Executive summary
Fluxia is designed to minimize personal-data collection by default. Access is by invitation, or by signing up through one of the demo promotions — we don’t build profiles or run ads, and the few operational data points we do store (session trace, optional thumb feedback) are justified by a documented need and have an explicit retention policy.
This page describes what we store, why, for how long, and how to exercise your rights under Regulation (EU) 2016/679 (GDPR).
Data controller
| Field | Value |
|---|---|
| Controller | Fluxia sole operator |
| GDPR contact | fluxia.soporte@gmail.com (response in ≤ 30 calendar days) |
| DPO | Not appointed (Art. 37 GDPR does not apply: no systematic large-scale processing) |
| Territorial scope | EU (Belgium, Ireland); no relevant international transfers, except the support contact email (Gmail, US) if you click “I want to talk to the Fluxia team” — see “Sub-processors” |
What data Fluxia collects
1. Query and response (ephemeral memory)
| Data | Purpose | Retention | Legal basis |
|---|---|---|---|
| Query text | Process the assistant’s response | Not persisted: only in RAM during the request | Legitimate interest (Art. 6(1)(f)) |
| Response text | Show it to the user and serve the active trace | Not persisted: only in RAM | Legitimate interest |
session_id UUID | Group related queries in the same session | Session cookie: expires when browser closes | Legitimate interest |
Queries and responses are not persisted in any product database. We do not retrain models on your prompts.
2. Observability trace
| Data | Purpose | Retention | Legal basis |
|---|---|---|---|
trace_id (UUID) | Post-incident forensics (AI Act Art. 73) | 90 days | Legal obligation (Art. 6(1)(c) + AI Act) |
| Per-node timings | Latency-regression detection | 90 days | Legitimate interest |
| Token usage | Environmental-footprint calculation (EcoMeter) | 90 days | Legitimate interest |
| Query text | Only if you enter it: the tracing system does not actively extract PII | 90 days | Legitimate interest + data minimization |
Warning: if you enter personal data (your name, ID number, address…) in the query, that data will sit in the observability trace for 90 days. Do not enter PII in queries. Fluxia doesn’t need it to answer about the hydrological plans. If you also click “I want to talk to the Fluxia team,” up to your 10 most recent queries are sent by email to the support inbox (see “Account data”).
3. Feedback (👍/👎 thumbs)
| Data | Purpose | Retention | Legal basis |
|---|---|---|---|
Rating (1 or -1) | Model improvement and continuous eval | Indefinite (anonymized after 1 year) | Consent (Art. 6(1)(a)), on thumb click |
| Free-text comment (optional) | Qualitative failure context | Indefinite (anonymized after 1 year) | Consent |
session_id + trace_id | Trace correlation | 90 days (then only rating remains) | Consent |
Feedback is strictly optional. If you don’t click the thumb, we don’t store anything related to your opinion. Consent is unambiguous (explicit click), informed (labeled button), and revocable (see “Your rights”).
4. Art. 73 incident reports
| Data | Purpose | Retention | Legal basis |
|---|---|---|---|
| Description + email (optional) | Investigation and authority notification | 5 years (AI Act legal obligation) | Legal obligation (Art. 6(1)(c)) |
Correlated trace_id | Forensics | 5 years | Legal obligation |
Art. 73 reports are handled under the incident procedure.
5. Data NOT collected
By contract and by design, Fluxia does not collect:
- IP addresses in plain text (not logged in the backend, not exposed to the frontend); demo-promotion signup does store an IP fingerprint — a salted hash; the IP itself is not stored — see “Account data”
- Tracking cookies (no Google Analytics, Hotjar, Meta Pixel…)
- Browser fingerprints (beyond the demo-signup IP fingerprint above)
- Geolocation
- Biometric data
- Information on sexual orientation, health, ideology, religion, union membership, minors’ data
6. Account data (access request, invitation, and demo signup)
| Data | Purpose | Retention | Legal basis |
|---|---|---|---|
| Email, full name (optional), organization (optional), reason (optional) — access request (app.fluxia-ia.com/register) | Let the team decide whether to grant access and contact the requester | Indefinite: no automatic deletion when the request is decided; deleted only on request (see “Your rights”) | Art. 6(1)(b) — steps prior to a contract, at the data subject’s request |
| Email of an account created by invitation | Identify the account and contact whoever uses it | For as long as the account exists | Art. 6(1)(b) |
| Internal note an admin may write when inviting (optional) | Let the team remember why that person was invited | For as long as the email stays on the access allow-list (not tied to the account’s lifecycle) | Art. 6(1)(b) |
| Email, name, organization (optional), profile, whatever you write in “What would you like to discuss with the Fluxia team?” (optional), an IP fingerprint (a salted hash; the IP itself is not stored), and the promotion you signed up through — demo promotion signup (app.fluxia-ia.com/demo or each promotion’s own address) | Create the demo account without email verification, apply its promotion’s query limit, limit how many signups happen from the same IP per day (anti-abuse), let the Fluxia team contact you if you ask, and know which promotion each signup came through | For as long as the account exists; deleting it erases your email, name, organization, whatever you wrote, and your IP fingerprint, and only an anonymous record of the signup remains (promotion, profile, and date), which counts toward the demo’s account limit | Art. 6(1)(b) — creating the account; Art. 6(1)(f) — limiting IP abuse |
| Email, name, organization, profile, whatever you wrote in “What would you like to discuss with the Fluxia team?”, and up to your 10 most recent queries — when you click “I want to talk to the Fluxia team” inside the demo account | Let the Fluxia team answer you | Sent as a single email to the support inbox (fluxia.soporte@gmail.com); the email is only deleted if you ask, and once sent it cannot be recalled. It also creates an access request with the same data, kept like the rest: deleted only on request | Art. 6(1)(b) — at your request |
None of this data is used to build profiles or for advertising. When an account (invited or demo) is deleted, your email, name, organization, and whatever you wrote are erased; for a demo account, only the anonymous record described above remains. You can also request deletion yourself through the same process as the rest of your rights (see “Your GDPR rights” below).
That deletion doesn’t reach everything: the email sent when you click “I want to talk to the Fluxia team” stays in the support inbox until its deletion is requested separately; the access request that same button creates is kept like the rest of access requests (not tied to any account, deleted only on request); the observability trace of your queries still lasts its 90 days (see “Observability trace” above); and the invitation’s internal note stays for as long as the email is on the access allow-list, because it isn’t tied to the account’s lifecycle.
Cookies and browser storage
Fluxia uses two browser-storage elements:
- Cookie
ia_water_session(strict, essential): session UUID, no advertising use. Expires on browser close. No consent required (technically-necessary cookie, Art. 22.2 of Spain’s LSSI, which transposes Art. 5(3) of the ePrivacy Directive 2002/58/EC). - Browser
localStorage: recent-response cache to speed up reformulations. Only in your browser, never sent to the server. You can clear it any time from your browser settings.
We do not use third-party or advertising cookies.
Sub-processors
Fluxia transmits minimal data to the following sub-processors. All but the support email (Gmail, last row) are based in the EU or covered by approved standard contractual clauses (SCCs):
| Function | Location | Data | DPA |
|---|---|---|---|
| Language model + embeddings provider | EU | Query text (ephemeral processing; not persisted) | Yes |
| Vector storage and database | EU | Hydrological-plan corpus embeddings (not user data); feedback ratings | Yes |
| Semantic reranking | Outside EU (with European Commission-approved SCCs 2021/914) | Query text + retrieved chunks (ephemeral, non-PII) | Yes |
| Static hosting | EU/US edge | Standard access logs (no PII) | Yes |
Support email (Gmail / Google, account fluxia.soporte@gmail.com) | Outside EU (US) | The contact email described in “Account data” (name, email, organization, profile, whatever you write, and up to your 10 most recent queries), only if you click “I want to talk to the Fluxia team” | No |
For sub-processors outside the EU covered by standard contractual clauses, applicable mitigations include European Commission-approved SCCs (2021/914) and a documented transfer impact assessment (TIA); their transmitted data does not identify anyone. The exception is Gmail: it’s a consumer account with no DPA (data processing agreement) and no SCCs signed with Google, and the email it receives does contain your personal data when you click “I want to talk to the Fluxia team”.
Your GDPR rights
As a data subject you have the following rights. Response time: 30 calendar days from verified-request receipt.
| Right | GDPR article | How to exercise |
|---|---|---|
| Access | Art. 15 | Email fluxia.soporte@gmail.com with your session_id (shown in the response footer) |
| Rectification | Art. 16 | Email stating which datum to rectify |
| Erasure (“right to be forgotten”) | Art. 17 | Email with session_id and/or trace_id: all related records deleted in ≤ 30 days |
| Restriction | Art. 18 | Email requesting pause while we review |
| Portability | Art. 20 | Request a JSON copy of your data (ratings + comments) |
| Objection | Art. 21 | Applicable to legitimate interest: explain the particular situation |
| No automated decisions | Art. 22 | Fluxia does not make automated decisions: a human is always in the loop |
| Withdraw consent | Art. 7(3) | Email fluxia.soporte@gmail.com: we delete the associated rating and comment |
Complaints: if you believe processing breaches GDPR you can file a complaint with the Spanish Data Protection Agency (AEPD) or your country’s supervisory authority.
Technical security
- In transit: TLS 1.3 on all public endpoints (HSTS preload)
- At rest: AES-256 across all storage layers
- Session isolation: each session can only read its own data
- Service authentication: periodic credential rotation; keys never in the repository
- Audit: traces with prompt SHA and model SHA per call
Changes to this policy
If this policy changes materially (not cosmetically), we will announce it on the home page for 30 days before the change takes effect. Version history is kept in the internal trustworthy-AI dossier.
Current version: 2026-09-14.