109 days until EU AI Act enforcement

Privacy Policy

Last updated: April 2026

What We Collect

When you complete an EU AI Act assessment, we collect:

  • Your quiz answers (what your AI system does, your role, risk factors)
  • Your company name (if you choose to provide it)
  • Your email address (only if you choose to provide it)
  • Your IP address (for consent verification)
  • Timestamp of consent

We do not use cookies, session tracking, or third-party analytics trackers. Rate limiting is IP-based and no identifiers are stored for this purpose.

How We Use Your Data

  • To generate your risk classification and compliance report
  • To send you your personalized assessment results and PDF report by email (if you opted in)
  • Aggregate, anonymized statistics (total assessments, tier distribution)

By providing your email, you consent to: "I agree to receive my personalized compliance report and EU AI Act updates from agentguard-eu by email."

Data Storage

Your data is stored in a SQLite database on Railway infrastructure with a persistent volume. The database file is not application-level encrypted. Railway provides infrastructure-level security including network isolation and access controls.

Data Retention

Assessment data is retained until you request deletion. You may request deletion at any time by emailing contact@navario.tech.

Your Rights (GDPR)

Under the EU General Data Protection Regulation, you have the right to:

  • Access: Request a copy of the data we hold about you
  • Erasure: Request deletion of your personal data
  • Rectification: Request correction of inaccurate data
  • Portability: Request your data in a machine-readable format

To exercise any of these rights, email contact@navario.tech.

Deletion requests are fulfilled within 30 days. Personal data (email, company name, quiz answers, IP address) is permanently erased. An anonymized record (SHA-256 hashed email, deletion timestamp) is retained for audit trail purposes only.

Data Controller

Navario
Website: navario.tech
Contact: contact@navario.tech

Third-Party Services

We do not sell or share your personal data with third parties for their own purposes. The following service providers process data on our behalf to operate the assessment tool:

  • Railway — Application hosting and database infrastructure
  • Resend — Email delivery service (processes your email address and delivers your PDF report, only if you provide an email address)