Privacy and Data Protection

How Logiks Solutions handles personal data under the GDPR — controller vs processor roles, legal bases, AI providers, international transfers, retention, your rights, and breach handling. Draft pending legal review.

Written By Logiks Solutions

Last updated 29 days ago

This privacy statement explains how Logiks Solutions handles personal data. It is provided for transparency under Articles 13 and 14 GDPR. Where Logiks processes personal data on behalf of a business customer, that customer is the controller and the applicable data processing agreement takes precedence over this statement.

Last updated: [to be completed: date / version]

1. Controller and Contact Details

Responsible for the processing of personal data described here (where Logiks acts as controller):

  • [to be completed: full legal company name and legal form]

  • [to be completed: registered address]

  • [to be completed: email address], [to be completed: telephone (optional)]

Data Protection Officer: [to be completed: name and contact details — or state "We are not legally required to appoint a Data Protection Officer" if that is the case].

EU representative (Art. 27 GDPR): [to be completed, if applicable].

You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for Logiks is [to be completed: name and contact of the competent authority].

2. Our Roles: Controller and Processor

Data protection law distinguishes the "controller", who determines the purposes and means of processing, from the "processor", who processes personal data only on the controller's documented instructions. Logiks does not act in a single fixed role; the role is determined separately for each processing activity.

  • Logiks acts as controller where it processes personal data for its own purposes — for example account administration, contract management, billing, customer support, communication with business contacts, and safeguarding the security of the Service.

  • Logiks acts as processor where customers use the Service to process personal data of their own employees, customers, suppliers or other individuals — for example the content of prompts, uploaded documents and data from connected systems. In these cases the customer is the controller, and Logiks processes the data only on the customer's documented instructions under a data processing agreement.

Please note: the users who sign in to the Service are not necessarily the "data subjects". Uploaded content may contain personal data of third parties (for example colleagues or business partners named in a document). A company (legal person) is not itself a "data subject" under the GDPR.

3. Categories of Personal Data

Depending on how the Service is used, Logiks may process the following categories of personal data:

  • Identification and contact data (e.g. name, email address, business contact details).

  • Account and authentication data.

  • Organisation / tenant membership.

  • Technical and device data (e.g. IP address, device and browser information, timestamps and login logs).

  • Usage and analytics data.

  • Support and communication data.

  • Payment and billing data (if applicable).

  • Content you enter, upload or provide through connected systems in the course of using the Service — including messages (prompts), documents, files and any personal data they contain.

  • Prompt and chat history, information about the AI models used, and feedback on AI responses.

Uploaded files may also contain personal data of third parties. Please only enter data that you are permitted to process.

4. Purposes and Legal Bases

Where Logiks acts as controller, it processes personal data for the following purposes on the following legal bases:

  • Providing and operating the Service, and — where you are personally our contractual partner — performing the contract: Art. 6(1)(b) GDPR.

  • Administering business contacts of our customers and communicating with them: Art. 6(1)(f) GDPR (our legitimate interest in managing the customer relationship).

  • Billing, accounting and complying with statutory retention obligations: Art. 6(1)(c) GDPR.

  • IT security, prevention of fraud and abuse, and ensuring the technical operation of the platform: Art. 6(1)(f) GDPR (our legitimate interest in a secure Service).

  • Optional product analytics and improvement: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(f) GDPR, depending on the specific feature.

  • Optional AI features (see section 5): Art. 6(1)(a) GDPR (consent) and/or Art. 6(1)(b) GDPR where the feature is a core part of the contracted service.

  • Direct marketing to existing customers: Art. 6(1)(f) GDPR, or consent where required.

Where processing is based on legitimate interests, we weigh those interests against your rights and freedoms in each case. Where Logiks acts as processor, the customer (as controller) determines the legal basis; Logiks processes the data on the basis of the data processing agreement and the customer's documented instructions.

If content may contain special categories of personal data (Art. 9 GDPR) — such as health data — an additional condition under Art. 9(2) GDPR is required (see section 13).

Where analytics tools store information on, or read information from, your device, the requirements of national e-privacy law (in Germany, § 25 TDDDG) may apply in addition, and non-essential access requires your prior consent.

5. AI Features and Third-Party AI Providers

Some features of the Service use artificial intelligence (AI) to generate responses. To provide these features, Logiks transmits certain data to external AI providers engaged as processors / subprocessors.

What data is sent and why

To generate a response, the information required for your specific request — such as your messages (prompts) and any files you choose to include — may be securely transmitted to the AI provider. The data is transmitted solely to process that request and generate a response for you.

Use for training

[to be completed — include only if contractually and technically guaranteed: "Customer inputs and uploaded files are not used to train general AI models of Logiks or of the external AI providers." If this cannot be guaranteed for every provider, describe the actual position per provider instead.]

Which providers receive the data

AI requests are processed by the third-party AI providers listed in our current subprocessor list: [to be completed: name of each provider, purpose, place of processing, whether third-country access occurs, transfer mechanism, retention/deletion period, and whether data is used for training]. The subprocessor list is available at [to be completed: link] and forms part of the applicable data processing agreement.

Legal structure (business use)

Where a business customer uses the Service, the customer is the controller and determines the legal basis for processing the content. Logiks processes the content on the basis of the data processing agreement and the customer's documented instructions, and engages the AI providers as approved subprocessors. Logiks engages further subprocessors only with the customer's prior specific or general written authorisation; where authorisation is general, customers are informed of intended changes and may object.

In-app consent

Before AI data is transmitted to an external AI provider for the first time, the Service asks the signed-in user to confirm they understand and agree. This confirmation supports transparency but does not replace the controller's own legal basis, and a user cannot consent on behalf of third parties whose data may be contained in uploaded files. You can review or withdraw this confirmation at any time in the application settings.

Safeguards

The AI providers are engaged under data processing terms pursuant to Art. 28 GDPR, covering in particular: processing only on documented instructions, confidentiality, security, assistance with data subject rights and with data breaches, deletion or return of data, records and audits, and the engagement of further subprocessors.

Please do not enter special categories of personal data (e.g. health data) or other highly sensitive information of third parties into AI features unless your organisation has confirmed this is permitted.

6. Recipients and Subprocessors

Personal data may be disclosed to: providers of hosting and infrastructure, the AI providers described in section 5, payment and billing providers, support and communication tools, and analytics providers, each engaged as processors where applicable. A current list of subprocessors is available at [to be completed: link].

7. International Transfers

Some recipients may process personal data outside the European Economic Area (EEA). Administrative remote access from a third country also counts as a transfer. For each such transfer, Logiks relies on one of the following mechanisms: an adequacy decision of the European Commission; for certified US organisations, the EU-US Data Privacy Framework; or the EU Standard Contractual Clauses together with additional technical and organisational measures where necessary.

The countries and providers concerned, and the specific mechanism relied on, are set out in our subprocessor list. You may request a copy of the relevant safeguards at [to be completed: contact].

8. Data Security

Logiks implements appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs of implementation and the risk involved. These include, where appropriate to the risk, encryption of personal data in transit and at rest, access controls and authentication, regular monitoring and testing, and staff training. The specific measures are documented in our technical and organisational measures (TOMs), available at [to be completed: link].

9. Retention

Logiks retains personal data only for as long as necessary for the purposes described here or to comply with statutory obligations. Indicative periods:

  • Contract and billing data: for the term of the contract plus statutory retention periods.

  • Account data: until the account is deleted or the contract ends.

  • Security logs: [to be completed: e.g. 30 / 90 / 180 days].

  • Support requests: [to be completed: defined period after closure].

  • Prompts and chat history: [to be completed: number of days or until deletion].

  • Uploaded files: until deleted by the customer or the contract ends.

  • Backups: deleted within [to be completed: defined backup cycle].

Where Logiks acts as processor, it retains customer data for the period set by the customer. After the end of the processing, the data is deleted or returned at the customer's choice, unless a statutory retention obligation applies.

10. Your Rights

Subject to the conditions of the GDPR, you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21).

  • Data portability applies only where processing is based on consent or a contract and is carried out by automated means.

  • Objection to direct marketing can be exercised at any time without giving reasons. An objection to processing based on legitimate interests must be based on grounds relating to your particular situation.

  • Withdrawal of consent: where processing is based on consent, you may withdraw it at any time with effect for the future.

You also have the right to lodge a complaint with a supervisory authority (see section 1). Where Logiks processes your data as a processor on behalf of a customer, please address your request to that customer as the controller; Logiks will support the customer as agreed in the data processing agreement.

11. Obligation to Provide Data

Where you are our contractual partner, providing certain data is necessary to enter into and perform the contract. If you do not provide it, we may not be able to provide the Service. [to be completed: confirm / adjust to the actual position.]

12. Automated Decision-Making

[to be completed: If the Service does not carry out automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR, state that. If it does, describe the logic involved and the significance and consequences.] Generating AI content at the user's request is generally not an automated decision within the meaning of Art. 22 GDPR.

13. Special Categories of Data and Minors

The Service is not intended for the input of special categories of personal data (Art. 9 GDPR). Such data may nevertheless appear in freely written prompts or uploaded documents. Responsibility for the admissibility of such processing lies with the controller, who must ensure an appropriate condition under Art. 9(2) GDPR and, where required, carry out a data protection impact assessment. [to be completed: state whether the Service is directed at minors; if not, say so.]

14. Personal Data Breaches

Where Logiks acts as controller, it notifies the competent supervisory authority of a personal data breach in accordance with Art. 33 GDPR without undue delay and, where feasible, within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk, Logiks also informs the affected data subjects in accordance with Art. 34 GDPR.

Where Logiks acts as processor, it informs the relevant customer (as controller) of any personal data breach without undue delay and supports the customer in meeting its legal obligations.

15. Changes to this Statement

We may update this statement to reflect changes in our processing or in legal requirements. The current version is indicated by the date at the top.

16. Interaction with an AI System

The Service includes AI features that interact directly with you. From 2 August 2026, Art. 50 of the EU AI Act requires that users be informed when they interact with an AI system, unless this is already obvious. When you use these features, you are interacting with an AI system.