Legal
Privacy Policy
Effective date: 30 September 2026 (replaces the version of 11 May 2026) · Last updated: 30 September 2026. How Autonomyware B.V. collects, uses, shares, and protects your personal data.
This Privacy Policy explains how Autonomyware B.V. (we, us, our) collects, uses, shares and protects personal data when you visit our website, create an account, use the Autonomous Engineering OS or engage our consulting services (together, the "Services").
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Dutch GDPR Implementation Act (UAVG), the Dutch Telecommunications Act for cookies and electronic marketing, and other applicable privacy laws. Section 14 contains additional information for users outside the European Economic Area (EEA).
1. Who We Are
The controller for the processing described in this Privacy Policy is:
Autonomyware B.V., Siaerdamasingel 57, 9035 GG Dronryp, the Netherlands. Chamber of Commerce number 42037699. VAT number NL869420446B01. Website: www.autonomyware.ai. Privacy contact: privacy@autonomyware.ai.
Where we process personal data on behalf of a business customer, the business customer is the controller and we act as processor (see section 17).
2. Scope
This Privacy Policy applies when you visit our website, create an account, purchase or manage a subscription or credits, use the Services including their AI functionality, contact us, receive communications from us, take part in demos, events or beta programmes, or apply for a job with us. It does not apply to third-party websites or services that we do not control, including AI models you access with your own API key.
3. Personal Data We Process
3.1 Account and identity data: name, email address, username, password hash, account identifiers, language settings, and whether you buy as a consumer or as a business (with business name and VAT number).
3.2 Contact data: email address, telephone number, billing address and correspondence.
3.3 Billing and transaction data: plan, credit purchases and balance, invoices, payment status, transaction identifiers and payment method metadata. Card details are processed by our payment service provider and are not stored by us.
3.4 Usage data: log files, Features used, credit consumption, session times, device and browser type, IP address, approximate location derived from the IP address, and diagnostic data.
3.5 Content and AI interaction data: prompts, specifications, files, configurations and other content you submit, the Outputs generated, and the model you selected for each Feature. This data contains personal data only if you include it.
3.6 Own keys: if you connect your own API key, we store that key in encrypted form.
3.7 Communications data: support requests, emails, feedback and survey responses.
3.8 Marketing and preference data: newsletter subscription, consent records, interaction with our emails and event registrations.
3.9 Security and compliance data: authentication logs, audit trails, consent records at checkout, abuse prevention data and incident records.
3.10 Cookie data: see our Cookie Policy.
3.11 Job application data: CV, cover letter, contact details and interview notes.
4. Purposes and Legal Bases
| Purpose | Legal basis (Article 6(1) GDPR) |
|---|---|
| Creating and managing your account, providing the Services, running Features and generating Outputs, transmitting Inputs to the model you select, support | Performance of a contract (b) |
| Payments, invoicing, credit administration, tax and accounting | Performance of a contract (b) and legal obligation (c) |
| Recording checkout statements (immediate performance, withdrawal right, auto-renewal) | Legal obligation (c) and legitimate interest in being able to demonstrate compliance (f) |
| Service messages, renewal reminders and security alerts | Performance of a contract (b) |
| Security, fraud and abuse prevention, enforcement of the Acceptable Use Policy and safety safeguards | Legitimate interest in a secure and lawful service (f); legal obligation where applicable (c) |
| Troubleshooting and improving the Services on the basis of usage data | Legitimate interest in a reliable and improving service (f) |
| Newsletters and product updates | Consent (a); for existing customers about similar services, legitimate interest (f) under the customer exception in Article 11.7 Dutch Telecommunications Act, with an opt-out in every message |
| Cookies other than strictly necessary cookies | Consent (a) |
| Compliance with legal obligations, requests from authorities, and establishing or defending legal claims | Legal obligation (c) and legitimate interest (f) |
| Recruitment | Steps prior to a contract (b) and legitimate interest (f) |
Where we rely on legitimate interests, we have balanced our interests against yours. You can ask us for more information about that assessment.
5. AI Processing
5.1 When you use a Feature, we process your Inputs to generate Outputs. For Features that use an Included Model, we send the Inputs needed for that Feature to the Model Provider of the model you have selected. The Model Providers we currently use are listed in section 9.
5.2 We do not use your Inputs or Outputs to train AI models. We have configured our accounts with the Model Providers of Included Models so that your Inputs and Outputs are not used to train their models. xAI does not retain your Inputs and Outputs after processing them (zero data retention). OpenAI and Anthropic retain Inputs and Outputs under their standard retention policies for API customers, generally for up to 30 days for abuse and misuse monitoring, and longer where the law requires this. Content flagged under a Model Provider's usage policies may be retained longer; for Anthropic, this is up to 2 years.
5.3 If you connect your own API key, your Inputs are sent to the supplier of that model under your own agreement with that supplier. That supplier's terms determine whether your data is retained or used for training. We are not responsible for that processing.
5.4 We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Our safety safeguards may automatically block certain requests; you can contact us to have such a block reviewed by a person.
5.5 Outputs may be inaccurate or incomplete. Please check them before you rely on them.
6. Special Categories of Personal Data
The Services are not designed for special categories of personal data (such as health data or data revealing ethnic origin, political opinions or religious beliefs). Please do not include such data in your Inputs unless this is necessary and lawful.
7. Minimum Age
The Services are intended for persons aged 18 or over. We do not knowingly collect personal data from persons under 18. If we learn that we have done so, we delete the data as soon as reasonably possible.
8. Sources of Personal Data
We collect personal data:
- directly from you, when you create an account, make a purchase, submit content, contact us or complete a form;
- automatically, through your use of the Services (logs, telemetry and cookies);
- from service providers and integrations you connect, such as our payment service provider;
- from publicly available sources, such as professional networking profiles and company websites, where relevant for business contacts and on the basis of our legitimate interest.
9. Recipients
We do not sell personal data. We share personal data only where necessary for the purposes in section 4:
9.1 Processors that act on our instructions under a data processing agreement: cloud hosting Scaleway (Paris, France), content delivery and security Cloudflare, payment service provider Stripe, email and support tools Microsoft 365, and analytics tools Google Analytics 4 (Google Ireland Limited) and Cloudflare Web Analytics.
9.2 Model Providers of Included Models: OpenAI (OpenAI OpCo, LLC), Anthropic (Anthropic, PBC) and xAI (X.AI LLC). They receive the Inputs needed to run the Feature you select.
9.3 Professional advisers, such as lawyers, accountants and auditors, under a duty of confidentiality.
9.4 Authorities and courts, where required by law or necessary to establish or defend legal claims.
9.5 Acquirers or investors, in connection with a merger, acquisition, financing or reorganisation, subject to confidentiality.
The current list of processors and Model Providers is available at autonomyware.ai/terms.
10. International Transfers
All data stored in the Services, including your account data, Inputs and Outputs, is hosted in the European Union, on servers of our hosting provider Scaleway in Paris, France. When you use a Feature, the Inputs needed for that Feature are sent to the Model Provider of the model you have selected. Some recipients, including the Model Providers, are located in the United States or other countries outside the EEA. We transfer personal data outside the EEA only where the GDPR allows this:
- on the basis of an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework for recipients certified under it; or
- on the basis of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures such as encryption.
You can request more information about the safeguards for a specific transfer through privacy@autonomyware.ai.
11. Retention
| Data | Retention period |
|---|---|
| Account and identity data | For the duration of your account and up to 12 months after closure |
| Content and AI interaction data (Inputs and Outputs) | For the duration of your account; deleted 30 days after closure, unless you delete it earlier |
| Own API keys | Until you disconnect the key or close your account |
| Billing and tax records | 7 years after the end of the financial year concerned (Dutch tax law) |
| Checkout statements | For the duration of the customer relationship plus 2 years |
| Usage data | Up to 24 months in identifiable form, then anonymised or deleted |
| Support communications | Up to 36 months after the request has been resolved |
| Security and audit logs | Up to 24 months, or longer where needed for an ongoing investigation or proceedings |
| Marketing consent records | For the duration of the consent and 2 years thereafter |
| Job application data | 4 weeks after the end of the procedure, or 1 year with your consent |
| Cookie data | See the Cookie Policy |
We may retain data longer where required by law or needed for legal claims. Copies in encrypted backups are deleted in the ordinary backup cycle.
12. Your Rights
You have the right to access your personal data, to have it corrected or erased, to restrict processing, to data portability, and to object to processing based on legitimate interests or for direct marketing. Where processing is based on consent, you may withdraw your consent at any time, without affecting processing before withdrawal.
You can exercise your rights through the privacy request option in your account settings or by email to privacy@autonomyware.ai. We respond within one month; for complex requests we may extend this by two months, in which case we inform you. We may ask you to verify your identity. Exercising your rights is free of charge.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl, Postbus 93374, 2509 AJ Den Haag). If you live elsewhere in the EEA, you may also contact your local authority.
13. Direct Marketing
We send marketing emails only with your consent or, if you are an existing customer, about similar services of our own. Every marketing email contains an unsubscribe link, and you can change your preferences in your account settings. Unsubscribing does not affect service messages such as invoices, renewal reminders and security alerts.
14. Users Outside the EEA
14.1 United Kingdom
We process personal data of users in the United Kingdom in accordance with the UK GDPR and the Data Protection Act 2018. Your rights are substantially the same as in section 12. For transfers we rely on the UK International Data Transfer Addendum to the Standard Contractual Clauses. You may complain to the Information Commissioner's Office (ico.org.uk).
14.2 United States
If you are a resident of California or another U.S. state with a consumer privacy law, you may have the right to know and access the personal information we hold, to correct and delete it, to obtain a portable copy, to opt out of the sale or sharing of personal information for cross-context behavioural advertising, targeted advertising and certain profiling, and to appeal a refusal of your request. We do not sell personal information for money. Where cookies may qualify as "sharing" under California law, you can opt out through the cookie settings, and we honour Global Privacy Control signals where the law requires this. You may use an authorised agent, subject to verification, and we will not discriminate against you for exercising your rights. The categories of personal information, sources, purposes and recipients are described in sections 3, 8, 4 and 9.
14.3 Brazil
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including access, correction, deletion and portability. Please contact privacy@autonomyware.ai.
14.4 Other jurisdictions
If local law gives you further rights, we comply with them. Please contact us with any questions.
15. Cookies
We use cookies and similar technologies. Strictly necessary cookies are placed without consent. All other cookies, including functional, analytics and marketing cookies, are placed only with your consent. We do not use device fingerprinting. Our Cookie Policy contains details and explains how to change your preferences.
16. Security
We apply appropriate technical and organisational measures to protect personal data, including access control based on least privilege, logging and monitoring, vulnerability management, incident response procedures and due diligence of our processors. No method of transmission or storage is completely secure. Please report potential vulnerabilities to privacy@autonomyware.ai.
17. Business Customers
Where a business customer uses the Services, we process the personal data contained in its Inputs and Outputs on its behalf as processor under our Data Processing Agreement, in accordance with Article 28 GDPR. The business customer is the controller for that data. Individuals whose data is processed in that context should contact the business customer.
18. Changes
We may update this Privacy Policy. We inform you of material changes in advance by email or in the Services. The date at the top shows the current version.
19. Contact
Autonomyware B.V., Siaerdamasingel 57, 9035 GG Dronryp, the Netherlands
Email: privacy@autonomyware.ai
Telephone: +3197032361729