Privacy Policy

Last updated: May 2026

This policy explains how Airmodus Ltd ("Airmodus", "we") processes personal data on the Airmodus website (airmodus.com) and the Airmodus dashboard (dashboard.airmodus.com), in line with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.

1. Data controller

Airmodus Ltd
Erik Palmenin aukio 1, FI-00560 Helsinki, Finland
Privacy contact: info.aerosols@envea.global

2. What we collect and why

2.1 Marketing site (airmodus.com)

2.2 Dashboard (dashboard.airmodus.com)

2.3 Embedded chat widget (on airmodus.com)

2.4 Email and Signal/Matrix support channels

3. Cookies and similar technologies

The dashboard uses one strictly necessary cookie, access_token, to keep you signed in. It is HTTP-only, Secure (in production), SameSite=Lax. The OAuth flow may set a short-lived consent cookie. The marketing site and the embedded chat widget set no cookies. We do not use analytics cookies, advertising cookies, or third-party trackers.

4. Recipients and processors

We share personal data only with the processors we need to operate the service. All act on our instructions under a data-processing agreement (Art. 28 GDPR).

We do not sell or rent personal data and we do not transfer it to other recipients for their own purposes.

5. International transfers

Where a processor is established outside the EEA (currently Tinfoil, Cloudflare, Google), the transfer is covered by the European Commission's Standard Contractual Clauses, supplemented by the technical safeguards described above (TLS in transit, confidential-compute enclaves for assistant content).

6. Retention

7. Your rights

Under GDPR Articles 15-22 you have the right to:

To exercise any of these rights, email info.aerosols@envea.global. We respond within 30 days.

8. Automated decision-making

The assistant uses a large language model to answer your questions. It does not make decisions that have legal or similarly significant effects on you. Any change it proposes to your data (knowledge base edits, instrument commands) requires explicit human approval before it is applied.

9. Security

Passwords are stored as bcrypt hashes. Session cookies are HTTP-only and transmitted over HTTPS. Production traffic is terminated by our edge proxy with modern TLS. Database backups are encrypted at rest. We follow the principle of least privilege for staff access and review privileged access on a regular basis.

10. Complaints

If you believe we have processed your data unlawfully, you may lodge a complaint with the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutettu): tietosuoja.fi. You may also contact the supervisory authority in your country of residence.

11. Changes to this policy

If we change how we process personal data we will update this page and adjust the "Last updated" date at the top. Material changes affecting registered users will additionally be notified by email.