Skip to content
AIRAS Cloud

Trust centre · For a data protection officer or privacy counsel

What we process, why, where, and for how long.

A governance platform holds the record of how an organisation decides on AI. That record is sensitive, and the processing position behind it has to be legible before anyone signs a contract.

How to read the evidence status on this page

Verified in product
Implemented in the platform and covered by automated tests or recorded verification evidence.
Controlled document
Maintained as a version-controlled internal artefact, issued under agreement rather than published.
In external assurance
Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
Not claimed
Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.
Data protection — claim register
ClaimStatusWhat evidences it
Customer content is never used to train modelsVerified in productNo customer content is used for model training, fine-tuning or evaluation. The regulatory engine is rules-based and does not learn from tenant data.
Tenant-scoped isolation of all customer records and documentsVerified in productEvery record and stored document is scoped to a single tenant in policy and re-checked in the application layer on each request.
Encryption in transit and at restVerified in productTransport is TLS-only with strict transport security; stored data and documents are encrypted at rest by the managed platform.
Append-only processing and audit historyVerified in productAudit events cannot be edited or deleted through the application; blocking triggers reject attempts and failures raise their own audit event.
Data processing agreement and sub-processor registerControlled documentIssued with the contract. The register names each sub-processor, its purpose and its processing location, and change notification is contractual.
Retention and deletion scheduleControlled documentAgreed per customer before onboarding and recorded in the order documentation, with a documented deletion and export route on exit.
Independent data-protection audit of AIRAS CloudIn external assuranceNot yet performed. We support customer-led privacy review and will disclose the outcome of any external audit once one exists.
Certified GDPR complianceNot claimedNo such certification exists in law and we do not imply one. We evidence our processing position, controls and contractual terms instead.

Pilot data position

Pilots and evaluations run on synthetic, de-identified or expressly approved data. Personal or sensitive production data requires a prior privacy and security review and the executed processing terms — it is not accepted by default.

Roles under the GDPR

For customer content placed into a tenant, the customer is the controller and AFRH Consulting Limited, trading as AIRAS Cloud, is the processor. We process that content only to deliver the service and on the customer's documented instructions.

For our own commercial contacts — interest submissions, enquiries and account administration — we act as controller, and the lawful basis, retention and rights position is set out in our privacy notice.

Individual rights and assistance

Because governance records are tenant-scoped and exportable, a controller can locate, export or delete the records relating to an individual without our intervention. Where assistance is required, the contractual assistance obligations and response windows are set out in the processing agreement.

Privacy review under way?

Send us your assessment template. We will complete it against the current controlled documentation rather than sending a generic pack.

No commercial commitment. No confidential information required.