n8n policy evolution
Before/after stance changes across captured policy versions, with exact citations. If no before/after delta is available yet, AIRIN shows the latest citation-backed stance events instead.
No before/after stance delta is available for this filter yet. Latest citation-backed stance events are shown below.
Jul 20, 2026commercial usemedium
data sharing
Latest stance: third party or vendor sharing
“We use an external payment service provider for the processing of online payments and, where applicable, invoicing and tax handling for digital products. The legal basis for the processing of personal data is Art. 6 (1) b) GDPR, as the processing is necessary for the implementation of pre-contractual measures and for the performance of a contract. This includes, in particular, name, email address, billing address, payment information (e.g., credit card details or other payment details), IP address, transaction data, and, where applicable, company-related information. The processing is carried out for the purpose of payment processing, fraud prevention, invoicing and tax compliance (e.g., VAT determination) The payment service provider may act as an independent controller within the meaning of Art. 4 No. 7 GDPR, in particular where it processes payment data in its own name as a so-called “merchant of record.” The payment service provider may also process personal data in order to comply with legal obligations (e.g., commercial and tax law retention requirements) and for fraud prevention or the assertion and defense of legal claims. Personal data will only be disclosed to third parties if this is necessary for contract processing, required by law, or carried out within the framework of commissioned data processing. The storage period for personal data is determined by statutory retention obligations and contractual requirements. Data relevant under commercial and tax law is generally stored for the duration of the applicable statutory retention periods.”
Open citationJul 20, 2026commercial usemedium
data sharing
Latest stance: third party or vendor sharing
“We may share personal data with carefully selected service providers that support our business operations. These include, in particular, providers of IT hosting and infrastructure services (e.g. cloud hosting and content delivery networks), cybersecurity and fraud prevention solutions, data storage and backup services, website analytics and performance monitoring tools, marketing and advertising platforms, subscription management, billing and revenue analytics systems, payment processing services, as well as customer relationship management software, internal collaboration and productivity tools, document management systems, and customer support and communication services (e.g. ticketing systems, live chat and email services). Where such service providers process personal data on our behalf, we conclude data processing agreements pursuant to Article 28 GDPR, ensuring that personal data is processed solely in accordance with our instructions and in compliance with applicable data protection standards. In some cases, third parties process personal data as independent controllers or joint controllers, in particular in the context of advertising and social media services. We may disclose personal data where required by law or where such disclosure is necessary to comply with legal obligations or lawful requests by public authorities, courts, or law enforcement agencies, enforce our commercial contracts or other agreements, investigate potential violations, prevent or address fraud, security, or technical issues, or protect our rights, property, users, or the public.”
Open citationJul 8, 2026commercial usemedium
data sharing
Latest stance: third party or vendor sharing
“We use an external payment service provider for the processing of online payments and, where applicable, invoicing and tax handling for digital products. The legal basis for the processing of personal data is Art. 6 (1) b) GDPR, as the processing is necessary for the implementation of pre-contractual measures and for the performance of a contract. This includes, in particular, name, email address, billing address, payment information (e.g., credit card details or other payment details), IP address, transaction data, and, where applicable, company-related information. The processing is carried out for the purpose of payment processing, fraud prevention, invoicing and tax compliance (e.g., VAT determination) The payment service provider may act as an independent controller within the meaning of Art. 4 No. 7 GDPR, in particular where it processes payment data in its own name as a so-called “merchant of record.” The payment service provider may also process personal data in order to comply with legal obligations (e.g., commercial and tax law retention requirements) and for fraud prevention or the assertion and defense of legal claims. Personal data will only be disclosed to third parties if this is necessary for contract processing, required by law, or carried out within the framework of commissioned data processing. The storage period for personal data is determined by statutory retention obligations and contractual requirements. Data relevant under commercial and tax law is generally stored for the duration of the applicable statutory retention periods.”
Open citationJul 8, 2026commercial usemedium
data sharing
Latest stance: third party or vendor sharing
“We may share personal data with carefully selected service providers that support our business operations. These include, in particular, providers of IT hosting and infrastructure services (e.g. cloud hosting and content delivery networks), cybersecurity and fraud prevention solutions, data storage and backup services, website analytics and performance monitoring tools, marketing and advertising platforms, subscription management, billing and revenue analytics systems, payment processing services, as well as customer relationship management software, internal collaboration and productivity tools, document management systems, and customer support and communication services (e.g. ticketing systems, live chat and email services). Where such service providers process personal data on our behalf, we conclude data processing agreements pursuant to Article 28 GDPR, ensuring that personal data is processed solely in accordance with our instructions and in compliance with applicable data protection standards. In some cases, third parties process personal data as independent controllers or joint controllers, in particular in the context of advertising and social media services. We may disclose personal data where required by law or where such disclosure is necessary to comply with legal obligations or lawful requests by public authorities, courts, or law enforcement agencies, enforce our commercial contracts or other agreements, investigate potential violations, prevent or address fraud, security, or technical issues, or protect our rights, property, users, or the public.”
Open citationGenerated from live stance events. Informational only, not legal advice.