Legal
Version 1.1 · effective 2026-08-03

Terms of Use and Data Processing Notice

RawKit — Version 1.1 · Effective 2026-08-03 · Last updated 3 August 2026

These Terms of Use ("Terms") govern your use of RawKit, a web application for evidence-based research and go-to-market work operated by Elijah Ross. They form a binding contract between you and the provider named in section 2.

Section 13 sets out in detail what personal data RawKit stores, why, on what legal basis, where, for how long, and who else receives it. It is written to satisfy the information duties of Articles 12–14 GDPR and is an integral part of these Terms.


1. Scope

1.1 These Terms apply to every use of the RawKit web application, its application programming interfaces, the collaborative canvas, the AI agent runtime, the research connectors and every associated service (together, the "Service"), whether or not you have created an account.

1.2 By creating an account or otherwise using the Service you accept these Terms. If you do not accept them, you must not use the Service.

1.3 Deviating, conflicting or supplementary terms of a business user do not become part of the contract, even where the provider performs without express objection, unless the provider has agreed to them in writing.

1.4 The Service is directed at users in the European Economic Area. It is not marketed to, and is not designed for compliance with the laws of, jurisdictions outside the EEA. You are responsible for whether your local law permits your use.


2. Provider (information under section 5 ECG and section 5 DDG)

<!-- ECG §5 (AT) / DDG §5 (DE) / UGB §14 -->
ProviderElijah Ross, sole trader (Einzelunternehmer)
AddressKulmgasse 38/20, 1180 Vienna, Austria
Emailservice@ml-canvas.com
VATNo VAT identification number. Small-business exemption under section 6(1)(27) of the Austrian VAT Act (UStG); no VAT is shown on invoices.
Trade authorityMagistrat der Stadt Wien, Magistratisches Bezirksamt für den 18. Bezirk
Chamber membershipWirtschaftskammer Wien, Fachgruppe UBIT (Unternehmensberatung, Buchhaltung und Informationstechnologie)
Applicable trade lawGewerbeordnung 1994 (GewO), available at www.ris.bka.gv.at
Data protection supervisory authorityÖsterreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at

No data protection officer has been appointed. The provider is a sole trader whose processing does not meet the thresholds of Article 37 GDPR; the appointment obligation is reassessed whenever the scope of processing changes.


3. Definitions

  • Account — your personal login, identified by a verified email address.
  • Workspace — the tenant that owns boards, files, conversations and connectors. Every object in RawKit belongs to exactly one workspace.
  • Board — a collaborative canvas. Its live state is a conflict-free replicated data type (Yjs) document.
  • Agent — the automated research runtime that plans and executes steps, calls language models and external data sources, and writes results onto a board.
  • Connector — a social or publishing account you connect by OAuth so the Service can publish on your behalf and read engagement metrics.
  • User Content — everything you or your workspace members create, upload or import: board contents, uploaded files, chat messages, drafts and publications.
  • Consumer / Business user — a consumer is a natural person acting outside their trade, business or profession (section 1(1)(2) KSchG, Article 2(1) of Directive 2011/83/EU). Everyone else is a business user.

4. The Service, and what it is not

4.1 What RawKit does. RawKit lets you run structured research on a canvas. An AI agent decomposes a question, queries public and commercial data sources, and writes the findings back onto the board as structured objects with citations. You can attach files, converse with the agent about the board, generate images and video, and publish drafted content to connected social accounts.

4.2 Alpha status. The Service is in open alpha. Features may change, degrade or be withdrawn at short notice; data loss, incorrect output and downtime are realistic possibilities. No service level is owed (section 15). This clause does not limit the statutory rights of consumers.

4.3 No professional advice. RawKit produces research output. It is not legal, tax, financial, medical or investment advice, and it is not a substitute for professional judgement. Funding deadlines, market figures, competitor data and regulatory statements produced by the agent may be incomplete, outdated or wrong. You must verify every material fact against the cited primary source before relying on it. In particular, the Service is expressly not an eligibility assessment for any grant, subsidy or public funding programme.

4.4 Third-party data. Findings derive from third-party sources listed in section 13.6. Their availability, accuracy, licensing and pricing are outside the provider's control, and a source may be removed without notice.


5. Registration, account and eligibility

5.1 An account requires a valid email address, which must be confirmed before the Service becomes usable. You may not register with a false identity or an address you do not control.

5.2 Minimum age. You must be at least 16 years old. Users under 18 may only conclude a paid contract with the consent of their legal guardian. The provider does not knowingly process the data of children below the age thresholds of Article 8 GDPR (16 in Germany; 14 in Austria under section 4(4) DSG) and will delete such accounts on becoming aware of them.

5.3 Credentials. You are responsible for keeping your password confidential and for all activity under your account. Notify the provider without undue delay at the address in section 2 if you suspect unauthorised access.

5.4 Workspace members. If you invite others into a workspace, you are responsible for ensuring that they are permitted to see the content in it, and that you have a lawful basis for any personal data you place there (section 13.9).

5.5 Status declaration. When registering you state whether you act as a consumer or as a business user. Clauses marked "business users only" do not apply to consumers, and clauses marked "consumers only" do not apply to business users. If you register as a business user while in fact acting as a consumer, the mandatory consumer protections still apply to you.


6. Plans, fees and payment

6.1 Current position. During the alpha the Service is provided free of charge. Paid plans (standard, premium) are prepared in the product but are not yet billable, and no payment service provider is integrated.

6.2 Introduction of paid plans. The provider may introduce paid plans. No charge will ever be levied on an existing account without the account holder's prior express consent to a paid plan. Free accounts will not convert automatically into paid accounts.

6.3 The following clauses (6.4–6.9) become effective only once billing is activated and you have expressly subscribed to a paid plan.

6.4 Prices. Prices are stated at the point of subscription. The provider applies the small-business VAT exemption (section 6(1)(27) UStG), so no Austrian VAT is shown. For cross-border supplies within the EU, statutory VAT rules including the reverse-charge mechanism and the EU SME scheme may apply.

6.5 Billing period and renewal. Subscriptions run for the period selected and renew for the same period unless terminated before the end of the current period. For consumers, any tacit renewal is subject to the limits of section 6(1)(2) and section 6(3) KSchG; the provider will send a reminder before each renewal and the notice period for consumers will not exceed one month.

6.6 Payment default. If payment fails, the provider may suspend paid features after a reminder with a reasonable grace period. Consumer accounts will not be deleted for non-payment; they revert to the free tier.

6.7 Usage-based cost. Agent runs consume paid third-party capacity (language models, search providers). The Service enforces a per-run ceiling (currently USD 10 per run, a maximum number of reasoning turns and a wall-clock limit) and records every run's cost in a ledger visible to you. Plan entitlements cap how much capacity you may consume; exceeding a cap blocks further runs rather than generating additional charges.

6.8 Price changes. For consumers, an enforceable price-adjustment clause must state the trigger, the yardstick and a termination right. The following is a conservative default and must be confirmed. The provider may change prices with at least eight weeks' notice, sent by email and in the application. If you do not accept the change, you may terminate with effect from the date the new price would take effect; continued paid use after that date constitutes acceptance. The notice will state this expressly.

6.9 Refunds. Statutory rights, including the right of withdrawal in section 7, remain unaffected. Beyond those, fees for a period already begun are not refunded on termination for convenience.


7. Right of withdrawal — consumers only

<!-- FAGG §11 ff. / RL 2011/83/EU -->

This section applies only if you are a consumer within the meaning of section 5.5.

7.1 Notice of the right of withdrawal

You have the right to withdraw from this contract within fourteen days without giving any reason. The withdrawal period expires fourteen days from the day of the conclusion of the contract.

To exercise the right of withdrawal you must inform the provider (Elijah Ross, Kulmgasse 38/20, 1180 Vienna, Austria, service@ml-canvas.com) of your decision to withdraw by an unequivocal statement (for example a letter sent by post or an email). You may use the model withdrawal form below, but it is not obligatory. To meet the withdrawal deadline, it is sufficient for you to send your communication concerning the exercise of the right of withdrawal before the withdrawal period has expired.

7.2 Effects of withdrawal

If you withdraw from this contract, the provider shall reimburse all payments received from you without undue delay and in any event not later than fourteen days from the day on which the provider is informed of your decision to withdraw. The provider will use the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in no event will you be charged any fees as a result of such reimbursement.

7.3 Early performance and loss of the right of withdrawal

If you have requested that the supply of the service begin during the withdrawal period, you shall pay the provider an amount which is in proportion to what has been supplied until the moment you informed the provider of your withdrawal, in comparison with the full coverage of the contract (section 16 FAGG).

For digital content not supplied on a tangible medium, the right of withdrawal lapses under section 18(1)(11) FAGG only where all of the following apply: you have expressly consented to performance beginning before the end of the withdrawal period, you have acknowledged that you thereby lose your right of withdrawal, and the provider has given you confirmation of that agreement on a durable medium.

8. Acceptable use

8.1 You must not use the Service to:

a) infringe the rights of others, in particular copyright, trade mark, trade secret, personality or data protection rights; b) upload or generate unlawful content, including content that is defamatory, inciting, terrorist, or that depicts the sexual abuse of minors; c) process special categories of personal data (Article 9 GDPR) or criminal conviction data (Article 10 GDPR) without your own valid legal basis and appropriate safeguards (see section 13.9); d) circumvent, or attempt to circumvent, the plan limits, run budgets, rate limits, authentication, tenant isolation or any other technical control; e) resell, sublicense or provide the Service or its agent runtime to third parties as a competing offering, or use it to build a substantially similar product; f) run automated bulk extraction of the Service or of the third-party sources it reaches beyond ordinary interactive use; g) generate or publish content that impersonates a real person or organisation, fabricates records, reviews or endorsements, or is designed to deceive as to its origin; h) use connected social accounts to send spam, engage in coordinated inauthentic behaviour, or otherwise breach the terms of the connected platform; i) use the Service to build profiles of identifiable natural persons for purposes those persons could not reasonably expect, or to make decisions about individuals that produce legal or similarly significant effects for them.

8.2 AI-specific rules. You must not use the Service to develop or operate an AI practice prohibited by Article 5 of Regulation (EU) 2024/1689 (AI Act), nor to produce synthetic audio, image or video content that is presented as authentic without the disclosure required by Article 50(4) of that Regulation.

8.3 Enforcement. Where there is a substantiated suspicion of a breach, the provider may restrict or suspend the affected function, workspace or account. The provider will notify you of the reason and, unless prohibited by law or the breach is serious, give you an opportunity to remedy it. Suspension is proportionate and temporary; termination follows the rules in section 19.


9. AI features, output and human oversight

<!-- VO (EU) 2024/1689 Art. 4, Art. 50 -->

9.1 You are interacting with an AI system. Chat replies, board objects, research summaries, drafts, images and video produced by the agent are generated by machine learning models. This disclosure is made under Article 50(1) AI Act.

9.2 Synthetic content. Images and video generated through the Service are artificially generated. If you publish such content, you are responsible for any marking or disclosure obligations that apply to you as a deployer, including Article 50(4) AI Act for deepfakes and the labelling rules of the platform you publish to.

9.3 Risk classification. The provider assesses the Service as an AI system of limited risk under the AI Act: it generates content and interacts with humans, and it is not intended for any use listed in Annex III. It must not be used as a high-risk system — in particular not for recruitment or worker management decisions, creditworthiness assessment, access to essential services, education access or law enforcement — because it has not been designed, tested or documented for those uses.

9.4 No automated decision-making about you. The provider does not use automated processing to take decisions producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Plan gating and budget enforcement are deterministic rule checks, not profiling.

9.5 Accuracy and hallucination. Language models produce fluent output that can be factually wrong, including invented citations. The Service mitigates this by requiring the agent to cite sources and by validating certain data (for example, funding deadlines are re-checked against the source at query time), but it cannot eliminate it. Human oversight is yours.

9.6 Rights in output. As between you and the provider, output generated for you belongs to you (section 11.3). The provider gives no warranty that AI output is free of third-party rights, and no warranty that output is copyrightable — under Austrian and EU law, purely machine-generated content may not attract copyright protection.


10. Third-party services and connectors

10.1 Connectors. You may connect accounts on LinkedIn, X, Instagram, Facebook, Reddit and further platforms by OAuth. In doing so you authorise the Service to act on your behalf within the scopes you grant: reading your account identity, publishing content you have created or approved, and retrieving engagement metrics for posts made through the Service.

10.2 Platform terms bind you. Each connected platform has its own terms and developer policies. Your use of a connector is additionally governed by them, and a platform may suspend or rate-limit your account for reasons outside the provider's control. The provider is not liable for a platform's decisions.

10.3 Revocation. You may disconnect a connector at any time in the application. On disconnection the stored OAuth tokens are marked revoked and the credentials are deleted; posts already published on the platform are not withdrawn, because the provider has no continuing authority over them after disconnection. Delete them on the platform itself.

10.4 Publishing is your act. Content published through a connector is published in your name, by you, using the Service as a tool. You are the author and the responsible party under media, advertising and competition law, including the labelling of advertising and the disclosure duties of the platform.


11. User Content and licences

11.1 You keep your rights. You retain all rights in your User Content. The provider claims no ownership of it.

11.2 Licence to operate the Service. You grant the provider a non-exclusive, worldwide licence, limited in time to the duration of your use and to the retention periods in section 13.8, to store, reproduce, transmit, display, adapt technically and — where a feature you invoke requires it — disclose your User Content to the sub-processors listed in section 13.5, for the sole purpose of providing the Service to you. The licence covers technical adaptation (format conversion, thumbnailing, text extraction, chunking and embedding for search) and nothing else.

11.3 No training licence. The provider does not use your User Content to train, fine-tune or evaluate its own models, and does not licence it to third parties for that purpose. The position of the AI providers the Service calls is set out in section 13.7.

11.4 No marketing use. The provider will not use your User Content, your name or your logo for marketing or reference purposes without your prior separate consent.

11.5 Your warranty. You warrant that you hold the rights necessary to upload and process your User Content, and that its processing through the Service does not infringe third-party rights or data protection law.

11.6 Provider's own rights. The Service itself, including its software, interface, prompt library, model registry and documentation, is protected and remains the provider's property. You receive a non-exclusive, non-transferable right to use it for the duration of your contract, and no more.


12. Availability and support

12.1 No availability figure is warranted during the alpha. The provider aims for continuous availability but performs maintenance, deploys changes and depends on upstream providers.

12.2 The provider may modify or discontinue individual functions. If a material function is discontinued to your disadvantage and you pay for it, you may terminate the paid plan with immediate effect and receive a pro-rata refund for the unused period.

12.3 Support is provided by email at the address in section 2, on a best-efforts basis and in English or German.


13. Data processing — what is stored, why, where and for how long

<!-- Art. 12–14, 28, 30, 44 ff. DSGVO -->

This section is the transparency notice under Articles 13 and 14 GDPR. It describes actual behaviour of the deployed system, not intentions.

13.1 Controller

The controller for the processing described here is the provider named in section 2. For processing you carry out on your own behalf inside a workspace, the role split in section 13.9 applies.

13.2 Infrastructure and processing locations

All primary systems are located in the European Union:

LayerProviderLocation
Web application, serverless functions, static hostingAmazon Web Services (Amplify, Lambda, CloudFront-equivalent delivery)eu-central-1, Frankfurt am Main, Germany
Relational database (PostgreSQL)NeonEU region, hosted on AWS eu-central-1, Frankfurt am Main, Germany
Object storage for uploaded and generated filesAmazon S3eu-central-1, Frankfurt am Main, Germany
Agent runtime, research clients, cost ledgerSelf-operated servers at Hetzner Online GmbHFrankfurt am Main / Falkenstein, Germany
Real-time collaboration (WebSocket) serviceSelf-operated, co-located with the agent runtimeGermany
Embedding generation for searchSelf-operated model serverGermany, no third party involved

No user data is stored at rest outside the EU. Personal data leaves the EU only as transient content of a request to a third-country service provider, and only where you invoke a feature that requires it — see section 13.6 and 13.7.

13.3 What is stored, and why

a) Account and identity data

DataPurposeLegal basisRetention
Email address, name (optional), profile image (optional)Account creation, authentication, transactional emailArt. 6(1)(b) GDPR — performance of the contractUntil account deletion
Password, stored only as a salted cryptographic hashAuthenticationArt. 6(1)(b) GDPRUntil account deletion
Email verification status and verification tokensPreventing registration with foreign addressesArt. 6(1)(b), 6(1)(f) GDPRTokens expire; deleted after use
Plan (free / standard / premium)Feature entitlementArt. 6(1)(b) GDPRUntil account deletion
Account creation and update timestampsAuditabilityArt. 6(1)(f) GDPR — legitimate interest in a traceable account historyUntil account deletion

b) Session and security data

DataPurposeLegal basisRetention
Session token, expiry, IP address, user agent stringKeeping you signed in; detecting session abuseArt. 6(1)(b) and 6(1)(f) GDPR — legitimate interest in securing accountsSession lifetime is 7 days, refreshed at most daily; rows are removed on expiry or sign-out
Bot-protection token and the IP address transmitted with itPreventing automated registration, credential stuffing and email-bombing of the mail relayArt. 6(1)(f) GDPRNot stored by the provider; transmitted to Cloudflare for verification (section 13.5)
Short-lived signed tickets scoped to one boardAuthorising a browser to open a collaboration socket for one board onlyArt. 6(1)(b) GDPRMinutes; never persisted

c) Workspace, board and collaboration data

DataPurposeLegal basisRetention
Workspace name, slug, membership and role of each memberMulti-tenancy, access controlArt. 6(1)(b) GDPRUntil the workspace is deleted
Board content as a CRDT (Yjs) binary document, plus a queryable JSON projection of nodes, edges and framesStoring your canvas; enabling search, thumbnails and agent reads without loading the CRDTArt. 6(1)(b) GDPRUntil the board or workspace is deleted
An append-only log of every incremental board updateCrash-safe persistence, version history and restoreArt. 6(1)(b) and 6(1)(f) GDPR — legitimate interest in recoverable stateUntil the board is deleted; the log is deleted with it
Board thumbnail imagesBoard overviewArt. 6(1)(b) GDPRUntil the board is deleted
The identity of the member who created an objectAttribution inside the workspaceArt. 6(1)(f) GDPRWith the object

Note on the update log: because board history is stored as an append-only sequence of changes, content you delete from a board remains recoverable in the history until the board itself is deleted. If you need a specific item irretrievably removed sooner, delete the board or contact the provider.

d) Files and generated media

DataPurposeLegal basisRetention
Uploaded files (any type you upload), stored in object storage under a key prefix unique to your workspaceProviding your files to you and as agent contextArt. 6(1)(b) GDPRUntil you delete the file, the board or the workspace
File metadata: filename, MIME type, size, status, uploader, timestampsFile managementArt. 6(1)(b) GDPRAs above
Text extracted from documents, stored as markdown in the databaseLetting the agent read document content without re-parsing the binaryArt. 6(1)(b) GDPRAs above
AI-generated images and video, ingested into the same object storagePersisting generated media beyond the provider's temporary URLArt. 6(1)(b) GDPRAs above

Files are never made public. Access is granted exclusively through short-lived pre-signed URLs issued by the server after it has verified that the requesting account belongs to the owning workspace.

e) Conversations and the search index

DataPurposeLegal basisRetention
Chat messages (your prompts, agent replies, system and tool messages), the board objects attached as context, and the identifier of the run that produced a replyConversation history, reproducibility, cost attributionArt. 6(1)(b) GDPRUntil you delete the conversation, board or workspace
Token counts and cost per messageUsage transparency and budget enforcementArt. 6(1)(b) and 6(1)(f) GDPRAs above
Message chunks and their vector embeddingsHybrid full-text and semantic search over your own transcripts, so the agent can retrieve only relevant passages instead of the whole historyArt. 6(1)(b) GDPRDeleted together with the message

Embeddings are computed on the provider's own infrastructure in Germany. No third party receives message text for the purpose of building the search index.

f) Connector credentials and publications

DataPurposeLegal basisRetention
OAuth access and refresh tokens for connected platforms, encrypted at rest with AES-256-GCMActing on your behalf on the connected platformArt. 6(1)(b) GDPRUntil you disconnect, the token is revoked, or the workspace is deleted
Granted scopes, platform account identifier, display name, handle, avatar URL, connection statusShowing you which account is connected and what it may doArt. 6(1)(b) GDPRAs above
Publication drafts, scheduled and published content, target (subreddit, page, and similar), attached media identifiersPublishing and schedulingArt. 6(1)(b) GDPRUntil you delete the publication or the workspace
Post identifier and permalink returned by the platform, plus retrieved engagement metrics (impressions, likes, comments, shares) and the time they were retrievedPerformance reportingArt. 6(1)(b) GDPRAs above

Tokens are encrypted, not hashed, because they must be usable. The encryption key is held in the server environment, separately from the database. The per-application OAuth client credentials belong to the provider and are never exposed to you or to other users.

g) Agent runs and the cost ledger

DataPurposeLegal basisRetention
Run records: the model used, number of turns and steps, tool calls made, token counts, estimated and actual cost in USD, status and errorsEnforcing budgets, billing accuracy, debugging failed runs, and showing you what a run costArt. 6(1)(b) and 6(1)(f) GDPRretention period — 12 months
Search-provider spend recorded per call, per providerCost transparency for paid data sourcesArt. 6(1)(b) GDPRAs above

These records are stored on the agent runtime's own database in Germany.

h) Transactional email

DataPurposeLegal basisRetention
Recipient address and message content for verification, password reset and account noticesOperating the accountArt. 6(1)(b) GDPRDelivery logs at the mail relay per its own retention; the provider stores no separate mail archive

The provider sends no marketing email and operates no newsletter. If that changes, it will be on the basis of a double opt-in and separate consent under Article 6(1)(a) GDPR and section 174 TKG 2021, with an unsubscribe link in every message.

i) Server logs

DataPurposeLegal basisRetention
Technical logs of requests to the application and the agent gateway, which may contain IP address, timestamp, requested path, status code and user agentOperation, error diagnosis, abuse and attack detectionArt. 6(1)(f) GDPR — legitimate interest in a secure, functioning servicelog retention period — a maximum of 14 days for raw logs, longer only for security incidents

j) Reach measurement on the marketing pages (web analytics)

The public marketing pages (landing page, documentation and these legal pages) use PostHog for reach measurement: page views, referrer, approximate device characteristics and interaction events. All requests are routed through the provider's own domain to PostHog's EU cloud (Frankfurt, Germany); no third-party script is loaded and no data leaves the EU for this purpose.

Two modes exist, controlled by the consent banner described in section 13.4:

  • With your consent (Art. 6(1)(a) GDPR, section 165(3) TKG 2021 / section 25(1) TDDDG): PostHog stores a first-party cookie so that repeat visits can be recognised. You can withdraw consent at any time via "Cookie settings" in the page footer, with effect for the future.
  • Without consent (declined, or no choice made): measurement continues in cookieless mode — nothing is stored on or read from your device, and visits are counted using a pseudonymous hash computed on PostHog's EU servers that rotates daily, so no persistent identifier exists. Legal basis is the legitimate interest (Art. 6(1)(f) GDPR) in aggregate, privacy-preserving reach statistics; no device access within the meaning of section 165(3) TKG 2021 takes place.

The application itself (everything behind sign-in) contains no web analytics of any kind.

k) What is not processed

The Service uses no tracking pixels, no advertising network, no A/B testing service, no session recording and no cross-site tracking of any kind. No profile of your browsing behaviour is created; analytics on the marketing pages is limited to what section 13.3(j) describes. The content security policy of the application permits third-party script loading only for the bot-protection widget; the marketing pages load no third-party scripts at all.

13.4 Cookies and local storage

<!-- TKG 2021 §165(3) / TDDDG §25 -->
NameTypePurposeDurationConsent required
Session cookie set by the authentication layerStrictly necessaryKeeps you signed inUp to 7 daysNo — Art. 6(1)(b) GDPR, exempt under section 165(3) TKG 2021 / section 25(2) TDDDG
"NEXT_LOCALE"Strictly necessary (user-set preference)Stores the interface language you chose1 yearNo — set only as a direct result of your explicit choice
Cloudflare bot-protection cookies set by the challenge widgetStrictly necessaryDistinguishing humans from automated clients on the sign-up, sign-in and password-reset endpointsPer Cloudflare's specificationNo — security measure necessary to provide the service you requested
Browser local storage / IndexedDB used by the collaborative canvasStrictly necessaryOffline-capable local copy of the board you have open, so edits are not lost on a reconnectUntil you clear it or leave the boardNo
PostHog analytics cookie ("ph_…_posthog") and associated local storageAnalytics — optionalRecognising repeat visits to the marketing pagesUp to 1 yearYes — set only after you accept in the consent banner
PostHog consent record ("_ph_opt_in_out…")Strictly necessaryRemembers the accept/decline choice you made in the banner, so you are not asked againUntil you clear itNo — storing the decision itself is necessary to honour it

The marketing pages therefore show a consent banner before any analytics cookie is set. Declining is as prominent as accepting and results in the cookieless measurement described in section 13.3(j) — nothing is stored on your device. A previously made choice can be changed at any time via "Cookie settings" in the page footer. The application behind sign-in continues to set no non-essential cookies and shows no banner.

13.5 Recipients and processors

The following recipients process personal data on the provider's behalf or receive data as independent controllers. The provider concludes a data processing agreement under Article 28 GDPR with every processor.

Infrastructure processors — data at rest

RecipientFunctionDataLocationTransfer basis
Amazon Web Services EMEA SARL, LuxembourgHosting, serverless execution, object storageAll application data and fileseu-central-1, GermanyEU; US parent access governed by the AWS GDPR addendum, SCCs and EU-US DPF
Neon Inc.Managed PostgreSQLAll relational dataEU region on AWS eu-central-1, GermanyStorage in the EU; SCCs and, where applicable, EU-US DPF for US-based support access
Hetzner Online GmbH, GermanyServer hosting for the agent runtime and collaboration serviceRun records, transient request contentGermanyEU — no third-country transfer
Cloudflare Germany GmbH / Cloudflare, Inc.Bot protection (challenge verification)Challenge token, IP address, coarse browser characteristicsGlobal anycast; verification endpoint operated by Cloudflare, Inc.SCCs and EU-US DPF
SMTP.com, Inc., USATransactional email deliveryRecipient address, message contentEU-hosted relaySCCs and EU-US DPF
PostHog, Inc., San Francisco, USAWeb analytics on the marketing pages only (section 13.3(j))Page views, interaction events, IP address (processed transiently), coarse browser characteristicsEU cloud, AWS eu-central-1, Frankfurt, GermanyStorage and processing in the EU; SCCs and EU-US DPF cover any US-based support access

AI providers — data in transit only, no storage by the provider

RecipientFunctionData sentSeatTransfer basis
OpenAILanguage models, including web-search-capable variantsPrompt content: your instructions, relevant board content, conversation excerpts, extracted document textUnited States (contracting entity in Ireland for EEA customers)EU-US DPF and SCCs
Google (Gemini API)Language models, image generationAs aboveUnited States (contracting entity in Ireland for EEA customers)EU-US DPF and SCCs
DeepSeekLanguage modelsAs abovePeople's Republic of ChinaNo adequacy decision. SCCs plus a transfer impact assessment required — see section 13.7
Moonshot AI (Kimi)Language modelsAs abovePeople's Republic of ChinaNo adequacy decision — see section 13.7
MiniMax, including the Hailuo media modelsLanguage models, image and video generationAs above, plus any source image you supplyPeople's Republic of China / SingaporeNo adequacy decision — see section 13.7
Replicate, Inc.Image and video generationGeneration prompt, any source image you supplyUnited StatesSCCs, EU-US DPF where certified

13.6 What actually leaves the EU, and when

Nothing is transferred to a third country by default. A transfer occurs only when you invoke a feature whose execution requires it, and it is limited to the content of that request:

  • You run the agent or send a chat message. The prompt, the board objects you attached as context, relevant excerpts of the conversation and any extracted document text are sent to the language model provider configured for the model you selected.
  • You generate an image or video. The generation prompt and any source image you supplied are sent to the media provider.
  • The agent performs research. The constructed search query is sent to the relevant search or data provider.
  • You publish through a connector. The post content, attached media and target are sent to the platform you selected.

Responses are stored in the EU. Nothing is transferred for any purpose other than executing the request you triggered.

Third-country risk you should be aware of. The Service can route to language models operated in the People's Republic of China (DeepSeek, Moonshot/Kimi, MiniMax and the Hailuo media models). China is not covered by an adequacy decision under Article 45 GDPR, and its legal framework provides state access powers that a European transfer impact assessment must weigh. If you do not wish your content to reach these providers, select only OpenAI or Google models in the workspace model settings, or disable the affected models for your workspace.

The EU-US Data Privacy Framework, on which transfers to certified US recipients rely, remains in force but is subject to a pending challenge before the Court of Justice of the European Union. Standard Contractual Clauses are maintained as a fallback for every US recipient.

13.7 Whether AI providers train on your content

The provider does not train models on your content (section 11.3). For the third parties it calls, the position depends on their API terms:

  • For the major US providers, inputs and outputs submitted through the paid API are, under their published API terms, not used to train their general models by default.
  • For the Chinese providers, an equivalent contractual guarantee has not been established.

Because this depends on contracts the provider does not control, no guarantee is given here beyond the provider's own conduct. If a no-training guarantee is material to you, restrict your workspace to the providers for which it is documented, and do not place confidential or personal data in prompts.

13.8 Retention and deletion

  • While your account exists, your data is retained so the Service can work.
  • You may delete individual objects — files, boards, conversations, publications, connectors — at any time. Deletion cascades to the dependent records (a board takes its update log, its conversations and their message chunks with it).
  • On account deletion, the provider deletes the object-storage prefix of every workspace of which you are the sole member, then deletes those workspaces, which cascades their boards, files, conversations, connectors and publications. Workspaces with other remaining members are preserved and only your membership is removed — content you contributed to a shared workspace stays with that workspace.
  • Backups. Database backups are retained for a limited period for disaster recovery. Deleted data may persist in a backup until it is rotated out. Retention window is 14 days.
  • Statutory retention. Once invoicing exists, accounting records must be kept for seven years under section 212 UGB and section 132 BAO. Such records are blocked from ordinary use and retained solely to meet that obligation.
  • Log and run data are retained for the periods stated in section 13.3(g) and (i).

13.9 Roles: when you are the controller

RawKit is a general-purpose tool. You decide what to put into it.

  • For account, billing, security and service-operation data, the provider is the controller.
  • For the content you place in a workspace — a board with named prospects, a file containing employee data, a research run about identifiable people — you determine the purposes and means. In that respect the provider acts as your processor under Article 28 GDPR, and you are the controller.

If you process personal data of third parties in the Service, you must have your own legal basis, you must satisfy the information duties owed to those people, and you must not upload special categories of data without appropriate safeguards. Business users processing personal data in the Service should conclude a data processing agreement with the provider; a template is available on request at the address in section 2.

Note specifically that the LinkedIn enrichment source returns data about identifiable natural persons who are not users of the Service. When you use it, you become the controller for that data, and Article 14 GDPR information duties may fall on you.

13.10 Security measures

The provider maintains technical and organisational measures appropriate to the risk, including: transport encryption for all connections; encryption of OAuth credentials at rest with AES-256-GCM under a key held outside the database; password storage as salted hashes only; strict tenant isolation with every query scoped to a workspace the caller belongs to; short-lived, board-scoped tickets for collaboration sockets; pre-signed, expiring URLs as the only path to stored files; a restrictive content security policy with framing denied and HSTS enabled; mandatory bearer authentication on the agent gateway, which denies rather than permits when unconfigured; hard per-run budget ceilings; and bot protection on all public authentication endpoints.

13.11 Personal data breaches

If a breach of the security of personal data occurs, the provider will notify the Austrian Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR), and will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR).

13.12 Your rights

You have the right to:

  • access your personal data (Article 15 GDPR);
  • rectification of inaccurate data (Article 16 GDPR);
  • erasure (Article 17 GDPR) — you can trigger this yourself by deleting your account;
  • restriction of processing (Article 18 GDPR);
  • data portability in a structured, commonly used, machine-readable format (Article 20 GDPR);
  • object to processing based on legitimate interests, on grounds relating to your particular situation (Article 21 GDPR);
  • withdraw consent at any time, with effect for the future, where processing is based on consent (Article 7(3) GDPR).

Send requests to the address in section 2. The provider responds within one month, extendable by two months for complex requests, and will tell you if an extension is needed.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Article 77 GDPR). The competent authority for the provider is:

Österreichische Datenschutzbehörde Barichgasse 40–42, 1030 Vienna, Austria dsb@dsb.gv.at · www.dsb.gv.at


14. Confidentiality

14.1 The provider treats your User Content as confidential and does not disclose it to third parties except to the recipients listed in section 13.5 for the purpose of providing the Service, where you instruct disclosure, or where disclosure is legally required.

14.2 Where a legal obligation to disclose arises, the provider will, to the extent legally permitted, inform you before disclosing, so that you can seek legal protection.


15. Warranty (statutory conformity)

15.1 Consumers. The Austrian Consumer Warranty Act (VGG) applies to the supply of digital services to consumers. The provider owes a service that conforms to the contract for the entire period of supply. Your statutory warranty rights — improvement, price reduction, termination — are not restricted by these Terms. The two-year limitation period of section 12 VGG applies where the supply is a single act; for continuous supply, conformity is owed throughout.

15.2 Business users. For business users the following applies: the Service is provided in its then-current state. The provider warrants that the Service substantially performs the functions described in the documentation. Warranty claims are excluded for defects caused by use contrary to these Terms, by modifications you make, by third-party services outside the provider's control, or — during the alpha — by the experimental character of a function that has been marked as such. The warranty period for business users is twelve months from provision. Section 924 ABGB (presumption of defectiveness) is excluded for business users.

15.3 No warranty of output correctness. For both groups: the provider does not warrant that AI-generated output is correct, complete, current or fit for a particular purpose (section 4.3, section 9.5). This is a description of what the Service is, not a limitation of statutory warranty for the service itself.


16. Liability

16.1 Consumers. The provider is liable without limitation for damage caused intentionally or by gross negligence, for personal injury, and under the Austrian Product Liability Act. For slight negligence the provider is liable only for the breach of a material contractual obligation — an obligation whose fulfilment makes proper performance of the contract possible in the first place and on whose observance you may regularly rely — and then limited to the foreseeable damage typical for this kind of contract. Statutory liability that cannot be excluded remains unaffected.

16.2 Business users. Liability for slight negligence is excluded. Liability for gross negligence and intent, for personal injury and under the Product Liability Act remains unaffected. Liability for indirect damage, loss of profit, loss of data (beyond the cost of restoring properly maintained backups), loss of savings and third-party claims is excluded to the extent permitted by law. Aggregate liability towards a business user is limited to the fees paid by that user in the twelve months preceding the event giving rise to liability, and where the Service is used free of charge, to EUR 1,000.

16.3 Data backup. You are responsible for keeping your own copies of content that matters to you. The provider's liability for loss of data is limited to the effort that would have been required to restore it had you kept backups in accordance with ordinary diligence. This does not apply to consumers where it would contravene section 6 KSchG.

16.4 Third-party content and services. The provider is not liable for the content, availability, accuracy or legality of third-party sources, connected platforms or AI provider output, nor for a connected platform's decisions about your account.

16.5 Use of output. You alone decide whether and how to act on the Service's output. The provider is not liable for decisions you take on the basis of research results, funding recommendations, market figures or drafted content, save within the limits of 16.1 and 16.2.


17. Indemnity — business users only

If a third party asserts a claim against the provider because of your User Content, your published content or your use of the Service in breach of these Terms, you will indemnify the provider against that claim and against the reasonable costs of legal defence, unless you are not responsible for the breach. The provider will inform you of the claim without undue delay and will not settle without your consent, which you may not unreasonably withhold.


18. Changes to these Terms

18.1 The provider may amend these Terms where an amendment is necessary because of a change in the law, in case law, in the technical operation of the Service, or because a new function is added, and where the amendment does not upset the balance of the contract to your disadvantage.

18.2 You will be notified of any amendment by email and in the application at least six weeks before it takes effect. The notice will state what changes, when it takes effect, and that you may object.

18.3 If you object before the effective date, the contract continues on the existing terms and either party may terminate on ordinary notice. If you do not object and continue to use the Service after the effective date, the amended Terms apply. The notice will state this consequence expressly.

18.4 Amendments to essential elements of the contract — the description of the service, the price, the term — require your express consent.


19. Term and termination

19.1 The contract runs for an indefinite period.

19.2 Your termination. You may terminate at any time, without notice, by deleting your account in the application or by notifying the provider. For paid plans, termination takes effect at the end of the paid period unless you exercise a statutory right of immediate termination.

19.3 Provider's termination. The provider may terminate a free account on one month's notice. Paid plans may be terminated at the end of the paid period. The right to terminate for cause remains unaffected; cause includes in particular a serious or repeated breach of section 8 that you fail to remedy after being asked to.

19.4 Effect of termination. You lose access to the Service. Export your data before terminating; the Service provides export functions for boards, tables and conversations. After termination the provider deletes your data as described in section 13.8. On request made within 30 days of termination, the provider will provide a copy of your data in a machine-readable format, if it is still available.

19.5 Discontinuation of the Service. If the provider discontinues the Service, users will be notified at least three months in advance and given the opportunity to export their data.


20. Governing law, jurisdiction and dispute resolution

20.1 Governing law. Austrian law applies, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods. For consumers, this choice of law does not deprive you of the protection of the mandatory provisions of the law of your country of habitual residence (Article 6(2) of Regulation (EC) No 593/2008).

20.2 Jurisdiction — business users. The exclusive place of jurisdiction is the court competent for Vienna Inner City, Austria.

20.3 Jurisdiction — consumers. The statutory rules apply. A consumer domiciled in Austria may only be sued in the court of their domicile, habitual residence or place of employment (section 14 KSchG); a consumer domiciled elsewhere in the EU may bring proceedings, and may only be sued, in accordance with Articles 17 to 19 of Regulation (EU) No 1215/2012.

20.4 Alternative dispute resolution. The European Commission's Online Dispute Resolution platform was discontinued on 20 July 2025 by Regulation (EU) 2024/3228 and is no longer available. The provider is not obliged and not willing to participate in dispute resolution proceedings before a consumer arbitration board. Consumers may nevertheless contact the Internet Ombudsstelle (www.ombudsstelle.at) or, for cross-border matters within the EU, the European Consumer Centre Austria (www.europakonsument.at), which advise consumers free of charge. Your right to bring court proceedings is unaffected.


21. Final provisions

21.1 Severability. If a provision of these Terms is or becomes invalid, the validity of the remaining provisions is unaffected. The invalid provision is replaced by the statutory rule. This clause does not reverse the burden of proof to the detriment of a consumer.

21.2 Assignment. You may transfer this contract to a third party only with the provider's written consent. The provider may transfer the contract to a legal successor of the business, in which case you may terminate within one month of being notified.

21.3 Written form. Text form, including email, is sufficient for notices under these Terms.

21.4 Language. These Terms are published in English and German. In the event of a discrepancy, the German version prevails; for consumers, the version in the language in which the contract was concluded prevails.

21.5 Contact. Elijah Ross, Kulmgasse 38/20, 1180 Vienna, Austria, service@ml-canvas.com.


Version 1.1, effective 2026-08-03. Previous versions are available on request.