. The version, effective date, and last-updated date appear at the top of this document. Material changes will be reflected on this page and, where you have an account, may also be notified through the Service or by other reasonable means.
15. Contact
Questions about this Privacy Policy or our data protection practices: legal@govbase.dev.
AIMLGov, s.r.o.
Příčná 1892/4, Nové Město
110 00 Praha 1, Czech Republic
Tenant-scoped acceptance is recorded only at /legal/acceptance after authentication — not on this page.