PRIVACY POLICY & DATA PROTECTION NOTICE

Brand / Trade Name: Human Oversight Laboratories

Effective Date: 30th of July 2026

Version: 1.0 (v1.0 MVP Pre-Incorporation Beta)

1. Scope & General Information

This Privacy Policy (“Policy”) explains how Human Oversight Laboratories (“we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal data obtained from individuals (“you” or “Data Subject”) who interact with our online services.

1.1 Material Scope

This Policy applies strictly to processing operations carried out through:

  • Our official website located at art50compliance.eu (including any subdomains);
  • Our early-access waitlist registration and pilot onboarding forms;
  • Communication channels used for user support and beta feedback; and
  • Version 1.0 of our software utility, specifically the manual attestation form tool and digital audit receipt generator known as “Art50” (collectively, the “Services”).

1.2 Statutory Compliance

We process all personal data in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation or “GDPR”);
  • Directive 2002/58/EC of the European Parliament and of the Council (ePrivacy Directive); and
  • Applicable national data protection laws of the Member States of the European Union.

1.3 Target Audience

By accessing our website, registering for our waitlist, or using our v1.0 MVP tools, you acknowledge that your personal data will be handled in accordance with this Policy. This Policy does not apply to third-party websites, applications, or services that may be linked from our platform.

2. Identity & Contact Details of Joint Data Controllers

2.1 Joint Data Controllership (Pre-Incorporation Phase)

Prior to formal corporate registration in Estonia, the Services are operated jointly by:

  • Mr. Viktor Arato, residing in Hungary; and
  • Mr. Marco Garzia, residing in Italy.

Pursuant to Article 26 of the GDPR, the co-founders act as Joint Data Controllers. They have entered into an internal Joint Controllership Agreement establishing their respective tasks and obligations regarding compliance with data protection laws.

2.2 Essence of the Joint Controller Arrangement (Art. 26(2) GDPR)

In accordance with Article 26(2) of the GDPR, the key responsibilities under our Joint Controllership arrangement are allocated as follows:

  • Data Subject Rights & Support: Marco Garzia acts as the designated primary point of contact for handling privacy inquiries, access requests, and communications with Data Subjects.
  • Technical Security & Infrastructure: Viktor Arato is primarily responsible for server administration, database security, and technical access controls.
  • Joint Responsibility: Both co-founders remain jointly responsible for ensuring the overall lawfulness of processing operations and policy updates.

2.3 Centralized Contact Point & Service Address

Regardless of the internal division of responsibilities, Data Subjects may exercise their rights or contact us directly regarding data protection matters using our centralized contact information:

  • Data Protection Email: contact@art50compliance.eu
  • Geographic Service Address for Legal Notices:

    Human Oversight Laboratories

    c/o Riviera Zanardelli 21

    00042, Anzio, Italy

2.4 Future Entity Assignment Clause

Upon formal corporate registration in Estonia, all Data Controller responsibilities, server databases, and processing operations governed by this Policy shall automatically transfer to Human Oversight Laboratories OÜ (Tallinn, Estonia). An updated revision of this Policy will reflect the corporate registration number and registered office details.

3. Categories of Personal Data Processed (v1 Scope & Beta Evolution)

We collect and process personal data strictly in accordance with the principle of Data Minimization (Art. 5(1)(c) GDPR). For version 1.0 of our platform, processing is limited to the specific data categories outlined below.

3.1 Personal Data Categories

a) Server Access & Technical Data:
When visiting our website, your web browser automatically transmits technical metadata to our web server. This includes your IP address, browser type and version, operating system, date and time of request, referring URL, and HTTP status code.

b) Waitlist & Contact Data:
When registering for early access or reaching out via our contact forms, we collect your full name, email address, job title/role, company or agency name, and any optional text submitted in your inquiry.

c) Account & Authentication Data:
To create a pilot account or access our v1.0 tools, we collect your email address, encrypted (hashed) password, and session tokens necessary to keep you securely logged in.

d) User-Submitted Attestation Data (v1 Core Functionality):
Our v1.0 software utility relies entirely on manual attestation form submissions. When generating an AI oversight receipt or audit log, we collect and process the user-entered fields and metadata listed below:

  • User & Organization Identifiers:
    • Reviewer’s full name;
    • Reviewer’s corporate or individual email address;
    • Reviewer’s role or job title; and
    • Company, organizational unit, or individual entity name.
  • Asset & Source Metadata:
    • Asset Title or identifier (“What’s this called?”);
    • Content Type (e.g., text, audio, image, multi-modal);
    • Generation Source (whether the content is AI-generated, human-made, or hybrid);
    • AI Model/Tool Identifier (e.g., the specific AI system that generated the content); and
    • External links or URLs pointing to the published content.
  • Content & File Artifacts:
    • The raw text, body content, or excerpts submitted for review;
    • Uploaded file attachments (e.g., documents, media files, or reference materials); and
    • Mentions of real individuals (flags indicating whether the content references living persons).
  • Oversight, Review & Risk Metrics:
    • Level of review (“How closely it was checked,” e.g., reviewed entirely, reviewed partially, spot-checked);
    • Risk classification (flags indicating whether the content is classified as “risky” or high-impact); and
    • Editorial modifications (notes detailing what was changed, edited, or flagged during review).
  • Audit & Cryptographic Receipts:
    • Verification Timestamps (user-declared date and time of when the content was checked);
    • System-generated creation timestamps; and
    • Cryptographic receipt hashes (e.g., SHA-256) proving the integrity of the submission log.

3.2 Beta Platform Evolution & Modifications

As Human Oversight Laboratories is actively developing and refining its services during the Beta Phase, future platform updates may require processing additional categories of data. In accordance with GDPR transparency obligations (Art. 13/14), we will not collect new categories of personal data without prior notice. Any expansion of data collection will be accompanied by an updated Privacy Policy and direct notification to registered users or an explicit opt-in mechanism before such processing begins.

3.3 Explicit Exclusions (Data Minimization Statement)

To maintain complete transparency regarding our v1.0 software architecture, we explicitly confirm that our current Services do not collect or process:

  • Automated background browser or desktop activity;
  • Cursor movement, mouse tracking, or keystroke dynamics;
  • Background document reading or automated character-diff scanning; or
  • Special categories of personal data pursuant to Article 9 of the GDPR (e.g., health, biometrics, or political opinions).

3.4 Statutory and Contractual Obligation to Provide Data (Art. 13(2)(e) GDPR)

The provision of your personal data is neither a statutory nor a regulatory requirement. However:

  • Providing your name and email address is a contractual requirement to create an account, access the v1.0 software utility, or join our waitlist.
  • Failure to provide this mandatory data will make it impossible for us to grant account access or generate attestation receipts.

4. Purposes & Legal Bases for Processing

Under Article 6 of the GDPR, every processing operation involving personal data must rely on a defined legal ground. The table below details why we process your personal data and the specific legal basis supporting each processing activity.

Processing Activity & Purpose Categories of Data Used Legal Basis under GDPR
1. Operating and Securing the Website
Ensuring web server functionality, preventing brute-force attacks, detecting security breaches, and maintaining platform uptime.
Server Access & Technical Data (IP addresses, system logs) Legitimate Interests (Art. 6(1)(f) GDPR)
Our legitimate interest lies in guaranteeing the technical security, integrity, and operational stability of our website.
2. Managing Waitlist & Early Access Communications
Registering waitlist requests, issuing beta access keys, and sending technical product updates regarding the v1.0 release.
Waitlist & Contact Data (Name, email, role) Consent (Art. 6(1)(a) GDPR) or Pre-contractual Steps (Art. 6(1)(b) GDPR)
Processing is based on your explicit request to join the waitlist and take steps prior to entering into a beta user agreement.
3. Account Management & Service Delivery
Creating user accounts, authenticating logins, delivering the manual attestation form tool, processing uploaded text/file artifacts, and generating digital audit receipts.
Account & Authentication Data, User-Submitted Attestation Data (including file attachments, raw text, and review metrics) Performance of a Contract (Art. 6(1)(b) GDPR)
Processing is necessary to perform our contractual obligations to you under our Beta Terms of Service.
4. Maintenance of Compliance Logs & Audit Defense
Providing users and enterprise clients with tamper-evident records to document and catalogue human oversight under EU AI Act framework (Article 50).
User-Submitted Attestation Data, Generated Receipt Hashes, User & Organization Identifiers Legitimate Interests (Art. 6(1)(f) GDPR)
Our and our users’ legitimate interest lies in maintaining verifiable, unalterable proof of human review for audit and compliance defense purposes.
5. File Attachment Security & Threat Prevention
Conducting automated virus, malware, and MIME-type validation scans on user-uploaded file attachments to prevent security compromises.
Uploaded File Attachments, Asset & Source Metadata Legitimate Interests (Art. 6(1)(f) GDPR) & Security Obligation (Art. 32 GDPR)
Our legitimate interest and legal duty lies in ensuring infrastructure resilience and protecting platform users from malicious file uploads.
6. Compliance with Statutory Obligations
Fulfilling lawful disclosure orders, court summonses, or statutory record-keeping duties under national laws.
All relevant data categories Legal Obligation (Art. 6(1)(c) GDPR)
Processing is necessary to comply with legal duties to which the Joint Controllers are subject under EU or national law.
7. Product Improvement & Aggregated Risk Analytics
Analyzing anonymized system usage (e.g., AI model types used, content risk classifications) to optimize software functionality and publish aggregated industry benchmarks.
Anonymized Asset Metadata, AI Model Identifiers, Risk Metrics (stripped of personal identifiers) Legitimate Interests (Art. 6(1)(f) GDPR)
Our legitimate interest lies in optimizing platform features and advancing research in human oversight standards under the EU AI Act.

5. Cookies & Local Storage Disclosures

In accordance with Directive 2002/58/EC (ePrivacy Directive) and applicable national implementations, this section explains how we store and access technical information on your terminal device.

5.1 Technical Necessity & Purpose

We use strictly necessary first-party cookies and local storage tokens (localStorage / sessionStorage) solely for essential technical functions required to deliver our Services:

  • Session Authentication: Secure tokens to keep you logged into your user account during your session.
  • Security & Anti-Forgery: Tokens designed to prevent Cross-Site Request Forgery (CSRF) attacks and ensure form submission integrity.
  • UI State Management: Session variables used to maintain the active state of manual attestation forms during data entry.

5.2 Third-Party Tracking & Analytics Exclusion

We operate under a strict privacy-first architecture:

  • We do not use non-essential marketing, targeting, or profiling cookies.
  • We do not integrate third-party cross-site tracking scripts, advertising pixels (e.g., Meta Pixel, LinkedIn Insight Tag), or intrusive user session replay tools (e.g., Hotjar).
  • We do not share browsing behavior or session metadata with third-party advertising networks.

5.3 Exemption from Cookie Consent Banners

Under Article 5(3) of the ePrivacy Directive, technical storage or access that is strictly necessary to provide an Information Society service explicitly requested by the user is exempt from the requirement of prior user consent. Because our website and v1.0 tools utilize strictly necessary storage only, no consent-management cookie banner is rendered on our platform.

5.4 Browser Cookie Controls

Although our cookies are strictly necessary for platform operation, you can configure your web browser settings to block or delete cookies at any time. Please note that disabling essential session cookies will prevent you from logging into your account or utilizing the v1.0 attestation receipt generator.

6. Technical Security & Organizational Measures

Pursuant to Article 32 of the GDPR, we implement appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk of processing personal data. These controls protect your data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

6.1 Technical Safeguards

  • Encryption in Transit: All traffic between your web browser and our servers is enforced via strict HTTPS utilizing Transport Layer Security (TLS 1.3) encryption protocols.
  • Encryption at Rest: User credentials, session metadata, and attestation form records stored within our production databases are encrypted at rest using industry-standard AES-256 encryption algorithms.
  • Secure Authentication: User account passwords are never stored in plaintext. We utilize strong, salted cryptographic hashing functions (such as bcrypt or Argon2) to prevent credential exposure.
  • Integrity & Cryptographic Hashing: Generated attestation receipts are processed using cryptographic hash functions (e.g., SHA-256) to produce tamper-evident hashes, ensuring records cannot be silently altered after creation.

6.2 Organizational Safeguards & Hosting Infrastructure

  • EU-Based Infrastructure: All primary database servers, web application servers, and automated backup stores are hosted exclusively within ISO/IEC 27001-certified data centers located inside the European Economic Area (EEA).
  • Strict Access Control: Administrative access to production databases and server infrastructure is restricted strictly to the two co-founders operating on the principle of least privilege, guarded by mandatory Multi-Factor Authentication (MFA).
  • Vulnerability Management: Server software and application dependencies are routinely updated and patched to mitigate known software vulnerabilities.

7. Data Retention & Erasure Criteria

In accordance with the principle of Storage Limitation (Art. 5(1)(e) GDPR), we store personal data only for as long as necessary to fulfill the specific processing purposes for which it was collected, or as required by applicable statutory retention laws.

7.1 Specific Retention Schedule

Category of Personal Data Retention Period Deletion / Anonymization Trigger
Server Access & Technical Logs Up to 7 days from log creation. Automatically purged or anonymized on a rolling 7-day cycle, unless required for ongoing security incident investigations.
Waitlist & Registration Data Retained for the duration of the beta testing phase, or up to 24 months from registration without active engagement. Deleted upon receipt of a valid erasure request or expiration of the 24-month inactive period.
Account Credentials & Profile Data Retained for the duration of your active pilot account subscription. Deleted within 30 days following formal account termination or closure request.
User-Submitted Attestation Data & Receipts Retained for the duration specified in your pilot agreement or enterprise workspace contract (3 years). Retained to preserve the legal validity of compliance audit logs under Article 50 of the EU AI Act and statutory defense periods under national civil codes.

7.2 Deletion Protocol

Upon the expiration of the applicable retention period, or upon a valid request to exercise the Right to Erasure, all personal data, attestation records, uploaded files, and their associated cryptographic hashes are permanently and irreversibly deleted from our production systems. No hashes, metadata, or other records of the deleted entries are retained following deletion.

8. Recipients & Sub-processors

We do not sell, lease, rent, or trade your personal data to third parties under any circumstances. We share your personal data only with trusted service providers who act as Data Processors on our behalf, or when strictly required by law.

8.1 Processing Under Data Processing Agreements (Art. 28 GDPR)

All third-party service providers who process personal data on our behalf are bound by written Data Processing Agreements (DPAs) pursuant to Article 28 of the GDPR. These agreements mandate that sub-processors:

  • Process personal data strictly in accordance with our documented instructions;
  • Maintain strict confidentiality and organizational security standards;
  • Implement technical safeguards equivalent to our own; and
  • Refrain from using personal data for their own independent purposes.

8.2 Categories of Sub-processors (v1 MVP Scope)

To deliver our v1.0 Services, we utilize a minimal infrastructure footprint involving the following categories of Data Processors:

  • EU Cloud Infrastructure & Hosting Providers: Our web servers, database systems, and secure backup infrastructure are hosted with European cloud infrastructure providers with physical data centers located exclusively inside the European Economic Area (EEA) (e.g., Paris, France) (Scaleway).
  • Identity & Authentication Provider: We use an EU-region identity and access management provider, to manage user account creation, authentication, and credential storage (including password hashing). It also dispatches account-related transactional emails on our behalf, including account confirmation codes and password reset links, from infrastructure hosted within the EEA (Zitadel).
  • Transactional Email Service Providers: We utilize GDPR-compliant transactional email services to dispatch account confirmation codes, waitlist notifications, password reset links, and system service alerts.

8.3 Disclosures to Statutory & Judicial Authorities

We may disclose personal data to official third parties (such as law enforcement, regulatory authorities, or judicial bodies) only where strictly necessary to:

  • Comply with a binding court order, legal summons, or statutory disclosure obligation under European Union or Member State law;
  • Protect and defend our legal rights, property, or system integrity; or
  • Prevent or investigate fraudulent, unauthorized, or illegal activities on our platform.

8.4 Pre-Incorporation Reorganization & Entity Assignment

As noted in Section 2, upon formal corporate registration in Estonia, all databases, sub-processor contracts, and customer personal data managed under this Policy will be assigned and transferred to Human Oversight Laboratories OÜ (Tallinn, Estonia). This corporate assignment will not alter the rights or protections granted to you under this Policy.

9. International Data Transfers

9.1 EEA Primary Processing Location

We operate under a strict data localization policy for our core infrastructure. All primary web servers, application databases, and user-submitted attestation records are physically located and processed within the European Economic Area (EEA).

9.2 Safeguards for Third-Country Transfers

We do not intentionally transfer, store, or process personal data outside the EEA. However, if an essential sub-processor (such as a transactional email provider or technical security service) routes or handles data outside the EEA or in a country without an automatic adequacy decision by the European Commission, we ensure that appropriate safeguards are implemented pursuant to Chapter V of the GDPR:

  • Adequacy Decisions (Art. 45 GDPR): Transfers to countries that the European Commission has officially recognized as providing an adequate level of data protection (e.g., adequacy decisions, including the EU-U.S. Data Privacy Framework for certified entities).
  • Standard Contractual Clauses (Art. 46(2)(c) GDPR): In the absence of an adequacy decision, we execute the European Commission’s Standard Contractual Clauses (SCCs) as established by Commission Implementing Decision (EU) 2021/914, supplemented by technical security measures such as end-to-end transport encryption (TLS 1.3) and pseudonymization.

Data Subjects may request a copy of the documentation detailing the specific safeguards applied for international transfers by contacting contact@art50compliance.eu.

10. Data Subject Rights & Supervisory Complaint Rights

Under Articles 12 to 22 of the GDPR, you possess fundamental rights regarding how your personal data is collected, processed, and stored.

10.1 Summary of Your Data Subject Rights

  • Right of Access (Art. 15 GDPR): You have the right to request confirmation as to whether we are processing your personal data and, where applicable, receive a copy of that data along with details regarding our processing operations.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the prompt correction of inaccurate personal data or the completion of incomplete data held about you.
  • Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): You have the right to request the deletion of your personal data where it is no longer necessary for the purposes collected, where you withdraw consent, or where processing is otherwise unlawful. (Note: This right may be limited where retention is legally required to defend compliance records or statutory claims).
  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to request that we temporarily restrict the processing of your data (e.g., while the accuracy of the data or the lawfulness of processing is being contested).
  • Right to Data Portability (Art. 20 GDPR): Where processing is based on consent or a contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV) or request its direct transmission to another controller.
  • Right to Object (Art. 21 GDPR): You have the right to object at any time to processing based on our legitimate interests (Art. 6(1)(f) GDPR). We will cease processing your data unless we demonstrate compelling legitimate grounds that override your interests or for the establishment, exercise, or defense of legal claims.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on your consent (e.g., waitlist communications), you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

10.2 How to Exercise Your Rights

To exercise any of your rights, please submit a written request to our dedicated privacy contact point:

  • Email: contact@art50compliance.eu

Process & Identity Verification:

  • No Fee: Exercising your rights is generally free of charge.
  • Response Time: We will respond to your request without undue delay and at the latest within one month (30 days) of receipt. In complex cases, this period may be extended by up to two additional months, in which case we will notify you of the extension within the first month.
  • Identity Verification: To prevent unauthorized access or fraud, we may ask you to provide reasonable proof of identity before processing your request.

10.3 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a competent Data Protection Supervisory Authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

Given our pre-incorporation Joint Controllership and target corporate location, you may contact any of the following lead authorities:

  • Italy (Residence of Joint Controller 1): Garante per la protezione dei dati personali — www.garanteprivacy.it
  • Hungary (Residence of Joint Controller 2): Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) — www.naih.hu
  • Estonia (Future Corporate Seat): Andmekaitse Inspektsioon (AKI) — www.aki.ee

11. Automated Individual Decision-Making & Profiling

Pursuant to Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

11.1 Absence of Automated Decision-Making

We confirm that our platform and v1.0 software utility do not employ automated decision-making algorithms, artificial intelligence profiling, or automated scoring systems that produce legal or binding effects on Data Subjects.

11.2 Nature of Attestation Logging

Our v1.0 tools collect and process user-submitted declarations strictly to record and timestamp human review actions. The software does not evaluate, grade, discipline, or pass automated judgment on individual reviewers, editors, or users.

12. Policy Changes & Version Control

We reserve the right to amend or update this Privacy Policy periodically to reflect changes in our legal status, technological advancements, software updates, or regulatory requirements.

12.1 Notification of Material Changes

  • Substantial Revisions: If we make material changes to how we collect or process personal data, or upon our formal corporate incorporation in Estonia (transferring Data Controller status to Human Oversight Laboratories OÜ), we will notify registered users via email or place a prominent notification banner on our website prior to the changes taking effect.
  • Minor Revisions: Non-material changes (e.g., updates to formatting, minor clarification of wording, or fixing typos) will take effect immediately upon publication on our website.

12.2 Versioning & Review

The “Effective Date” and “Version Number” at the top of this Policy indicate when it was last revised. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.