European by design
Spinrun is operated by BirdAI S.R.L., a company in București, Romania, under the GDPR and the supervision of ANSPDCP. The documents below are what a buyer's due diligence will ask for, written so that each claim can be checked against the product.
Terms & commercial
What you are agreeing to, who you are contracting with, and how either side can end it.
Privacy & data protection
GDPR roles, what is collected and for how long, and every company that touches your data.
Privacy Policy
What is collected, why, how long it is kept, and the rights you have over it.
Read →Data Processing Agreement
The Article 28 terms under which we process personal data on your behalf. Incorporates the SCCs by reference.
Read →Subprocessors
Every provider that processes data for us, what each one does, where it runs, and how we announce changes.
Read →Cookie Policy
Every cookie the site can set, one by one, and which of them wait for your consent.
Read →Security
Where data is held, how tenants are isolated, and what is enforced at the gateway rather than in a prompt.
AI governance
Which models are used, what they may do with your data, and how the EU AI Act applies to you and to us.
Built in Europe, to European standards
- GDPR
A Romanian company under the GDPR and ANSPDCP, with a DPA that binds on acceptance and a countersigned copy on request.
- EU AI Act aligned
Human oversight at the gateway, transparency duties named, no conformity claim we cannot back.
- Core data hosted in Frankfurt, EU
Database, authentication and application functions run in Frankfurt. What is not region-pinned, we say so.
- No training on your data
Neither we nor the model providers we route through may train on your content.
- SCCs for non-EEA transfers
Standard Contractual Clauses, with encryption and access control behind them, wherever data leaves the EEA.
Questions, a countersigned DPA, or the transfer safeguards for a particular provider: legal@spinrun.ai