Privacy Policy
Version 2 · effective 8 October 2026 · replaces the version of April 11, 2026
This policy explains how personal data is processed on the aio platform (aioengine.io), in line with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Who is responsible
Michael König-Weichhardt, trading as aio (sole proprietor) Bachweg 10, 8410 Wildon, Styria, Austria Email: support@aioengine.io
We are the controller for:
- visitors of aioengine.io and docs.aioengine.io,
- site owners: their platform account, plan and billing relationship, and support requests.
We are a processor (Art. 28 GDPR) for the data of members and visitors of websites that site owners run on the platform ("tenant sites"), whether on their own domain or on a subdomain of aioengine.io. For that data the site owner is the controller. Each tenant site publishes its own imprint and privacy notice; this policy does not replace it. If you are a member of a tenant site, please contact that site's owner first; if you write to us, we pass your request on to the site owner.
2. Data we process
2.1 Site owners (platform accounts)
- Name, email address, workspace name and web address, selected plan, and where you came from when you signed up (for example campaign parameters).
- Sign-in data: one-time sign-in links and session cookies. Sign-in is passwordless; no passwords are stored.
- Subscription and billing references from Paddle (no card data; see section 4).
- Support messages you send us.
2.2 Members of tenant sites (processing on behalf of the site owner)
- First and last name, email address, language, an approximate city derived from the connection, membership and purchase references, and the newsletter opt-in state with its confirmation and opt-out dates.
- Content you create: posts, comments (including voice comments), private messages, course progress.
- If you use the aio network to join several sites with one sign-in: your name, email address, avatar and language are kept in a platform-wide network profile so that other sites you join can use it.
2.3 Visitors
- Technical connection data (IP address, browser, device) is processed by Cloudflare to deliver pages and protect the service.
- Usage statistics in Cloudflare Analytics Engine: site, event, country, device type and a short, truncated hash of the IP address. Registration events currently also contain the email address of the new account.
3. Purposes and legal bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the platform, accounts, sign-in, content hosting, service email | Art. 6(1)(b) contract |
| Newsletters and other optional email | Art. 6(1)(a) consent (double opt-in; withdraw at any time with the unsubscribe link or by email) |
| Security, abuse prevention, rate limiting, usage statistics, operating and improving the service | Art. 6(1)(f) legitimate interest |
| Accounting and tax records | Art. 6(1)(c) legal obligation |
| Processing for tenant sites | the site owner's legal basis; we act on its instructions (Art. 28 GDPR) |
No automated decision-making with legal or similarly significant effects (Art. 22 GDPR) takes place.
4. Processors and other recipients
We use the following service providers. Where a provider is outside the EU/EEA, the transfer is based on an adequacy decision (including the EU-US Data Privacy Framework for certified providers) or on the EU Standard Contractual Clauses.
| Provider | Location | Purpose | Data |
|---|---|---|---|
| Cloudflare, Inc. | USA, global network | Hosting and storage (Workers, R2, KV, D1, Durable Objects, Queues), delivery and security, email sending (Cloudflare Email Service), usage statistics (Analytics Engine), selected internal AI functions (Workers AI) | all platform data |
| Mistral AI | France (EU) | Main AI provider: chat, drafting, translation, moderation, transcription of audio and video | the content submitted to the AI feature |
| netcup GmbH | Germany (EU) | Servers for media processing (images, audio, video), translation and search | media files and texts being processed |
| Paddle.com Market Ltd | United Kingdom | Merchant of record for platform subscriptions: checkout, invoicing, tax | billing and payment data (Paddle's privacy policy applies) |
| Stripe | USA / Ireland | Payments in tenant shops, through the site owner's own Stripe account | payment and billing data of shop customers |
| Linear | USA | Support requests: messages to the platform support inbox are filed as tickets | sender, message content |
| Black Forest Labs | Germany / USA | Image generation on request of a site owner | the image prompt |
| Composio | USA | Automation tools that a site owner connects | the data of the connected task |
| Zoom (USA), OpenTalk (Germany), Whereby (Norway) | as listed | Video meetings, only if a site owner configures the meeting scheduler | meeting time and participant details |
AI features only receive the content needed for the task, for example a text, an audio file or an image. That content may contain personal data if you include it. We do not send analytics data or browsing histories to AI providers.
Browser requests to third parties: the documentation site docs.aioengine.io loads a script library from the jsDelivr CDN, which then sees your IP address. A site owner can add other external content (for example embedded videos) to their own site.
5. Cookies
We only use cookies that are strictly necessary for the service (Art. 5(3) ePrivacy Directive, section 165(3) TKG 2021). No tracking or advertising cookies are set.
| Cookie | Purpose | Duration |
|---|---|---|
cms_token | Admin sign-in session | 7 days |
csrf_token | Protection against cross-site request forgery | browser session |
aio_network | aio network sign-in across tenant sites | 30 days |
__Host-aio_* | Secure hand-over of a sign-in between admin, inbox and site | from 60 seconds up to the sign-in session |
content_unlock_<slug> | Access to password-protected content | 1 day |
6. Retention
| Data | Retention |
|---|---|
| Account and member data, content | while the account or membership exists; then deleted on request or with the site, unless a legal obligation requires us to keep it |
| Newsletter opt-out records | kept so that the opt-out stays respected |
| Usage statistics | individual events: 90 days (Analytics Engine); daily summaries: 1 year; monthly summaries: 7 years; yearly summaries: while the site exists. Summaries keep event labels, so the email address of a registration event currently stays in them for as long |
| Billing and accounting records | 7 years (section 132 BAO) |
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and you can withdraw consent at any time with effect for the future. Write to support@aioengine.io. We answer within one month. For data of a tenant site, the site owner decides as controller; we support it.
You can lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.
8. Children
The platform is not directed at children under 14. A tenant site may set its own rules for its members.
9. Security
All traffic is encrypted (HTTPS). Sign-in is passwordless with short-lived, single-use links and secure HttpOnly cookies. Data of different tenant sites is stored separately, and access is limited to the site concerned.
10. Changes
We publish a new version of this policy with a new version number and effective date. Material changes are announced on the platform.
Related: Terms · Refund Policy · Imprint
