This page forms part of the Terms of Service and implements Chapter VI of the EU Data Act.
Your right to switch
You can move your data to another provider or to your own systems at any time, or simply take it and leave.
How it works
- Notice. Tell us at hello@aeratus.app that you want to switch, export or end the contract. The longest notice period we can require is 2 months; you may choose a shorter one, and we start helping as soon as you ask.
- Transition period. Up to 30 days after the notice period. During it we keep the Services running, help you export, and keep your data secure. If 30 days is technically impossible, we tell you within 14 working days and propose an alternative period of no more than 7 months. You may extend the transition period once.
- Retrieval. You have at least 30 days after the transition period to retrieve your data.
- Erasure. We then erase all your exportable data and digital assets. They leave our backups when those expire, within 7 days. On request we confirm the erasure in writing.
- End of contract. The contract ends when the switch is complete — or as soon as you tell us that you only want your data erased.
- Charges. None. We charge no fees for switching, for exporting or for transferring your data.
What you can export
Everything in this table is exportable; the list is complete for the data each product holds for you. vox registrations and their answers are anonymised 24 months after the event (Data Processing Agreement, Annex I) — export them before then if you need them for longer.
| Product | Data | How |
|---|---|---|
| vox | Events and programme; speakers and speaker-intake answers; call-for-papers submissions; registrations and their answers; tickets; check-ins; waitlists; feedback; questions and messages; gallery photos; the address book; reminder and email preferences; certificates; uploaded files; workspace settings and branding | CSV exports of registrations, feedback, messages, reports and programme in the admin; everything else as JSON and original files on request |
| q | Knowledge base (questions, answers, categories, attachments); conversations and ratings; unanswered questions and escalations; contact-form messages; forwarded emails still awaiting a decision; workspace settings | JSON or CSV on request |
| scito | Forms; submissions; uploaded files; invitations and waitlists; email-consent records; workspace settings | CSV and XLSX exports in the admin; JSON and original files on request |
| gslk | Club and programme data; members and member cards; applications; forms; events; website content and media; workspace settings | JSON and original files on request |
| mag | Articles and metadata; user accounts; submissions; reviews and editorial notes; messages; site settings | JSON and original files on request |
Not exportable — and only this: (a) our software and its source code; (b) our own operational and security records — server logs, rate-limit counters and the audit records of our staff's actions — where they would reveal other customers' data or our security measures. Your own data, including your workspace's settings and configuration, is never withheld, and never treated as our trade secret.
Register of data structures and formats
| Data | Format | Structure |
|---|---|---|
| Tables (registrations, submissions, members, feedback, messages, knowledge-base entries, and every other record type) | CSV — UTF-8 with a byte-order mark (so spreadsheet programs read Lithuanian letters correctly), comma-separated, every field quoted as in RFC 4180, a header row, dates and times in ISO 8601; a cell that starts with =, +, - or @ gets a leading apostrophe so that spreadsheets do not run it as a formula | One row per record; one column per field, with one extra column per question the organisation defined |
| The same tables, complete | JSON — UTF-8, RFC 8259 | One file per record type; an array of objects whose field names are the database column names; references between records by identifier (UUID); a field dictionary describing every field travels with the export |
| Uploaded files, photos, certificates, attachments | The original file, unchanged | A folder per record type; each file named by the identifier of the record it belongs to |
| Website content and branding (gslk, vox) | JSON, with images as original files | One object per page or setting |
Interfaces
Exports are free of charge in the formats above. A documented programming interface for exporting workspace data is not yet available for every product; until it is, ask us and we deliver a complete export within 30 days.
Where our infrastructure is, and whose law applies to it
| Provider | Role | Data location | Jurisdiction of the provider |
|---|---|---|---|
| Supabase (on Amazon Web Services) | Database, authentication, file storage | Stockholm, Sweden (AWS eu-north-1) | Supabase Pte. Ltd. — Singapore; Amazon Web Services — USA |
| Lovable, over Cloudflare's network | Web hosting | Global network | Lovable Labs AB — Sweden; Cloudflare, Inc. — USA |
| Resend | Sent from Ireland, stored in the USA | USA | |
| Anthropic, OpenAI | AI features | USA | Ireland (contracting entities); USA (processing) |
| Stripe | Payments | Ireland and the USA | Ireland; USA |
The full list, with transfer safeguards, is on the sub-processor page.
Requests from public authorities
We disclose customer data — personal or not — to an authority only where EU or Member State law, or an international agreement binding the EU, obliges us to. We check that the request is lawful, disclose the minimum necessary, and tell the customer first unless the law forbids it. Our measures against unlawful access by governments outside the EU: customer data is stored in the EU; it is encrypted in transit and at rest; each feature is sent only the data it needs; and an authority's request that reaches one of our providers falls under that provider's own published policy on government requests. Transfers of personal data outside the EEA rely on the safeguards under Chapter V GDPR — with the one exception, until its data processing agreement is signed, of our web host Lovable, as the sub-processor page explains.