Privacy Policy

Last updated: February 2026

At RCIID ("Subsumio"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

1. Information We Collect

We collect information you provide directly, such as your name, email address, company information, and payment details when you create an account. We also collect usage data, device information, and log data automatically to improve our services.

2. How We Use Your Information

We use your information to provide and maintain our services, process transactions, send communications, improve our platform, ensure security, and comply with legal obligations.

3. Data Storage & Security

All data is stored exclusively in EU data centers (Frankfurt, Germany). We use AES-256 encryption at rest and TLS 1.3 in transit. Our zero-knowledge architecture ensures we cannot access your document contents.

4. Data Sharing

We do not sell your personal data. We only share information with service providers who assist in operating our platform, and only under strict data processing agreements.

5. Your Rights (GDPR)

Under GDPR, you have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. Contact our DPO at privacy@subsumio.ai.

6. Cookies

We use essential cookies for platform functionality and optional analytics cookies (only with your consent). You can manage cookie preferences at any time through our cookie banner.

7. Data Retention

We retain your data for as long as your account is active. Upon account deletion, all personal data is permanently deleted within 30 days. Document data is deleted immediately.

8. Contact

For privacy inquiries, contact our Data Protection Officer at privacy@subsumio.ai or write to RCIID, Kärntner Straße 1, 1010 Vienna, Austria.