> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/data-and-privacy/gdpr.md).

# GDPR

How Memori applies the European data protection regulation on the AIsuru platform.

Memori s.r.l. designs and operates the AIsuru platform in full compliance with EU Regulation 2016/679 (GDPR). This means that the protection of personal data is not treated as a box-ticking exercise but as a technical and organizational requirement built into every stage of development and delivery of the service, following the principle of **Privacy by Design and by Default**.

### Roles and responsibilities in data processing

Correctly identifying roles is essential to understand the responsibility of each party involved:

| Party                                                    | GDPR role                       | Data processed                                                                  |
| -------------------------------------------------------- | ------------------------------- | ------------------------------------------------------------------------------- |
| Customer (company or professional using AIsuru)          | Data Controller                 | End-user data of the Agents (conversations, authenticated profile, known facts) |
| Memori s.r.l.                                            | Data Processor                  | Platform data on behalf of the Customer                                         |
| Infrastructure providers (AWS and others, all in the EU) | Sub-processors (infrastructure) | Data hosted on the infrastructure                                               |
| LLM providers (OpenAI, Anthropic, Mistral, etc.)         | Sub-processors (LLM processing) | Queries sent by the Customer for processing                                     |
| End user                                                 | Data Subject                    | Their own personal data                                                         |
| Memori s.r.l.                                            | Data Controller                 | Account data of users registered on aisuru.com, billing data                    |

> **Fundamental principle:** Data entered into the platform (Agent content, conversations, uploaded files) remains the exclusive property of the Customer. Memori does not collect, use or transfer such data to train, modify or improve its own models or those of third parties.

### Technical and organizational measures

Memori has implemented the following measures to protect personal data:

**Technical measures**

* Encryption in transit via HTTPS/TLS for all communications
* Protection of files stored on AWS S3 in accordance with the security policies documented in the management system
* Automatic anonymization of IP addresses in system logs
* Automatic malware scanning of uploaded files (AWS GuardDuty)
* Access control on internal systems with strong authentication policies for the team
* Logical (multi-tenant) or physical (Private Cloud, On-Premise) separation of customer data

**Organizational measures**

* Information Security Management System certified ISO 27001:2022
* Quality Management System certified ISO 9001:2015
* Periodic audits of processing activities
* Staff training on data protection
* Least privilege access policies for the internal team
* Data Processing Agreements (DPA) with all sub-processors

### Non-EU data transfers

Memori's main infrastructure is located in the EU. For LLM providers based in the USA (OpenAI, Anthropic), the transfer takes place in compliance with Article 46 of the GDPR, in particular through:

* Standard Contractual Clauses (SCC) approved by the European Commission
* Adherence to the EU-US Data Privacy Framework (where applicable)
* Short provider-side retention windows, used solely to prevent abuse. Some providers offer zero data retention on request. For details on each provider, please refer to the relevant official documentation.

### Data subject rights and how to exercise them

Every user of the AIsuru platform has the right to:

* **Access** — view the processing activities in the dashboard; request written information at <info@memori.ai>
* **Rectification** — modify their profile data directly from the dashboard
* **Erasure** — delete conversations, known facts or their own account from the dashboard
* **Portability** — export their data in the available formats
* **Restriction of processing** — request the suspension of processing in certain cases
* **Objection** — object to processing on legitimate grounds
* **Complaint** — lodge a complaint with the Italian Data Protection Authority: [www.garanteprivacy.it](https://www.garanteprivacy.it)

To exercise your rights: <info@memori.ai>

### GDPR documentation available

| Document                        | Available                                                                      |
| ------------------------------- | ------------------------------------------------------------------------------ |
| Privacy and Cookie Policy       | [aisuru.com/en/privacy\_and\_cookie](https://aisuru.com/en/privacy_and_cookie) |
| Acceptable Use Policy           | Acceptable Use Policy of the AIsuru Platform                                   |
| Data Processing Agreement (DPA) | On request — <privacy@memori.ai>                                               |
