Legal
The fine print, in plain sight.
Every document that governs your relationship with Tisser, in one place — with the terms that matter to your data written out in plain language, not buried. Where a commitment comes from our backend provider rather than from us, we say so and point at the document.
last updated · August 2026 · questions → compliance@tisser.ai · see also · Security
Data processing · GDPR art. 28
“You are the controller. We process your data on your written instructions, for the service you signed up for — and for nothing else.”
The documents
Everything that governs the relationship.
Privacy Policy
What personal data we collect on tisser.ai, why, the legal basis for each purpose, and the rights you can exercise over it.
[ document follows at launch ]
Terms of Service
The terms on which you use Tisser — scope, responsibilities, availability and limits.
[ document follows at launch ]
Data Processing Agreement
Our GDPR Art. 28 agreement, issued with your contract. The upstream agreement it rests on is public and summarised below.
[ with your contract ]
Sub-processor list
The third parties that may process your data, with the source document for each one and what it does and does not say.
Cookie Policy
The (few) cookies tisser.ai sets, what they do, and how to decline the non-essential ones.
[ document follows at launch ]
Acceptable Use Policy
What Tisser may and may not be used for — the guardrails that keep the platform safe for everyone.
[ document follows at launch ]
Where the commitments come from
Two contracts, not one.
Tisser is the product. The platform underneath it is built and operated by Artific B.V. as our backend and inference provider. That means two agreements sit behind your data, and it is worth knowing which is which.
- Your agreement, with us
- AIO B.V., trading as Tisser, is your contracting party. Our Data Processing Agreement under GDPR Art. 28 is issued with your contract and is the document that governs your relationship with us. It is being finalised ahead of launch; we will publish it here.
- Our agreement, with Artific
- Artific operates the platform as our sub-processor, under its own verwerkersovereenkomst. That document is published in full — you can read it before you talk to us. Its core terms are summarised below, with article references so you can check them yourself.
The upstream agreement · what Artific commits to
The clauses that matter, in plain language.
These are the terms of the published Artific verwerkersovereenkomst (7 May 2025), with the article each one comes from. They describe the platform Tisser runs on — not a summary of your own contract with us, which follows at launch.
- You are the controller · art. 3.2
- You hold the role of controller under the GDPR. Artific acts as processor. Tisser sits between you as your contracting party. The decisions about your data stay yours.
- Processing only on written instruction · art. 4.1, 4.3
- Your data is processed only on your written instructions and only for the agreed service. Processing is limited to the categories of personal data set out in the annex to the agreement.
- Assistance with your GDPR duties · art. 4.6
- Support for the obligations that stay yours: responding to data subjects, carrying out a DPIA, and the duties under GDPR Art. 32–36.
- Confidentiality · art. 9.1, 9.2
- Your data is treated as confidential, and every employee involved in processing it is bound by a confidentiality clause.
- Sub-processors and your right to object · art. 10.2, 10.3
- Any addition or replacement of a sub-processor is notified in advance, and you have seven days to object. Sub-processors are bound to the same data-protection obligations.
- Annual right to audit · art. 7.1
- You may audit compliance once per calendar year. You bear the cost — unless the audit shows a material breach or that changes are required, in which case that cost sits with the processor.
- Breach notification · art. 8.1, 8.2
- You are told without undue delay, with the nature and cause, the categories and number of people affected, the likely consequences and the remedial steps. The decision to notify the supervisory authority, and the notification itself, remain yours as the controller — that is how GDPR Art. 33 allocates it. The 72-hour clock is yours; our job is to get you what you need inside it.
- Return or destruction · art. 12.1
- Within 30 days of the agreement ending, personal data is returned to you or destroyed — your choice — unless a statutory retention period says otherwise. Remaining copies and back-ups are destroyed at a moment you set.
- Processing inside the EEA · art. 4.7
- The agreement commits the processor to aim not to process personal data outside the European Economic Area. We are deliberate about the wording here: as published, this is an obligation of effort, not an absolute guarantee of EU residency. If you need a hard commitment, raise it and we will put it in your contract rather than imply it on a web page.
- Governed by Dutch law · art. 14
- Dutch law applies; disputes go to the Rechtbank Overijssel, Almelo. Artific B.V. is registered with the Kamer van Koophandel under number 92661564.
Sub-processors
Who else can touch your data — and where.
Below is the sub-processor annex of the published Artific verwerkersovereenkomst, reproduced as it stands, plus the hosting Artific documents publicly. We have not edited it to look tidier than it is.
| Provider | Purpose | Location, as published | Source |
|---|---|---|---|
| Google Cloud | Hosting & core infrastructure | EU region | artific.nl |
| OpenAI | Language-model processing | Not published | DPA, annex 3 |
| Vertex AI (Google Cloud) | Language-model processing | Not published | DPA, annex 3 |
| Perplexity.ai | Search & retrieval | Not published | DPA, annex 3 |
| LangChain Inc. | Orchestration tooling | Not published | DPA, annex 3 |
Source: Artific verwerkersovereenkomst, annex 3 (7 May 2025), and artific.nl. Two of these providers are US-incorporated, and their processing location is not stated in the published annex. We are confirming with Artific which of them are engaged for a Tisser tenant and under what transfer mechanism, and this table will say so once we have it in writing. The list that binds your own contract is the one attached to your Data Processing Agreement.
Breach notification
Without delay
You are informed as soon as a breach is known, with what you need to assess it. The 72-hour notification to the supervisory authority is the controller's — yours — under GDPR Art. 33.
Return or destruction
30 days
Within 30 days of the agreement ending, your personal data is returned or destroyed at your choice, subject to statutory retention. Remaining copies and back-ups follow on your instruction.
Right to audit
1× / year
An annual audit right, and assistance with any DPIA under GDPR Art. 35. You bear the cost unless the audit finds a material breach.
Scope
What this page does not claim.
A short list, because the absence of a claim is easy to miss and a compliance officer should not have to go looking for it.
- No ISO certification of our own
- Neither AIO B.V. nor Artific B.V. holds an ISO 27001 certificate. Where ISO 27001 appears on this site it refers to the Google Cloud infrastructure the platform runs on, and the certificate is Google's. We will not present someone else's certificate as ours.
- No blanket EU AI Act compliance
- The Act's obligations phase in over time and there is no conformity scheme covering most of them yet. We build to its requirements. Nobody can honestly claim finished compliance today, so we don't.
- No guarantee of zero retention at model providers
- Artific states that data sent to OpenAI is not used for training purposes. It makes no published zero-retention commitment, and neither do we until it is in a contract we can show you.
A legal or data-protection question?
DPAs, DPIAs, sub-processor changes, retention — our team answers directly. For anything covered by GDPR data-subject rights, we respond within one month, as GDPR Art. 12 requires.
- Data protection · privacy · contracts
- compliance@tisser.ai
- Who you are contracting with
- AIO B.V., trading as Tisser — AI AM, The Hubb
Building, Jacob Bontiusplaats 9, 1018 LL Amsterdam, the Netherlands.
KVK 93333390 · VAT NL866359655B01 - Our role under the GDPR
- AIO B.V. is the controller for personal data we collect in our own right — website visitors, prospects, account administrators. It is a processor for the content you put into Tisser, which we handle on your instructions under the Data Processing Agreement.
- Right to complain
- You can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, under GDPR Art. 77.
Bring your compliance officer.
Technical and legal questions are welcome on the first call — it is the part we built for.