← Back to home

Privacy Policy

Last updated: 24 April 2026

This policy explains how FileGPT.dev processes personal data under the GDPR when you access the website, submit an initial contact form, or participate in a Sovereign AI Assessment or RAG pilot project.

1. Controller and contact

Damir Andrijanic c/o Postflex PFX-202-985 Emsdettener Str. 10 48268 Greven Germany

VAT ID (USt-IdNr.): DE461042625

For privacy requests, contact info@filegpt.dev. Legal details are available in the Impressum.

2. Personal data we process

  • Contact data: name, business email address, company, and process description submitted via the contact form.
  • Project data: technical documents, requirements, and system descriptions processed within a contracted assessment or pilot — exclusively within the contractually defined infrastructure.
  • Operational metadata: timestamps, request status, technical log data, and security signals when using the website.

3. Purposes and legal bases (Art. 6 GDPR)

  • Pre-contractual and contractual necessity (Art. 6(1)(b)): handling contact requests, preparing proposals, and conducting assessment and pilot projects.
  • Legitimate interests (Art. 6(1)(f)): website security, abuse prevention, and operational monitoring.
  • Legal obligations (Art. 6(1)(c)): where statutory retention or legal defence obligations apply.

4. AI processing and data flow

Within pilot projects, documents and queries are processed exclusively within the contractually agreed infrastructure — on-premise or within a customer-controlled private cloud tenant. No processing via external public model APIs takes place without explicit agreement with the customer.

Models, vector databases, and embedding services used are jointly defined during the assessment phase and documented in writing.

5. Recipients and subprocessors

For the operation of this website, the following categories of subprocessors may be used:

  • Hosting and infrastructure providers for website delivery.
  • Email services for handling contact requests.

Within projects, the full subprocessor and infrastructure structure is documented in the DPA. The customer's infrastructure is subject to the customer's own data processing agreements.

6. International transfers

Data may be processed in the EU/EEA and, depending on provider infrastructure, in third countries. Where required, we rely on transfer safeguards such as EU Standard Contractual Clauses and supplementary measures.

7. Retention and deletion

  • Contact requests are retained for as long as necessary for handling and potential follow-up communication.
  • Project data is deleted or returned after project completion in accordance with contractual agreements.
  • Statutory retention periods (e.g. tax or commercial law obligations) remain unaffected.

8. Cookies and local storage

The website uses only technically necessary cookies and local storage entries for session management and consent state. No marketing trackers are used.

9. Your GDPR rights

Subject to applicable law, you have rights to access, rectification, erasure, restriction, portability, and objection.

To exercise rights, contact info@filegpt.dev. We may verify identity before acting on requests.

10. Complaints to supervisory authorities

You may lodge a complaint with your local supervisory authority in the EU/EEA. Information for Germany is available at bfdi.bund.de.

11. Business processing and security references

Business customers can rely on our Data Processing Agreement and our Security page for details on processor obligations and technical controls.