Skip to content
AINew: 5-layer quality architecture for cited answers
Subsum•ioLEGAL INTELLIGENCE
Pricing
Subsum•ioLEGAL INTELLIGENCE

AI legal software that never forgets — the firm brain for lawyers in Europe.

Your data, your keys. Self-hosted on your hardware or our EU cloud with DPA — GDPR-ready, end-to-end encrypted, zero training on your data.

Platform

  • Overview
  • SuperBrain
  • Features
  • Security
  • WhatsApp Copilot
  • Pricing
  • Download

Solutions

  • For Individuals
  • For Legal Professionals
  • For Law Firms
  • For Solo Lawyers
  • For In-House
  • For Mid-Sized Firms
  • For Tax Advisors

Resources

  • Documentation
  • Blog
  • Benchmark
  • Partner Program
  • Dashboard

Company

  • About
  • Contact
  • Imprint

Legal

  • Terms of service
  • Privacy

© 2026 Subsumio · AI legal software & legal intelligence for law firms

EU cloud or self-hosted · GDPR-ready · AVV included · § 203 StGB compliant

← Subsumio

Privacy Policy

As of June 2026

1. Controller

Responsible for data processing on this website and the hosted Subsumio service (hereinafter “Service”) is:

RCIID — Rocket Chain Investigation & Intelligence Division
Hauslabgasse 42/3/2
1050 Vienna, Austria
Email: help@rciid.at

No Data Protection Officer has been appointed at this time. Appointment is required e.g. when processing special categories of personal data on a large scale (Art. 37 GDPR; DE: § 38 BDSG; AT: § 9 DSG; CH: n/a — DSG does not require a DPO). Privacy inquiries can be directed to help@rciid.at.

2. Principle: data minimisation and operating models

Subsumio is designed as a data-minimising product. There are two operating models with different data-protection roles:

  • Self-hosting: The engine runs on your own infrastructure. Content is never transmitted to us; we have no access.
  • Hosted EU cloud: We process content exclusively to provide the Service — never to train AI models.

3. Website operation

When you visit the site, the hosting provider processes technically necessary server log data (IP address, timestamp, requested resource, user agent) for delivery and security — legitimate interest (Art. 6(1)(f) GDPR). No marketing/tracking cookies are set without consent.

4. Account, authentication, billing

To use the Service, we process account data: email, name, an irreversibly hashed password (scrypt), referral code — for contract performance (Art. 6(1)(b) GDPR). Login/registration attempts are rate-limited for abuse prevention (Art. 6(1)(f) GDPR). Paid plans are billed via a payment provider.

5. Content and client data — processing agreement

Where you upload personal data of your clients/customers, you are the Controller and we act as Processor (Art. 28 GDPR). A DPA must be concluded before such use (template provided). Professionals bound by secrecy (DE: § 203 StGB; AT: § 9 RAO; CH: Art. 321 StGB) must additionally ensure compliant involvement of supporting persons — we recommend self-hosting or the EU cloud with a separate confidentiality agreement.

6. AI functions

For synthesis and agent functions, relevant content excerpts are transmitted to LLM/embedding providers who process under instruction and do not use the data for training (Art. 6(1)(b) GDPR or DPA). With self-hosting, you choose providers and models freely or run a local model.

7. Processors and recipients

Depending on configuration, the following categories may be involved (all with DPAs; third-country transfers only on the basis of EU Standard Contractual Clauses, Art. 46 GDPR):

  • Hosting/infrastructure (web app and/or engine), primarily EU data centres
  • LLM providers (answers/agents) and embedding providers (search)
  • Payment provider for paid plans
  • Email delivery service for transactional messages (deadline digest, password reset)
  • Optional: distributed rate-limiting service

Current providers: Hosting via EU data centres (Hetzner, DE); LLM via OpenRouter (US, EU Standard Contractual Clauses); Embeddings via OpenRouter (US, SCCs); Payment via Stripe (US, SCCs); Email via Resend (US, SCCs). All processors are bound by DPAs.

8. Retention period

Account data for the duration of the contract; deletion after termination, subject to retention obligations (DE: § 147 AO, § 257 HGB; AT: § 132 BAO; CH: OR 962). Content is deleted on your instruction or at contract end. Server logs are retained for 14 days.

9. Your rights

You have rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can trigger a full export of your account and brain data as JSON via Settings → Account → Export data. You have the right to lodge a complaint with a supervisory authority.

10. Changes

The version published on this page at any given time is authoritative.

See also: Terms of Service · Imprint

Privacy Policy — Subsumio