Data Privacy
Deepentix builds sovereign, auditable AI knowledge infrastructure for regulated enterprises. We apply the same rigor to your data that we ask our platform to apply to yours: verifiable, traceable, and never moved further than it has to be.
This page explains what personal data we collect, why, how it is protected, and how it interacts with the EU General Data Protection Regulation (“GDPR”) and the EU Artificial Intelligence Act (“EU AI Act”).
01 Who is responsible for your data
The data controller for this website and for our sales, marketing, and recruiting activities is:
Deepentix FlexCo
Platanenstraße 19, 2522 Oberwaltersdorf, Austria
Registered with the Landesgericht Wiener Neustadt, FN 648262 b
Managing Director: Morteza Amini
For privacy questions or to exercise your rights, contact us at privacy@deepentix.com. Given our current size and processing activities, we are not required to appoint a statutory Data Protection Officer under Art. 37 GDPR; the above inbox is monitored directly by our leadership team and reaches the person accountable for data protection.
02 Two roles we play under the GDPR
Deepentix is a business-to-business platform, so most of the personal data we touch flows through two distinct relationships:
- As a data controller — for data about you as a website visitor, prospect, business contact, partner, or job applicant (Sections 3–4 below).
- As a data processor — when an enterprise customer uses the Deepentix Platform to ingest and query its own documents (policies, protocols, claims files, clinical or contract data). In that relationship, the customer is the data controller, we process data strictly on its documented instructions under a Data Processing Agreement (Art. 28 GDPR), and terms are set out in that customer’s agreement rather than in this public policy. If you are an end user of a Deepentix-powered workflow inside one of our customers’ organizations, please direct data subject requests to that organization first; we support them in fulfilling those requests.
03 What information we collect (as controller)
| Category | Examples | Typical source |
|---|---|---|
| Business contact data | Name, work email, phone, company, job title | Demo requests, contact forms, events, LinkedIn, partner introductions |
| Sales & support communications | Emails, call and meeting notes, content of support tickets | Direct correspondence with our team |
| Website usage data | IP address, browser and device type, pages viewed, referring page, approximate location | Cookies and server logs when you visit landings.deepentix.com or deepentix.com |
| Recruitment data | CV, cover letter, references, interview notes | Job applications and recruiting conversations |
| Platform administration data | Admin account names, emails, roles, permissions, access and audit logs | Provisioning and use of a customer’s Deepentix instance |
We do not knowingly seek special categories of data (Art. 9 GDPR) through this website, and we ask that you avoid including sensitive personal data in free-text fields such as contact forms.
04 Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Responding to demo requests and inquiries, running pilots and contracts | (b) performance of a contract or pre-contractual steps |
| Sending product, security, or partnership information you asked for; account and platform administration | (b) contract, (f) legitimate interest |
| Marketing communications you can opt out of at any time | (a) consent, or (f) legitimate interest for existing business contacts |
| Website analytics and product improvement, using aggregated or pseudonymized data where possible | (f) legitimate interest |
| Recruitment and candidate evaluation | (b) contract, (a) consent |
| Complying with tax, corporate, and other legal obligations | (c) legal obligation |
05 Our AI-specific commitments
Deepentix exists to make enterprise AI auditable rather than opaque, and we hold ourselves to the same standard with your data and the EU AI Act (Regulation (EU) 2024/1689):
- We do not train shared or third-party models on your content. Documents you or your organization ingest into a Deepentix instance are used only to build that instance’s Claim Graph and answer your queries. They are never used to train foundation models, shared with other customers, or repurposed for unrelated products without your explicit written consent.
- Human oversight is built into the workflow. Extracted ontologies and claims are reviewed and approved by your domain experts before they power any downstream decision-support tool — supporting the human-oversight obligations of Art. 14 of the EU AI Act rather than replacing them.
- Every answer is traceable. Outputs resolve through an explicit chain of evidence (Answer → Claim → Paragraph → Document → Author), giving your risk, compliance, and audit teams the transparency called for under Articles 13 and 50 of the EU AI Act, and under Art. 22 GDPR where automated processing could affect individuals.
- We support your conformity obligations, we don’t assume them. Where customers deploy Deepentix inside a use case that the EU AI Act classifies as high-risk — for example, life or health insurance risk assessment and pricing under Annex III, or clinical evidence review — the customer is typically the AI system’s provider or deployer, and we supply the technical documentation, data lineage, and audit logs needed to support their risk classification, Fundamental Rights Impact Assessment (FRIA), and conformity assessment.
- No fully automated decisions with legal or similarly significant effect. Deepentix is a decision-support and evidence layer; underwriting, claims, or regulatory determinations remain with your named human reviewers.
- Model tuning stays inside your boundary. Where a vertical small language model is fine-tuned on your data, that tuning happens inside your own sovereign environment — on-prem or your own cloud tenant — under your instructions, following data governance practices consistent with Art. 10 of the EU AI Act (relevance, representativeness, and error minimization of training data).
06 Sovereign-by-design hosting and data residency
Deepentix is deployed in one of two ways, and this choice governs where personal and customer data physically resides:
- On-premises or air-gapped, inside the customer’s own infrastructure — data never leaves the customer’s security boundary.
- Deepentix-hosted or customer cloud tenant (e.g., Microsoft Azure, AWS, Databricks) — hosted in EU/EEA regions by default, logically isolated per customer, and never pooled across tenants.
For the limited administrative and marketing data we hold as controller (Section 3), we store data with providers located in the EU/EEA wherever possible. Where a service provider is located outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (Art. 46 GDPR) or an adequacy decision, and we can provide details on request.
07 Who we share data with
We do not sell personal data. We share it only as follows:
- Infrastructure and business tooling providers who process data on our behalf under a data processing agreement — for example, cloud hosting, email/CRM, scheduling, and accounting tools. We keep an up-to-date subprocessor list available on request at privacy@deepentix.com.
- Font delivery (Google Fonts): our website loads its typefaces from Google Fonts. When a page loads, your browser requests the font files from Google LLC (USA), which therefore receives your IP address and browser details for that request. This transfer is covered by the EU–US Data Privacy Framework, under which Google is certified, and the European Commission’s Standard Contractual Clauses. No cookies are set and we do not receive any data back from this request.
- Third-party model providers, only where a specific workflow requires it, only under contractual confidentiality and data-processing terms, and never for training their models on your content.
- Professional advisors (legal, accounting, insurance) under confidentiality obligations.
- Authorities, where required by law, regulation, court order, or to protect the rights, safety, or property of Deepentix, our customers, or others.
- A successor entity, in the event of a merger, acquisition, or asset sale, subject to the same or equivalent privacy protections.
08 How long we keep data
- Marketing and sales contact data: for as long as we have an active relationship or legitimate interest, and deleted or anonymized on request or after a period of inactivity.
- Recruitment data: retained for up to 6 months after a hiring decision to defend against potential claims, unless you consent to being kept in our talent pool for longer.
- Web server logs: kept only for as long as needed for security monitoring and troubleshooting, then deleted or anonymized.
- Customer platform data: governed by the retention and deletion terms in the applicable customer agreement; on termination, customer content is deleted or returned within the timeframe set in that agreement, and immediately within the customer’s own control in on-premises/air-gapped deployments.
09 Security measures
We protect data with layered technical and organizational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control, least-privilege administration, and multi-factor authentication
- Network isolation and tenant separation for hosted deployments; full customer control in on-premises/air-gapped deployments
- Immutable audit logging across the platform, consistent with our “chain of evidence” design principle
- Vulnerability management and regular security testing
- Written incident response procedures and breach notification in line with Art. 33–34 GDPR
- Confidentiality obligations and security awareness training for all staff and contractors
Certification status: Deepentix does not currently hold ISO/IEC 27001 or SOC 2 Type II certification. As we scale, we have begun formal preparation for ISO/IEC 27001 certification, and our internal controls are already modeled on ISO 27001 Annex A and SOC 2 Trust Services Criteria. We are happy to complete customer security questionnaires (e.g., CAIQ, SIG Lite) or share our security documentation under NDA during due diligence.
11 Your rights under the GDPR
Subject to the conditions set out in the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase your data (“right to be forgotten”) (Art. 17)
- Restrict processing under certain circumstances (Art. 18)
- Object to processing based on legitimate interest or for direct marketing (Art. 21)
- Port your data to another provider in a machine-readable format, where processing is based on consent or contract (Art. 20)
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact us at privacy@deepentix.com. We may need to verify your identity before responding, and we will respond within the timeframes required by the GDPR.
Austria’s supervisory authority is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria (dsb.gv.at). You may also contact the supervisory authority in your own EU/EEA member state.
12 Children’s privacy
Our website and platform are intended for business use and are not directed at children. We do not knowingly collect personal data from individuals under the age of 16.
13 Changes to this policy
We may update this policy as our products, legal obligations, or practices evolve — including as EU AI Act implementing guidance continues to develop. We will update the “Last updated” date above and, where changes are material, notify active customers and contacts directly.
14 Contact us
Deepentix FlexCo
Platanenstraße 19, 2522 Oberwaltersdorf, Austria
privacy@deepentix.com · contact@deepentix.com
This policy is informed by Regulation (EU) 2016/679 (GDPR) and Regulation (EU) 2024/1689 (EU AI Act).