Legal

Privacy Policy

Your data is yours. This explains exactly what we collect, why, where it lives, and what you can ask us to do with it.

Last updated: 1 August 2026

1. Who we are

GraphBI is a business analytics platform operated from Austria. We act as the data controller for account information and as a data processor for the business data you upload. For any privacy question, write to privacy@graphbi.com.

2. Information we collect

Account information you give us: your name, email address, business name, industry, and country. Business data you upload or connect: spreadsheets, database query results, and the dashboards and reports built from them. Usage information generated automatically: IP address, browser and device type, pages visited, and actions taken inside the product. Payment information is handled by our payment providers — we never see or store full card numbers.

3. Why we process it, and on what legal basis

To provide the service you signed up for and to bill you, on the basis of performing our contract with you. To keep accounts secure, detect abuse, and maintain audit logs, on the basis of our legitimate interest in protecting the platform and its users. To send product updates and marketing, on the basis of your consent, which you can withdraw at any time. To meet accounting, tax, and other legal duties, on the basis of legal obligation.

4. Business data you upload

Data you upload remains yours. We process it only to deliver the service: profiling columns, generating insights, building charts, producing reports, and running the optimisation features you request. We do not sell it, share it with other customers, or use it to train models offered to anyone else. Each customer account is isolated at the database level, so one account can never read another account’s data.

5. Health and other sensitive data

Medical laboratory customers may upload data that includes health information. Where our system detects potentially sensitive columns it flags them, restricts them, and records every access in an audit log retained for six years. You remain the controller of that data and are responsible for having a lawful basis to process it. If you need a Data Processing Agreement before uploading such data, contact privacy@graphbi.com and we will provide one.

6. Where your data is stored

All data is hosted in ISO 27001-certified data centres in the European Union. Storage volumes are encrypted, database contents are encrypted at rest, and all traffic between you and GraphBI is protected with TLS 1.3. Credentials for any database you connect are encrypted before being written to our systems and are never returned through the interface.

7. How we protect your account

Multi-factor authentication is available and enforced for administrative access. Passwords are stored as one-way hashes and are never recoverable, by us or anyone else. Every significant action is written to an audit log. API keys are scoped and revocable. We apply rate limiting and automated blocking of suspicious traffic, and we run automated dependency and vulnerability scanning on every deployment.

8. Who else processes your data

We use a small number of service providers, each bound by contract to protect your data: Contabo GmbH (Germany) for hosting; Stripe and Paystack for payment processing; Mailtrap for transactional email delivery; and a self-hosted analytics instance we operate ourselves, which uses no cookies and shares no data with third parties. We do not share your data with advertisers.

9. How long we keep it

Account and business data is kept while your account is active. If you close your account, personal data is deleted within thirty days, except where we must keep records longer for legal or accounting reasons. Audit logs relating to sensitive data access are retained for six years to meet healthcare record-keeping expectations. Backups are rotated and expire within thirty-five days.

10. Your rights

You may request a copy of the personal data we hold about you, correct anything inaccurate, ask us to delete your account and data, receive your data in a portable format, object to processing based on legitimate interest, or withdraw consent for marketing. Write to privacy@graphbi.com and we will respond within thirty days. If you are unhappy with our response, you may complain to your local data protection authority — in Austria this is the Datenschutzbehörde.

11. Cookies

We use cookies that are strictly necessary to keep you signed in and to protect against cross-site request forgery, plus cookies that remember your preferences such as language and theme. Our website statistics are collected by a self-hosted analytics tool that we operate ourselves, does not use cookies, and does not track visitors across sites. We use no advertising or third-party tracking cookies.

12. International transfers

Our infrastructure is located in the European Union. Where a customer or service provider is outside the EU, transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision.

13. Children

GraphBI is a business tool intended for use by adults acting on behalf of an organisation. We do not knowingly collect personal information from anyone under eighteen.

14. Changes to this policy

If we make a significant change we will email account owners and show a notice inside the product at least thirty days before it takes effect. The date below always shows when this policy was last revised.

15. Contact

Privacy questions and data rights requests: privacy@graphbi.com. General support: support@graphbi.com. We aim to reply to every privacy request within thirty days, and usually much sooner.

GraphBI

Analytics and operations research for retail, medical laboratories, and logistics.

Hosted in ISO 27001-certified EU data centres.

Product
FeaturesIndustriesPricingSecurity
Company
AboutBlogCareersContact
Legal
Privacy PolicyTerms of Service
Get started
Start free trialSign in
© 2026 GraphBI · Operating from Austria