The short version
Core application data is hosted in Helsinki, Finland and private file storage is in AWS Stockholm. Aeglio-managed AI uses Mistral's EU regional endpoint; a team owner can instead connect the team's own supported provider. Aeglio does not sell customer data, and Chat with Aeglio remains permission-scoped and read-only.
Last updated: 14 September 2026
This policy explains how Aeglio OÜ collects, uses, stores and shares personal data through the Aeglio website and application. It also explains how Aeglio handles business data on behalf of customer organisations.
1. Who is responsible for the data?
Aeglio OÜ, registry code 16311541, registered in the Estonian Commercial Register, is the controller for personal data connected with website visits, account registration, subscriptions, support and Aeglio's own business operations. You can contact us at info@aeglio.com or through the contact page.
When a customer organisation uses Aeglio to manage its employees, clients, suppliers, projects, invoices, expenses, documents, approvals or banking records, that organisation normally decides why and how the personal data in those records is used. The customer organisation is the controller and Aeglio acts as its processor. If your data was added by an Aeglio customer, contact that organisation first. We will assist the organisation with an appropriate request.
2. Data we process
Depending on how Aeglio is used, we process:
- Account and team data: name, email address, password hash, profile photo, language, time zone, team membership, roles, permissions and authentication-provider identifiers.
- Business records: client and supplier contacts, projects, tasks, time entries, invoices, recurring invoices, expenses, reimbursement and travel reports, uploaded files, approval records, comments and related audit history.
- Banking and payment data: account identifiers, statement transactions, payment references, reconciliation decisions and payment status. Aeglio does not ask for online banking passwords.
- Integration data: identifiers, access tokens, configuration and records exchanged with a service that an authorised user connects to Aeglio.
- Subscription data: plan, billing contact, Paddle customer and subscription identifiers, invoices and payment status. Paddle handles payment-card details; Aeglio does not store full card numbers.
- Technical and security data: IP address, browser and device details, request logs, session data, authentication events and error information.
- Website and communication data: public-page interactions, analytics identifiers where analytics is enabled, contact-form messages, support correspondence and newsletter status.
Please avoid uploading special-category personal data or other unusually sensitive information unless it is necessary for your business process and your organisation has a lawful basis to use it.
3. Why we process data
| Purpose | Typical legal basis when Aeglio is the controller |
|---|---|
| Create accounts, authenticate users and provide the service | Performance of a contract or steps requested before entering one |
| Operate projects, invoices, expenses, approvals, banking and connected integrations | Performance of a contract; for customer content, the customer's documented instructions |
| Bill for the service and keep required transaction records | Performance of a contract and legal obligations |
| Secure the service, prevent abuse, troubleshoot and preserve audit history | Legitimate interests in operating a safe and reliable service and, where applicable, legal obligations |
| Respond to support and contact requests | Performance of a contract, steps requested by you or legitimate interests in responding |
| Understand and improve the public website | Consent where required; otherwise legitimate interests where permitted by law |
| Send a requested newsletter or marketing communication | Consent, which can be withdrawn at any time |
Aeglio does not sell personal data and does not use customer financial records for third-party advertising.
4. AI-assisted features
Aeglio uses a configured AI provider for supported document extraction and Chat with Aeglio. Aeglio-managed processing uses Mistral through its dedicated EU regional inference endpoint. Mistral states that regional inference keeps processed data within data centres in EU and EFTA countries. An authorised team owner may instead connect the team's own Mistral, OpenAI or Anthropic account, or another OpenAI-compatible provider that Aeglio has centrally approved and described. The team settings show the provider and configured processing region before that connection is used.
For document extraction, a request may include document text, an image of the document, email subject or body text, and limited matching context such as supplier names, expense categories and tax rates.
The output is a suggestion for fields such as supplier, document number, dates, totals, currency, tax or category. Aeglio users can review and correct it. AI extraction does not approve an expense, initiate a bank payment, post an accounting entry or make a decision that has legal or similarly significant effects on a person.
For Chat with Aeglio, a request can include the user's question, recent conversation context, a compact continuity summary, and permitted excerpts or calculated results from relevant Aeglio records. Aeglio does not give the model direct database access. It executes only registered read-only tools, applies team scope and the current user's record permissions to every result, and excludes credentials, private profile data, raw banking payloads and integration secrets from tool output. Chat with Aeglio cannot create, change, approve, send, pay or delete records.
Aeglio stores chat messages, linked source references, provider and model metadata, and reported token usage in its main database. New activity extends the configured conversation-retention period, which is 90 days by default. A user can permanently delete their own conversation sooner. Conversation content is not added to the semantic search index. To support authorized retrieval, Aeglio stores derived record text and mathematical embedding vectors on Aeglio-controlled infrastructure, separated and filtered by team. Every retrieved record is authorized again before its content enters an AI request.
Mistral states that most API inputs and outputs may be retained for abuse monitoring for 30 rolling days unless zero-data-retention is active. Its training and retention controls depend on the customer's plan and configuration. See Mistral's regional inference documentation, privacy policy and zero-data-retention information.
If a team selects OpenAI, OpenAI states that API inputs and outputs are not used to train its models by default. Under OpenAI's standard API data controls, API content may be retained for abuse monitoring for up to 30 days unless a different approved retention control applies or longer retention is legally required. See OpenAI's enterprise privacy information and API data controls.
If a team selects Anthropic, Anthropic states that commercial API inputs and outputs are not used to train its models unless the customer opts in and are normally deleted from its backend within 30 days, subject to agreed controls, usage-policy enforcement and legal requirements. Claude Fable 5 specifically requires 30-day provider retention and is not available under zero-data-retention agreements. Anthropic states that processing may occur in several regions and storage is in the United States unless otherwise agreed. See Anthropic's commercial data-retention information, model-specific retention requirements and location information.
When a team uses its own provider credentials, that team controls the provider account, agreement, selected model and provider-side privacy settings. The provider's own terms, retention settings and data location then apply. Removing the credentials stops new requests through that account. Aeglio encrypts the credentials at rest and does not show a saved key again. AI usage records do not contain prompt or response content, although Chat with Aeglio stores the conversation separately as described above.
AI output can be incomplete or wrong. The customer organisation remains responsible for reviewing extracted data, following linked source records and deciding whether an answer is suitable for a business decision.
5. Where core Aeglio data is stored
- The main Aeglio application and database run on Hetzner infrastructure in Helsinki, Finland.
- Uploaded business files and database backups are stored in private Amazon Web Services storage in the Europe (Stockholm) region, identified by AWS as eu-north-1 in Sweden.
- Temporary upload and processing copies are removed after the relevant workflow or by automated cleanup. Livewire temporary uploads are configured for cleanup after 24 hours.
These locations describe Aeglio's core infrastructure. A connected integration or specialist provider may process limited data in another location as described below.
6. Processors, service providers and other recipients
We use only the data each provider needs for its role. The current core providers are:
| Provider | Role and data involved | Primary location or transfer note |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting, including daily full-server backups retained for 7 days | Helsinki, Finland |
| Amazon Web Services EMEA SARL | Private file storage, database backups, transactional email and inbound document processing | Europe (Stockholm), Sweden for Aeglio storage; provider support may involve other locations |
| Mistral AI | Aeglio-managed AI-assisted extraction and chat, plus the same features through a customer-configured Mistral account | Aeglio uses Mistral's EU regional endpoint; processed inference data remains within EU/EFTA data centres |
| OpenAI | AI-assisted extraction and chat when a team connects its own OpenAI account | The team's OpenAI project, region, agreement and retention controls apply; processing may otherwise involve the United States or other locations covered by OpenAI's safeguards |
| Anthropic | AI-assisted extraction and chat when a team connects its own Anthropic account | The team's Anthropic agreement and routing choice apply; Anthropic states that default processing is global and storage is in the United States |
| Customer-selected AI provider | AI-assisted extraction and chat through an Aeglio-approved OpenAI-compatible endpoint | The provider, processing region, agreement and retention settings shown for the configured connection apply |
| Laravel Nightwatch | Production error reporting and sampled application telemetry, limited to pseudonymous and application-redacted diagnostic data | Nightwatch's EU data region is selected for Aeglio; its service retention and access controls apply |
| Google Analytics | Aggregated traffic measurement on public pages and completed-registration conversion measurement when configured | Google may process data in the EEA and other countries |
| Hotjar Ltd | Public-page heatmaps and interaction analysis when configured; authenticated financial application pages are excluded from Hotjar | Hotjar stores collected site data in Ireland and uses listed subprocessors |
| Mailgun Technologies, Inc. | Newsletter subscriptions and email delivery where enabled | Provider infrastructure may involve the United States and other locations |
Paddle acts as Aeglio's merchant of record for paid subscriptions and processes buyer and payment data under its own privacy notice. Paddle is not given access to customer projects, documents or banking records.
An authorised customer user can direct Aeglio to exchange data with optional services, including LHV Connect, Billberry, Google Drive, Microsoft OneDrive and Dropbox. The exact data depends on the integration. It can include bank statements, payment instructions, e-invoices, files, account identifiers and OAuth tokens. The connected provider's own terms and privacy notice also apply. Disconnecting an integration stops new exchanges but does not automatically delete records already imported into Aeglio or retained by the provider.
Users may also choose Google, GitHub or LinkedIn for sign-in. In that case, the provider sends Aeglio the account information needed to identify the user, and the provider learns that the user signed in to Aeglio.
We may disclose data when required by law, to protect the service or its users, or as part of a corporate transaction subject to appropriate confidentiality and data-protection safeguards.
7. International transfers
Aeglio's primary hosting and storage described above are in the European Economic Area. Some providers or customer-selected integrations may process data outside the EEA. Where an adequacy decision does not apply, Aeglio relies on an appropriate transfer mechanism made available under the provider agreement, such as the European Commission's Standard Contractual Clauses, together with additional safeguards where required.
8. Cookies and public-site analytics
Aeglio uses necessary cookies and similar storage for sessions, security, authentication, language and other requested functionality. Blocking these may prevent parts of the application from working.
When configured, Google Analytics measures public-page visits, approximate location, device and browser information, traffic sources and selected conversion events. After a successful account registration, a one-time completion page sends a registration conversion and the registration method to Google Analytics when analytics consent is active. It does not send an authenticated user ID or financial application data. Hotjar helps us understand how public pages are used through de-identified interaction data and heatmaps; it is disabled on the registration completion page and in authenticated financial application layouts. Aeglio does not intentionally send invoice, expense, document or banking content to either analytics service.
Necessary cookies are always active because they keep the service secure and working. Before Aeglio loads optional analytics, we ask for your explicit choice. You can accept or reject analytics cookies and change or withdraw that choice at any time through the Cookie settings link on public pages. Your choice applies to Google Analytics and Hotjar together; declining does not affect access to the public website. We retain a minimal pseudonymous record of each choice, the policy version and the time of the decision to demonstrate consent without storing browsing activity or an IP address.
9. Retention and deletion
Customer content is normally kept while the customer account is active so that the customer can use the service and maintain its business history. Individual records and files are deleted when an authorised user uses an available deletion function, subject to dependencies, audit integrity and legal restrictions.
When an account or customer workspace is deleted, Aeglio removes the associated data from active systems once it is no longer needed for service delivery, legal obligations, fraud prevention or legal claims. Billing records may be retained for the period required by accounting and tax law. Newsletter data is kept until unsubscribe or deletion. Provider-held data follows the provider's retention rules as well as Aeglio's configured controls.
Aeglio uses two daily backup layers for disaster recovery. Hetzner creates a full-server backup at 19:00 and retains the latest 7 days. Separately, Aeglio creates a password-encrypted database backup at 00:00 in private AWS storage. The database-backup rotation keeps all backups for 7 days, daily backups for 16 days, weekly backups for 8 weeks, monthly backups for 4 months and yearly backups for up to 2 years. As a result, deleted data may remain in restricted backup copies until the relevant backup ages out. Backups are not used as an active archive and are not restored to recover an individually deleted record. If a backup must be restored after an incident, deletion requirements are reapplied where technically feasible.
Security and operational logs are retained only for as long as reasonably needed to protect, troubleshoot and operate the service. Production error reports and sampled application telemetry may also be processed in Laravel Nightwatch's selected EU data region. Aeglio removes request payloads, headers, client IP addresses, concrete route parameters, outgoing URL paths and query strings, command arguments and mail subjects before sending Nightwatch telemetry, pseudonymises user identifiers, and keeps its free-plan spending cap at zero. Aeglio may retain a minimal record of a deletion request and its completion when needed to demonstrate compliance.
To request deletion of an account or other personal data, email info@aeglio.com. We may need to verify your identity and authority. If your data belongs to a customer organisation's workspace, the organisation may need to authorise the request.
10. Security
Aeglio uses HTTPS in transit, password hashing, team-scoped access, role and permission checks, two-factor authentication, short-lived file links, encrypted integration credentials, audit histories and daily database backups. Access is limited to people and providers who need it to operate or support the service. No online service can guarantee absolute security.
If you believe data in Aeglio has been accessed or disclosed improperly, contact info@aeglio.com promptly.
11. Your rights
Subject to the GDPR and other applicable law, you may have the right to:
- receive information about how your personal data is used;
- access and receive a copy of your personal data;
- correct inaccurate or incomplete data;
- request erasure or restriction of processing;
- receive portable data in a machine-readable format where applicable;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent without affecting earlier lawful processing; and
- lodge a complaint with a supervisory authority.
Send a request to info@aeglio.com. We may ask for information needed to verify identity and prevent unauthorised disclosure. We normally respond within one month, subject to extensions and exceptions permitted by law.
You may also complain to the Estonian Data Protection Inspectorate or the data-protection authority in the country where you live or work.
12. Children
Aeglio is a business service and is not directed to children. We do not knowingly create accounts for children who cannot lawfully enter the relevant agreement or provide required consent.
13. Changes to this policy
We may update this policy when the product, providers or law changes. The date at the top identifies the latest version. If a change materially affects how existing customer data is used, we will provide an appropriate notice before the change takes effect where required.
14. Contact
For privacy questions, requests or concerns, contact:
Aeglio OÜ, registry code 16311541, Estonian Commercial Register
Email: info@aeglio.com
Web: Contact form