Who is responsible for the data processing and how you can get in touch.
Responsibility
Controller
The controller within the meaning of the GDPR (Art. 4(7) GDPR), the service provider within the meaning of Section 5 ECG (Austrian E-Commerce Act) and the media owner within the meaning of Section 25 MedienG (Austrian Media Act) is AI Finance Association Europe – Verein für europäische Innovationen im Finanzbereich (ZVR-Zahl 1153480125), Friedrich Janik-Gasse 3, 2345 Brunn am Gebirge, Austria, represented by its president Leszek Downarowicz. You can reach us at aifae.org@gmail.com.
Permutis is the product name of the platform operated by the controller for non-commercial swapping between users. No money is exchanged between users on the Permutis platform; platform services (subscriptions, credits, Founders Club) are offerings made by the operator to users and are never a price for a specific user-to-user swap.
Privacy contact
The point of contact for access, rectification, erasure, objection, data portability, withdrawal of consent and any other data protection request is the contact address stated in the legal notice: aifae.org@gmail.com.
Data protection requests should where possible state the email address concerned, the process concerned and the specific matter at hand. Permutis may request additional information where this is necessary in order to reliably identify the requesting person or to protect the rights of third parties.
Version date
As of September 10, 2026. This statement applies to the website, web app and mobile apps including account, offers, matching, communication, verification and platform services.
The record of processing activities is maintained internally in accordance with Art. 30 GDPR and can be demonstrated to the competent supervisory authority upon a substantiated request. This policy is updated whenever features, service providers, retention periods, AI features, payment processes or international transfers change.
Which data is processed in the account, listings, matches, chat and support.
Data types
Account and profile
Permutis processes account and profile data such as name or display name, email address, profile picture, language, region, reviews, plan status, verification status and settings. In addition, login and authentication data, device and session information, security events and technical log data are processed.
This data is required in order to create an account, recognise users, display profiles, ensure security, prevent misuse, provide support and correctly deliver features such as notifications, language, visibility or plan limits.
Listings, images and location
We process listing data such as title, description, category, type of listing, condition, availability, images, time of creation, updates, active status, visibility, reported problems and technical metadata. Images may contain additional information; Permutis is intended to remove or minimise EXIF or GPS metadata as far as technically provided for.
Location or radius data is used for proximity search, sorting and local relevance. Public displays are not intended to reveal an exact private address. Depending on the feature, approximate distances, regions or radius information may be shown so that users can find suitable swap opportunities without publishing unnecessarily precise location data.
Swipe, match, chat, review and support
Permutis processes swipe decisions, match data, chat messages, read status, handover or completion confirmations, reviews, reports, support tickets, notification data and admin audit data. This data documents which listings were brought together and whether a swap was prepared, carried out, reported or reviewed. You can voluntarily share your precise current location once in a private chat. The position, measurement time and, where available, accuracy are stored as a normal chat message; there is no live tracking.
Chats are as a rule visible to the users involved. Purpose-bound staff access is only considered in the case of reports, support cases, suspected misuse, security checks, error analysis or legal obligations. Such access is intended to be restricted on a role basis, logged and limited to what is necessary. The recipient, access and deletion rules described here apply to location messages. Only when you explicitly open a location card in the Permutis app, the location is sent to the selected map service (Google Maps, Apple Maps, OpenStreetMap or another map app). Revoking location permission in the operating system or browser prevents further collection but does not automatically delete location messages already sent.
Wishes, profile and matching signals
In order to provide suitable swap suggestions, Permutis may evaluate user-related wishes and signals, for example categories being searched for, desired goods or services, wish lists, preferred handover formats, radius, approximate location, language, region, device or app settings, swipe behaviour, match and chat context, reviews, reported interests and the characteristics of a user's own listings.
In addition, profile details such as adult status, a voluntarily stated age group, a voluntarily stated gender or other self-selected preferences may be taken into account where this is necessary for better suggestions, safety, community protection or relevant filters. Such details must not be used to disadvantage users unlawfully or to evaluate legally protected characteristics for discriminatory purposes.
Cookies, local storage and similar technologies may support matching, for example by storing language, search filters, radius, recently used categories, cookie consent or convenience settings. Non-essential tracking, analytics or personalisation cookies are only used for this purpose after consent has been given and must remain revocable via the cookie settings.
Why Permutis processes data and which legal bases may apply.
Purposes & legal bases
Platform operation
The processing serves account creation, sign-in, profile display, listing creation, discovery, swipe logic, matching, chat, completion confirmation, reviews, support, notifications, misuse prevention and technical provision of the service. Without certain data, Permutis cannot reliably offer central features.
We process account data, offers, exchange communications and requested platform features to perform our contract under Article 6(1)(b) GDPR. Statutory recordkeeping and retention obligations are fulfilled under Article 6(1)(c). Security and abuse prevention serve our legitimate interest in protecting users and the service under Article 6(1)(f). Optional analytics, marketing and device access requiring consent are based on consent under Article 6(1)(a).
Optimal matching and personalisation
Permutis processes matching signals in order to suggest relevant swap opportunities, desired categories, nearby listings, similar interests, suitable counter-offers and safe communication channels to users. The aim is a better swap fit: fewer irrelevant suggestions, better local relevance, more suitable category recommendations and a higher chance of a fair swap.
For nearby searches and exchange suggestions you request, we process your offers, search preferences, chosen location and radius, and swipe and match data under Article 6(1)(b) GDPR. Non-essential tracking or cross-device personalisation requires consent under Article 6(1)(a). Abuse detection serves our legitimate interest in protecting users and the platform under Article 6(1)(f).
Matching is a recommendation and sorting function. It does not create an entitlement to a match, an entitlement to visibility, an obligation to swap or an automated decision producing legal effects. Users can change or withdraw filters, radius, location permissions, cookie consent and voluntary profile details insofar as the feature provides for this.
Security, moderation and enforcement of rights
Data may be processed in order to detect, examine and document spam, fraud, monetary demands, prohibited content, security risks, rule violations, multiple accounts, phishing, harassment, infringements of rights and misuse. This protects users, the integrity of the platform and the Permutis no-money rule.
Moderation and prevention of fraud and abuse serve our legitimate interest in a safe platform under Article 6(1)(f) GDPR. Legally required disclosures are based on Article 6(1)(c). Access to reported content is restricted to responsible staff and the relevant case; sensitive administrative actions are logged.
AI features and product improvement
Permutis may use AI to suggest listing titles and descriptions, enhance images, detect categories, flag prohibited content, improve match quality, prepare support responses or assist moderation. AI results are intended to be understood as an aid and may be reviewed or corrected by humans.
When you request AI assistance, we process the inputs needed to provide that function under Article 6(1)(b) GDPR. Content moderation protects against abuse under Article 6(1)(f). Separate consent is required where we rely on Article 6(1)(a) or, for biometric identification, Article 9(2)(a). Granting microphone access alone does not replace any required data protection consent.
Which data may arise in connection with subscriptions, credits, Founders Club and the partner programme.
Platform services
Important: swapping between users remains free of money and free of any price. Payment data concerns only platform services such as subscriptions, boosts, credit packages or Founders Club benefits.
Subscriptions, credits and Founders Club
Payments for subscriptions, credit acquisitions, the Founders Club or other platform services are handled via payment service providers. Permutis stores the necessary payment metadata, status, receipts, terms, allocations, error messages and support information insofar as this is necessary for provision of the service, proof, accounting, fraud prevention or customer service.
This data is not a price for user listings. It relates exclusively to platform features such as visibility, subscriptions, boosts, credits, the partner programme or Founders benefits. Payment data such as full card numbers should not be stored unnecessarily at Permutis but should remain with the respective payment service provider.
Partner programme and payouts
Payouts to partners in the Permutis affiliate programme are made via Stripe Connect (Stripe Payments Europe Ltd., Ireland). For this purpose we process status data, allocations, commission records, tax details, payment information as well as KYC and identity checks (see the service provider matrix under “Recipients and processors”). The legal basis is performance of a contract (Art. 6(1)(b) GDPR) as well as compliance with statutory retention obligations (Art. 6(1)(c) GDPR in conjunction with Section 132 BAO (Austrian Federal Fiscal Code) and Section 212 UGB (Austrian Commercial Code)).
No money is exchanged between users on the Permutis platform. Affiliate commissions are exclusively remuneration paid by the operator to referring partners for platform services (subscription, credit acquisitions, Founders Club membership); they are never a price for a user-to-user swap.
Cookies, local storage, service providers and possible third-country transfers.
Cookies & recipients
Cookies and local storage
Essential cookies or local storage entries serve language, session, security, login status, cookie settings and basic website functionality. This storage is necessary so that the website works reliably, language settings are retained and security features can take effect.
Optional audience measurement using Google Analytics 4 (GA4) processes pseudonymous identifiers and usage data only after you consent to analytics. You can withdraw this consent at any time in the cookie settings. Other analytics or marketing services requiring consent must also wait for your consent. See the Cookie Policy for providers, storage and withdrawal details.
For matching, cookies or similar local storage may be used to recognise voluntary preferences such as language, radius, search filters, saved categories, recently used views or consent status. Insofar as such storage is not technically necessary, it is only used after consent has been given and must not be secretly extended to tracking or advertising purposes.
Recipients and processors
The matrix and the AI section describe the recipients and their tasks. Order processing requires a contract in accordance with Article 28 GDPR. Payment and app store providers also process certain data under their own responsibility. You can obtain information about the recipients and protection agreements that apply to your process via our data protection contact.
Services and processing methods – as of September 10, 2026
Special categories of data (Art. 9 GDPR) – biometric data in profile verification
Voluntary profile verification processes facial images and the movement sequence only to compare the person shown with the ID document and to detect liveness. No reusable biometric template for general identification is created or stored.
Voluntary biometric identity verification requires your separate explicit consent under Article 9(2)(a) GDPR. Unclear results and rejections are checked by humans. The private photos and videos submitted will be stored for 30 days. A process that runs daily deletes the files whose retention period has expired. You can revoke your consent at any time with future effect and request deletion.
The internal verification service stores ID photos, proof of address, and facial photos and videos privately at Supabase. Only if the operator has separately activated the AI-supported identity verification and you have expressly consented will the AI service used for this receive this data. The recipients and transfers of personal data to countries outside the EEA described in the table then apply. Your statutory data protection rights remain in effect.
Third-country transfers
Outside the EEA, a different level of data protection may apply. The transfer of personal data requires an applicable basis according to Chapter V GDPR: an adequacy decision or appropriate safeguards such as standard contractual clauses, with supplementary measures if necessary. Certification of the recipient under the EU-US Data Privacy Framework can only secure the data transfers to which this certification applies. It is not a blanket guarantee for all services mentioned.
You can find out which basis applies to a specific recipient and how to obtain a copy of the relevant guarantees via aifae.org@gmail.com. New recipients or processing purposes require verification and updated information before use. A technical provider option alone does not mean data protection clearance.
Data security, protection of minors, AI and automated support.
Security & AI
Technical and organisational measures
Permutis uses appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. These include role-based access, logging of sensitive admin actions, secure authentication, transport encryption, private storage areas, RLS policies, backups, monitoring and regular reviews.
The website stores the login status with access tokens under permutis_session in LocalStorage. The renewal token is located separately in the tab-related SessionStorage under permutis_refresh_token. Old sessions will be converted to this separation. Website and embedded Flutter app can use an ephemeral submission mechanism for login.
We protect data through transport encryption, restricted access, private storage areas and input validation. Content security policy and other browser headers limit permitted sources; the rules differ between website, admin area and Flutter app. This does not mean that all integrated scripts are exclusively local or that all inline scripts will be blocked.
Users can remove the session immediately at any time by signing out. On shared devices, browser data should additionally be deleted. If a token is lost or stolen, expires_at expires automatically; the client renews the token before it expires. If a compromise is suspected, users should change their password and end all active sessions.
In the event of personal data breaches, Permutis assesses notification obligations towards supervisory authorities and affected persons. Security incidents are intended to be documented internally, prioritised and handled in such a way that risks to users are limited as quickly as possible.
Minors and vulnerable persons
Permutis may be used from the age of 14. Accounts belonging to persons under 14 may be restricted, suspended or deleted. Users aged 14 to 17 are subject to the limits on legal capacity and consent requirements described in the Terms. The 18+ area remains restricted without verified proof of identity and age.
Content that endangers minors, enables grooming, contains sexualised approaches, discloses private data of minors or exploits vulnerable persons may be removed immediately and, where necessary, reported to the authorities.
Being able to use Permutis from the age of 14 does not automatically mean that you can consent to any optional processing of personal data. To the extent that Article 8 GDPR is applicable, this age limit in Austria is 14 years. In other countries, a different age limit may apply and the consent of legal representatives, such as parents, may be required. Additional age requirements for an AI service or language service must also be checked separately. Identity verification is not generally required for normal exchanges.
ID Austria is currently not activated. Permutis is not yet registered as a service provider and does not yet have the necessary authorizations. A voluntary identity and age check is planned for accounts with an Austrian address; the age limits 14 and 18 are examined separately. Before activation, we provide information about released data characteristics, recipients, legal basis and storage. No data is currently being submitted to ID Austria for review.
AI processing and transparency
MiniMax (Nanonoble Pte. Ltd.) is currently configured for article help, matching, moderation and the assistant for logged in users. Depending on the function, input text, selected images, relevant offer and profile data as well as the context of the conversation are processed. Visitors who are not logged in receive prepared answers from the public website content directly in the browser.
Fish Audio is currently configured for spoken responses. Fish Audio receives the response text to be read out. In this mode, voice input uses the browser's voice recognition; Depending on the browser, audio data may go to its service provider. If xAI/Grok is activated instead, its real-time service will receive your voice recording and the content of the conversation with the assistant. This alternative is not the same as the currently configured Fish Audio voice.
MiniMax mentions Singapore and the processing of personal data in the USA; Fish Audio describes international processing of personal data. There is no general promise of immediate deletion by the provider for AI requests. The storage period depends on the processing of the request, security, legal obligations and the applicable provider agreements. You can request information about specific recipients, storage periods and guarantees for the international transfer of personal data from aifae.org@gmail.com.
You can stop voice, revoke microphone permissions, or close Assistant. Do not send ID, health information, or sensitive information in General Assistant. The separate identity check has its own process. AI results may be inaccurate and do not constitute legal advice or a binding decision about your exchange.
Automated decisions and profiling
Permutis may use automated signals, for example for spam detection, money-wording filtering, fraud prevention, ranking, security checks, feed sorting, matching, personalisation or moderation prioritisation. Such systems are intended to have supporting, sorting and pre-sorting functions and must not unreasonably impair users' rights.
Insofar as a decision is based solely on automated processing and produces legal effects or similarly significantly affects a person, users are informed in accordance with the GDPR about the logic involved, the significance, the right to human review, the right to contest the decision and the right to express their point of view.
Which GDPR rights users have, how requests are handled and when data must be deleted or retained for longer.
GDPR rights & storage
Retention period
Account data is processed for the duration of the account; published offers during their publication. Once the purpose no longer applies, data will be deleted unless a legal obligation or necessary legal defense justifies further storage. The special deletion process described above applies to private verification media.
Chats, reports, payment data, audit logs, security events, suspension notes and legal records may be subject to longer periods where this is necessary for handling disputes, preventing misuse, accounting, legal defence or statutory retention obligations. Backups may, for technical reasons, be deleted with a delay.
Access, copy of data and transparency
You can request information about whether we process personal data about you. If this is the case, you will receive the legally required information, in particular about data, purposes, recipients, storage period or their criteria, data origin and your rights (Article 15 GDPR).
The first copy of your personal data is free of charge. A reasonable fee based on administrative costs may be charged for additional copies. Rights and freedoms of other people are protected. Only the exceptions permitted by law apply to applications that are obviously unfounded or excessive; We have to prove the requirements (Article 12 Paragraph 5 and Article 15 GDPR).
Rectification, erasure and restriction
Users can request that inaccurate personal data be rectified and that incomplete data be completed. Many profile details, language settings, notification settings or visible listing data are intended to be correctable directly in the account; for data that cannot be changed by users themselves, support can be contacted.
Users can request the erasure of personal data where the data is no longer necessary for the purposes, where consent has been withdrawn, where an effective objection has been raised, where data has been processed unlawfully or where there is a statutory obligation to erase it. Instead of immediate erasure, a restriction of processing may be considered where the data is still needed for legal claims, prevention of misuse, security, open swap or support cases, tax records, payment receipts or statutory retention obligations.
We will notify recipients of any correction, deletion or restriction unless this is impossible or involves disproportionate effort. Upon request, we will inform you about these recipients (Article 19 GDPR). Technically still existing backup copies may not be used again for normal processing; Legitimate retention obligations remain taken into account.
Objection, withdrawal and data portability
Users can object, on grounds relating to their particular situation, to processing operations based on legitimate interests. This concerns, for example, certain security, misuse, analytics or improvement purposes, insofar as Permutis cannot demonstrate compelling legitimate grounds or the processing is not necessary for the establishment, exercise or defence of legal claims.
Consent can be withdrawn at any time with effect for the future, for example for optional cookies, marketing, certain location features or optional notifications. The withdrawal does not affect the lawfulness of the processing carried out before the withdrawal. Settings are intended to be changeable where the respective feature is offered; in addition, support can help.
Insofar as data is processed by automated means on the basis of consent or for the performance of a contract, users can request a structured, commonly used and machine-readable copy of the data they have provided. Direct transmission to another provider only takes place insofar as this is technically feasible and legally permissible.
Request process, deadlines and complaints
Data protection requests can be submitted via the contact point stated in the legal notice. The request should state the email address concerned, the account reference, the right being invoked and the relevant process so that Permutis can reliably assign the request. Permutis may require an identity check where this is necessary in order not to disclose data to unauthorised persons.
We respond to requests to exercise your data protection rights without undue delay and at the latest within one month of receipt. For complex or numerous requests, this period may be extended by up to two further months. We will notify you of the extension and the reasons within the first month (Article 12(3) GDPR).
If we do not comply with a request, we will inform you of the reasons and your options for complaint and legal protection within one month at the latest. In particular, you can contact the Austrian Data Protection Authority or a responsible supervisory authority where you are.
Changes to this policy
This privacy policy is adapted whenever features, providers, legal bases, data flows, retention periods, AI features, cookie categories, payment processes, admin access or international transfers change. Material changes are intended to be communicated transparently.
For new features, we assess whether additional data is processed, whether consent is required, whether app and website texts need to be adapted and whether the technical implementation follows the principle of data minimisation.