Privacy Policy.
Last updated: September 21, 2026
1. Who we are
This Privacy Policy is issued by Airlock BV, a Belgian limited company having its seat at Colmarstraat 38, 9100 Sint-Niklaas, Belgium, registered with the Crossroad Bank of Enterprises under number 1037836652 ("airlock"). The Service is operated from the European Union and hosted on AWS in Frankfurt (eu-central-1), subject to the content-delivery, analytics-proxy, and certificate qualifications set out in section 5.
This policy explains what personal data we collect from visitors to our website and from customers of the airlock Service (including the Control Room and the MCP proxy), how we use it, and the choices you have.
For the purposes of the GDPR, airlock acts as a data controller for account, marketing, billing, and website-analytics data, and as a data processor for the Customer Data your organization sends through the Service (including audit logs, approval records, and connected-API credentials). Processing on your behalf is governed by our Data Processing Agreement.
2. Information we collect
Account and organization data
- Account information: name, work email, and organization details when you create an account in the Control Room.
- Authentication data: OAuth tokens and session identifiers used to authenticate you with the Service and with third-party APIs you connect. Passwords are not stored by airlock. Authentication is handled by AWS Cognito (OAuth 2.0 with PKCE), with optional federation to Google Workspace and Microsoft Entra ID.
- Billing data: for paid subscriptions, we collect the billing details needed to issue invoices and process payments (organization name, billing address, VAT number where applicable, contact details, subscription tier and status). Payment instrument details are handled by our payment provider and are not stored by airlock.
API and proxy data
- API credentials: credentials you supply to connect third-party services (API keys, OAuth tokens). Encrypted at rest using AES-256-GCM and only decrypted at the moment of API execution.
- Request metadata (audit trail): when AI agents call third-party APIs through airlock we log metadata such as the tool invoked, timestamp, organization, and approval status, along with redacted and truncated copies of the request and response bodies so you can audit and replay execution. Secret-bearing fields are stripped before this record is written.
- Full tool-call payloads (call analytics): separately from the audit trail above, we store a record of each tool call that keeps the complete, unredacted textual arguments and responses exchanged with your connected application or API, alongside the acting user's identifier and email address, the source IP address, and the user agent. The redaction and truncation described in the previous bullet apply to the audit trail and not to this record. Two limits do apply: non-textual blocks in a response (images, audio, PDFs, and other binary content) are replaced by a short descriptor before the record is written, and the response of a management tool that releases a credential is replaced by a redaction marker. This is the same record described in Annex A, entry 5 of our Data Processing Agreement. Because its content is determined entirely by what your agents request from your own systems, it is the category most likely to contain special category data — see section 9.
- Approval records: when a request requires approval, the request payload and tool arguments are stored to drive the workflow.
Audit log data
airlock writes an audit log for each customer organization. These logs are for your auditing. airlock personnel do not read the contents of your audit logs, approval payloads, or proxied request/response data unless you have given us explicit, written approval: for example, when you open a support ticket that asks us to investigate. Limited exceptions apply where strictly required to maintain the security or integrity of the Service, or where compelled by law.
Website and usage data
- Product and website analytics: we monitor how visitors interact with the website and the Control Room (pages viewed, features used, session length, and — on the public website only — session replays). Visitors to the public website are analysed pseudonymously unless they identify themselves to us. Analytics in the Control Room are not anonymized: while you are signed in we transmit your user identifier, email address, first name, last name, role, organization identifier, and organization name to our analytics provider and associate your subsequent product-usage events with them. See "Cookies and analytics" below.
- Technical data: browser type, operating system, approximate region derived from IP, and device identifiers, used for security, debugging, and abuse prevention.
3. How we use your information
- Provide, maintain, and improve the Service, including proxying API requests on your behalf and enforcing your configured policies and approval workflows.
- Authenticate you and authorize access to the third-party APIs you have connected.
- Communicate with you about updates, security alerts, and support.
- Monitor for abuse, enforce rate limits, and maintain system security.
- Generate product and usage analytics to improve the Service, including the identified Control Room analytics described in section 6.
- Comply with legal obligations.
We do not use your data to train AI models. Your API credentials, request data, and response data are never used for machine-learning training by airlock or shared with third parties for that purpose. We do not sell your personal information.
Derived data. Aggregated and anonymized usage analytics, model and policy performance metrics, and similar derived data generated by the Service belong to airlock. To the extent such derived data, after de-identification, no longer constitutes personal data, it falls outside the scope of our Data Processing Agreement and may be retained and used to operate and improve the Service.
4. Legal bases (GDPR)
We process personal data under the following legal bases:
- Contract: to provide the Service to you (account, authentication, proxy, audit log).
- Legitimate interest: for security, abuse prevention, bot protection, product analytics inside the Control Room, defence of legal claims, and limited service-related communications. You may object to the Control Room analytics at any time by writing to privacy@air-lock.ai.
- Consent: for optional marketing emails and for the non-essential cookies and analytics on our public website.
- Legal obligation: for tax, accounting, and compliance with lawful requests.
5. Data storage and security
Customer Data is stored at rest on AWS in the EU (Frankfurt, eu-central-1). Three qualifications apply to that statement, and we state them rather than leaving the residency claim unqualified. They mirror Clause 4.1 of our Data Processing Agreement.
- Content delivery uses a global edge network. Our web interfaces are served through Amazon CloudFront, which terminates TLS and serves cached content from edge locations worldwide, including outside the EEA. A request carrying personal data traverses the edge location nearest you before reaching the origin in
eu-central-1. - Analytics events reach PostHog through a global-edge reverse proxy. Browser analytics events are not sent to PostHog's EU ingest endpoint directly. They are sent to a PostHog-operated managed reverse proxy on an airlock-branded hostname (
v.air-lock.ai), which accepts the request at the edge location nearest you — including outside the EEA — before forwarding it to PostHog's EU project. This is a different path from the CloudFront delivery above, and is stated separately for that reason. - TLS certificates are issued in us-east-1. AWS requires certificates for CloudFront distributions and for Amazon Cognito custom domains to be issued in the us-east-1 region, so we hold certificates there. Certificates contain domain names and public keys only; they carry no personal data, and no Customer Data is stored or processed in us-east-1 as a result.
We implement, among other measures:
- Encryption at rest: API credentials and sensitive fields encrypted with AES-256-GCM under AWS KMS envelope encryption (per-record data keys wrapped by a customer master key); all database tables use AWS-managed encryption at rest.
- Encryption in transit: TLS 1.2+ everywhere; calls to third-party services use HTTPS.
- Authentication: AWS Cognito with OAuth 2.0 and PKCE. Passwords are not stored by airlock.
- Tenant isolation: each organization's data is logically separated and access is enforced at the application and database layer.
- Audit trail of staff access: any airlock-personnel access to a tenant's environment is itself logged.
- Personal Data Breach notification: where airlock acts as processor, we will notify your designated administrators without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your Customer Data, and assist you in meeting your notification obligations under the GDPR.
No transmission over the Internet or electronic storage is 100% secure; we cannot guarantee absolute security.
6. Cookies and analytics
Strictly necessary cookies. The website and Control Room set a small number of cookies and similar storage items required to keep you signed in, remember your theme/preferences, and maintain session security. These are essential to the Service and cannot be disabled.
Website analytics (with your consent). On the public website we use PostHog (EU project) and Google Analytics to understand how visitors use the site. We display a cookie consent banner on first visit, and neither tool loads until you click Accept; withdrawing consent stops further capture and clears the analytics identity. PostHog captures page views, a restricted set of click and form-submit events, and session replays — a reconstruction of your interaction with the page. Replay masks the value of every form field, so anything you type into a form is not recorded. PostHog is configured to honour the browser's Do Not Track signal.
Control Room analytics (no consent gate). Analytics in the signed-in Control Room work differently, and we state the difference rather than implying a single regime. PostHog initialises there for every signed-in session without a consent banner, on the legitimate-interest basis in section 4, and the processing is not anonymized: we send PostHog your user identifier, email address, first name, last name, role, organization identifier, and organization name, and associate your subsequent product-usage events with them. Client-side errors and unhandled exceptions are captured with their stack traces, and server-side failures are sent from our backend to PostHog carrying the acting user identifier, organization identifier, request identifier, request path and method, and the handler or tool involved. Earlier versions of this policy described this activity as anonymized product analytics; that description was inaccurate and has been corrected. To object, write to privacy@air-lock.ai.
Form submissions. When you submit the Teams subscription form, the fields you enter (name, work email, phone, company, number of users, location, and any additional info) are sent directly to PostHog as a team_subscription_requested event with your email as the identifier. This happens regardless of cookie consent, because you are explicitly providing this information to us rather than being measured in the background. We use it to contact you about your subscription request and to maintain our prospect pipeline.
Email gates on our free tools. When you ask us to email you a generated AI policy, or download a skill from this site, the work email address you give us — and your newsletter opt-in, if you tick it — is sent to our email provider Brevo and added to a contact list there. Newsletter signups (including from the footer) use double opt-in: you are only added to the newsletter list after clicking the confirmation link we email you.
AI Policy Generator. The generator at air-lock.ai/ai-policy is a chat tool. Your draft — both the chat history and the parsed policy fields — is held in your browser and is not stored on our side. Your messages are sent to an Amazon Nova model on AWS Bedrock in the EU so it can reply; our worker logs request metadata (timing, token counts) for cost control, not message content. When the model needs fresh public context it issues a short search query of its own to Perplexity (United States). Your chat is not forwarded, but the query is written from what you told it — asked for your company or website, it searches on that name or domain — so details you supply can reach Perplexity inside a search string. Queries are capped in length, and the model's reply to you is written on our side, in the EU.
Bot protection. The AI Policy Generator, its email gate, and the skill download gate are protected by Cloudflare Turnstile, which loads a challenge from challenges.cloudflare.com and receives your IP address and browser signals in order to distinguish humans from bots. The footer newsletter signup does not load Turnstile; it is protected by rate limiting and by the double opt-in confirmation email. All of these endpoints are rate-limited, and the rate-limit records store a truncated SHA-256 hash of your IP address and, where you submitted one, of your email address — never the address itself in either case.
No advertising or retargeting. airlock does not run advertising or retargeting pixels on this site, and we do not sell or share personal data for advertising purposes. The third-party measurement tools we do load are PostHog and Google Analytics, both described above, both consent-gated on the public website.
7. Sub-processors and connected integrations
Sub-processors. We rely on the following categories of sub-processors engaged by airlock to deliver the Service:
- Cloud infrastructure (Amazon Web Services EMEA SARL, Luxembourg): hosting, database, authentication (Cognito), serverless compute, transactional email (Amazon SES), content delivery (CloudFront), and model inference via AWS Bedrock. Bedrock is used for four purposes, all in EU regions: embedding models that index content you connect for search; generative inference on the default model route, which receives the content of your requests; automated security scanning of skill content you import, which sends the body and attachments of that content to a model for assessment; and the AI Policy Generator chat on this website. AWS services run in EU regions, with the global edge delivery and us-east-1 certificate qualifications described in section 5.
- Runtime application security (Aikido Security NV, Belgium): Zen Firewall, which receives runtime telemetry from our Lambda functions (route, request shape, suspicious-traffic signals) to detect and block attacks against the Service.
- Product and website analytics (PostHog Inc., EU Cloud,
eu.i.posthog.com, data hosted in the EU): product analytics, session replay on the public website, and backend error telemetry. This processing is not anonymized for signed-in Control Room users — see section 6 for the identifiers involved. Browser events reach PostHog through the global-edge reverse proxy described in section 5. - Website measurement (Google, United States): Google Analytics on the public website only, loaded solely after you accept analytics cookies. It is not loaded in the Control Room and receives no Customer Data.
- Internal operational notifications (Slack Technologies, a Salesforce company; United States): the Service posts two kinds of message to airlock's own internal Slack workspace. Account-lifecycle alerts (free-trial warnings and expiries) carry the organization's name, slug, identifier, and member count, and no user-account fields. Integration-interest alerts, sent the first time someone in your organization clicks an integration we do not yet support, carry that person's email address and user identifier alongside the organization identifier and the integration name. Neither kind carries Customer Data routed through the Service.
- Bot protection (Cloudflare, United States): Cloudflare Turnstile on the AI Policy Generator, its email gate, and the skill download gate. Receives IP address and browser signals for the challenge only. Not used on the footer newsletter signup.
- Public web search for the AI Policy Generator (Perplexity, United States): receives short search queries written by the model. Your chat is not forwarded, but the model writes those queries from what you told it, so details you supply — a company name or domain — can be included. Used only by the free AI Policy Generator; not part of the Service.
- Customer Relationship Management (Attio): used to manage prospect and customer contact details and our sales pipeline. Stores name, work email, organization, and notes about our interactions with you.
- Transactional and marketing email (Brevo, EU-hosted): used to send signup confirmations, security alerts, support replies, and (with your consent) product updates and newsletters.
- Embedded video: some blog posts embed YouTube videos via Google's privacy-enhanced domain (
youtube-nocookie.com). The video player only loads, and Google may only then set cookies, after you click play. Nothing is requested from Google before that. Playback is governed by Google's privacy policy.
Where airlock acts as processor, we will give you at least 15 days prior written notice of any intended addition or replacement of a sub-processor. You may object on reasonable data-protection grounds within that period. A current sub-processor list is available on request from privacy@air-lock.ai.
Note on the recipients added to this list on August 26, 2026. Google, Slack, Cloudflare, and Perplexity were already receiving the data described above before that date. Listing them is a correction of an incomplete disclosure, not a new engagement, so the 15-day notice period above is not triggered by the listing itself. We nevertheless extend the objection right: you may object to any recipient listed here for the first time on that date, on reasonable data-protection grounds, on the same terms as for a newly engaged sub-processor.
Connected integrations are not airlock sub-processors. When you connect third-party services (for example: GitHub, Google Workspace, Datadog, Zoom, Slack, OpenAPI endpoints, or MCP servers you supply), airlock acts as an authorized proxy and forwards requests using credentials you supplied. Those connected services are your tools, operated under your exclusive responsibility. Their use does not constitute the engagement of those providers as airlock sub-processors. airlock is not responsible for the availability, accuracy, security, or behavior of any third-party service, MCP server, or AI provider you choose to connect through the Service, and we share data with them only on your instruction through tool execution.
We do not sell your personal information. We share data with third parties only as described in this policy or when required by law.
8. International data transfers
Customer Data is stored at rest in the EU, subject to the three qualifications in section 5. Personal data does, however, reach the following recipients outside the EEA, and we name them rather than describing the transfers in the abstract:
- Slack Technologies (United States) receives the internal account-lifecycle and integration-interest notifications described in section 7 — the latter including a user's email address and identifier.
- Google (United States) receives Google Analytics measurement data from the public website, after you accept analytics cookies.
- Cloudflare (United States) receives IP address and browser signals when a Turnstile challenge is rendered.
- Perplexity (United States) receives model-written search queries from the AI Policy Generator.
- Global edge paths. Requests to our web interfaces traverse Amazon CloudFront edge locations worldwide, and browser analytics events traverse a PostHog-operated managed reverse proxy at the edge, before coming to rest in the EU. See section 5.
Each of these transfers is governed by the Standard Contractual Clauses adopted by the European Commission and, where applicable, additional safeguards such as encryption in transit, pseudonymization, and data minimization. Details of the safeguards in place for any named recipient are available on request. Where section 7 does not state an establishment for a sub-processor, its current location is given in the sub-processor list available from privacy@air-lock.ai.
Separately, if you configure the Service to route model requests through a non-EU provider using your own credential, that transfer is directed by you as controller and is governed by Clause 4.5 of our Data Processing Agreement. We do not enable any such route on your behalf.
9. Customer responsibilities for high-risk processing
airlock provides an infrastructure-level service. Whether your deployment involves higher-risk categories of processing depends entirely on the agents, business applications, and APIs you connect to it. As controller, you are responsible for determining, before deployment, and where applicable documenting:
- whether special category data (Art. 9 GDPR) or criminal-offence data (Art. 10 GDPR) will flow through the Service, and whether an applicable exception applies;
- whether a Data Protection Impact Assessment (Art. 35 GDPR) is required (note that use of AI agents acting on your behalf may meet several EDPB criteria for likely high-risk processing: innovative technology, systematic monitoring, automated decision-making, large-scale processing);
- whether routed requests result in automated decisions with legal or similarly significant effects on individuals, in which case you implement the safeguards required by Art. 22 GDPR;
- whether any AI system you operate through the Service qualifies as a high-risk AI system under the EU AI Act (Regulation (EU) 2024/1689), in which case the Fundamental Rights Impact Assessment (FRIA) and the transparency obligations applicable to deployers are your sole responsibility.
airlock will provide reasonable assistance under Art. 28(3)(f) GDPR on request.
10. Data retention
- Account data: retained while your account is active. Personal data is deleted within 30 days of account closure (longer retention may apply where required by law).
- API credentials: retained while the connected service is active; deleted immediately when you disconnect that service.
- Audit trail — operational copy: 90 days from creation, then automatically deleted.
- Audit trail — tamper-resistant archive: a second copy of the audit trail is written to write-once storage under a retention lock of at least one year, applied when each object is written, so that it survives deletion of the operational copy. That lock is what gives the archive its evidential value. It is a security control, not a legal obligation, and we state it here because it is the one category that is not deleted at 90 days and is carved out of the end-of-service deletion promise below. No automatic expiry runs once the lock ends; archived records are deleted on written request from that point.
- Full tool-call payloads: no automatic expiry currently applies to this record. It is retained until Customer Data is deleted or returned at the end of service. We state this rather than implying a shorter period, intend to bound this retention, and will update this policy when we do.
- Approval requests and their outcomes: 90 days from creation, then automatically deleted. Where an approved result is too large to store inline, the overflow copy is held in separate object storage and expires 100 days after it is written; because a request is approved some time after it is created, that copy can outlive the request it belongs to.
- Product analytics and error telemetry (PostHog): 30 days from the event being recorded. Signing out stops further events being associated with you; it does not delete events already recorded.
- Control-plane and credential-access records (AWS CloudTrail): 365 days.
- Infrastructure and application operational logs: 30 days in production, and shorter in non-production environments.
- OAuth client registrations: dynamically registered OAuth clients expire 90 days after registration.
- Session data: Cognito access and ID tokens expire after 8 hours; refresh tokens expire after 30 days.
- Aggregated derived data: the derived data described in section 3 may be retained indefinitely once aggregated, because it no longer contains personal identifiers. This is a different category from the identified product analytics above, which expire on the 30-day period stated there.
- End of service: on termination of your subscription, Customer Data is made available for export for at least 60 days, after which it is deleted, except for data we are legally required to retain (such as billing records), aggregated/anonymized derived data, and the tamper-resistant audit archive described above, which remains under its retention lock where termination falls inside that window.
- Defence of claims: we may retain personal data relating to Authorized Representatives for up to 10 years after the end of your subscription to the extent necessary to defend against legal claims or to comply with legal obligations.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information; to object to or restrict processing; and to withdraw consent at any time where processing is based on consent. EU/EEA residents may lodge a complaint with their local data protection authority. In Belgium, this is the Gegevensbeschermingsautoriteit (Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be).
Where airlock acts as processor, any rights request relating to Customer Data should be directed to the customer organization that controls the data. If a data subject contacts us directly about Customer Data, we will forward the request to the relevant customer without undue delay and acknowledge receipt to the data subject, without otherwise responding substantively.
To exercise any rights where airlock is controller, or for any other privacy question, contact privacy@air-lock.ai.
12. Children's privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn we have collected such data, we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by updating the "Last updated" date and, where appropriate, by direct notice. Continued use of the Service after the effective date constitutes acceptance.
14. Contact
For privacy questions or to exercise your rights, contact privacy@air-lock.ai.