Privacy Policy
Effective: 3 June 2026
1. Data Controller
The AIMS (AI Monitoring System) software is developed and operated by Tapodi Máté, a sole trader trading as Workflo.
| Name | Tapodi Máté (sole trader, trading as Workflo) |
|---|---|
| Registered address | 17 Ashbrook, Enniscorthy, Y21 A0Y2, Co. Wexford, Ireland |
| Legal form | Sole trader |
| Contact | info@workflo.hu |
| Website | workflo.hu |
Controller and processor roles. For your own account (the email address and subscription of the customer who registers) Workflo is the data controller. For the AI-usage data collected from monitored company devices (detected tools, device and host identifiers, detection events, and enrolled employee records), the employer that deploys AIMS is the data controller and Workflo acts as a data processor on the employer's behalf under a data processing agreement (GDPR Article 28). Monitored employees should address requests about that data to their employer as controller; we assist the employer in fulfilling them.
Governing law. This policy and the processing described in it are governed by Irish law and the GDPR (EU 2016/679).
2. What data does AIMS process?
AIMS collects only the data necessary for AI tool monitoring. It never records personal communications, file contents, browsing history, or keystrokes.
| Data | Purpose | Legal basis |
|---|---|---|
| Detected AI tool name and category | EU AI Act classification, monitoring | Performance of contract |
| Tool risk level (GPAI / High / Limited / Minimal) | EU AI Act compliance | Legal obligation |
| Machine name (hostname) | Device identification on network | Performance of contract |
| Detection timestamp | Event log, audit trail | Legitimate interest |
| AI blocking event (tool name, machine, timestamp, "blocked" action) | Enforcing AI blocking, compliance audit | Legitimate interest / employer policy |
| Account email address | Authentication, subscription management | Performance of contract |
| Subscription data (via Stripe) | Billing | Performance of contract |
3. What AIMS does NOT collect
- URLs, browsing history
- File contents, documents
- Keystrokes, mouse clicks
- Screenshots, images
- Chat messages, communication content
- Passwords, credentials
- Employee phone numbers, home addresses, or private (non-work) contact details
To be clear about the employee data AIMS does hold on behalf of the employer (see the controller/processor roles in section 1): the enrolled employee's name and email address (as provided by the employer when the device is enrolled, stored encrypted), the device hostname (stored encrypted; it can identify a person), and the detected AI-tool events listed in section 2. It holds no other personal data about the employee.
4. Data storage and security
Data is stored on EU servers (Hetzner, Germany). All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
| Data type | Retention period |
|---|---|
| Event log (Watcher plan) | 60 days |
| Event log (Guardian plan) | 120 days |
| Event log (Shield plan) | 365 days |
| Account data | Until subscription ends + 30 days |
| Billing data | 8 years (tax obligation) |
5. Third-party processors
AIMS works with the following trusted processors:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server infrastructure | EU (Germany) |
| Stripe, Inc. | Payment processing | USA (SCCs) |
| Supabase, Inc. | Database, authentication | USA (SCCs) |
We do not sell personal data or share it for marketing purposes.
6. AI blocking and the browser extension
On the Guardian and Shield plans the administrator can set a "block" rule. AIMS then terminates the designated AI tool in real time on the company (managed) machine, and in the browser the AIMS browser extension (Chrome/Edge) redirects the restricted AI site to a notice page. Blocking applies only to employer-managed devices, under the employer's AI usage policy.
The browser extension does not collect browsing history, page content, typed text, or personal data. It acts only on the domains listed in the policy and only redirects the top-level page load (main-frame navigation).
| Data | Purpose | Legal basis |
|---|---|---|
| Organisation token (agent token) | Fetching the block-domain list from our own AIMS server (not a third party) | Legitimate interest / employer policy |
| Block-domain list | Redirecting restricted AI sites in the browser | Performance of contract |
The token identifies the organisation, not the individual employee. The extension communicates only with the organisation's AIMS server and transmits no data to external providers.
7. Your rights
Under GDPR, you have the following rights:
- Right of access: Request information about data we hold about you.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure ("right to be forgotten"): Request deletion of your data.
- Right to restriction: Request restriction of processing.
- Right to data portability: Request your data in machine-readable format.
- Right to object: Object to processing of your data.
Send requests to info@workflo.hu. Response time: 30 days.
8. Supervisory authority
You may lodge a complaint with the Irish data protection authority:
Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
9. Contact
For privacy enquiries: info@workflo.hu