Skip to content
ChartreuseAI
Home Government Consultancies Request a demo
Home Government Consultancies Contact Request a demo

Legal

GAIA Trial Privacy and Security Notice

Last updated 26 July 2026

This notice explains how Chartreuse AI handles personal data in the GAIA Impact Assessment Tool during its trial. It also sets out the service's data residency, hosting arrangements, sub-processors, and security controls, so that customers can complete a data protection or supplier assurance review from a single document.

Our website and general business contact are covered by our separate website privacy policy. Please address any questions to engineering@chartreuseanalysis.com.

Chartreuse AI is the trading name of Chartreuse AI Ltd., a company registered in England and Wales under company number 16395691. Our registered details, including our registered office, are on the Companies House register.

Where we act as a processor, our data processing agreement with the customer governs that processing. If anything here conflicts with that agreement, the agreement applies.

What GAIA does with data

GAIA helps users draft UK Government Impact Assessments. A user uploads a policy document, GAIA analyses it, searches public government datasets, and produces a formatted draft.

Documents uploaded to GAIA should not contain personal data. The Acceptable Use Policy requires users to remove or anonymise personal data before uploading, and an Impact Assessment does not normally require it. Uploaded documents are therefore not treated as a source of personal data.

The service holds a limited amount of personal data about its users for authentication and security. The remainder of this notice describes that processing.

Personal data we hold

Each trial user has their own separate deployment of GAIA, with its own access password. GAIA is not a shared multi-user system, so a user's documents and activity sit in their own deployment and are not visible to other users.

For each deployment we hold:

  • A username label, which is the user's name or work email address. It tags every log and audit event from that deployment.
  • The access password for the deployment, and a session cookie that expires after seven days. The cookie keeps a user signed in and carries no information about them. We set no analytics, advertising, or third-party tracking cookies.
  • Activity logs: messages to the agent, uploads, downloads, tool activity, and sign-in events, tagged with the username label.
  • The IP address a request comes from, recorded against sign-in events and used to rate-limit failed login attempts.

We do not process special category data about users, use personal data for marketing, or sell it.

Controller and processor

Chartreuse AI Ltd. is the controller for the access and log data above.

For the content a user uploads and the drafts GAIA produces, Chartreuse AI is a processor acting on the customer's documented instructions. The customer is the controller for that content, including any personal data it contains.

Why we process it, and our lawful basis

Deployments are set up for named staff at the request of the customer organisation. Our contract is with that organisation rather than with the individual user, so we rely on legitimate interests rather than contract for most of this processing.

  • To provide the service: giving a named user access and authenticating them. Lawful basis: legitimate interests, ours and the customer's, in delivering the service the customer has asked for.
  • To keep the service secure: logging and monitoring activity to detect and investigate misuse. Lawful basis: legitimate interests. We monitor only what is needed for security, audit, and service improvement, as described in the Acceptable Use Policy.
  • To defend legal claims. Lawful basis: legitimate interests.
  • To comply with the law, where we are required to disclose or retain data. Lawful basis: legal obligation.

We have weighed these interests against the rights of the people concerned. Where we rely on legitimate interests you can object to the processing; see Your rights below.

We do not use the data for any other purpose.

Data residency and hosting

All processing takes place in the European Economic Area, in Google Cloud Platform's europe-west4 region (Amsterdam). The application is hosted on Railway, which runs on Google Cloud infrastructure in that region. Model inference runs on Anthropic models served through Google Cloud in the same region. No processing takes place in the United States.

Personal data stays within the UK and the European Economic Area. Transfers to the EEA are covered by the UK adequacy regulations, so no additional transfer safeguard is required. If we ever need to process data outside the UK and the EEA, we will put appropriate safeguards in place, such as an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, tell affected customers in advance, and update this notice.

Data processors

We use two sub-processors:

Sub-processor Role Location
Railway Application hosting (on GCP) europe-west4 / Amsterdam
Google Cloud Platform Infrastructure for Railway, and model inference europe-west4 / Amsterdam

GAIA uses Anthropic's Claude models, but these are served through Google Cloud in the region above, so service data is not sent to Anthropic and Anthropic is not a sub-processor. Models run in inference-only mode, so no customer or user data is used to train or fine-tune them.

No other party has access to personal data in the service. Each sub-processor is bound by written terms equivalent to our own.

We give customers 30 days' notice before adding or replacing a sub-processor. A customer can object on data protection grounds within that period. If we cannot resolve the objection, they can end the affected part of the service without penalty.

Who else we share data with

Beyond the sub-processors above, we share personal data only where the law requires it, or to establish, exercise, or defend legal claims, and with our professional advisers where they need it to advise us.

How long we keep it

  • Session cookies: seven days.
  • Activity logs: written as structured events and shipped off the container to Railway's cloud logging, from where they are exported to storage we control. They are kept for the duration of the trial and deleted when it ends.
  • Username labels and access passwords: for as long as the deployment is running, then removed when it is shut down.

The trial keeps no persistent store of uploaded documents or generated drafts. Retention for any production release will be set out in the customer agreement, and this notice updated before that release.

Deletion and return

When the trial ends, or earlier if the customer asks, we delete the personal data we hold as processor and return any customer content still in the service. We do this within 30 days and confirm in writing. Deployments and their activity logs are removed at the same time. If the law requires us to keep something, we keep it under this notice until we can delete it.

Security controls

We use appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, disclosure, or alteration. The controls in place for the trial are:

  • Encryption in transit using TLS 1.2 or higher, and at rest by our hosting and infrastructure providers.
  • A separate deployment per trial user, so there is no shared environment and no cross-user access by design.
  • A password gate on every deployment, with failed logins rate-limited by IP address and locked out after five attempts in fifteen minutes. Session cookies are HTTP-only, restricted to HTTPS, and signed so they cannot be forged.
  • Multi-factor authentication on all staff accounts with administrative access, including Railway, the source repository, and cloud consoles.
  • Outbound traffic from the agent restricted to an allowlist of approved domains, so it cannot reach arbitrary external services.
  • No persistent store of uploaded documents or generated drafts in the trial environment.
  • Activity and audit logging shipped off the container, so records survive a restart or redeploy.

We built GAIA with OFFICIAL-tier UK Government data in mind. The technical and organisational measures we commit to are recorded in the data processing agreement.

Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects concerning individuals (Article 22 UK GDPR). GAIA produces draft documents for human review; responsibility for the final output, and for any decisions informed by it, remains with the customer.

Your rights

Users, and customers acting for their staff, have the rights under UK GDPR: access, rectification, erasure, restriction, objection, and portability. Not every right applies in every case, and we may decline a request where a legal exemption applies or where the request is unfounded or excessive; if we do, we explain why. Send requests to engineering@chartreuseanalysis.com and we respond within the statutory timescale.

Where we hold the data as a processor, we pass the request to the customer who controls it and help them respond.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. If you are in the EEA, you may instead complain to your local supervisory authority.

Data breaches

Where a personal data breach is likely to result in a risk to individuals, we notify the Information Commissioner's Office without undue delay, and in any event within 72 hours of becoming aware of it, and inform affected customers within the same period. Where we act as processor, we tell the customer as soon as we become aware and give them what they need to meet their own obligations as controller.

Personal data submitted in an uploaded document contrary to the Acceptable Use Policy is handled under our incident management process: the material is contained and deleted, and the customer, as controller for uploaded content, is informed.

Changes to this notice

We may update this notice, for example when the service or the sub-processor list changes. The current version is the one published on this page, and the date at the top shows when it last changed. We notify customers of material changes in advance.

ChartreuseAI

GAIA drafts Green Book impact assessments and Five Case business cases, for government and consultancies.

Site HomeGovernmentConsultanciesContact Sample report
Legal Security Privacy GAIA security notice
Get in touch Request a demo →
Chartreuse AI Ltd.
London, UK
Company No: 16395691

© 2026 Chartreuse AI. All rights reserved.