Privacy Policy

Your data stays yours.

Last updated April 2026

Data controller

Decidian AS, Oslo, Norway. Contact: privacy@decidian.io

What we collect and why

Account data (email, name) — to provide the service. Legal basis: contract (GDPR Art. 6(1)(b)).

Analysis data (company names, URLs, chat conversations, decisions) — to deliver and improve analysis. Legal basis: contract.

Publicly available business data (financial reports, registry data, news) — to generate company analysis. Legal basis: legitimate interest (GDPR Art. 6(1)(f)). We only process data that is already public.

Usage data (pages visited, features used) — to improve the product. Legal basis: legitimate interest. We use PostHog with EU data residency.

AI processing

Analysis is powered by Anthropic Claude under Zero Data Retention. Your inputs are processed and immediately discarded by the AI provider — never stored or used for model training. Decidian stores your analysis results in our database so you can return to them.

Sub-processors

Anthropic (AI inference, US — EU-US Data Privacy Framework).
Vercel (hosting, EU region).
Supabase (database, Stockholm eu-north-1).
Resend (email delivery).
Tavily (web search for company data).

Data Processing Agreements are in place with all sub-processors. A full list is available on request.

Where your data lives

Supabase Stockholm (eu-north-1). Data does not leave the EU except for AI inference (Anthropic, covered by EU-US DPF). Encrypted in transit (TLS 1.3) and at rest (AES-256).

How long we keep your data

Account and analysis data: as long as your account is active, plus 30 days after deletion request. Usage analytics: 12 months. AI processing: zero retention (not stored by Anthropic).

Cookies

Essential authentication cookies only. PostHog analytics with EU data residency. No third-party advertising cookies.

Your rights (GDPR Art. 15-22)

You have the right to access, correct, export, or delete your data at any time. You can object to processing based on legitimate interest. You can withdraw consent where applicable. We respond within 30 days. You may lodge a complaint with Datatilsynet (Norwegian Data Protection Authority).

Automated decision-making

Decidian uses AI to generate analysis and advice. This is decision-support only — no automated decisions are made about you or on your behalf. You retain full control over all decisions.

Contact

Decidian AS, Oslo, Norway — privacy@decidian.io