Data Protection & Privacy
Data processing principles applicable to MathIAs+® Structural Intelligence Studio, designed for deterministic, traceable, and controlled data analysis.
1. Roles and responsibility
The customer acts as the data controller for all submitted datasets. Mathias Plus acts as a data processor, processing data strictly under customer instructions.
2. Data scope
The platform processes only datasets explicitly provided by the customer. No external enrichment, data merging, or hidden data sources are used.
3. Core processing principles
- Deterministic data processing (no randomness)
- No model training on customer data
- No reuse of datasets across customers
- No hidden learning or adaptive behaviour
- Full reproducibility under identical inputs
4. Data handling and retention
Submitted datasets are stored temporarily within the region associated with the selected plan. Data is automatically deleted within a maximum of 4 days after submission.
The platform is designed to minimize persistent data storage. Generated artifacts contain only processed outputs and analytical results, and do not include raw input datasets.
Artifacts remain available for download for the duration of the active subscription.
5. Traceability and audit
Each execution is associated with a unique Job ID, enabling full traceability between jobs and generated artifacts.
A cryptographic (SHA-based) hash of the input dataset is recorded to ensure data integrity and reproducibility of results.
Audit artifacts document processing parameters, execution context, and configuration.
6. Identity and access data
No personal data is stored by the service apart from technical identifiers strictly required for access control and auditability, such as Entra ID object identifiers (OID) and tenant identifiers.
7. Security and hosting
The platform is hosted on Microsoft Azure within controlled infrastructure environments. Logical isolation mechanisms ensure strict separation between customer datasets.
8. Subprocessors
The platform relies on Microsoft Azure as its infrastructure provider. No additional subprocessors are used without appropriate safeguards.
9. Customer responsibilities
Customers are responsible for ensuring that submitted datasets comply with applicable data protection regulations.
10. Contact and privacy requests
For any questions regarding data protection, privacy, or processing activities, customers may contact the publisher directly.
Requests related to data access, correction, or deletion will be handled in accordance with applicable regulations and contractual terms.