Skip to content
ASK & CHART

Legal

Last updated: August 14, 2026

This page consolidates the legal commitments behind Ask & Chart beyond the Terms of Service and the Privacy Policy: how we process the business data you pour into your workspace, the subprocessors we rely on, the security measures we operate, where data lives, and how billing and taxes work. It forms part of the Terms of Service between you and us.

1. Roles

Ask & Chart is operated by Athanix OÜ, the entity identified in our Legal Notice and the entity you contract with. For the account data we hold about you, we are the controller, as described in our Privacy Policy. For the business data you pour into your workspace, you are the controller and we are the processor: we process it only to provide the Service (profiling your sources, proposing and computing over confirmed joins, rendering dashboards, exporting on your request) and on your documented instructions, which are the configuration choices you make in the Service. You are responsible for having a lawful basis for the personal data you pour in.

2. What we will not do with workspace data

We do not sell workspace data. We do not use it to train third-party models. We do not read it except to operate, support, or secure the Service, and access is limited to personnel who need it for those purposes and who are bound by confidentiality obligations.

3. Subprocessors

We rely on a limited set of vetted subprocessors, each engaged under a written contract that restricts their use of data to providing their service:

SubprocessorRoleProcessing locationTransfer safeguard
Vercel Inc.Web application hosting and content deliveryEuropean UnionUS-incorporated; EU-US Data Privacy Framework and/or SCCs
Neon Inc.Managed PostgreSQL databaseEuropean UnionUS-incorporated; DPF and/or SCCs
Cloudflare, Inc.Object storage for uploaded documents (R2)European Union and global edgeUS-incorporated; DPF and/or SCCs
Stripe Payments Europe, Ltd. and Stripe, Inc.Payment processing for paid plansEuropean Union and United StatesDPF and/or SCCs
Brevo (Sendinblue SAS)Transactional email delivery (sign-in links)European Union (France)Not applicable (EEA)
Anthropic PBCThe AI model that proposes queries and connection candidatesPer the region configured for your workspaceDPF and/or SCCs
Hetzner Online GmbHInfrastructure for the durable processing pipelineEuropean Union (Germany)Not applicable (EEA)
Functional Software, Inc. (Sentry)Error monitoringEuropean Union and United StatesDPF and/or SCCs

We will give account holders reasonable notice before adding or replacing a subprocessor that processes workspace data, so you can object on legitimate grounds.

4. Security measures

Encryption: TLS for data in transit; encryption at rest for workspace data, account data and backups. Credentials you connect (for example a read-only database connection string) are encrypted at rest and never stored in plain text.

Access control: least-privilege access on a need-to-know basis; restricted administrative access; personnel bound by confidentiality.

Isolation: per-workspace data isolation enforced at the database layer, so one tenant cannot reach another tenant's data.

Application integrity: every figure is computed by a version-stamped deterministic engine from confirmed data; the AI proposes and explains but never produces a number, so a model error cannot silently corrupt output.

Authentication: passwordless sign-in via one-time links; secure sessions tied to the account.

Resilience: established cloud infrastructure with managed databases and object storage; regular encrypted backups; monitoring and incident response. If we become aware of a personal data breach affecting workspace data we process for you, we will notify you without undue delay and cooperate with your notification obligations.

5. Where data lives

Workspace data is hosted in the European Union by default. Processing that happens in the United States (payments through Stripe, and AI proposals depending on the region configured for your workspace) is covered by the written contract we hold with each provider, listed with its transfer safeguard in the subprocessor table above.

6. Data subject requests, export, and deletion

Requests from data subjects whose personal data sits in your poured-in sources are yours to handle as controller; the Service gives you tools to inspect, export, and delete workspace data directly, and we will provide reasonable assistance where a request needs more than those tools. If a data subject contacts us directly, we will refer them to you. On termination you have a reasonable period to export workspace data before it is deleted, except where we must retain data by law.

7. Billing and taxes

Paid plans are billed in advance through Stripe at the prices shown at checkout and on the pricing page, in US dollars. Subscriptions renew automatically until cancelled. We are not currently subject to VAT collection. Where taxes apply, Stripe computes them automatically from the billing location. Except where required by law, payments are non-refundable.

8. Audit and information

On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide information reasonably necessary to demonstrate our compliance with the commitments on this page.

9. Contact

Legal and contractual matters: legal@askandchart.com. Privacy and data protection: privacy@askandchart.com. Security reports: security@askandchart.com. Our postal address and registered details are in the Legal Notice.

Legal | Ask & Chart