Privacy

Privacy notice

Last updated 20 August 2026

This notice covers routerlabs.ai, the website. It does not cover the Router Labs service itself. Processing under a customer engagement is governed by the data processing agreement signed with that customer, not by this page.

01Who is responsible

The controller for this website is Router Labs, currently being incorporated in the Republic of Cyprus. Registered company name, number and address will be stated here once incorporation completes: ENTITY NAME, HE NUMBER, REGISTERED ADDRESS. ADD ON INCORPORATION. Until then, contact CONTACT EMAIL.

Cyprus is an EU member state, so this processing sits inside the EEA and the GDPR applies directly. The supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

Data protection officer: NAME AND CONTACT, or "not appointed, see below". Under Art. 37 GDPR and § 38 BDSG a DPO is mandatory in some circumstances, including where core activities involve regular and systematic monitoring or large-scale processing of special categories. Confirm with counsel whether that applies to you.

02What this site collects

Two things, and nothing else.

DataWhenWhy
Work email, organisation, sector, seat band, and your answer about the AI you run today Only when you submit the access form To evaluate the request and reply to it
Your browser's user-agent string and the time of submission With that same submission Abuse control and support
Connection metadata, including IP address, held by our hosting provider Every request, as with any web server Delivering the site, security, denial-of-service protection

Your IP address is not stored alongside your form submission.

03What this site does not do

The site stores two preferences, your colour theme and your language, in your browser's localStorage. That never leaves your device and is never read by us. It is a strictly necessary convenience under § 25(2) TTDSG rather than something requiring consent, but it is disclosed here because it is technically storage on your terminal equipment.

04Legal basis

For the access form: Art. 6(1)(b) GDPR, steps taken at your request prior to entering a contract. If you are enquiring purely out of interest rather than to procure, the basis is Art. 6(1)(f), our legitimate interest in answering people who contact us.

For server logs: Art. 6(1)(f), our legitimate interest in operating a secure website.

05Where it is processed

ProcessorPurposeLocation
SupabaseStores access-request submissionseu-central-1, Frankfurt, Germany
CloudflareHosting, DNS and edge deliveryGlobal edge network; company incorporated in the United States

Because Cloudflare is a US company, transfers outside the EEA can occur in the course of delivering the site. Those are addressed by STANDARD CONTRACTUAL CLAUSES AND/OR EU–US DATA PRIVACY FRAMEWORK. CONFIRM CURRENT BASIS. Your form submission itself is written to a database located in Germany.

06How long it is kept

Access requests are kept for RETENTION PERIOD, e.g. 24 months from the last contact, then deleted. If we enter a commercial relationship, the record moves under that contract's retention terms. Server logs are retained by our hosting provider under its own schedule.

07Your rights

You may request access to your data, correction of it, erasure, restriction of processing, and portability, and you may object to processing based on legitimate interest. Write to CONTACT ADDRESS and we will respond within one month.

You may also complain to a supervisory authority. For us that is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or the authority where you live or work.

08Changes

If this notice changes materially, the date at the top changes with it. We do not alter it quietly.