Privacy Policy

Last updated: April 2026 · Járnhaus

1. Controller Identity

Järnhaus operates the Völundr platform (völundr.dev). You can contact us at: legal@volundr.dev.


2. Data Protection Officer (DPO)

We have not appointed a Data Protection Officer as we are not required to do so under Article 37 GDPR at this time.


3. Data Collected

We collect and process the following personal data:

  • Email address (collected at registration via NextAuth)
  • Project name, description, and AI-generated artifacts (project data you submit)
  • Technical identifiers: session tokens (HTTP-only cookies), IP address (in server logs)
  • Usage data: page views, feature interactions (if analytics consent is granted)

4. Purposes and Legal Basis

We process your personal data for the following purposes:

  • Service delivery and account management — legal basis: Article 6(1)(b) performance of contract
  • Security, fraud prevention, and authentication — legal basis: Article 6(1)(f) legitimate interests
  • Analytics to improve the platform — legal basis: Article 6(1)(a) consent (only if analytics cookies accepted)
  • Transactional email notifications (e.g., email verification) — legal basis: Article 6(1)(b) performance of contract

5. Sub-processors

We engage the following sub-processors to operate the platform:

Neon Inc. / PostgreSQL (data storage)

Your project data and account information are stored in a managed Postgres database hosted by Neon. [REGION: verify Neon database region — confirm EU-Frankfurt or US-East before publication]

Resend Inc. (transactional email)

Your email address is shared with Resend to deliver verification and notification emails. Resend is US-based; data is transferred under Standard Contractual Clauses (SCCs).


6. International Transfers

Resend Inc. is headquartered in the United States. Data transferred to Resend is protected by Standard Contractual Clauses (SCCs) approved by the European Commission. [REGION: if Neon database is US-hosted, add SCC/DPF language for Neon here.]


7. Retention Periods

  • Account data: retained until you delete your account
  • Project artifacts (AI-generated code, PRDs, architecture docs): retained until you delete the project or your account
  • Session data: cleared on sign-out or after browser session ends
  • Email delivery logs: retained for up to 30 days by Resend; we do not store email logs independently
  • Server access logs: retained for up to 90 days

8. Your Rights (GDPR Chapter III)

Under GDPR you have the right to: access your personal data; correct inaccurate data; request erasure (“right to be forgotten”); restrict processing; receive your data in a portable format; object to processing based on legitimate interests. To exercise these rights, contact us at legal@volundr.dev.


9. Consent Withdrawal

You may withdraw cookie consent at any time by visiting our Cookie Policy page and clearing your preferences, or by clearing localStorage in your browser settings. Withdrawal does not affect processing that occurred before withdrawal.


10. Right to Lodge a Complaint

You have the right to lodge a complaint with your national data protection authority. [SA: insert your national supervisory authority name and URL — e.g., Polish DPA (UODO): uodo.gov.pl for Polish-registered entities]


11. Automated Decision-Making

Völundr uses AI models to generate software artifacts (code, architecture documents, test plans) based on your project descriptions. This AI-assisted generation is a service feature requested by you — it does not constitute automated decision-making or profiling of your personal data within the meaning of GDPR Article 22.


12. Cookies

We use strictly necessary cookies for session authentication (see our Cookie Policy for the full list). Optional analytics and marketing cookies are off by default and only activated with your explicit consent via our cookie consent banner.


Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email to registered users or via a notice on the platform. The “Last updated” date at the top of this page reflects the most recent revision.

If you have questions about this Privacy Policy, please contact us at legal@volundr.dev.