As of June 2026
Responsible for data processing on this website and the hosted Subsumio service (hereinafter “Service”) is:
RCIID — Rocket Chain Investigation & Intelligence Division
Hauslabgasse 42/3/2
1050 Vienna, Austria
Email: help@rciid.at
No Data Protection Officer has been appointed at this time. Appointment is required e.g. when processing special categories of personal data on a large scale (Art. 37 GDPR; DE: § 38 BDSG; AT: § 9 DSG; CH: n/a — DSG does not require a DPO). Privacy inquiries can be directed to help@rciid.at.
Subsumio is designed as a data-minimising product. There are two operating models with different data-protection roles:
When you visit the site, the hosting provider processes technically necessary server log data (IP address, timestamp, requested resource, user agent) for delivery and security — legitimate interest (Art. 6(1)(f) GDPR). No marketing/tracking cookies are set without consent.
To use the Service, we process account data: email, name, an irreversibly hashed password (scrypt), referral code — for contract performance (Art. 6(1)(b) GDPR). Login/registration attempts are rate-limited for abuse prevention (Art. 6(1)(f) GDPR). Paid plans are billed via a payment provider.
Where you upload personal data of your clients/customers, you are the Controller and we act as Processor (Art. 28 GDPR). A DPA must be concluded before such use (template provided). Professionals bound by secrecy (DE: § 203 StGB; AT: § 9 RAO; CH: Art. 321 StGB) must additionally ensure compliant involvement of supporting persons — we recommend self-hosting or the EU cloud with a separate confidentiality agreement.
For synthesis and agent functions, relevant content excerpts are transmitted to LLM/embedding providers who process under instruction and do not use the data for training (Art. 6(1)(b) GDPR or DPA). With self-hosting, you choose providers and models freely or run a local model.
Depending on configuration, the following categories may be involved (all with DPAs; third-country transfers only on the basis of EU Standard Contractual Clauses, Art. 46 GDPR):
Current providers: Hosting via EU data centres (Hetzner, DE); LLM via OpenRouter (US, EU Standard Contractual Clauses); Embeddings via OpenRouter (US, SCCs); Payment via Stripe (US, SCCs); Email via Resend (US, SCCs). All processors are bound by DPAs.
Account data for the duration of the contract; deletion after termination, subject to retention obligations (DE: § 147 AO, § 257 HGB; AT: § 132 BAO; CH: OR 962). Content is deleted on your instruction or at contract end. Server logs are retained for 14 days.
You have rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can trigger a full export of your account and brain data as JSON via Settings → Account → Export data. You have the right to lodge a complaint with a supervisory authority.
The version published on this page at any given time is authoritative.
See also: Terms of Service · Imprint