Skip to main content

Connector privacy

Effective date: 25 September 2026

Operator and responsibilities

AI Ledger is operated by ATTACK Simulator SRL (RO43550687), CLUJ-NAPOCA, STR. AUGUSTIN PRESECAN NR. 6, JUD. CLUJ, ROMANIA. Contact: info@ailedger.eu. We determine the purposes of account administration, service security and business communications. For organization-controlled governance content, we process data on that organization's documented instructions. The organization is responsible for informing its people and establishing an appropriate legal basis; granting OAuth permissions is not itself a legal basis for every employee's data.

Purpose and scope

We process account/contact details, organization membership, session/security metadata, support communications and governance records to provide, secure and support AI Ledger. Depending on the context, our own processing relies on performance of a contract, legitimate interests in service administration and security, or legal obligations. Required account data is necessary to provide access. Optional connector authorization may be withheld or withdrawn without preventing manual inventory entry. Discovery is manually initiated and may be incomplete; observations are not confirmation of AI use, approval or certification.

Google Workspace

Authorization validates the connecting account using OpenID and email. Read-only customer access identifies the Workspace organization. OAuth audit reports provide application identifiers, names and authorization times. These scopes do not request Gmail messages or Drive document contents. Application names may contain personal information.

Microsoft

Read-only access retrieves available applications, successful application sign-ins and Intune detected applications where permitted. Sign-in responses may contain employee, IP and device information in transit; discovery extraction discards these fields and retains application-level observations.

Storage and access

Connections store organization/provider identifiers, encrypted access credentials, collection progress and application observations. Workspace permissions control access. Review decisions and connector actions create audit records. Temporary collection checkpoints expire; this is separate from observation retention.

Service providers and transfers

Primary hosting and the database are declared in Nürnberg, Germany, with Hetzner. Resend handles application email; Cloudflare provides DNS and inbound email routing to the operator's Google Workspace mailbox. Microsoft and Google process authorization/API requests. Optional AI features use OpenAI. Provider processing or support may occur outside the EEA; applicable processing agreements and transfer mechanisms, such as standard contractual clauses where required, govern those transfers. Contact us for information about the applicable safeguards. We do not promise that all processing stays in the EU.

Retention

Pending observations that have never been reviewed, linked to inventory or referenced by evidence become eligible for permanent deletion more than 90 days after last seen by default. Administrators can change the period. Scheduled batches remove up to 500 eligible observations per organization per run; processing failures or a backlog may delay removal. Active documented extensions preserve records. Reviewed records and governance evidence are retained according to organization instructions and applicable preservation needs, not automatically deleted under this rule. Marking a governance record expired is not physical deletion. Account closure or deletion requests require an authorized review of records, legal obligations and holds.

Backups and deletion requests

Scheduled database dumps are rotated by the successful daily backup job after they are more than eight days old. Approved manual release/restore dumps are reviewed for deletion after 30 days from their last modification. A documented preservation marker suspends that deletion and must be reviewed when the reason ends. Failed jobs may delay cleanup. Backups are not erased immediately when a record is deleted; authorized restores must reapply completed deletion requests before normal use. Contact info@ailedger.eu for requests; we verify identity and authority, coordinate organization-controlled records with the organization, assess legal holds and record the outcome. Local backups alone do not constitute off-site disaster recovery.

Disconnect and revoke

Local credentials are removed on disconnect. The Google connector requests provider revocation and reports when it cannot confirm it; in that case remove AI Ledger access in your Google account. Microsoft permissions must be revoked separately by an authorized administrator. Google revocation may affect other workspaces using the same account and OAuth project.

Optional AI features

Discovery does not call a language model. When optional AI-assisted rewriting, translation or generation is enabled and invoked, the supplied text and prompt context are sent to OpenAI. Provider-derived names may be included if copied into inventory or submitted by a user. Only submit information you are authorized to share. We do not use Google API data to train generalized AI models. We do not claim Zero Data Retention or EU-only model processing; OpenAI's applicable API terms and project settings govern its processing. AI output requires human review.

Google data — Limited Use

AI Ledger's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We limit use to disclosed, visible user-facing functionality and permitted security/legal purposes. We do not sell Google API data, use it for advertising or credit decisions, or transfer it for those purposes. Human access is limited to your affirmative authorization for specified data, necessary security investigation, legal requirements or other exceptions permitted by the policy. These limits also apply to aggregated or derived Google data.

Google API Services User Data Policy

Your rights and policy changes

Where applicable, you may request access, correction, erasure, restriction, portability or object to processing. You may withdraw consent-based processing without affecting its earlier lawfulness and complain to a competent supervisory authority, including Romania's ANSPDCP (dataprotection.ro). For employer-controlled content, contact your organization; we assist with authorized requests. We respond within applicable legal deadlines, subject to lawful exceptions. Discovery does not itself make solely automated decisions with legal or similarly significant effects. Material policy changes will be identified by an updated date and communicated as required.

Privacy contact

info@ailedger.euTerms & Disclaimer