Overview
aidrop.it is operated by AIDROP Technologies, Avenue "Solidarności" 117/615, 00-140 Warsaw, Poland — a company established in the European Union. This page explains how the General Data Protection Regulation (GDPR) applies to the Service: which data the Owner is responsible for as a controller, which it processes on a User's behalf as a processor, where that data lives, who else touches it, what protects it, and how a person exercises their rights.
It complements the Privacy Policy, which lists every processing activity in detail, and the Terms and Conditions, which govern the contract. Where the documents overlap, the Privacy Policy governs data protection and the Terms govern the contract.
The Service is a Project Workspace: a connected source repository, the knowledge and working instructions a Team keeps about it (Team Context), scoped access for an AI coding agent, and managed hosting for the application. Each of those brings personal data with it, and the Owner is not responsible for all of it in the same way.
Two roles, and which one applies
Under the GDPR a company is a controller when it decides why and how personal data is processed, and a processor when it processes data on somebody else's instructions. The Owner is both, for different data.
| The Owner is a controller for | The Owner is a processor for |
|---|---|
| Account and Team records: email addresses, names where given, sign-in identifiers, roles and invitations | Source code and repository contents the User connects |
| Billing and subscription records, and the notices sent about them | Project knowledge, working instructions and Team Context that the User's team writes or an agent records |
| Audit and action logs: who did what, from which address, and when | Runtime values the User enters for an application |
| Website usage and advertising measurement, after consent | Data stored in a managed database, cache or queue, and the logs an application writes |
| Support conversations and abuse reports | Personal data of the User's own end users, received by an application the User deploys |
For the right-hand column the User — or the organisation the User's Team belongs to — is the controller. The Owner processes that data only to provide the Service, as the Terms and the User's own configuration instruct, and uses it for no purpose of its own. The Terms, the Privacy Policy and this page together set out that processing.
What the Owner processes as a controller
| Activity | Data | Legal basis | Kept for |
|---|---|---|---|
| Providing an account and a Team | Email address, name where given, password hash, sign-in provider identifiers, Team membership and role | Contract — Art. 6(1)(b) | The life of the account; deleted on request |
| Billing | Plan, subscription status, invoices, and the customer identifier held by the payment provider | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) | As long as Polish accounting and tax law requires, currently five years from the end of the fiscal year |
| Transactional email | Email address, Team name, the notice sent — an invitation, a billing or hosting notice | Contract — Art. 6(1)(b) | As long as the account exists |
| Security, abuse prevention and audit | IP address, User-Agent, the action taken, timestamps; edge and application logs | Legitimate interest — Art. 6(1)(f): keeping the Service and the other Users safe | Audit and action logs for the life of the Team; server logs are rotated within days |
| Website analytics and advertising measurement | Device information, session statistics, masked session recordings, an advertising click identifier | Consent — Art. 6(1)(a), given in the cookie banner and withdrawable there at any time | Until consent is withdrawn |
| Error monitoring | The request that failed, the account it belonged to, stack traces | Legitimate interest — Art. 6(1)(f): keeping the Service working | Ninety days, the monitoring provider's default |
| Support and abuse reports | What the User or the reporter sends, and the address it came from | Contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) | As long as needed to handle the matter and any follow-up |
What the Owner processes on a User's behalf
Everything a User puts into a Project is processed on the User's instructions, which are the Terms together with what the User configures. In practice the Owner reads a connected repository at the revision the User authorises, indexes it, and builds it; stores Team Context and Project knowledge in versioned form; runs the application and the backing services behind it; and sends parts of that content to the AI providers listed below, for the three purposes the Service uses models for. It does not read a User's content for any other reason, and it does not train machine-learning models on it.
- Retention. Until the User deletes it — by archiving a Project, resetting a Team's context, or deleting a service — or until the deletion timelines in the Terms run out: sixty days after a Team's plan stops covering hosting, thirty days after a suspension for abuse.
- No backups. The Owner keeps no backup copies of User data and makes no restore promise. A managed database can be exported by its owner on demand, and the Owner retains no copy of the export. Deletion is final, which is why it is stated here rather than discovered.
- End users. A User who deploys an application that collects personal data is the controller for the people it collects from. The User is responsible for their privacy notice and their legal basis, and may rely on the Owner only as a processor. The Owner has no relationship of its own with a User's end users and does not use their data.
Where the data lives
The core of the Service — the control plane, the runtime servers on which Users' applications and managed databases run, the build servers, the Git hosting and the container registry — runs on servers in the Netherlands, rented from LeaseWeb and operated by the Owner. Some parts of the Service are provided by other companies, listed below.
Sub-processors
| Provider | What it does | What reaches it | Location |
|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL, authentication and blob storage behind the control plane | Account and Team records, connector tokens, the versioned Team Context and Project knowledge | United States |
| Cloudflare, Inc. | Proxy and edge in front of aidrop.it, app.aidrop.it and api.aidrop.it | Every request to those hostnames, including IP addresses | Global network; company in the United States |
| Paddle.com Market Ltd | Merchant of Record: checkout, invoicing, taxes and payment processing | Billing name, email address, plan; payment details, which the Owner never holds | United Kingdom, with processing in the United States |
| OpenAI, L.L.C. | The model that consolidates the signals a Team saves into its Team Context | The signals being merged and the Team Context pages they touch | United States |
| LangChain, Inc. (LangSmith) | Tracing of those consolidation runs | The run's transcript, token counts and cost | United States |
| Hetzner Online GmbH | Hosted model inference for the repository review in a preflight and the content check before publication | The repository contents and analysis under review; the content of an application about to be published | Germany |
| Functional Software, Inc. (Sentry) | Error monitoring | Failed requests, the account they belonged to, stack traces | United States |
| Amplitude, Inc. | Product analytics and session replay, after consent | Device information, usage events, masked session recordings | European Union, under EU data residency |
| Google Ireland Limited | Google Ads conversion measurement, and Google sign-in where chosen | An advertising click identifier and conversion events after consent; sign-in identity when chosen | Ireland, on Google's global infrastructure |
| GitHub, Inc. | Repository access through the aidrop GitHub App, and GitHub sign-in where chosen | The repositories the User authorises; sign-in identity | United States |
| Notion Labs, Inc. | The Notion connector, when a User enables it | The pages and databases the User shares | United States |
| Zoho Corporation | Transactional email: invitations, billing and hosting notices | Email address, Team name and the notice | European Union data centre |
| Crisp IM SARL | Support chat inside the dashboard | What the User writes in the chat, with their email address and name | France |
An AI tool the User connects to a Project — Claude, ChatGPT, Codex, Cursor, or any other client speaking the Model Context Protocol — is not a sub-processor of the Owner. The User chooses it, the content it reads is sent at the User's request, and the tool's provider processes it under its own terms.
This list is the current one, and the date at the top of the page is the date it was last changed.
Transfers outside the European Economic Area
Where a provider listed above processes data outside the European Economic Area, the transfer rests on the European Commission's Standard Contractual Clauses contained in that provider's data processing terms, or on the EU-US Data Privacy Framework where the provider is certified under it. Users may ask the Owner which safeguard applies to a given provider.
Security: the shapes, not the promises
None of the following is a policy. Each is a property the system was built with, which is the only kind of protection worth describing to a person whose data it holds.
- Every connection to the Service is encrypted in transit. Certificates are issued and renewed automatically, and a name serves nothing until it is proved.
- Runtime values a User enters for an application are encrypted at rest under a key held only by the control plane. They are never returned to anyone — not to the dashboard that set them, not to an agent — and are decrypted only for a deploy.
- Every record carries the Team it belongs to, and every read and write is checked against it, so one Team cannot reach another's data. An agent's grant resolves exactly one Project and nothing wider.
- Each Project's application runs in a private network of its own, on a read-only root filesystem. The step that builds a User's code holds no credential of the Owner's, and a runtime server stores no platform credential at all.
- A newly deployed application answers only behind a password or the Team's sign-in until its owner publishes it deliberately, and publication passes a content check first.
- Every action taken through the dashboard, the API or an agent is written to an audit log the Team can read.
- Payment card details never reach the Owner; the payment provider holds them.
What the Owner deliberately does not do is keep backups. That is stated in the Terms, in the Privacy Policy and above, because it changes what a User should plan for: an export taken on demand is the copy.
If something goes wrong
Where a personal data breach is likely to result in a risk to people, the Owner notifies the competent supervisory authority within 72 hours of becoming aware of it, as Article 33 requires, and informs the affected Users without undue delay with what is known at the time: what happened, which data was involved, what has been done, and what they can do. Where the breach concerns data the Owner processes on a User's behalf, that User is informed so that they can meet their own obligations towards their end users.
Your rights, and how to use them
Any person whose personal data the Owner holds as a controller may:
- access it, and learn how it is processed and with whom it is shared;
- rectify it — account details can also be changed in the dashboard;
- erase it, subject to what the Owner must keep by law, such as billing records;
- restrict its processing while a dispute about it is settled;
- object to processing based on legitimate interest, and to direct marketing at any time;
- receive it in a structured, machine-readable form, and have it transmitted to another controller where technically feasible;
- withdraw consent at any time, for the processing that rests on it — analytics and advertising measurement, through Cookie preferences in the footer of every page;
- complain to a supervisory authority.
Write to info@aidrop.it with the right you are exercising in the subject line; the links under Your data at the bottom of this page open a prepared message. Requests are free and are answered as early as possible and always within one month. The Owner may ask for enough information to be sure the request comes from the person it concerns.
For data the Owner processes on a User's behalf — a repository, Team Context, or the records of an application a User deployed — the request belongs to that User, who is the controller; the Owner will assist them in answering it.
The supervisory authority for the Owner is the Polish data protection authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl. A person may also complain to the authority of the member state where they live or work.
Automated decisions
Two steps of the Service are decided by software. A preflight reports whether a repository can run and what it is missing; it is a statement about code, not about a person. Before an application is published to the public, a model checks its content: a clean result publishes, and anything else — a refusal, a doubt, or a check that could not run — goes to a person. Neither step produces a legal or similarly significant effect on a natural person in the sense of Article 22, and a person can always be reached about either. The Owner does not profile Users for marketing.
Age
The Service is for adults: Users must be eighteen or older, as the Terms say. The Owner does not knowingly process a child's personal data and deletes it if it learns of any.
Contact
The Owner has not appointed a Data Protection Officer and is not required to appoint one. Questions about this page, or a request under it, go to info@aidrop.it with "GDPR" in the subject. The postal address is at the top of the page.
Changes to this page
The Owner updates this page when a sub-processor, a location or a practice changes. The date of the latest update is shown at the top. A change that affects processing based on consent is put to Users for new consent where the law requires it.