top of page

Privacy Policy

​​​

Last updated: 11 August 2026

​

This Privacy Policy explains how Post AI Systems collects, uses, stores and otherwise processes personal data when you visit this website, contact us, submit an enquiry or structured intake, discuss a possible collaboration, or work with us.

Post AI Systems is a capability-development and innovation practice based in Berlin, Germany. Our work includes capability architecture and positioning; collaborative R&D, consortium and European project development; and, where appropriate, governed AI-enabled delivery systems.

Our work may involve technology companies, research organisations, public institutions, NGOs, consortia and other professional partners operating in areas including deep technology, security, defence, resilience, dual-use innovation, civic participation and public-sector innovation.

We apply data minimisation and do not ask visitors to submit classified, export-controlled, restricted or highly sensitive technical information through general website forms or ordinary website enquiries. If your work involves sensitive information, appropriate handling arrangements should be agreed before it is shared.

​

1. Who is responsible for your data?

​

For personal data processed through this website and our own business activities, the controller is:

Post AI Systems
Joe Mac
Berlin, Germany
Email: contact@postaisystems.com
Website: www.postaisystems.com

 

For privacy-related questions or requests, please contact:

contact@postaisystems.com

 

In some client or consortium engagements, Post AI Systems may process personal data on behalf of another organisation rather than for its own purposes. Where Post AI Systems acts as a processor, the respective client or partner remains the controller and the processing is governed by the relevant agreement and, where required, a data-processing agreement.

 

2. What personal data may we collect?

 

The information we process depends on how you interact with us.

 

Website and technical data

When you visit the website, technical information may be processed automatically, including:

  • IP address;

  • browser and device information;

  • operating system;

  • approximate location derived from technical information;

  • date and time of access;

  • referring page;

  • pages viewed;

  • website interactions; and

  • security, diagnostic and performance information.

 

Contact and enquiry information

When you contact us, submit an enquiry, arrange a discussion or complete a structured intake, we may process information such as:

  • name;

  • professional email address;

  • telephone number, where provided;

  • organisation;

  • website;

  • country or location;

  • professional role;

  • organisation type;

  • your enquiry or requested service;

  • communication history; and

  • any additional information you choose to provide.

 

Capability, project and collaboration information

Where relevant to assessing or delivering an engagement, you may also provide information concerning:

  • technical assets, technologies, results or services;

  • operational requirements;

  • intended users or use cases;

  • capability or technology maturity;

  • readiness level or TRL;

  • complementary technologies or dependencies;

  • existing or prospective partners;

  • consortium status;

  • research or development gaps;

  • demonstration or validation requirements;

  • programme or funding interests;

  • project concepts;

  • organisational constraints;

  • governance or delivery requirements; and

  • other information necessary to understand the capability, project or collaboration.

Please provide only information you are authorised to share.

 

Client and project information

If you become a client, partner or collaborator, we may additionally process:

  • contracts and commercial correspondence;

  • invoicing and payment information;

  • project documents;

  • capability and project materials;

  • partner and consortium information;

  • meeting notes;

  • research and evidence records;

  • draft and final deliverables;

  • review and approval records;

  • workflow and delivery records; and

  • other information required to perform the agreed work.

Project documents may sometimes contain personal data relating to employees, consortium members, experts, stakeholders or other individuals. Organisations providing such information are responsible for ensuring that they are entitled to share it.

 

3. Why do we process personal data?

​

We may process personal data to:

  • operate, maintain and secure this website;

  • respond to enquiries and communications;

  • understand your organisation, capability, project or collaboration context;

  • assess whether Post AI Systems can appropriately contribute to an initiative;

  • prepare discussions, proposals, offers or contracts;

  • provide capability-development services;

  • develop capability architectures, use cases and partnership structures;

  • support collaborative R&D, consortium and European project development;

  • coordinate project or partner contributions;

  • design and deliver governed AI-enabled systems where agreed;

  • manage client, partner and consortium relationships;

  • maintain project documentation, evidence and decision records;

  • organise meetings and professional communications;

  • issue invoices and maintain accounting records;

  • fulfil contractual and legal obligations;

  • protect our systems, information and business activities;

  • improve our services, methods and website; and

  • establish, exercise or defend legal claims where necessary.

 

4. Legal bases for processing

​

Depending on the circumstances, personal data is processed under one or more of the following legal bases under the GDPR.

 

Contract or steps before entering into a contract

We process information where necessary to respond to a service request, assess a possible engagement, prepare an offer or contract, or perform an agreed service.

 

Legitimate interests

We may process information where necessary for legitimate professional purposes, including:

  • operating and protecting the website;

  • responding to relevant business communications;

  • managing professional relationships;

  • documenting enquiries, projects and decisions;

  • developing and improving our services;

  • maintaining appropriate business records; and

  • protecting legal or commercial interests.

Where we rely on legitimate interests, we consider the interests and rights of the individuals concerned.

 

Consent

Where consent is required — for example for certain non-essential website technologies or specific optional communications — processing is based on your consent.

You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

Legal obligation

Certain information must be processed or retained to comply with accounting, tax, regulatory or other legal obligations.

 

5. Website enquiries and structured intake

​

Post AI Systems may use contact forms, structured intake processes or similar tools to understand a prospective capability, project, collaboration or service requirement before a detailed discussion.

Information submitted through these mechanisms may be used to:

  • understand the context of your enquiry;

  • identify relevant capability-development needs;

  • assess potential service or collaboration fit;

  • understand requirements, use cases, technologies, partners or development gaps;

  • identify possible project, consortium, pilot or implementation routes; and

  • prepare an appropriate follow-up.

Any initial assessment is an orientation or professional assessment only. It is not an automated legal, eligibility, procurement, investment or funding decision, and no funding, consortium, procurement or programme outcome is guaranteed.

Submitted information may be stored using appropriate business systems, including Google Workspace, Google Sheets, Google Apps Script or other systems used by Post AI Systems for enquiry and project management.

​

6. AI use, governance and automated workflows

 

Post AI Systems works with governed AI and automation where these tools materially improve a capability or delivery process.

AI-supported tools may therefore be used, where appropriate, for bounded functions such as:

​

  • information extraction and classification;

  • research support;

  • structuring information;

  • retrieval from approved sources;

  • drafting, translation and communication support;

  • summarisation and synthesis;

  • consistency checking;

  • evidence organisation;

  • document and project structuring;

  • workflow routing; and

  • coordination of information across approved systems.

 

AI is used as a support and delivery mechanism rather than as an autonomous authority. Post AI Systems retains human responsibility for substantive professional judgements and high-impact outputs. AI systems do not independently enter contracts, determine formal eligibility, approve funding applications, submit proposals, make binding decisions on behalf of clients or replace accountable human review.

AI tools may also support the drafting, structuring, translation or refinement of professional communications. Such use is intended to improve clarity, precision and efficiency. Communications sent by Post AI Systems remain our intended communications, and responsibility for their content remains with us. The use of AI assistance in preparing a communication does not mean that the recipient is communicating autonomously with an AI system.

 

Where an AI system interacts directly with an individual on our behalf, or where AI-generated or AI-manipulated content is subject to a specific transparency requirement, we apply the transparency measures required by applicable law.

Where personal or confidential client information may be processed using external AI, automation or cloud services, the appropriateness of that processing is assessed in the context of the engagement and applicable confidentiality and data-protection requirements.

We do not intentionally submit classified, export-controlled, restricted or highly sensitive technical information to general-purpose AI services. Projects requiring enhanced information-security or data-handling controls must be identified and agreed separately before such information is processed.

 

Our use of AI is subject to applicable European Union and German law, including, where relevant, the General Data Protection Regulation (GDPR) and Regulation (EU) 2024/1689 (EU Artificial Intelligence Act). Our practices may be reviewed and adapted as applicable legal requirements, regulatory guidance and technical standards evolve.

 

7. Sensitive and restricted information

​

The public website and ordinary enquiry channels are not intended for:

  • classified information;

  • export-controlled technical data;

  • military or security information subject to special handling restrictions;

  • security credentials or access information;

  • highly confidential third-party intellectual property;

  • special-category personal data unless specifically required and agreed; or

  • other information requiring dedicated secure infrastructure.

If an engagement is likely to involve such information, please contact Post AI Systems first so that appropriate scope, security and processing arrangements can be established.

 

8. Cookies and similar technologies

​

This website is hosted using Wix and may use cookies or similar technologies.

Some technologies are necessary for the website to function, maintain security, remember technical settings or provide requested website features.

Other technologies may support analytics, performance measurement or user experience.

Where consent is legally required for a non-essential technology, it should only be activated in accordance with the applicable consent mechanism.

Where a cookie preferences or consent tool is presented on the website, you can use it to manage your preferences. You can also control or delete cookies using your browser settings.

Disabling some technologies may affect website functionality.

 

9. Service providers and recipients

​

Post AI Systems uses selected third-party services to operate the website, communicate, manage information and deliver work.

Depending on the activity, these may include:

  • Wix, for website hosting and website functionality;

  • Google Workspace, including email, documents and cloud storage;

  • Google Sheets and Google Apps Script, where used for structured information or workflow handling;

  • email, calendar and online-meeting providers;

  • cloud storage and productivity tools;

  • AI model and AI-service providers, where appropriate;

  • automation, integration and workflow platforms;

  • databases and project-management systems;

  • professional advisers such as accountants, lawyers or other specialists; and

  • specialist collaborators or project partners where their involvement is required for an agreed engagement.

Personal data is shared only where reasonably necessary for the purposes described in this policy, where you have authorised the sharing, where another party requires the information to perform an agreed role, or where disclosure is legally required.

Where specialist collaborators participate in an engagement, access should be limited to the information reasonably required for their role.

Post AI Systems does not sell personal data.

Where an engagement requires specific information about subprocessors, security requirements or data-processing arrangements, these can be addressed in the relevant contractual documentation.

 

10. International data transfers

​

Some technology and service providers may process or store personal data outside Germany or the European Economic Area.

Where international transfers of personal data require safeguards under applicable data-protection law, appropriate mechanisms may be used, including:

  • European Commission adequacy decisions;

  • Standard Contractual Clauses;

  • contractual data-protection arrangements; or

  • other legally recognised safeguards.

The specific mechanism depends on the provider and processing context.

 

11. Professional contacts and business follow-up

​

If you contact Post AI Systems, meet us through a professional event or network, are introduced by a professional contact, or engage in a project or partnership discussion, we may retain relevant professional contact information and correspondence where there is a legitimate reason to do so.

Follow-up communications are intended to remain relevant to the original professional relationship, enquiry, capability, project or collaboration context.

Website or project enquiries are not used as permission for unrelated mass marketing.

You may object to relevant business follow-up at any time by contacting:

contact@postaisystems.com

 

12. How long do we keep personal data?

​

Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, taking account of contractual, operational, legal and legitimate business requirements.

Retention is determined according to criteria such as:

  • whether an enquiry remains active;

  • whether a professional relationship or potential collaboration continues;

  • whether information remains necessary for an active or completed project;

  • whether records are required to document decisions, approvals or deliverables;

  • contractual limitation periods;

  • legal, accounting and tax-retention requirements; and

  • whether information is required to establish, exercise or defend legal claims.

Information that is no longer required should be deleted or anonymised where appropriate.

You may request deletion of your personal data. Certain information may nevertheless need to be retained where a legal obligation, contractual requirement or other lawful basis applies.

 

13. Data security

​

Post AI Systems uses reasonable technical and organisational measures intended to protect personal data against accidental or unlawful loss, alteration, unauthorised access, disclosure or misuse.

Depending on the context, measures may include:

  • data minimisation;

  • controlled access;

  • professional cloud services;

  • access permissions;

  • authentication controls;

  • limited sharing;

  • confidentiality requirements;

  • structured approval processes;

  • separation of sensitive information where appropriate;

  • logging and traceability in governed workflows; and

  • documented handling procedures.

No internet-based system can provide absolute security.

For that reason, classified, export-controlled, highly sensitive or specially restricted information should not be sent through ordinary website forms or general email without prior agreement on appropriate handling arrangements.

 

14. Your data-protection rights

​

Subject to the conditions set out in the GDPR, you may have the right to:

  • request access to personal data held about you;

  • request correction of inaccurate or incomplete data;

  • request deletion of personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • receive certain personal data in a portable format;

  • withdraw consent where processing is based on consent; and

  • lodge a complaint with a competent data-protection supervisory authority.

Where applicable, you also have rights concerning decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

Post AI Systems does not use website enquiry information to make such solely automated decisions.

To exercise your rights, contact:

contact@postaisystems.com

We may request reasonable information to verify your identity before responding to a request.

 

15. Data received from other sources

​

In some professional or project contexts, Post AI Systems may receive contact or project information from sources other than the individual concerned.

Examples may include:

  • introductions from professional contacts;

  • consortium or project partners;

  • publicly available professional information;

  • organisational websites;

  • professional networking platforms;

  • conference or event contacts; and

  • documents legitimately provided as part of a project.

Such information is processed only where there is an appropriate purpose and lawful basis.

 

16. Third-party websites

​

This website may contain links to external websites, professional platforms, programme websites or other third-party services.

Post AI Systems does not control the privacy practices of independent third-party websites. Their own privacy notices apply when you use those services.

 

17. Children

​

This website and Post AI Systems services are primarily intended for organisations, professionals, researchers, institutions, project teams and other professional users.

The website is not directed at children.

Where a specific civic-participation, research or public-interest project involves children or other vulnerable participants, appropriate project-specific data-protection, consent and safeguarding arrangements must be established separately.

 

18. Changes to this Privacy Policy

​

Post AI Systems may update this Privacy Policy where services, technologies, processing practices or legal requirements change.

The current version will be published on this page together with the date of the latest update.

 

19. Supervisory authority

​

You have the right to lodge a complaint with a competent data-protection supervisory authority.

For Berlin, the supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany

Email: mailbox@datenschutz-berlin.de

You may also contact another competent supervisory authority where applicable.

 

20. Contact

​

For questions concerning privacy, personal data or this Privacy Policy, contact:

Post AI Systems
Berlin, Germany
Email: contact@postaisystems.com
Website: www.postaisystems.com

AI Transparency
bottom of page