Privacy Policy
Last updated September 4, 2026
AedID ("we", "us"), operated from Lisbon, Portugal, is the controller of the personal data described here. This policy covers aedid.com and the AedID product. The short version: we collect what the product needs to keep your building's record, we sell nothing, and you can see, correct, export, or delete your data.
1. What we collect
- Account data — email address, name, password hash (or your Google account identifier if you sign in with Google), organization membership and role.
- Building records — the documents, photographs, and details you upload about properties, and the facts extracted from them. Documents about a building (deeds, invoices, reports) can contain personal data about you or others; you are responsible for having the right to upload them.
- Usage and technical data — server logs (IP address, user agent), session records, and — only with your consent — analytics events and session replays (see the Cookie Policy).
- Support records — correspondence with us, and an audit log of any access our staff make to your account while assisting you.
2. Why, and on what legal basis
- Providing the service (contract) — storing your record, processing your documents, sending transactional email such as invitations, verification, and maintenance digests.
- AI document processing (contract) — documents and photos you upload are read by AI models to extract the facts that build your record. Results are marked as extracted and remain yours to correct; no decision with legal effect on you is made automatically.
- Security and abuse prevention (legitimate interest) — logs, session records, and the support audit trail.
- Analytics (consent) — optional, off until you say yes.
3. Who processes it for us
We use a small set of processors, under data-processing agreements: cloud hosting (DigitalOcean), managed Postgres database (Neon), file storage and transactional email (Amazon Web Services), AI model providers for document processing (Google, OpenAI, Mistral), and — with consent — analytics (Google Analytics, Microsoft Clarity). Where data leaves the EU/EEA, transfers rest on adequacy decisions or Standard Contractual Clauses. We do not sell personal data, and we do not share it with anyone for their own advertising.
4. Retention
Your record exists to be permanent, so we keep it while your account is active. When you delete data, or your account, it is removed from live systems promptly and from backups on their rotation (at most 35 days). Audit logs of support access and legally required records are kept longer where the law demands it.
5. Your rights
Wherever you live, you can ask us to access, correct, export (in a portable format), or delete your personal data, to restrict or object to processing, and to withdraw consent at any time. EU/EEA residents have these rights under the GDPR and may complain to a supervisory authority — in Portugal, the CNPD (cnpd.pt). California residents have equivalent rights under the CCPA/CPRA, including the right to know, delete, and correct; we do not sell or share personal information as those terms are defined there, and we do not discriminate for exercising rights.
To exercise any of these, write to [email protected] from the address on your account. We answer within a month.
6. Security
Data is encrypted in transit, passwords are hashed, access inside AedID is scoped per organization and role, and staff access to customer accounts is logged and time-limited. No system is perfect; if a breach affects your data we will notify you and the authorities as the law requires.
7. Children
AedID is not directed at children under 16 and we do not knowingly collect their data.
8. Changes
When this policy changes materially we will tell you by email or in the product before the change applies. The date above always reflects the current version.