AIRON is a data processing service provider within the meaning of Chapter VI of Regulation (EU) 2023/2854 (the Data Act). This page is the public register of exportable data required by Arts. 26 and 30, and it applies to contracts already in force as well as to new ones. The corresponding contractual clauses are in clause 12 of the data processing agreement.
1. What is exported, and in which format
| Category | Content | Format |
|---|---|---|
| Chat conversations | Conversations, messages, folders and ratings | JSON |
| Approvals and drafts | Proposed actions, reply drafts, human decisions and the outbound queue | JSON |
| CRM contacts and companies | Company and person records, relationships and notes | CSV and JSON |
| Entities and facts | Resolved entities, identities, relationships and attributed facts | JSON |
| Invoices and invoice ledger | Headers, line items, statuses and the original attached PDFs | CSV and JSON, plus the PDFs |
| Objectives and signals | Objectives, milestones, signals, findings and baselines | JSON |
| Automated flows | The full definition of each flow | YAML and JSON |
| Web Studio sites | Published sites and their content data | HTML in a ZIP, or the customer’s own repository |
| Uploaded documents | The original files exactly as uploaded, with their path and metadata | Original format plus a JSON index |
| Memory and lessons | Memories, user and customer profiles, style profile and account lessons | JSON |
| Connector configuration | Provider, connected account, granted scopes, dates and status — metadata only | JSON |
| Users and permissions | Portal users, roles and permissions per agent and per connector | JSON |
| Audit log | Trail of actions and access within the customer workspace | JSON |
| Usage and consumption | Billable usage record for the account | CSV |
The export is delivered as an encrypted ZIP with a manifest listing every file, its row count and its checksum, plus a readable document explaining formats and restrictions. If a table, collection or attachment cannot be exported, the manifest records it as an error: there are no silently incomplete exports.
2. What is NOT exported, and why
- Connector tokens, keys and secrets. For security we export connection metadata, never credentials: at the destination the customer reconnects each service.
- Embeddings. These are derived data, dependent on the specific model that produced them; outside AIRON they are neither portable nor interpretable. The original content they derive from is exported (documents, memories).
- Other customers’ data. Tenant isolation.
- AIRON’s models, prompts, routing heuristics and code. Trade secret.
- Anonymised global lessons. These are aggregated distillations not attributable to a customer; the provenance originating from the account is exported.
- Backups. These are not an export channel: they follow their own 30-day life cycle.
3. Known restrictions (Art. 26)
- AIRON is SaaS, not IaaS: functional equivalence at the destination is not guaranteed. The applicable obligation is to export data and digital assets, not to reproduce the service.
- Automated flows depend on AIRON’s action specification: they are exported as a readable definition, but they are not executable elsewhere without translation.
- Memory and lessons are exported as structured text; their effect on agent behaviour is not reproducible outside AIRON.
- Reconnecting connectors requires the customer to authorise each third-party service again.
- The infrastructure sits in Frankfurt (Germany, EU); sub-processors and transfers are listed in the sub-processor list.
4. Procedure and deadlines
| Step | Deadline |
|---|---|
| Request, identifying the requester and verifying that they administer the workspace | — |
| Acknowledgement and confirmation of scope, format and destination | 5 working days |
| Delivery of the export, as an encrypted ZIP via a temporary link | 30 calendar days from the request |
| Customer’s notice of termination | A maximum of 2 months |
| Transition period, with the service operational for consultation and export | 30 calendar days, extendable once with written justification |
| Recovery window: data remains retained and exportable | 30 calendar days |
| Definitive deletion across the database, the vector store and the cache | When the window closes; in backups, up to 30 days more |
| Certificate of deletion | 5 working days after deletion |
Where we stand today, plainly: the export is currently produced with assistance from our team, within the deadlines stated above. Self-service export from the panel is under development; until then the request goes to info@airon.team or privacidad@airon.team. Every delivered export leaves a trace in the account’s audit log.
5. Fees
AIRON charges no fee for switching providers or for exporting data. Art. 29 of the Data Act would allow us to pass on the actual costs until 11 January 2027 and prohibits any fee from 12 January 2027: we waive them from the outset, so customers need not wait for that date.
6. Third-country authority access (Art. 32)
AIRON will act on a request from a non-EU authority only where an applicable international agreement or a valid legal basis exists. Otherwise it objects and, where permitted, informs the customer before handing over any data. The same obligation is passed on to sub-processors.
Context on personal data is in the platform privacy policy.