Skip to content

GDPR · Reg. 2016/679

Privacy what we keep and what we don't

Fluxia keeps the bare minimum: querying requires no signup, we build no profiles, and operational logs are anonymized. Here is what is stored, on which legal basis, for how long, and how to exercise your rights.

Executive summary

Fluxia is designed to minimize personal-data collection by default. Access is by invitation, or by signing up through one of the demo promotions — we don’t build profiles or run ads, and the few operational data points we do store (session trace, optional thumb feedback) are justified by a documented need and have an explicit retention policy.

This page describes what we store, why, for how long, and how to exercise your rights under Regulation (EU) 2016/679 (GDPR).

Data controller

FieldValue
ControllerFluxia sole operator
GDPR contactfluxia.soporte@gmail.com (response in ≤ 30 calendar days)
DPONot appointed (Art. 37 GDPR does not apply: no systematic large-scale processing)
Territorial scopeEU (Belgium, Ireland); no relevant international transfers, except the support contact email (Gmail, US) if you click “I want to talk to the Fluxia team” — see “Sub-processors”

What data Fluxia collects

1. Query and response (ephemeral memory)

DataPurposeRetentionLegal basis
Query textProcess the assistant’s responseNot persisted: only in RAM during the requestLegitimate interest (Art. 6(1)(f))
Response textShow it to the user and serve the active traceNot persisted: only in RAMLegitimate interest
session_id UUIDGroup related queries in the same sessionSession cookie: expires when browser closesLegitimate interest

Queries and responses are not persisted in any product database. We do not retrain models on your prompts.

2. Observability trace

DataPurposeRetentionLegal basis
trace_id (UUID)Post-incident forensics (AI Act Art. 73)90 daysLegal obligation (Art. 6(1)(c) + AI Act)
Per-node timingsLatency-regression detection90 daysLegitimate interest
Token usageEnvironmental-footprint calculation (EcoMeter)90 daysLegitimate interest
Query textOnly if you enter it: the tracing system does not actively extract PII90 daysLegitimate interest + data minimization

Warning: if you enter personal data (your name, ID number, address…) in the query, that data will sit in the observability trace for 90 days. Do not enter PII in queries. Fluxia doesn’t need it to answer about the hydrological plans. If you also click “I want to talk to the Fluxia team,” up to your 10 most recent queries are sent by email to the support inbox (see “Account data”).

3. Feedback (👍/👎 thumbs)

DataPurposeRetentionLegal basis
Rating (1 or -1)Model improvement and continuous evalIndefinite (anonymized after 1 year)Consent (Art. 6(1)(a)), on thumb click
Free-text comment (optional)Qualitative failure contextIndefinite (anonymized after 1 year)Consent
session_id + trace_idTrace correlation90 days (then only rating remains)Consent

Feedback is strictly optional. If you don’t click the thumb, we don’t store anything related to your opinion. Consent is unambiguous (explicit click), informed (labeled button), and revocable (see “Your rights”).

4. Art. 73 incident reports

DataPurposeRetentionLegal basis
Description + email (optional)Investigation and authority notification5 years (AI Act legal obligation)Legal obligation (Art. 6(1)(c))
Correlated trace_idForensics5 yearsLegal obligation

Art. 73 reports are handled under the incident procedure.

5. Data NOT collected

By contract and by design, Fluxia does not collect:

6. Account data (access request, invitation, and demo signup)

DataPurposeRetentionLegal basis
Email, full name (optional), organization (optional), reason (optional) — access request (app.fluxia-ia.com/register)Let the team decide whether to grant access and contact the requesterIndefinite: no automatic deletion when the request is decided; deleted only on request (see “Your rights”)Art. 6(1)(b) — steps prior to a contract, at the data subject’s request
Email of an account created by invitationIdentify the account and contact whoever uses itFor as long as the account existsArt. 6(1)(b)
Internal note an admin may write when inviting (optional)Let the team remember why that person was invitedFor as long as the email stays on the access allow-list (not tied to the account’s lifecycle)Art. 6(1)(b)
Email, name, organization (optional), profile, whatever you write in “What would you like to discuss with the Fluxia team?” (optional), an IP fingerprint (a salted hash; the IP itself is not stored), and the promotion you signed up through — demo promotion signup (app.fluxia-ia.com/demo or each promotion’s own address)Create the demo account without email verification, apply its promotion’s query limit, limit how many signups happen from the same IP per day (anti-abuse), let the Fluxia team contact you if you ask, and know which promotion each signup came throughFor as long as the account exists; deleting it erases your email, name, organization, whatever you wrote, and your IP fingerprint, and only an anonymous record of the signup remains (promotion, profile, and date), which counts toward the demo’s account limitArt. 6(1)(b) — creating the account; Art. 6(1)(f) — limiting IP abuse
Email, name, organization, profile, whatever you wrote in “What would you like to discuss with the Fluxia team?”, and up to your 10 most recent queries — when you click “I want to talk to the Fluxia team” inside the demo accountLet the Fluxia team answer youSent as a single email to the support inbox (fluxia.soporte@gmail.com); the email is only deleted if you ask, and once sent it cannot be recalled. It also creates an access request with the same data, kept like the rest: deleted only on requestArt. 6(1)(b) — at your request

None of this data is used to build profiles or for advertising. When an account (invited or demo) is deleted, your email, name, organization, and whatever you wrote are erased; for a demo account, only the anonymous record described above remains. You can also request deletion yourself through the same process as the rest of your rights (see “Your GDPR rights” below).

That deletion doesn’t reach everything: the email sent when you click “I want to talk to the Fluxia team” stays in the support inbox until its deletion is requested separately; the access request that same button creates is kept like the rest of access requests (not tied to any account, deleted only on request); the observability trace of your queries still lasts its 90 days (see “Observability trace” above); and the invitation’s internal note stays for as long as the email is on the access allow-list, because it isn’t tied to the account’s lifecycle.

Cookies and browser storage

Fluxia uses two browser-storage elements:

  1. Cookie ia_water_session (strict, essential): session UUID, no advertising use. Expires on browser close. No consent required (technically-necessary cookie, Art. 22.2 of Spain’s LSSI, which transposes Art. 5(3) of the ePrivacy Directive 2002/58/EC).
  2. Browser localStorage: recent-response cache to speed up reformulations. Only in your browser, never sent to the server. You can clear it any time from your browser settings.

We do not use third-party or advertising cookies.

Sub-processors

Fluxia transmits minimal data to the following sub-processors. All but the support email (Gmail, last row) are based in the EU or covered by approved standard contractual clauses (SCCs):

FunctionLocationDataDPA
Language model + embeddings providerEUQuery text (ephemeral processing; not persisted)Yes
Vector storage and databaseEUHydrological-plan corpus embeddings (not user data); feedback ratingsYes
Semantic rerankingOutside EU (with European Commission-approved SCCs 2021/914)Query text + retrieved chunks (ephemeral, non-PII)Yes
Static hostingEU/US edgeStandard access logs (no PII)Yes
Support email (Gmail / Google, account fluxia.soporte@gmail.com)Outside EU (US)The contact email described in “Account data” (name, email, organization, profile, whatever you write, and up to your 10 most recent queries), only if you click “I want to talk to the Fluxia team”No

For sub-processors outside the EU covered by standard contractual clauses, applicable mitigations include European Commission-approved SCCs (2021/914) and a documented transfer impact assessment (TIA); their transmitted data does not identify anyone. The exception is Gmail: it’s a consumer account with no DPA (data processing agreement) and no SCCs signed with Google, and the email it receives does contain your personal data when you click “I want to talk to the Fluxia team”.

Your GDPR rights

As a data subject you have the following rights. Response time: 30 calendar days from verified-request receipt.

RightGDPR articleHow to exercise
AccessArt. 15Email fluxia.soporte@gmail.com with your session_id (shown in the response footer)
RectificationArt. 16Email stating which datum to rectify
Erasure (“right to be forgotten”)Art. 17Email with session_id and/or trace_id: all related records deleted in ≤ 30 days
RestrictionArt. 18Email requesting pause while we review
PortabilityArt. 20Request a JSON copy of your data (ratings + comments)
ObjectionArt. 21Applicable to legitimate interest: explain the particular situation
No automated decisionsArt. 22Fluxia does not make automated decisions: a human is always in the loop
Withdraw consentArt. 7(3)Email fluxia.soporte@gmail.com: we delete the associated rating and comment

Complaints: if you believe processing breaches GDPR you can file a complaint with the Spanish Data Protection Agency (AEPD) or your country’s supervisory authority.

Technical security

Changes to this policy

If this policy changes materially (not cosmetically), we will announce it on the home page for 30 days before the change takes effect. Version history is kept in the internal trustworthy-AI dossier.

Current version: 2026-09-14.