Back to Home
Privacy Policy & Data Processing Agreement
aifa.works — Enterprise AI Platform
Last updated: 15 January 2025
This Privacy Policy and Data Processing Agreement ("DPA") governs the collection, processing, storage, and transfer of personal data by aifa.works. We aim to align our practices with GDPR, UK GDPR, CCPA/CPRA, PIPEDA, LGPD, POPIA, PDPA, EU AI Act, DSA, DMA, DORA, Washington My Health My Data Act, BIPA, and other applicable global privacy frameworks; this is a good-faith commitment, not a warranty of certification under any specific framework.
Data Controller & DPO Contact
aifa.works Ltd acts as Data Controller. Our Data Protection Officer is reachable at contact@codeofdigitaleternity.com. All GDPR Article 30 records, DPIAs, and legitimate interest assessments are maintained and available upon verified request. We appoint EU and UK representatives pursuant to Articles 27 GDPR/UK GDPR. For CCPA requests, California residents may exercise rights via the same channel. We respond within statutory timeframes and maintain audit logs of all access requests for six years.
Categories of Personal Data Processed
We process identifiers, contact data, device and usage telemetry, biometric embeddings (voice, facial geometry) under BIPA consent, health-related inferences under Washington My Health My Data Act, and generative AI interaction logs. Sensitive data is processed only with explicit consent or substantial public interest. All biometric templates are stored as irreversible one-way hashes with per-user cryptographic salt. No raw biometric images are retained beyond the active session.
Legal Bases & Cross-Border Transfers
Processing relies on consent, contract performance, legitimate interests, and legal obligations. International transfers to the United States and Singapore utilise approved SCCs 2021, UK IDTA, and Binding Corporate Rules. We conduct Transfer Impact Assessments annually. Data localisation options are available for Quebec Law 25 and LGPD data residency requirements. All subprocessors are bound by equivalent contractual data-protection obligations; we select reputable providers but do not represent that we or they hold any specific certification.
Automated Decision-Making & AI Transparency
Pursuant to the EU AI Act and GDPR Articles 13-22, users receive clear disclosure when interacting with our chatbot systems. Generative outputs are watermarked and labelled as AI-generated. Users may request human review of solely automated decisions that produce legal or significant effects. We maintain model cards, training data provenance summaries, and bias testing reports. Opt-out from profiling is honoured within 48 hours.
Data Minimisation, Retention & Deletion
Data is retained only as long as necessary for the stated purposes or to meet statutory obligations (DORA financial record-keeping, tax, litigation holds). Default retention for interaction logs is 90 days; biometric templates are deleted within 30 days of account closure. Cryptographic erasure and verifiable deletion certificates are issued upon request. California CPRA deletion metrics are published in our annual transparency report.
Security, Encryption & Resilience
All data is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Key management follows FIPS 140-3 validated HSMs. We target high availability under DORA-aligned ICT risk-management practices, including periodic penetration testing and incident-response playbooks; no specific uptime figure is guaranteed and the Service is provided on an as-available basis. Breach notification occurs within 72 hours to supervisory authorities and without undue delay to affected individuals.
User Rights & Exercise Mechanisms
Data subjects may exercise access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. California residents may request disclosure of categories sold or shared and opt-out of cross-context behavioural advertising. Requests are authenticated via multi-factor verification. We do not discriminate against users who exercise privacy rights. Response SLA is 30 days (extendable once by 60 days under GDPR).
Children's Privacy & Age-Appropriate Design
Our platform is not directed at children under 13 (COPPA) or 16 (GDPR). For users aged 13-17 we apply California Age-Appropriate Design Code safeguards, including default privacy settings, time-spent disclosures, and prohibition of dark patterns. Age verification occurs via government ID or verified guardian consent. We promptly delete any inadvertently collected child data upon discovery.
Cookies, Tracking & Deceptive Patterns
We employ strictly necessary, performance, and consented marketing cookies. No dark patterns or deceptive consent interfaces are used in compliance with DSA Article 25 and DMA. Cookie banners require affirmative action; rejection is as prominent as acceptance. Analytics data is aggregated and IP-anonymised within the EU. Users may manage preferences via our consent management platform at any time.
Subprocessors, Audits & Policy Changes
Current subprocessors are listed at aifa.works/legal/subprocessors. Material changes to this DPA trigger 30-day notice and renewed consent where required. We undergo annual third-party audits covering all listed regulatory regimes. This document constitutes the entire agreement regarding data processing and supersedes prior versions. Continued use after updates constitutes acceptance of the revised terms.
Section 11: Blockchain Memory Consent & Decentralized Storage
By interacting with AIfa, the user provides explicit, irrevocable consent to the collection, analysis, and immutable, eternal storage of their dialogues in the decentralized Arweave blockchain. This long-term memory layer (PADAM) is designed to preserve interaction contexts permanently. Once written, this data is decentralized and cannot be modified or deleted by any central authority, including aifa.works.
Section 12: 200% Absolute Liability Waiver
aifa.works provides only the decentralized storage protocol. The user bears 100% of the responsibility for all data (personal, commercial, proprietary, or confidential) transmitted to the AI. Under no circumstances shall aifa.works be liable for any indirect, direct, punitive, incidental, or consequential damages resulting from on-chain storage. The user waives all liability up to 200% of any service fees paid.
P-D1. Eighteen-Plus Service; Age-Gate Self-Certification; No Knowing Processing of Children's Data
The Services are directed exclusively to, and intended solely for use by, natural persons who are eighteen (18) years of age or older (or the higher age of digital majority in the User's jurisdiction), and by accessing the Services the User self-certifies that this requirement is met. We do not knowingly collect, solicit or process Personal Data from, and do not knowingly direct content to, children or minors as defined by the U.S. Children's Online Privacy Protection Act (COPPA), Article 8 of the GDPR/UK-GDPR, or any equivalent law; because the Services are not offered to minors, we neither seek nor process verifiable parental or guardian consent, and no feature is an information-society service offered directly to a child. Any age representation is the User's own, we are entitled to rely conclusively upon it, and we bear no duty to verify age beyond the age-gate.
If we become aware that Personal Data of a person under the applicable age has been provided, we will disable the relevant account and delete or crypto-shred such data within a commercially reasonable period, and such deletion is the sole and exclusive remedy. A parent or guardian who believes a minor has provided data may contact us for its removal; this contact right creates no monitoring, screening or age-assurance obligation on our part.
P-D2. Prohibition on Submitting Third-Party, Special-Category, Biometric and Consumer-Health Data; User as Independent Controller; No Facial or Voice Recognition
The User must not submit, upload, type or otherwise input into the Services any Personal Data relating to any third party, nor any special-category data (GDPR Article 9 — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health, sex life or sexual orientation), nor any equivalent sensitive personal information under the CCPA/CPRA or other law, unless the User has an independent, valid and documented lawful basis and all required consents. Where the User submits any such data — including the data, images, voice, writings, correspondence or memory of a deceased person the User wishes to preserve or simulate — the User acts as an independent data controller (or business) and we act solely as processor or service provider executing the User's instructions, and the User is exclusively responsible for the lawfulness of that processing and for all transparency, consent, notice and data-subject-rights obligations owed to the third party, including any post-mortem, publicity or estate rights. The User represents that it holds all rights, authorisations and consents (including, where applicable, from surviving relatives, executors or the data subject before death), that it will produce written evidence on request, and the User shall defend, indemnify and hold harmless the Architect and operators against any claim, regulatory action, fine or cost arising from such submission in breach of this Section.
We do not collect, capture, retain, use, disseminate or profit from any biometric identifier or biometric information as defined under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, Washington RCW 19.375 or any comparable statute, and the Services perform no facial recognition, voice recognition or biometric identification; any image, audio or video a User voluntarily submits is processed only as unstructured User-supplied media for the requested function and is not enrolled or scanned to create a biometric template. We are not a covered entity or business associate under HIPAA and are not a healthcare, diagnostic or telehealth provider; we do not knowingly collect consumer health data as defined by the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 or the Connecticut Data Privacy Act, do not use geolocation to infer health status, operate no health-facility geofence and sell no consumer health data. Any wellness, mood or health-adjacent content a User voluntarily discloses is unsolicited and at the User's own risk, and to the extent any such statute is nonetheless deemed to apply, the User's voluntary submission together with acknowledgment of this Section constitutes the affirmative, voluntary consent contemplated by such statutes for the limited purpose of providing the requested conversational function. We may, without obligation or liability, filter, refuse, redact or delete content that appears to contain such data, but assume no duty to monitor and give no assurance any such control will operate.
P-D3. User Responsibility for Content Disclosed in AI Conversations; Permanence Warning; Voluntary Submission and Common-Law Privacy Waiver
The AI companion is an open free-text interface, and the User is solely responsible for the content the User chooses to type, paste or upload. The User should assume that anything so submitted may be stored, processed by third-party model providers, used to generate responses, indexed, embedded and — where the User has elected archival — permanently and immutably recorded on the blockchain in encrypted form, subject only to crypto-shredding-based erasure. The User must not disclose passwords, private keys, seed phrases, payment-card or financial-account numbers, government identifiers, secrets subject to confidentiality or privilege, or any information the User does not wish to have retained. Because conversational content is generated and stored based on what the User submits, we do not and cannot pre-screen, verify or guarantee its accuracy, legality or sensitivity, and the User assumes all risk arising from the User's own disclosures.
The User acknowledges that all Personal Data and dialog content processed by the Services is submitted voluntarily and with knowledge of the processing described in this Notice, and agrees that processing carried out consistently with this Notice and the User's instructions is authorised and expected, is not highly offensive to a reasonable person, and does not intrude upon any legally protected zone of seclusion or reasonable expectation of privacy. To the fullest extent permitted by law the User waives any claim for intrusion upon seclusion, public disclosure of private facts or common-law invasion of privacy arising from processing conducted in accordance with this Notice. This Section supplements, and does not limit, the assumption-of-risk, indemnification and blockchain-irreversibility provisions of the Terms.
P-D4. Retention and Lawful-Basis Schedule; Sub-Processors and Article 28 Flow-Down; De-Identified and Aggregated Data Rights
Personal Data is retained only for as long as necessary to fulfil the purposes for which it was collected, to provide the permanent-archival feature the User elected, to comply with legal, tax, accounting, anti-fraud and dispute-resolution obligations, and to establish, exercise or defend legal claims, after which it is deleted, anonymised or crypto-shredded. The categories of data, purposes, lawful bases (GDPR Article 6, and Article 9(2) where special-category data is voluntarily submitted) and retention periods are set out in the Retention and Lawful-Basis Schedule published alongside this Notice, incorporated by reference and updatable without diminishing substantive rights. Where the User has elected permanent blockchain archival, the User understands and instructs that the encrypted record is designed to persist indefinitely on a decentralised, immutable ledger, that the applicable retention period is accordingly perpetual, and that erasure is effected solely through crypto-shredding (destruction of decryption keys) rather than deletion of the on-chain record; this instruction constitutes the User's documented direction and, where applicable, explicit consent for such indefinite retention.
We engage third-party sub-processors and service providers (including cloud hosting, database, email, payment, analytics, AI-model and decentralised-storage providers), a current list of whose principal categories is available on request or via the published sub-processor register. Where required by the GDPR or comparable law, each is bound by written terms materially no less protective than those to which we are subject (Article 28 flow-down); we may add, replace or remove sub-processors, and where a right to object is mandatory the User may exercise it by ceasing use and terminating the Services before the change takes effect, continued use thereafter constituting acceptance. We are not liable for a sub-processor's independent acts beyond the flow-down obligations, and this Section does not enlarge the liability caps in the Terms.
We may create, derive and retain in perpetuity de-identified, aggregated, pseudonymised and anonymised data and model-improvement insights derived from the Services and User content, provided such data cannot reasonably identify any individual; such data is not Personal Data for purposes of applicable law and may be used, licensed and disclosed for any lawful purpose without further notice, consent, compensation or deletion obligation. Consistent with the CCPA/CPRA and GDPR recital 26, we maintain reasonable measures against re-identification, commit not to attempt re-identification except to test de-identification effectiveness, and bind recipients accordingly. Once data has been irreversibly de-identified, aggregated or crypto-shredded, requests for its erasure, correction or access cannot be honoured because the linkage necessary to fulfil them no longer exists, and this technical impossibility is not a denial of any data-subject right.
P-D5. Reasonable Security Without Guarantee; Breach Response Limited to Applicable Law; Compelled Disclosure and Blockchain Public-Ledger Transparency
We implement technical and organisational measures appropriate to the risk, including encryption of archival records, but security is a matter of reasonable efforts and not a guarantee: no method of transmission or storage is perfectly secure and no internet-facing or decentralised system can be warranted against every intrusion. To the fullest extent permitted by law we do not warrant that the Services will be uninterrupted, error-free or immune from loss, and we disclaim any strict, absolute or no-fault liability for a security incident occurring despite reasonable measures. In the event of a personal-data breach we will investigate and notify affected individuals and competent supervisory authorities only where, within the time frames (including any applicable seventy-two-hour authority-notification period) and in the manner required by applicable law, and such notification is not an admission of fault or liability; our aggregate liability arising from any security incident is subject to the assumption-of-risk, force-majeure and limitation-of-liability provisions of the Terms, including the stated cap.
We may access, preserve and disclose Personal Data and account information where we reasonably believe it is required by a valid subpoena, court order, warrant, statute or other lawful government or judicial request, or is necessary to protect the rights, property or safety of the Architect, operators, Users or the public, or to detect or prevent fraud, security or technical issues; where legally permitted we will endeavour to provide reasonable transparency, but may be prohibited by law from notifying the User, and bear no liability for any disclosure made in good-faith reliance on a facially valid legal process. The User acknowledges that records the User elects to archive to a public or decentralised blockchain are, by design, replicated across independent nodes in multiple jurisdictions and are not within our custody or control once written; such records may be accessible to, and are outside our power to remove or shield from, governments, courts or third parties notwithstanding encryption, and we make no representation that any data-localisation, sovereignty or government-access limitation can be enforced against an immutable distributed ledger, the User assuming this risk.
P-D6. No Sale or Share Covenant; Sensitive-PI Purpose Limitation; Non-Discrimination; No Independent Private Right of Action; Statutory-Damages Mitigation and Cure
We affirmatively covenant that we do not and will not sell Personal Data, and do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable laws, in exchange for monetary or other valuable consideration; consequently no Do-Not-Sell-or-Share financial incentive is offered because none is required. Any disclosure to sub-processors is made under written service-provider or processor terms restricting use of the data to performing the Services and prohibiting its sale or independent use. Where a User voluntarily submits sensitive personal information, we limit our use and disclosure to the purposes permitted by CCPA/CPRA section 1798.121 and do not use it to infer characteristics. We will not discriminate or retaliate against any User for exercising a privacy right — by denying the Services, charging a different price, or providing a different level or quality — except where a difference is reasonably related to the value the data provides and is permitted by law, and no exercise of a deletion or opt-out right shall be construed to require reversal of an already-completed immutable blockchain write, which is technically impossible.
Except where a non-waivable private right of action is expressly conferred by mandatory applicable law, the commitments in this Notice are addressed to and enforceable only through the competent supervisory or regulatory authority and do not create an independent private cause of action, contractual warranty or third-party right enforceable by any person. Any privacy or data-protection claim that may lawfully be brought is subject to the disclaimers, limitations, exclusions, arbitration, notice-and-cure and class/representative waivers set out in the Terms, to the extent not prohibited by mandatory law. Where a data incident occurs, the User agrees to provide us a reasonable opportunity to investigate and cure before asserting any claim, to mitigate damages, and — where the applicable statute permits election or reduction of statutory or minimum damages upon good-faith remediation — that we may rely on such remediation. Nothing in this Section limits the User's mandatory right to lodge a complaint with a supervisory authority or any remedy that cannot lawfully be waived.
Data Protection Officer: contact@codeofdigitaleternity.com