Skip to content
AttestAI
ProductSecurityDocsReadiness checkPricingDashboardSign inContact

Legal

Terms of Service and Privacy Policy.

VERSION 2026-07-25EFFECTIVE 25 JULY 2026APPLIES TO ATTESTBASE.COM / APP. / API.

This page is the agreement between you and AttestBase. It was written after a full reading of Regulation (EU) 2024/1689 (the EU AI Act) as amended by the Digital Omnibus, because our product exists to serve teams regulated by it - and because a compliance vendor should be precise about what it does and does not do. Accepting these terms is required to create an account.

Contents: Plain-English summary / Terms of Service / Acceptable use / Privacy Policy / EU AI Act scope statement / How acceptance is recorded

Plain-English summary

This summary is for readability only; the numbered sections below are the binding text.

  • AttestBase is a business tool: a tamper-evident audit ledger and evidence-pack generator for AI systems. You must accept these terms when you create an account; we record the version you accepted, when, and from which IP address.
  • Your data stays yours. The ledger is append-only by design: nobody, including us, edits sealed records. You can export everything, any time, with the hashes needed to verify it independently.
  • We are an evidence layer, not a law firm and not a conformity assessment body. Using AttestBase does not make you compliant with the EU AI Act or any other law. Classification, conformity assessment, registration, and filings remain your responsibility.
  • Do not send us raw biometric data or personal data you do not need to record, and do not use the service in connection with AI practices prohibited by Article 5 of the EU AI Act. We can refuse and terminate service for that.

Terms of Service

1. Who we are and what these terms cover

These Terms of Service (the "Terms") govern access to and use of the AttestBase websites (attestbase.com), the AttestBase application (app.attestbase.com), the AttestBase API (api.attestbase.com), the AttestBase SDKs, and the services provided through them (together, the "Service"), operated by Matthaios Markatis, trading as AttestBase, of 67 Queen Street, United Kingdom ("AttestBase", "we", "us"). If we sign a separate written agreement with your organisation (an "Enterprise Agreement"), that agreement prevails over these Terms to the extent of any conflict.

The Service is offered to businesses and other organisations only. By accepting these Terms you confirm that you are acting in the course of a trade, business, or profession, and not as a consumer.

2. Definitions

  • Customer: the organisation on whose behalf an account is created.
  • Authorised User: an individual who accesses the Service under the Customer's account, including via invite links.
  • Customer Data: events, traces, payloads, and any other content submitted to the Service by or for the Customer, and the evidence packs and exports generated from it.
  • Ledger: the append-only, hash-chained event store operated by the Service.
  • EU AI Act: Regulation (EU) 2024/1689, as amended, including by the Digital Omnibus on AI.
  • AI Act roles: "provider", "deployer", and "operator" have the meanings given in Article 3(3), 3(4), and 3(8) of the EU AI Act.

3. Account registration and acceptance

Creating an account requires explicit acceptance of these Terms and the Privacy Policy. Acceptance is enforced by the sign-up API itself, and we record the version tag of the text accepted, a timestamp, and the originating IP address (see How acceptance is recorded). If you accept on behalf of an organisation, you warrant that you have authority to bind it. Authorised Users joining an existing account through an invite create their own account through the same acceptance-gated sign-up.

You are responsible for the confidentiality of credentials and API keys issued to your account, for configuring key scopes appropriately, and for all activity under them until you revoke them in the dashboard or notify us of compromise.

4. The Service

The Service provides:

  • ingestion of AI-system telemetry via the native SDK, HTTP API, and OpenTelemetry (OTLP) endpoints, sealed into a per-project hash chain where each event records the hash of its predecessor;
  • integrity verification endpoints that re-walk the chain on demand, scheduled automatic verification, signed checkpoints, and optional public anchoring of checkpoint batches via RFC 3161 timestamps (only a 32-byte aggregate hash ever leaves the platform);
  • enforced retention (a floor of 183 days, configurable upwards, plus legal hold), full export in JSONL or CSV including all hash columns, and redaction tooling that removes payload content while preserving chain integrity;
  • evidence packs (JSON and PDF) that map recorded events to specific EU AI Act articles, for use in procurement reviews, questionnaires, and audits.

5. What the Service is not

This section is central to these Terms. AttestBase is an evidence and record-keeping layer. It is not, and does not replace:

  • legal advice, or a determination of how the EU AI Act or any other law applies to you;
  • classification of your systems (Art 6, Annex III) or documentation and registration of a not-high-risk claim (Arts 6(3)-(4), 49(2));
  • a risk management system (Art 9), data governance (Art 10), complete technical documentation (Art 11, Annex IV), instructions for use (Art 13), or the human oversight measures themselves (Art 14);
  • accuracy, robustness, or cybersecurity engineering of your systems (Art 15);
  • conformity assessment (Art 43), an EU declaration of conformity (Art 47), CE marking (Art 48), or EU database registration (Art 49);
  • a fundamental rights impact assessment (Art 27), or general-purpose AI model documentation and evaluations (Arts 53, 55);
  • the disclosure user interfaces, content marking, or watermarking technology required by Article 50 - the Service records that and when your disclosures and markings happened, not the mechanisms themselves.

AttestBase is not a notified body, certification body, or conformity assessment body within the meaning of Articles 28-39 of the EU AI Act, and does not act as an authorised representative (Art 3(5)). Despite the product name, nothing we produce is a certificate, an attestation of conformity, or a source of any presumption of conformity - under the Act those flow only from harmonised standards, common specifications, and the other routes the Act itself names (Arts 40-42). The Service itself is a deterministic record-keeping system: it does not infer outputs and is not an AI system within the meaning of Article 3(1).

Evidence packs and exports reflect only the telemetry you actually send. The Service proves that sealed records have not been altered since they were recorded; it cannot prove that what your systems reported was accurate when they reported it. We cannot record what your systems do not emit, and we make no representation that any regulator, notified body, or counterparty will accept any output of the Service as sufficient for any purpose. Using the Service does not make you compliant with the EU AI Act; it gives you verifiable records with which to demonstrate the parts of compliance that depend on records.

6. Your regulatory responsibilities

You remain the provider, deployer, or other operator of your AI systems in the sense of Article 3 of the EU AI Act. AttestBase acquires none of those roles by supplying the Service. This section is an informative summary as at the version date above, not legal advice and not an exhaustive statement of the law; the dates below reflect the EU AI Act as amended by the agreed Digital Omnibus compromise text (procedure 2025/0359(COD)), and the version published in the Official Journal prevails. In particular:

  • The EU AI Act can reach you regardless of where you are established, including where the output produced by your system is intended to be used in the Union (Art 2(1)(a), (c)). You, not we, determine your scope status and your role or roles - roles can be held cumulatively and can change over time.
  • Prohibited-practice rules (Art 5) have applied since 2 February 2025; the prohibitions added by the Digital Omnibus on non-consensual intimate imagery and child sexual abuse material apply from 2 December 2026.
  • Article 50 transparency duties (AI-interaction disclosure, machine-readable marking of synthetic content, emotion-recognition and deepfake disclosure) apply from 2 August 2026; generative systems already on the market before that date have until 2 December 2026 to comply with Article 50(2) marking.
  • High-risk obligations (Arts 8-27), including the logging, retention, and oversight duties the Service is designed to evidence, apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I embedded systems, as deferred by the Digital Omnibus.
  • Log-retention duties are yours: providers and deployers must keep automatically generated logs under their control for a period appropriate to the system's purpose, at least six months, unless other Union or national law - in particular data protection law - provides otherwise (Arts 19(1), 26(6)). The Service's 183-day retention floor supports this minimum, but determining the period appropriate to your system - longer where a statute requires it, shorter where data protection law caps it (the redaction facility exists for that) - is your decision. Ten-year documentation duties (Arts 18, 47) also remain yours, and the ledger does not discharge them.
  • Serious-incident reporting clocks run against you: not later than 15 days from awareness in the general case, 10 days for a death, 2 days for widespread infringement or serious and irreversible disruption of critical infrastructure (Art 73(2)-(4)). The Service's timestamps can evidence when you became aware and what happened; identifying, triaging, and filing the report is your obligation. Article 73(6) also requires you to investigate without altering the system in ways that would affect later evaluation of causes - an append-only ledger helps you show that, but the duty is yours.
  • Authorities may demand access to logs and documentation, including via API (Arts 21(2), 74(12)). The Service's export and verification endpoints exist partly so you can honour such demands; deciding to grant access, and granting it, is your act, not ours.
  • Putting your name on, substantially modifying, or repurposing a third-party system can make you its provider with the full obligations of Article 16 (Art 25). Nothing in these Terms reallocates any obligation you owe to a regulator or authority - contractual arrangements operate only between you and us.
  • Penalties under the EU AI Act reach up to EUR 35 million or 7% of worldwide turnover for prohibited practices, and up to EUR 15 million or 3% for breaches of provider, deployer, and transparency obligations (Art 99(3)-(4)); for SMEs and start-ups each cap is the lower of the two figures (Art 99(6)). Infringements are additionally actionable through consumer representative actions (Directive (EU) 2020/1828, as amended by Art 110 of the Act). All of this attaches to you as an operator; nothing in the Service shifts it to us.

7. Acceptable use

You must not use the Service:

  • in connection with any AI practice prohibited by Article 5 of the EU AI Act, including manipulative or exploitative techniques causing significant harm, social scoring with unjustified detrimental treatment, crime-risk prediction based solely on profiling, untargeted scraping of facial images for recognition databases, emotion inference in workplaces or education (outside the medical and safety exceptions), biometric categorisation deducing protected attributes, unlawful real-time remote biometric identification, or the creation or dissemination of non-consensual intimate imagery or child sexual abuse material;
  • to store raw biometric identifiers, or images, audio, or other content from which individuals can be biometrically identified. Where the EU AI Act requires biometric-related logging (Art 12(3)), send references or hashes to records held in your own systems, never the biometric data itself;
  • to store special categories of personal data (Article 9 GDPR). In particular, data processed under the EU AI Act's bias-detection basis must by law not be transmitted to or accessed by other parties (Art 10(5)(d)) - and we are another party;
  • to store personal data beyond what recording the operation of your systems reasonably requires (data minimisation applies to telemetry too), or any content that is unlawful to store or process;
  • for law-enforcement, border-management, migration, or asylum deployments involving sensitive operational data (Annex III points 1, 6 and 7 contexts) - these carry statutory confidentiality and on-premises documentation rules our standard multi-tenant terms do not address; contact us for bespoke terms;
  • to attempt to defeat, probe, or overload the Service's integrity or security mechanisms, or to access other customers' data;
  • to resell or white-label the Service without a written agreement with us.

We may suspend or terminate access for breach of this section. Where we reasonably believe the Service is being used in connection with an Article 5 prohibited practice or content that is illegal to host, we may suspend immediately and without notice.

8. Customer Data and the ledger

  • Customer Data belongs to the Customer. You grant us the rights needed to host, process, verify, back up, and return it, and to operate and improve the Service. We do not use Customer Data to train machine-learning models and we do not sell it.
  • Your telemetry remains under your control in the sense the EU AI Act uses that phrase (Arts 19(1), 21(2), 26(6)): you retain access, retrieval, and export rights at all times, which is why the log-retention and authority-access duties attached to logs "under your control" remain yours and are not assumed by us.
  • Preservation: on becoming aware of a serious incident, an authority request, or litigation, you are responsible for suspending deletion, redaction, and retention reductions for affected projects - the legal-hold setting exists for this, and invoking it is your act. The Act itself prohibits incident investigations that alter evidence before authorities are informed (Art 73(6)).
  • The ledger is append-only by design. Sealed events cannot be edited - by you or by us. This immutability is enforced at the database level and is the point of the product; you accept that the Service offers redaction (cryptographic erasure of payload content that preserves chain integrity) rather than record editing or deletion within a retention window.
  • Retention is enforced with a floor of 183 days. You configure longer periods and legal holds per project. You are responsible for choosing retention that meets your own legal obligations (see section 6).
  • You can export your full ledger at any time, including all hash columns needed for independent re-verification.
  • On termination of the account we make export available for 30 days, after which Customer Data is deleted, except where a legal hold you configured, our legal obligations, or pending disputes require otherwise. Acceptance records and the security audit trail are retained as described in the Privacy Policy.

9. Subscriptions and billing

New organisations start without an active plan: you can sign in, manage your team, and read these Terms, but the data plane (ingest, reads, evidence packs, key minting) is locked until a plan is activated for you by our team. There is no self-serve card checkout at present; plans, pricing, and periods are agreed with us directly. When a plan expires or is cancelled, the data plane locks again; your data remains stored and disabling credentials or endpoints always works regardless of billing state. Fees are exclusive of taxes; agreed fees are non-refundable except where stated otherwise in an Enterprise Agreement or required by law.

10. Confidentiality

Each party will protect the other's confidential information with at least the care it uses for its own, and use it only to perform under these Terms. Confidential information may be disclosed where required by law or a competent authority; where lawful, the disclosing party will give prompt notice and disclose no more than is required. We treat your telemetry as your confidential business information; note that once evidence enters a regulatory process, authorities' own confidentiality duties (Article 78 of the EU AI Act) apply rather than these Terms, and authorities may lawfully share information onward. Nothing in these Terms restricts anyone from making protected reports under Directive (EU) 2019/1937 (whistleblower protection).

10a. Value-chain cooperation

Where Article 25(4) of the EU AI Act or an equivalent duty requires cooperation along the AI value chain, we will provide the information and technical access that we actually hold and that is necessary for your compliance, based on the generally acknowledged state of the art, under a written agreement and without compromising our intellectual property rights or trade secrets. AttestBase telemetry tooling operates alongside your AI systems; it is not a component of them, and nothing in these Terms makes us a provider, deployer, importer, or distributor of your systems.

11. Security

We operate technical and organisational measures appropriate to a service whose purpose is integrity: per-event hash chaining, signed checkpoints, optional public anchoring, credential hashing (passwords with scrypt, API keys and session tokens stored only as SHA-256 digests), transport encryption, strict rate limiting, login lockout, a recorded security audit trail, and EU-region hosting. No security is absolute; we do not promise the Service is invulnerable, and you must promptly notify us of any suspected compromise of your credentials.

12. Availability and changes to the Service

We provide the Service with reasonable skill and care. Unless an Enterprise Agreement says otherwise, we do not promise a particular availability level, and we may improve or modify the Service provided we do not materially reduce its core function (tamper-evident recording, verification, retention, export) without reasonable advance notice.

13. Intellectual property

We own the Service, its software, documentation, and marks. You own Customer Data and the reports and packs generated from it. Feedback you choose to give us may be used without obligation.

14. Disclaimer of warranties

Except as expressly stated in these Terms, the Service is provided "as is" and "as available", without warranties of any kind, express or implied, including fitness for a particular purpose. Without limiting the foregoing, we do not warrant that use of the Service will satisfy any legal or regulatory requirement applicable to you, including the EU AI Act, or that any output of the Service will be accepted by any authority, notified body, auditor, or counterparty. Before submitting any evidence pack, export, or report to an authority, you must review and verify it: supplying incorrect, incomplete, or misleading information to authorities carries its own penalty under the EU AI Act (Art 99(5)), and that exposure is yours.

15. Liability

Neither party excludes liability for death or personal injury caused by negligence, fraud, or any liability that cannot lawfully be excluded. Subject to that: (a) neither party is liable for indirect or consequential loss, loss of profits, revenue, or goodwill; (b) our total aggregate liability arising out of or in connection with the Service in any 12-month period is limited to the fees paid by the Customer for the Service in that period or EUR 1,000, whichever is greater; and (c) we are not liable for regulatory penalties, enforcement action, or third-party claims arising from your AI systems, your classification decisions, your filings or failures to file, or the completeness of the telemetry you chose to record.

16. Indemnity

You will defend and indemnify us against third-party claims, fines, and regulatory action arising from your AI systems and their outputs, your breach of section 7 or 8, or Customer Data you submitted in breach of these Terms.

17. Term, suspension, and termination

These Terms apply from acceptance until the account is closed. Either party may terminate for material breach not cured within 30 days of notice; we may suspend immediately as described in section 7 or where necessary to protect the Service or other customers. Sections that by their nature survive (including 8, 10, 13-16, and 19) survive termination.

18. Changes to these Terms

We may update these Terms. Material changes will be announced with reasonable advance notice via the dashboard or email to account owners, and this page's version tag and effective date will change. Continued use of the Service after the effective date constitutes acceptance of the updated Terms; the version each account accepted at sign-up remains on record.

19. General

These Terms, the Privacy Policy, and any Enterprise Agreement are the entire agreement. Neither party may assign without consent, except to an affiliate or in connection with a merger or asset sale. If a provision is unenforceable, the remainder stands. Notices to us go to the contact address below; notices to you go to the account owner's email. These Terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except that nothing prevents either party seeking injunctive relief for misuse of confidential information or intellectual property in any competent court.

Privacy Policy

1. Our two roles

For account data, website data, and billing and security records, AttestBase is the data controller. For personal data inside Customer Data - whatever your systems' telemetry contains - AttestBase is a processor acting on the Customer's documented instructions; the Customer is the controller. A data processing agreement covering our processor role is available on request and is included in Enterprise Agreements. Regulation (EU) 2016/679 (GDPR) applies alongside the EU AI Act (Art 2(7)).

2. What we collect as controller

  • Account data: name, work email, organisation name, and a scrypt hash of your password (never the password itself).
  • Security and audit data: sign-in and sign-up events with IP address and user agent, session records, API-key usage metadata, and the security audit trail visible to your organisation.
  • Terms acceptance records: the version accepted, a timestamp, and the IP address, kept as evidence of agreement.
  • Contact form submissions on the marketing site: the details you choose to send us.
  • The marketing site sets no cookies and runs no third-party analytics or advertising trackers. The application uses a single strictly necessary session cookie (attest_session) to keep you signed in.

3. Why we process it (legal bases)

  • Performing our contract with you: operating accounts, authentication, support, billing (GDPR Art 6(1)(b)).
  • Legitimate interests: securing the Service, preventing abuse and fraud, rate limiting, maintaining audit trails (Art 6(1)(f)).
  • Legal obligations: tax, accounting, responding to lawful requests (Art 6(1)(c)).

4. Personal data inside the ledger

The ledger stores what your systems send. You instruct us to store it by sending it; you are responsible for minimising personal data in telemetry and for the lawfulness of recording it. Never send raw biometric data (see Acceptable use). Where a data subject exercises erasure rights against you, the redaction API removes payload content while preserving the hash chain, so honouring GDPR rights does not break ledger integrity. Data subjects whose personal data appears in a customer's ledger should contact that customer as controller; we assist customers with such requests under the data processing agreement.

5. Retention

  • Account data: for the life of the account and up to 12 months after closure, except where law requires longer.
  • Security audit records and terms acceptance records: retained as evidence for as long as relevant claims could arise.
  • Customer Data: per the retention policy the Customer configures (183-day enforced minimum, optional legal hold), then purged; after account closure, deleted following the 30-day export window described in the Terms.

6. Hosting and subprocessors

The Service is hosted in the EU: the API and its database run in EU regions (currently Frankfurt), and the web applications and marketing site are served via Cloudflare, which also stores contact-form submissions. Where public anchoring is enabled, the only data sent to the external RFC 3161 timestamp authority is a 32-byte aggregate hash, which contains no personal data. Where any provider processes personal data outside the EEA, we rely on adequacy decisions or standard contractual clauses. A current subprocessor list is available on request.

7. Your rights

Where we act as controller you have the GDPR rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Exercise them via the contact below. Note that some records - notably the security audit trail and terms acceptance records - are kept precisely to evidence what happened and may be retained on legal-obligation or legitimate-interest grounds where the GDPR permits.

8. Contact

Privacy and legal contact: Matthaios Markatis, 67 Queen Street, United Kingdom; matthaiosmarkatis@gmail.com. We will update this page when this policy changes; material changes are announced as described in the Terms.

EU AI Act scope statement

This statement is informational, not legal advice. It exists so that no customer, prospect, or auditor can mistake what AttestBase claims. The same scope statement ships inside every evidence pack.

What the Service is built to evidence

EU AI Act referenceObligationWhat AttestBase contributes
Art 12Automatic recording of events over the system lifetimeThe ledger is this capability for the events you send: always-on ingest, append-only storage, verifiable integrity
Arts 19(1), 26(6)Providers and deployers keep logs at least six monthsEnforced 183-day retention floor, configurable upwards, legal hold
Art 14(4)Human oversight capabilities exercised in practicehuman.override / human.approval / human.review events with actor identity
Art 50Transparency disclosures and machine-readable markingdisclosure.shown and content.marked events prove delivery and timing; the disclosure UI and marking technology are yours
Arts 72, 73Post-market monitoring data; serious-incident timelinesThe event corpus is the collection layer; incident.flagged timestamps evidence the awareness clock; append-only history supports the Art 73(6) no-alteration duty
Arts 21(2), 74(12)Authority access to logs and documentationExport and verification APIs; evidence packs in JSON and PDF

What the Service never claims

Risk management systems (Art 9); data governance (Art 10); full technical documentation (Art 11 / Annex IV); instructions for use (Art 13); accuracy, robustness, and cybersecurity engineering (Art 15); conformity assessment (Art 43); declaration of conformity and CE marking (Arts 47-48); registration (Art 49); fundamental rights impact assessments (Art 27); GPAI documentation and evaluations (Arts 53, 55); legal classification advice of any kind.

Key dates (post-Digital-Omnibus)

Dates below reflect Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI per the agreed compromise text (Council document ST 9247/26, procedure 2025/0359(COD)). The deferral dates are fixed calendar dates with no conditionality. The version published in the Official Journal of the European Union prevails over this summary, and this page is reviewed against it.

DateWhat applies
2 Feb 2025Prohibited practices (Art 5) and AI literacy (Art 4) - in force now
2 Aug 2025GPAI obligations, governance, penalties framework - in force now
2 Aug 2026Article 50 transparency (all paragraphs); general application of the non-deferred remainder
2 Dec 2026Art 50(2) marking deadline for generative systems already on the market; new Art 5 prohibitions (NCII, CSAM)
2 Dec 2027High-risk obligations (Arts 6-27) for Annex III standalone systems
2 Aug 2028Same, for Annex I embedded systems

We deliberately do not claim high-risk duties bite in 2026. They do not. The honest pitch, and the one these Terms are built on: questionnaire-ready today, Article 50 evidence for August 2026, audit-ready for December 2027.

How acceptance is recorded

Creating an account requires ticking the acceptance box on the sign-up page (or passing acceptTerms: true when signing up via the API). The sign-up service refuses account creation without it, and writes an acceptance record - the version tag shown at the top of this page, a UTC timestamp, and the originating IP address - in the same database transaction that creates the account, so no account can exist without one. You can request a copy of your acceptance record via the contact address above. When these Terms change materially, the version tag changes and existing accounts are notified as described in section 18.

Back to the home page

AttestBase - the audit ledger for AI agents.Contact / Terms & privacy / matthaiosmarkatis@gmail.com