PrivateSovereignControlled

Operational AI for
every decision.

Private AI designed to operate with your data, your systems and the way you really work.

Scroll
Sovereign

Deploy AI where your data lives

No data egress, full control. You choose the models and policies; we turn them into outcomes.

Compliance

Auditable by design

Auditable workflows, role-based access and approvals. GDPR and ENS compliance out of the box.

ROI

Prove ROI fast

Automate one core process in days and expand across systems. No lock-in: extend what you already have.

Trusted by leading organizations across regulated industries, government and mission-critical sectors
Santander Telefónica Indra Acciona El Corte Inglés Arval, BNP Paribas Group Universidad Europea Farmaenlace Health in Code English Connection MásOrange Proeduca Cotown Residelia
The platform

Your operations controlled and running on one private platform.

From construction to intelligence to governance — the complete operating system for private, operational AI inside your perimeter.

Agentes de Airflows orquestando un expediente en producción
01Construction

Build the operation.

Agents, workflows and production applications on a single foundation.

  • Agents — classify, extract and escalate with human oversight.
  • Workflows — orchestration with SLAs, queues and approvals.
  • Applications — back-office apps ready in days.
Grafo semántico de Airflows explorado sobre tablet
02Intelligence

Turn data into decisions.

Knowledge base, semantic layer and graphs: your knowledge, queryable.

  • Knowledge base — a single queryable source of truth.
  • Semantic layer — models your business objects.
  • Graphs — relationships and context across your data.
Equipo revisando y aprobando una decisión operativa
03Governance

Every decision, under control.

Traceable, auditable and compliant by design, inside your perimeter.

  • Traceability — every action logged and auditable.
  • Access control — RBAC and MFA, always.
  • Compliance — GDPR and ENS by design.
Impact at organizational scale

AI that moves the whole organization, not a feature.

Productivity gains

Teams free up critical hours and deliver more across every process — with the same headcount.

Full enterprise compliance

Every decision auditable, traceable and inside your perimeter — GDPR and ENS by design.

Sector regulado
In production
“We automated a critical back-office process in days and scaled it across systems. Without moving data outside our perimeter.”
Head of Operations

Operational AI for
every decision.

Product · Platform

One platform for
intelligent business processes.

Airflows turns your organization’s knowledge, systems and rules into operations that execute: agents, workflows and applications running under your control, inside your perimeter.

The operating system for decisions

Not another chat window.
An operation that runs by itself.

Business context

Bring together the information, rules and priorities your teams need to make better decisions.

Decision flows

Turn recurring business decisions into structured processes that move from input to outcome.

Enterprise action

Connect people, systems and AI so work can be executed safely across your organization.

Operational control

Keep visibility over what happens, who approves it and how every decision moves forward.

The platform

Built to operate,
not to chat.

Agents

Agents that execute decisions.

Task-specific agents that classify, draft, validate and escalate work, with human checkpoints where it matters.

Workflows

Auditable workflows, end to end.

Model your business processes and automate them with full traceability of every step and decision.

Applications

Back-office apps in days.

Spin up production-ready apps —forms, case inboxes, document viewers— ultra-efficiently with AI.

Architecture

From source to decision.

Your systems of record stay the source of truth. Airflows orchestrates agents, workflows and apps on top of them, inside your perimeter, and returns auditable decisions.

Sources Airflows platform Operation SAP Oracle Microsoft 365 Email · Databases Private AI · under your control Governance Decision Automated action Audit & trace

Building with Airflows is this easy.

Platform modules

Everything connected
under one platform.

01

Agents

Task-specific AI agents that classify, extract, draft and escalate work automatically, with human-in-the-loop checkpoints.

Agent RuntimeAssistants
02

Workflows

Orchestrate end-to-end processes with SLAs, queues, approvals and deterministic routing across teams and systems.

OrchestrationSLAs
03

App Builder

Build production-ready operational interfaces visually: forms, inboxes, viewers and dashboards.

Low-CodeTheming
04

Integrations

Connect your systems of record via API-first and webhooks, keeping them as the source of truth.

API-firstWebhooks
05

Security

Private deployment, no data egress. Encryption, role-based access control and perimeter isolation.

RBACNo egress
06

Governance & Auditability

Every model decision is explainable and logged. GDPR and ENS compliance by design.

Audit logRGPD · ENS
07

Developer Experience

SDK, documentation and environments to extend the platform without friction.

SDKDocs
08

Observability

Real-time metrics, traces and monitoring of agents, workflows and apps in production.

MetricsTraces

Operate for less

Agents take on repetitive work end to end, so operating cost falls without cutting capacity.

From months to days

Production-grade apps and workflows ship in a fraction of the usual time.

Compliance, no trade-offs

Every decision is private, traceable and auditable by design, ready for your regulatory framework.

Integrations

Integrates with your
existing tools.

Connect to SAP, Oracle, Microsoft 365/SharePoint, Salesforce, ServiceNow, document repositories, email and databases. Trigger actions through webhooks/APIs and keep your systems of record as the source of truth.

SAP

SAP

Integrate ERP data and workflows seamlessly.

Oracle

Oracle

Databases and cloud services for data management.

Salesforce

Salesforce

Sync customers, leads and sales flows.

ServiceNow

ServiceNow

Automate ITSM and business processes.

Microsoft 365

Microsoft 365

Office, Teams and cloud services integrated.

SharePoint

SharePoint

Documents, lists and collaboration.

Google Sheets

Google Sheets

Google Workspace spreadsheets.

Gmail

Gmail

Secure, efficient email communication.

OpenAI

OpenAI

Advanced models like GPT-4 for AI capabilities.

People in control

AI operates.
Your organization stays in control.

Airflows automates the repetitive work and surfaces the decision that matters —with the human checkpoint exactly where your organization needs it.

Ready to build?

Solutions

Specialized solutions
for your industry.

Pick a starting point and get pains, quick wins and architecture at a glance, by industry or use case.

By use case

Common challenges solved with AI.

Invoice processingExtraction · validation · posting
Contract managementReview · redlining · renewals
Approval workflowsQueues · SLAs · routing
Document classificationTagging · auto-routing
Compliance reportingAudit · traceability · evidence

Find your starting point.

Case studies

Find the project
that suits you best.

Explore some of our work and discover how the platform has transformed various industries.

Featured solution · Public sector

CPI · Intelligent Public Procurement.

The full procurement cycle with private AI: files audited against the LCSP in seconds, traceable evidence and human validation.

Discover how Intelligent Public Procurement works
Administración pública
Featured solution · Public sector

Urban digital twin.

See the city live, decide on the map and act — all in one model.

Discover how the urban digital twin works
Administración pública
Banca
Banking & insurance · Contract management
“We automated document review and scoring with full audit of every decision. We went from months to weeks.”
CTO, financial institution
Public administration · Processing
“Traceability gave us the confidence to deploy AI in real procedures, without moving data outside our perimeter. Citizens notice it.”
Director of Digital Transformation
Administración pública
Industria
Industry · Invoice processing
“Automatic extraction and posting of invoices, with human-in-the-loop where it matters. 80% less hidden cost.”
Head of Operations
Use cases

Common challenges, solved.

Documents

Invoice processing

Automatic extraction, validation and posting with human oversight.

Contracts

Contract management

Guided review, redlining and renewal control.

Compliance

Compliance reporting

Audit, traceability and evidence ready for the regulator.

Your case, next.

Solutions · Public sector

The future, today, for public administration.

Trustworthy, sovereign and traceable AI in service of citizens. We modernize public management without losing control of data.

Edificio institucional
Citizen attention

Public assistants

24/7 resolution of procedures in natural language, smart routing and answers verified against current regulation.

Files

Smart processing

Automatic classification, extraction and prioritization of files. Cuts times while keeping human oversight.

Policy

Impact analytics

Simulate and evaluate the effect of public policies on real data before implementing them.

Sovereignty

Data under control

On-premise or sovereign-cloud deployment. ENS, GDPR compliance and full audit of every model decision.

Transparency

Full traceability

Every system output is explainable and logged. Accountability by design.

Interoperability

Integration with legacy systems

Connect to existing registries and platforms without mass migrations or service downtime.

Files that move forward

Administrative work is resolved in a fraction of the time, without losing guarantees.

Decisions that withstand an audit

Every resolution is explained and traced, ready for oversight.

Attention that never closes

Citizen service responds continuously, with no queues or office hours.

Customer stories

Operational workflows the public sector modernizes first

Explore some of our work and discover how our platform has transformed public-sector operations.

ANH
Energy · Data

ANH: Extract intelligence from your geophysical reports

Automated data extraction and AI-powered semantic search so your engineers make precise decisions — without slow, error-prone manual reviews.

  • Automatically extract data from unstructured sources with no manual effort
  • Query geophysical data in plain language through an AI assistant
  • Free up engineers and analysts to focus on high-value decisions
Ministerio del Interior
Security · On-premise

Ministerio del Interior: AI that never leaves your perimeter

Deploy powerful AI applications in fully isolated, air-gapped environments — no internet connection required, no data ever leaving your infrastructure.

  • Run AI models fully on-premise, with zero exposure to external networks
  • Meet the strictest compliance and data sovereignty requirements across regulated industries
  • Keep sensitive operations — defense, energy, finance — fully secured and auditable
Public sector

Let’s modernize the public sector,
together.

Government & Defense · Public sector

CPI · Intelligent Public Procurement.

Private, sovereign and governed AI for the entire public procurement cycle. Files audited against the LCSP in seconds, with human oversight and traceable evidence end to end.

CPI is the Airflows suite that applies private, sovereign AI across the entire public procurement cycle. It covers three use cases on a single platform —drafting tender documents, managing files and evaluating bids— so the Administration gains efficiency without giving up control of its data or the final decision. A single, ready-to-run solution that offloads the team and keeps every step traceable.

The solution

What CPI does.

01

From blank page to a tender ready to publish

CPI turns the need into a structured tender: it defines subject matter, CPV, budget and coherent criteria, and drafts the PCAP and PPT from your templates and precedents. It also validates LCSP compliance and flags the clauses with the highest risk of appeal, so the file is defensible from the very first version.

02

Less administrative burden, more files resolved

CPI reads, classifies and structures the file's documentation, extracting key information such as subject matter, CPV, amounts, award criteria, solvency and associated documents. It audits calculations, taxation and fraud risks before approval, and keeps human oversight where it matters. This reduces manual work and speeds up the procedure.

03

Every score, anchored to its evidence

CPI normalizes each bidder's proposals, applies the tender criteria —value judgment and formula— and anchors every score to the specific evidence in the proposal. It generates a weighted ranking and a reasoned award report, with criterion → evidence → score traceability ready to hold up against appeals.

How it works

From the official repository to the verdict, in one continuous flow.

The system connects to the Public Sector Procurement Platform (PLACE) and downloads files automatically and continuously, in the standard CODICE format (the Spanish profile of UBL 2.1). The download is parameterizable — start date, incremental or full mode, pausable without losing progress — and every run is logged: entries processed, files created or updated, status. Any month can be reprocessed.

Alongside each file, its documents are downloaded — PCAP, PPT, Justification Report. A document-extraction agent reads the PDFs and structures their content: subject matter, CPV, amounts, award criteria with their formulas, required solvency, clauses. In the same process, the full content is indexed for semantic search. Manual upload is also supported: a reviewer can upload a tender document before its publication on PLACE and audit it with the same flow.

When a file comes in, the audit workflow is triggered automatically:

Legal verification

That award criteria add up to exactly 100 points; that taxation matches the territory (IVA, IGIC or IPSI); that the required economic solvency respects the limit of Article 87 of the LCSP; that the document contains all mandatory clauses. Each breach generates an alert with its criticality level.

Split-contract detection

The system cross-references the awardee against the full PLACE history. If the sum of minor contracts per company, body and year exceeds the legal thresholds — €40,000 in works, €15,000 in the rest — it raises a red flag.

Evaluation

With no critical alerts or red flags, the file is approved automatically. With them, the process moves on to human review.

The system generates the audit report in three sections: economic, legal (LCSP compliance article by article) and technical (split-contract analysis). And it goes one step further: it produces a Version 2 of the PCAP and PPT with the proposed corrections marked on the document itself, like tracked changes. The drafter receives exactly what to change, where, and why.

Two automatic emails: to the technical reviewer, with the alerts ordered by criticality and the report attached; to the document drafter, with the corrected documents. The reviewer validates from the file's record, with a viewer that jumps to the exact paragraph where each issue was detected, and approves or rejects. The final decision is always human — and it is recorded.

Asistente analítico
The analytical assistant

Expert agents 24/7 for any query.

Teams query the entire history in natural language. The assistant generates charts directly from the data — amounts per file, per contract type, per awardee — searches inside the tender documents' content ("which files include late-delivery penalty clauses?") and returns the exact citation with a link to the record and the paragraph in the document. And it understands the domain: it knows what the Estimated Contract Value is, how it is calculated and which LCSP article regulates it.

Capa semántica
The semantic layer

Your operations and your legal framework, modeled in a knowledge base. Ready for AI to reason over.

The data model is aligned with the eProcurement Ontology (ePO), the European Union's official semantic standard for public procurement. Agents don't know the meaning of each field because someone wrote it in a prompt: they know it because it is defined in the ontology, with the legal semantics of the LCSP. That knowledge is reusable, auditable and aligned with the European standard used by member states' procurement platforms. It is the knowledge base that turns every file into operational intelligence for the Administration.

Privacy, control, sovereignty

Private, sovereign and governed AI.

Privacy

Data remains protected within the organization's environment.

Control

Governance, access and traceability: every verification, alert and validation is recorded.

Sovereignty

Deployment on your infrastructure or sovereign cloud: data and models remain under your jurisdiction.

Indicators

System performance indicators.

100x

analysis speed per file

100%

file analysis coverage

<1 min

average analysis time per file

Grafo semántico de Airflows sobre expedientes de contratación
Beyond procurement

The tool that adapts to your processes.

The same architecture — ingestion from official sources, document extraction, agent-driven audit workflow, analytical assistant and semantic layer — applies to sanction files, fleet and equipment control, personnel management or any domain with multiple data sources and a need for continuous audit.

Take-away

The whole cycle, under your control.

A single sovereign platform for all procurement: from tender to award, without taking data out of the Administration’s environment and with the human decision always at the center. CPI doesn’t replace your team: it offloads it, shields the file and makes every decision traceable and defensible.

Procure better, faster
and with greater assurance.

Every file is processed with AI, validated with human control and backed by traceable evidence end to end.

Operational AI for Every Decision
Government & Defense · Public sector

Urban digital twin.

See the city live, decide on the map and act — all in one model.

A city generates millions of data points every minute —fleets in motion, cameras, stations, incident reports— yet deciding still depends on systems that don't talk to each other and on the memory of whoever is on duty. The urban digital twin turns that territory into a single living model on Airflows: every vehicle, base, sensor and alert on the same operational map, understandable and actionable. It is not a dashboard to watch the city; it is the environment where you decide and act on it —private, sovereign and under the administration's control.

The model

The city, turned into data.

01

The city’s territory, turned into data

The starting point is not a generic map: it is the real city —districts, road network, infrastructure— loaded as the twin’s foundation. Every operational layer lives on that same map, ready to be queried or activated.

02

The city now measures itself

Traffic, cameras and stations stop being isolated sources and start feeding one single model. The twin doesn’t wait for the report: it senses the state of the city in real time and keeps it up to the minute.

03

Know what you have and where it is

Every base, vehicle and material resource, with its location and status kept current. When the call comes in, the question “what do I have available, and where?” is already answered —before deciding.

Use cases

From the alert to the action, on the same map.

01

Entity dispatch — From the alert to the resource, assigned on the map

When an alert comes in, the twin identifies the most suitable resource and assigns it on the map —with its route, estimated time of arrival and priority. What used to be a chain of phone calls becomes a traceable decision in seconds.

02

Fire simulation — Simulate the fire before deciding

Before committing resources, the twin simulates the fire: how it spreads and how it hits the city’s operation —blocked access, compromised coverage, resources required. You decide on the scenario, not on intuition.

03

Workflows · Alert management — Every alert becomes a process

An alert is not a notice that resolves itself: it is a process with detection, escalation and resolution. The twin models it as a governed workflow, so nothing depends on someone remembering the next step.

The same engine beats in all three: AI agents that query the twin, decide with the rules of the domain and act within their permissions —with every step traced.

How it works

Underneath every action, agents with permissions.

Every step is executed by an agent with its own tools and its own limits.

The twin detects or receives the alert: a sensor, a camera, a manual report.

The agent queries the semantic layer: what exists, where it is and in what state.

It applies the rules of the domain —priority, availability, coverage— to choose the resource.

It executes —dispatch, alert, escalate— only within the tools and limits assigned to it.

Every step is recorded: which agent decided, with what data and why.

Capa semántica
The semantic layer

The semantic layer is the model of the city.

Underneath everything there is a semantic model: the city’s entities, how they relate and the rules that govern them. That is what gives meaning to the data —an ambulance is not a point on the map, it is a resource with a state, a base, coverage and priority. On top of that model, the twin and its agents can reason and decide, not merely represent.

01

A single operational picture where there used to be systems that didn’t talk to each other.

02

From observation to action without leaving the platform.

03

Every decision, traceable: which agent, with what data and within what limits.

Take-away

The whole city, in front of whoever decides.

The urban digital twin does not replace the person who decides: it puts the whole city in front of them, understandable and in real time, with action one click away. The same intelligence the city was already generating, finally turned into a decision —and into action.

See the city live,
decide on the map.

Observation, decision and action in the same model —private, sovereign and under the administration’s control.

Operational AI for Every Decision
Free assessment · 18 questions

Operational AI Adoption Index.

Where your organization actually stands with operational AI —measured across six dimensions, compared with organizations like yours, and with the one thing that is holding you back named plainly.

18 questions · 6 to 8 minutes · you can leave it half-done and continue later

What you get

Four things, none of them generic.

01

A score from 0 to 100 and a level from 1 to 5

Calculated with per-dimension weights and capping rules. If a level does not hold up, the report says so.

02

The breakdown across six dimensions

Use, processes, data, governance, sovereignty and ownership, each with its band: critical, in progress or consolidated.

03

The constraint that is limiting you

The dimension holding the others back, explained. This is the part of the report that gets discussed in an internal meeting.

04

A recommended first use case

The one that matches your constraint and your type of organization, not an entire catalogue.

Who it is for

Three questionnaires, one instrument.

The questionnaire adapts to your type of organization: the wording, the questions and the weight of each dimension. Scores are reported and compared separately —a company of 30 people is never compared with a regional government.

Public sector

Files, case handling, procurement and the Spanish National Security Framework. 18 questions.

Companies over 250

Processes, ERP and CRM, and your sector’s compliance framework: banking and insurance, healthcare, utilities, industry, telco. 18 questions.

Companies up to 250

Day-to-day tools, invoicing, customers and documents. No formal audit or security framework questions. 12 questions.

Scope of the assessment

It tells you where you stand. It does not estimate savings or return.

With 18 answers no one can calculate a saving, a return or a time-to-value, and we are not going to pretend otherwise. What this instrument does is measure your current state, place it against comparable organizations and name what is blocking you. That is a harder promise to fake and a more useful one to act on.

The six dimensions

What gets measured, and how much it weighs.

Weights shown for the public sector and large-company branch. The small-business branch redistributes them: more weight on use, processes and data; less on governance, sovereignty and ownership.

Find out where you actually stand.

18 questions. No email until the end, and nothing is charged for the result.

Operational AI for Every Decision
Paso 1 de 4

First, four questions with no typing.

They decide which questionnaire you see and which organizations you are compared with. No personal data yet.

Your result is ready.

Two fields, nothing else. No phone number.

0/ 100

Breakdown by dimension

Main constraint

Recommended first use case

Next steps

The comparison with equivalent organizations is not shown yet: until there are enough comparable organizations there is no comparison, and we are not going to invent one.

Review it with a specialist
Inside · Resources & Partners

Learn, download, deploy.

Documentation, courses and training to master Airflows like a pro, and a partner program to grow together.

Training & documentation

Everything there is to know
about Airflows.

Whitepaper

The business case for operational AI

How to quantify the return of AI beyond the pilot.

Download
Guide

AI in government: from ENS to production

Practical framework for compliance, sovereignty and traceability.

Download
Brand kit

Logos, colors and usage

Download the Airflows brand kit.

Open kit
Partners

Join the Airflows partner network

Access training, documentation, certifications and new markets.

Become a partner
Inside · Blog

AI ideas that
actually execute.

Product, applied engineering and sector learnings, no fluff.

Back to blog

From assistant to operational AI: the leap that really matters.

Most organizations have already tried AI. They’ve opened a chat window, asked questions and seen plausible answers. And there, almost always, they stop: at the demo. The assistant impresses, but it doesn’t execute real work.

The leap that really matters isn’t conversational, it’s operational. It happens when AI stops answering and starts doing: classifying a file, extracting invoice data, drafting a document, escalating an exception to the right person, and leaving a record of every step.

Why pilots stall

An AI pilot usually dies for three reasons: the data lives in systems the model can’t touch, there’s no way to audit what it decides, and the return never reaches production because every new case requires rebuilding everything.

  • Data is trapped in ERP, ECM and BPM that nobody wants to replace.
  • Without traceability, no leader signs off a real deployment.
  • The demo doesn’t scale: what works for one case doesn’t serve the next.
AI only transforms when it stops being a technical project and becomes an everyday tool.

What changes with operational AI

Operational AI starts from a different premise: your systems of record stay the source of truth, and AI operates on top of them, inside your perimeter. Agents execute tasks with human-in-the-loop checkpoints where it matters, workflows orchestrate the process end to end with SLAs and approvals, and every decision is logged and explainable.

The result is measurable from the very first process: less hidden cost, more delivery speed and compliance that isn’t an add-on, but part of the design.

The practical path

Start with a critical back-office process, automate it in days while keeping human oversight, prove the return and expand to other systems. No lock-in, no replatforming, without moving data outside your house.

Ready to move from pilot
to production?

News & press

Airflows in the media.

Product announcements, company milestones and press appearances.

Funding · June 2026

Airflows raises €2M from Adara Ventures and Armilar.

AI in the enterprise cannot be a black box. It has to be private, governed, controllable and predictable. That’s what we’re building: AI companies can actually operate in production — across applications, workflows, processes and agents. Because enterprise AI is not about the best demo; it’s about trust, control and real-world deployment.

Read on LinkedIn →
10 ABR 2026

Airflows scales its private AI platform in regulated sectors

The company accelerates its expansion across enterprise and public administration.

22 MAR 2026

New native integration with SAP and ServiceNow

More API-first connectors to orchestrate processes over your systems of record.

14 FEB 2026

Airflows strengthens its governance for ENS compliance

Audit and traceability of every model decision, by design.

30 ENE 2026

Back-office case: 80% reduction in hidden cost

Results from one of our most notable deployments.

Brand kit

Download our logos, colors and usage guidelines.

Open brand kit
Inside · Company

The people behind
the platform.

A team that combines product engineering, applied AI and deep sector knowledge.

Antonio Lillo
Antonio LilloCEO & Co-founder

25 years leading technology, strategy and business development at companies focused on Digital Transformation.

Ignacio Cabrera
Ignacio CabreraChairman & Co-founder

Serial entrepreneur with 30 years launching and scaling technology startups.

Eduardo Rivas
Eduardo RivasCRO & Co-founder

25 years leading business and technology teams, transforming companies through the intelligent use of their data.

Paco Hernández
Paco HernándezR&D&i & Co-founder

25 years directing large engineering teams and defining the technical architecture of major companies' digital products.

Julio Casal
Julio CasalCo-founder

Serial entrepreneur with 30 years launching technology startups and guiding them on their path to Silicon Valley.

Track record

Founders of successful companies.

Datio Paradigma Stratio Wazuh Constella Intelligence AlienVault Overview Effect
Our vision

“Operational AI, private and under your control. Built for how your organization actually works.”

Airflows is born from a conviction: AI only transforms when it stops being a technical project and becomes an everyday tool. We build so any organization, large or small, private or public, can access that capability, without giving up control of data.

Get a demo

Private AI for
your operations.

Tell us your case and we’ll show you how Airflows solves it. We reply in under 24h.

Oficinas de Airflows — sede en Madrid We reply in under 24h
Back to blog

New Airflows UX and UI.

Nueva interfaz de Airflows

We rebuilt the Airflows look & feel to guide every user with confidence: a full visual refresh, tighter performance, and a friendlier on-ramp through new wizards.

UI best practices everywhere

We applied modern UI heuristics —predictable spacing, strong contrast and simplified hierarchies— so people can find, decide and act faster.

  • Consistent component sizing and focus states to reduce ambiguity.
  • Clear empty states and inline hints to cut friction on first use.
  • Readable typography scale with generous line-height for long sessions.

Guided wizards that lower the learning curve

New step-by-step wizards walk users through critical flows —setup, data connections, model publishing— so teams ship value without steep ramp-up.

  • Contextual tips per step to prevent dead-ends and rework.
  • Smart defaults informed by common industry patterns.
  • Progress checkpoints with undo-friendly actions.
A cohesive look & feel, UI best practices, brand cues and guided wizards now work together to shorten the path from idea to outcome.

Brand-led navigation that orients you

We leaned on Airflows’ visual language —color, iconography and micro-interactions— to help users recognize areas instantly and build spatial memory across the platform.

  • Section theming aligned with the Airflows palette so you always know where you are.
  • Icon cues paired with concise labels for faster scanning.
  • Motion tuned to be informative, not distracting.

WCAG-first redesign

Contrast, focus order, landmarks and keyboard paths were audited to align with WCAG best practices, improving accessibility for all users.

  • Higher contrast tokens for text, controls and interactive states.
  • Visible focus rings and logical tab order across critical flows.
  • ARIA labels and semantic structure on key templates.

Lean static assets, faster loads

We optimized and consolidated static assets, reducing payload size and improving response times —especially on first paint.

Want to see the new
experience live?

Back to blog

Enhanced GIS Viewer.

Visor GIS de Airflows

Airflows GIS now handles rich entities, layered views, time controls, live data and AI-first exploration —from single-point maps to full geospatial canvases.

Beyond single points

In 2.1, any entity can be marked Geospatial and added to richer GIS visualizations —no longer limited to a single point layer.

  • Multiple layers with on/off visibility toggles.
  • Custom styling per layer for clarity and brand fit.
  • Support for points, lines, polylines and polygons —any GIS element is welcome.

AI-first exploration

Integrated with Airflows agents so teams can query, summarize and correlate spatial data in plain language.

  • Ask for hotspots, anomalies or trends without writing GIS queries.
  • Agent-guided filters to focus on what matters.
  • Explainability baked in: how results were derived and what changed.
Layered maps, AI-first exploration, temporal playback, live monitoring and enterprise exports —all while keeping performance lean.

Temporal & live views

Scrub through time to see how entities evolve, or switch to Live Mode to monitor changes as they happen.

  • Time sliders to pick the exact moment you need.
  • Real-time updates for operational monitoring.
  • Layer-aware playback so each dataset respects its own cadence.

Precision tools & export

Measure areas and distances with built-in tools, then export your views to share or archive.

  • Area and distance measurement overlays.
  • Export snapshots or data for downstream analysis.
  • Full on-prem support for air-gapped environments.

Put your data
on the map.

Back to blog

Finetune LLMs faster with curated corpora and full traceability.

Constructor de corpus de Airflows

We’ve added the ability to train and tune your own model on the Airflows platform: pick your data, clean it, enrich it, and ship models with minimal time to market.

Curate the right corpus

Select exactly which elements belong in your corpus, then prune, edit or enrich them manually or automatically.

  • Source selection with filters and quality checks.
  • Manual and automated enrichment paths.
  • Quick removal of noisy or stale data.

Traceability end-to-end

Track every corpus change, training run and generated model with audit-ready logs.

  • Versioned corpora and training metadata.
  • Lineage from dataset to model artifact.
  • Rollbacks with confidence.
Curate, trace and ship custom models with rich corpus control, strong lineage and the flexibility to choose the right foundation every time.

Broad model palette

Fine-tune on the models that fit your use case: Bloom, Falcon, Gemma, GPTOSS, Llama, Mistral, Phi, Qwen and more.

  • Pick architectures by latency, cost or license.
  • Swap baselines without reworking pipelines.
  • Benchmark variants with side-by-side evals.

Minimal time to market

Prebuilt flows accelerate data prep, training and deployment so teams deliver in weeks, not quarters.

  • Opinionated defaults for common industries.
  • CI-friendly hooks to automate retrains.
  • Safe rollout with canaries and quick rollback.

Train your own
model with Airflows.

Solutions · Banking & insurance

Risk decisions fast and auditable.

Automate document review, scoring and compliance with full audit of every decision, without moving data outside your perimeter.

Challenges
  • Slow, manual document review.
  • Regulatory pressure and audit needs.
  • Sensitive data that cannot leave.
Quick wins
  • Automatic document extraction and validation.
  • Explainable, traceable scoring.
  • GDPR compliance by design.
Use cases

From file to compliance.

Onboarding

KYC / AML

Document verification and automatic checks, with human escalation on exceptions.

Risk

Credit scoring

Custom models on your context, with every decision explained and logged.

Claims

Claims handling

Automatic classification and prioritization to resolve the urgent first.

Earn trust in every conversation

Precise, confidential and empathetic answers that strengthen customer confidence at scale.

Deliver error-free responses

In financial services a mistake can cost a customer for life; AI delivers instant, accurate and compliant support.

Guide complex journeys

From onboarding to loans, claims and disputes, with full-context handoff to a person when needed.

Customer stories

Operational workflows banking teams modernize first

Explore some of our work and discover how our platform has transformed banking operations.

Banco de Fomento
Documents · Agents

Banco de Fomento: Intelligence built into every document

Structured access to unstructured data — AI agents that surface the right information from transaction reports and client files, instantly and on demand.

  • Transform voluminous, unstructured records into searchable applications
  • Deploy AI agents that locate critical data to your teams in real time
  • Eliminate intensive review across client files, reports, and operational records
Minsait
Platform · Time-to-market

Minsait: A full factoring platform, shipped on your timeline

A production-ready product delivered at a speed and cost no conventional approach could match.

  • Compress development cycles with AI-powered tooling without sacrificing quality
  • Deploy a white-label solution ready to roll out across your client portfolio
  • Ambitious delivery windows, out of reach with conventional development stacks
Banking & insurance

Risk under control,
faster decisions.

Solutions · Healthcare

Less admin burden, more clinical time.

Clinical document management and administrative processes with privacy by design, so teams focus on the patient.

Challenges
  • Fragmented clinical documentation.
  • Strict privacy and consent.
  • Admin tasks that steal time.
Quick wins
  • Structured extraction from reports.
  • Privacy by design, data under control.
  • Automation of administrative circuits.
Use cases

From document to care.

Patients

Administrative attention

Assistants that handle appointments and procedures, freeing staff.

Documentation

Clinical reports

Structures and summarizes documentation with traceability and privacy.

Compliance

Consent & GDPR

Access controls and logging of every use of sensitive data.

Less admin, more care

Teams reclaim hours from paperwork to spend on the patient.

Every record, traced

Clinical information is governed with full traceability and compliance by design.

Care that never rests

Continuous support for patients and professionals, at any time.

Customer stories

Operational workflows healthcare teams modernize first

Explore some of our work and discover how our platform has transformed healthcare operations.

HealthInCode
Clinical data

Clinical data structured from the source

An interoperable taxonomy platform that standardizes heterogeneous clinical data at intake — so analysis, decisions, and compliance are built on a single reliable foundation.

  • Collect and structure clinical information through intelligent, standardized intake interfaces
  • Unify fragmented clinical datasets into an interoperable, audit-ready structure
  • Accelerate decision-making with clean, contextual data available across every care team
Healthcare

Technology in service
of the patient.

Solutions · Utilities / Infrastructure

Critical assets, operated with intelligence.

Predictive maintenance and critical-asset operations combining IoT data and custom models, with human oversight.

Challenges
  • Costly unplanned downtime.
  • Scattered IoT data without context.
  • Distributed assets hard to monitor.
Quick wins
  • Predictive maintenance on IoT signals.
  • Early anomaly detection.
  • Operations with human oversight.
Use cases

From signal to action.

Maintenance

Predictive

Anticipate failures and plan interventions before breakdown.

Operation

Monitoring

Dashboards that update instantly across your assets.

Efficiency

Optimization

Tune consumption and resources to real demand.

Fewer unplanned stops

The operation anticipates incidents before they halt service.

From signal to action

Field signals are analyzed and turned into operational decisions in real time.

Traceable operation

Every action is logged and auditable end to end.

Customer stories

Operational workflows utilities & infrastructure teams modernize first

Explore some of our work and discover how our platform has transformed utilities and infrastructure operations.

Acciona
Sustainability

Acciona: Sustainability impact, made visible and verifiable

A dynamic platform that publishes sustainability initiatives to the public in real time.

  • Publish sustainability projects through a visual portal
  • Onboard new initiatives quickly through an agile management layer
  • Bring real value of sustainability work to the public
Arval
Mobility · Real time

Arval: Smarter mobility costs in real time

A high-performance configuration and calculation engine that lets clients instantly model their mobility costs — built to handle the scale of a major national campaign.

  • Give clients a visual, intuitive tool to configure and compare mobility scenarios
  • Run complex cost calculations in real time, powered by a robust backend interaction layer
  • Scale seamlessly under high traffic without compromising speed or user experience
Utilities / Infrastructure

Critical infrastructure,
always running.

Solutions · Industry / Telco

Plant and network processes, truly automated.

AI automation of plant and network processes, keeping human oversight where risk demands it.

Challenges
  • Repetitive manual processes.
  • High volume of incidents.
  • Legacy systems hard to integrate.
Quick wins
  • End-to-end process orchestration.
  • Automatic incident classification and routing.
  • Integration with legacy systems, no migration.
Use cases

From incident to resolution.

Plant

Process automation

Workflows that run repetitive tasks with human oversight.

Network

Incident management

Automatic classification and routing to resolve faster.

Quality

Quality control

Real-time detection of defects and deviations.

Processes that fly

Critical flows resolve at a speed manual work can't reach.

Less manual work

Agents take on repetitive tasks and free teams for what adds value.

Full traceability

Every process is documented and ready for audit and compliance.

Customer stories

Operational workflows industry & telco teams modernize first

Explore some of our work and discover how our platform has transformed industry and telco operations.

+Orange
Compliance · Governance

+Orange: Gift compliance, controlled end to end

A centralized gift management platform with a built-in rules engine — so every interaction is tracked.

  • Enforce spending thresholds automatically with configurable rules
  • Route approvals through hierarchical review flows
  • Immutable audit trail that satisfies regulators and compliance teams
Universidad Europea
Education · Review

Universidad Europea: half the time, twice the accuracy in reviews

An AI platform that reads, extracts, and routes academic programme documents — cutting cycles by 50% while keeping control.

  • Extract student outcomes and impact from lengthy academic reports
  • Automatically assign documents to the right reviewers via a BPM engine
  • Reduce error-prone manual validation while keeping faculty sign-off as the final gate
Industry / Telco

Plant and network,
operated with AI.

Company · Partners

Grow with Airflows.

Join an ecosystem of technology, implementation and channel partners building private, operational AI for regulated industries and the public sector.

Our partners

An ecosystem that delivers.

Technology, implementation and channel partners building private operational AI together with us.

Now available on Google Cloud Marketplace

Deploy Airflows directly from your Google Cloud account, with consolidated billing.

Available onGoogle Cloud Marketplace
Partner tiers

Three ways to partner.

Technology

Technology partners

Integrate your models, connectors or data products with the Airflows platform.

Implementation

Implementation partners

Deliver and scale Airflows projects with certified teams and shared methodology.

Channel

Reseller & channel

Bring private operational AI to your market with commercial and enablement support.

How to join

From application to delivery.

01

Apply

Tell us about your company and focus.

02

Enable

Access training, documentation and certification.

03

Build

Develop and validate your first joint solution.

04

Grow

Go to market with commercial support.

Let’s build together.

Company · Careers

Build the future
of operational AI.

We’re a small team with big impact, building private AI for organizations that can’t compromise on control. Join us.

Equipo de Airflows trabajando
Why Airflows

Small team,
big impact.

  • Work on real AI in production, not demos.
  • Ownership from day one, with a flat team.
  • Hybrid work from Madrid and remote (ES).
  • Shape a product used in regulated, mission-critical settings.
Open roles

Join the team.

AI Engineer (Agents)

Madrid · HybridApply

Platform Engineer

Madrid · HybridApply

Product Designer

Remote (ES)Apply

Customer Success Manager

MadridApply

Solutions Engineer (Public Sector)

MadridApply

Don’t see your role? Write to us anyway.

Let’s talk.

Downloads area

Everything you need to get to know us.

Private, operational and governed AI — explained on paper. Dossiers, datasheets, brand kit and corporate material, ready to download.

Product Hub

Resources.

Brand

Logos & brand kit.

Airflows logo blanco
Logo — white
For dark backgrounds
Airflows logo negro
Logo — black
For light backgrounds

Need the full brand kit — colors and usage guidelines?

Open brand kit

Can’t find what you need?

Brand kit

The Airflows brand kit.

Logos, colors and usage guidelines. Use them to represent Airflows consistently.

Logo

Download the logo.

Airflows logo blanco
Logo — white
For dark backgrounds
Airflows logo negro
Logo — black
For light backgrounds
Colors

The palette.

Ink#070809
Green#00FF6D
Blue#009DFF
Pink#F9006C

Black is the spine of the brand. The RGB accents (green, blue, pink) live inside the flow imagery and data, never as flat color walls.

Usage

Do & don’t.

Do

  • Keep clear space around the logo.
  • Use white logo on dark, black logo on light.
  • Let accent colors live inside imagery and data.

Don’t

  • Don’t recolor or distort the logo.
  • Don’t place the logo on busy backgrounds.
  • Don’t use accents as flat color walls.

Need something else?

Legal

Privacy Policy

Last updated: 16/11/2025.

At Air Flows Data Platform, S.L., we are committed to protecting the privacy and trust of our clients and potential clients. This policy details how we collect, use, store, protect, disclose, and manage your personal information (also known as personal data).

Our goal is to ensure maximum transparency and security in the handling of your information, strictly complying with current data protection legislation, including the General Data Protection Regulation (GDPR) in the European Union, the Organic Law on Personal Data Protection and guarantee of digital rights (LOPD GDD) in Spain, and other applicable regulations.

This policy applies to the processing of your personal information in connection with the use of our websites and applications that link to this Privacy Policy (collectively, the "Sites"), our products and services (the "Services"), and in the normal course of our business activities, such as events, sales, and marketing activities.

Scope of the Policy

This Privacy Policy is applicable to the personal information we collect, use, and process in connection with:

  • Our Websites and Applications: any website, mobile application, software, or other digital services that we own and that link to this policy.
  • Our Services (products and services): information processed when you contract or use our products and services.
  • Our Regular Business Activities: information collected in the context of events, trade shows, sales activities, marketing initiatives, webinars, and any other interaction we have with you.

Exclusions. This policy does not apply to data our clients upload to our platform services and that we process on their behalf (governed by the client agreement); to any product, service, website, or content offered by third parties with its own privacy policy; nor to information processed in connection with recruitment, covered by a separate candidate privacy policy.

Personal Information We Collect

Information You Provide to Us

  • Identifiers: full name, title, position, email address, phone number, postal address, country.
  • Professional/employment information: company name, industry, company size, position, role.
  • Account information: authentication information used to access the Services if you create an account.
  • Customer service and other interaction information: information collected when you interact and communicate with us (support, surveys, feedback, event registration, marketing), including records of communications, which may be stored as an audio file or transcript.
  • Commercial and financial information: purchase history and past transactions, and information about your designated payment method(s), which may be collected by third-party payment and billing providers.
  • Information posted in public forums: any information you post publicly will be visible to other users and potentially through search engines; be careful and do not provide personal information you do not want made available this way.

Information We Collect Automatically

We use standard automatic data collection tools, such as cookies, web beacons, tracking pixels, tags, and similar tools, to collect information about internet and device activity, as well as how people use our Sites and interact with our emails.

This may include information about your computer or device (operating system, device identifier, browser language, IP address) and about your activities on our Sites (how you arrived, access times, links you click, browsing behavior). We also collect "Usage Data" when you use the Services, to provide, support, secure and improve them. See our Cookie Policy for more detail.

Information We Receive from Other Sources

We may obtain information about you from third-party sources, including resellers, distributors, business partners, event sponsors, security and fraud detection services, social media platforms, and publicly accessible sources, and combine it with information we receive from you.

Purposes and Legal Bases for Data Processing

We use your personal information to provide, maintain, improve, and update our Services. The purposes and the legal bases that legitimize them are:

PurposeLegal basis (GDPR/LOPDGDD)
A. Provision of ServicesPerformance of a contract (Art. 6.1.b GDPR)
B. Commercial communication and marketingConsent (Art. 6.1.a GDPR)
C. Communication with youLegitimate interest (Art. 6.1.f) / Performance of a contract
D. Online advertisingConsent (Art. 6.1.a GDPR)
E. Personalization and improvement of ServicesLegitimate interest (Art. 6.1.f GDPR)
F. Legal and security purposesLegal obligation (Art. 6.1.c) / Legitimate interest
G. Administrative and financial managementPerformance of a contract / Legal obligation
H. Other purposes with your consentConsent (Art. 6.1.a GDPR)

For these purposes we may use tools such as large language models (LLMs) and other forms of artificial intelligence in accordance with applicable law. We may de-identify or anonymize information so it cannot reasonably identify you; our use of de-identified information is not subject to the restrictions of this policy.

How We Collect Data

  • Direct interactions: by phone, email, chat, in person (fairs, events, meetings), or by completing surveys and forms.
  • Our Websites and Applications: registration forms, newsletter subscriptions, demo requests, content downloads, or use of our online platforms.
  • Automatic data collection technologies: cookies, web beacons, tracking pixels and similar tools (see Cookie Policy).
  • Social networks and third parties: interactions on social media and data from partners, sponsors and publicly accessible sources, in accordance with regulations.

Data Recipients and International Transfers

We do not sell or rent your personal information to third parties for their own direct marketing without your explicit consent. We may disclose it to: service providers (data processors) who assist us (billing, payments, support, marketing, analytics, hosting, security), bound by confidentiality; partners and sponsors where a legal basis exists; for legal purposes; with your consent; and as part of business transactions.

International Data Transfers

We may transfer your information to countries other than your country of residence. Whenever we do, we apply appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and supplementary measures, to protect your data in accordance with applicable law.

Data Retention Period

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected and to address potential liabilities. The criteria are:

  • Clients: during the contractual relationship and, thereafter, the legally required periods (e.g. 5 years for personal actions; 6 years for accounting documentation).
  • Potential clients (leads): as long as business interest is maintained and consent is not revoked or the right to erasure is exercised.
  • Marketing purposes: until you revoke consent or object to the processing.
  • Legal obligations and fraud prevention: the time required by law and a reasonable period to detect and prevent fraudulent activity.

Once the retention period ends, data is securely deleted or anonymized, unless there is a legal requirement to keep it.

Security Measures

We implement technical, physical, and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction, including:

  • Data encryption in transit (SSL/TLS) and at rest where possible.
  • Access controls based on least privilege and identity management with multi-factor authentication.
  • Regular backups, monitoring and intrusion detection.
  • Security audits, staff training and confidentiality agreements.

However, no security measure is perfect or impenetrable, so we cannot guarantee the absolute security of your information.

Your Privacy Choices and Rights

As a data subject you have the rights of access, rectification, erasure (right to be forgotten), restriction of processing, portability, objection, to withdraw consent, and not to be subject to solely automated decision-making, as well as to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

How to Exercise Your Rights

To exercise them, contact us through the channels in "How to Contact Us". We may require proof of your identity to verify you are the data subject; that information will only be used to process your request.

Opting out of marketing communications

You can opt out by following the unsubscribe instructions in each communication or by emailing support@airflows.com. We may still send you important service- or account-related communications.

Additional Important Information

Third-Party Services

Our Services may contain links to third-party websites, applications, services or social networks, or allow login with third-party credentials. Information you submit to those services is not covered by this policy; review their terms and privacy notices.

Children’s Data

The Sites and Services are not directed to children under 18, and we do not knowingly collect personal information from children under 18. If we learn we have collected such data, we will take steps to delete it.

Changes to the Privacy Policy

We may change this Privacy Policy from time to time. We will post changes on this page and, if substantial, provide a more prominent notice. If you do not agree with the changes, you must stop using the Services.

How to Contact Us

If you have any questions about our privacy practices or this Privacy Policy, contact us at support@airflows.com.

Postal address:
Air Flows Data Platform, S.L.
Carretera de Fuencarral, 56, Edif. Neogreen
28108 Alcobendas (Madrid), Spain

Legal

Terms of Service

Last updated: 16/11/2025.

These subscription conditions are an inseparable part of the subscription contracted through the Order Form and will come into effect on the date of their signature between Airflows Data Platform SL. ("Airflows") and the entity signing these General Conditions (the "Client"). They may be referred to jointly as the "Parties".

Purpose

The purpose of the General Conditions is to establish the terms on the basis of which Airflows grants the "Beneficiary" (the Client or a third party) a right of use subscription for the software it exclusively owns, Airflows Data Platform (the "Software"), in a Software as a Service (SaaS) modality.

Subscription

Rights

The Subscription grants the Beneficiary, during its term, a non-exclusive and non-transferable right to access and use the Software in its SaaS modality, exclusively for its internal business purposes and in accordance with the General Conditions and the Use Documentation. Any other access or use will constitute a breach of the Agreement.

The Beneficiary undertakes to maintain the confidentiality of its accounts, credentials and passwords, being responsible for any use of the Software made through them, and to immediately notify Airflows of any loss, theft or suspected unauthorized use.

The Subscription allows remote access and use of the Software’s functionalities via the Internet and includes management and operation services for the Cloud infrastructure on which it is installed, as well as updates, bug fixes and hot-fixes to keep the product operational.

Through the subscription, the Beneficiary is entitled to: 8x5 support for logging cases (incidents and requests) related to the platform; technical support related to installation and use; and access to platform documentation from the contracted instance.

Not included: support for applications developed on the platform; consulting or other services not expressly contracted; installation or troubleshooting of third-party software; nor resolution of incidents caused by improper use of the Software or by modifications not authorized by Airflows.

Service levels included: Monitoring (N1): environment monitoring, attention and incident logging. Operation (N2): expert personnel in operation and administration of clusters. Systems (N3): expert personnel in operation, administration and installation of Airflows instances.

The standard SaaS subscription includes an Airflows cloud instance with: 2 vCPUs; 4 GiB of memory; 20 Tb outbound data transfer (€3/Tb additional); and 50 Gb storage (€0.16/Tb additional).

Beneficiary’s Responsibilities

  • Manage and maintain the product in accordance with the defined best practices and not modify it.
  • Provide the connectivity and necessary access for the correct performance of the Support Service.
  • Keep the teams responsible for Software maintenance available for incident resolution.

Prohibitions

Under the Agreement no right beyond the described access and use is granted; no rights of reproduction, distribution, public communication or transformation of the Software are granted. Unless expressly authorized by Airflows, the Beneficiary shall not, among others: use the Software in a way that causes damage or interruptions; transmit viruses or malicious code; use it unlawfully; access without authorization any section, system or network; break its security measures; saturate its infrastructure; infringe third-party rights; reverse engineer it; transfer, sell, resell, sublicense, rent or distribute the Software; nor copy, adapt or incorporate it into another program to create a derivative work.

Prohibition of access to third parties

The Beneficiary may not provide access to the Software to third parties, in whole or in part, without prior written authorization from Airflows. In no case may such third party be a direct or indirect competitor of Airflows. If agreed, that third party must accept these General Conditions and sign the corresponding confidentiality agreement.

Duration

The Subscription has the duration established in the "Order Conditions" of this document.

Billing and Payment Method

If invoices are not paid within the established period, a monthly default interest of 1.5% (or the maximum legal amount) will accrue from the due date until full payment. In the event of non-payment, Airflows may suspend the Subscription, without liability, until settlement, or terminate the Agreement.

Representations and Warranties

The Parties mutually guarantee compliance with their commitments and will indemnify each other against third-party claims linked to the Agreement. Airflows has developed the Software in accordance with international secure development standards, but does not guarantee uninterrupted continuity of service, the total absence of errors, or its suitability for a specific purpose.

Each Party’s maximum liability arising from the Agreement is limited to the amount actually paid to Airflows for the Subscription during the twelve (12) months prior to the event giving rise to the claim, except in cases of fraud, gross negligence or personal injury. The Parties shall not be liable for indirect, consequential or punitive damages.

Termination

In addition to the legal causes, the Agreement may be terminated early for breach of material obligations, after prior request and once thirty (30) days have elapsed without remedy. It may also be terminated immediately by mutual agreement, extinction of a Party’s legal personality or other foreseen causes. Termination entails the return of the documentation and information provided and payment of amounts accrued up to the effective date.

Confidentiality

During the term of the Agreement and after its termination, the Parties will maintain strict confidentiality over its content and all derived information, without using it for their own or third parties’ benefit. However, unless expressly indicated by the Beneficiary, Airflows may use its name and logo in commercial materials and documentation to demonstrate its market experience.

Intellectual and Industrial Property

Each Party retains ownership of its respective intellectual and industrial property rights. In particular, the Software and all its components (texts, images, technology, know-how, software, graphic design and source code) are the exclusive property of Airflows, and no right over them is deemed assigned beyond the use license. All developments, improvements and new versions of the Software shall also be the exclusive property of Airflows.

Airflows’ liability for intellectual property infringements is limited to a maximum amount equivalent to the net amount received for the Subscription during the twelve (12) months prior to the infringement.

Access to Data on Behalf of the Beneficiary

When, in the performance of the Agreement, Airflows provides a service involving access to and processing of personal data, it shall be considered the "Processor" and the Beneficiary the "Controller". The Processor will process the data solely to provide the Subscription, following the Controller’s instructions.

Possible processing operations: collection, recording, consultation, storage, dissemination, modification and deletion of personal data.

Processor’s obligations

  • Process the data only to provide the Subscription, in accordance with the Controller’s written instructions.
  • Maintain the duty of secrecy, even after the relationship ends, and ensure staff confidentiality commitments.
  • Apply appropriate technical and organizational measures (pseudonymisation and encryption; confidentiality, integrity, availability and resilience; recovery after incidents; and regular evaluation of their effectiveness).
  • Delete or return the data at the end of the service and notify the Controller of any security breach in accordance with Art. 33 GDPR.
  • Not transfer data outside the EEA without prior authorization from the Controller and adequate safeguards (standard contractual clauses, binding corporate rules or authorization from the competent authority).

Relationship Between the Parties

The Parties acknowledge the commercial nature of their relationship and their absolute independence and autonomy. Nothing in the Agreement shall be interpreted as the constitution of a company, agency or joint venture, nor as an employment relationship between them.

Force Majeure

The Parties shall not incur liability for breaches arising from a fortuitous event or force majeure (events beyond their will, unforeseeable or unavoidable). If the impediment persists for more than thirty (30) days, either Party may terminate the Agreement by written notice.

Prohibition of Assignment

The assignment or transfer of the rights and obligations assumed by either Party may only be carried out with the express written agreement of the other. Any assignment contrary to this clause shall be void.

Notifications

The Parties accept email as a valid means of communication for the purposes of the Agreement. Communications are deemed notified when received legibly, unless a delivery-failure notice is received. Communications sent after 5 p.m. in the destination city shall take effect on the next business day.

Partial Nullity

If any clause of the Agreement is declared null or illegal, the Parties will maintain the contractual relationship with respect to the rest, integrating or correcting the effects of such nullity as far as possible.

Enforceability

A Party’s failure to demand compliance with any stipulation shall not affect its right to require it later, nor constitute a waiver to denounce future breaches.

Applicable Law and Jurisdiction

For anything not provided for in the Agreement, the Spanish legislation in force shall apply. For any dispute arising from its interpretation or application, the Parties expressly submit to the Courts of the city of Madrid, waiving any other jurisdiction.

Legal

Information Security Policy

Last updated: 24/06/2026.

Introduction

AIR FLOWS DATA PLATFORM SL, hereinafter AIRFLOWS, depends on information systems to achieve its objectives. These systems must be managed with due diligence, taking appropriate risk-based measures to protect them against accidental or deliberate damage that may affect the authenticity, traceability, integrity or confidentiality of the information processed, or the availability of the services provided.

The ultimate goal of information security is to ensure that the organization can meet its objectives, carry out its functions and deliver the services for which it was established, acting proactively, supervising daily activity and responding promptly to incidents.

ICT systems must be protected against rapidly evolving threats that may affect the confidentiality, integrity, availability, intended use and value of information and services. Defending against these threats requires a strategy that adapts to changing environmental conditions to ensure continuous service delivery. This means departments must apply the minimum security measures required by the National Security Framework (ENS), continuously monitor service levels, track and analyze reported vulnerabilities, and prepare an effective incident response to ensure continuity of services.

AIRFLOWS must ensure that ICT security is an integral part of every stage of the system lifecycle, from conception to decommissioning, including development or acquisition decisions and operational activities. Security requirements and funding needs must be identifiable and included in planning, requests for proposals and tender specifications for projects involving personal data, ICT services or services that affect information systems.

Document information

FieldValue
DocumentInformation Security Policy
Document typeRegulatory framework
ClassificationPublic
CompaniesAIR FLOWS DATA PLATFORM SL
PurposeEstablish the information systems security policy
AuthorAIRFLOWS
Version1.1
StatusApproved

Review and approval

ActionByDate
Reviewed bySecurity Officer / System Owner29/01/2026
Approved bySecurity Committee24/06/2026

Change control

VersionDateAuthorDescriptionStatus
1.028/01/2026Telefónica consultants; Security Officer; System Owner; Information and Service OwnersInitial versionReview
1.124/06/2026Security CommitteeFormal approval by the Security CommitteeApproved

Scope

This policy applies to all AIRFLOWS information systems, to the people who make up the organization, and to AIRFLOWS ICT service providers or solution suppliers.

Information system of HIGH category pursuant to Royal Decree 311/2022.

Mission and objectives

At AIRFLOWS we define ourselves as a technology company specialized in the intelligent orchestration of operations through AI, by developing a product made available to customers via SaaS and different partners.

The security objectives that AIRFLOWS aims to ensure with this Policy are:

  • Ensure the confidentiality, integrity and authenticity of information and continuity in the delivery of services.
  • Implement security measures based on risk.
  • Train and raise awareness among AIRFLOWS members regarding information security.
  • Implement security measures that enable access traceability and respect, among others, the principle of least privilege, also reinforcing users’ duty of confidentiality regarding information they access in the course of their duties.
  • Deploy and control physical security so that information assets are located in secure areas, protected by access controls, according to the risks identified.
  • Establish security in communications management through the necessary procedures, ensuring that information transmitted over communications networks is adequately protected.
  • Control the acquisition, development and maintenance of information systems throughout their lifecycle, ensuring security by default.
  • Control compliance with security measures in service delivery, maintaining control over the acquisition and incorporation of new system components.
  • Manage security incidents for their proper detection, containment, mitigation and resolution, adopting the measures necessary to prevent recurrence.
  • Protect personal information by adopting technical and organizational measures according to the risks arising from processing, in line with data protection legislation.
  • Continuously supervise the security management system, improving and correcting detected inefficiencies.

Guiding principles of the policy

  • Strategic scope: information security must have the commitment and support of all levels of the organization and must be coordinated and integrated with other strategic initiatives in a coherent way.
  • Comprehensive security: security shall be understood as a comprehensive process made up of all technical, human, material and organizational elements related to information systems, avoiding one-off or ad hoc actions. Information security must be part of day-to-day operations, present and applied from the initial design of ICT systems.
  • Risk-based security management: managing security based on identified risks will maintain a controlled environment, minimizing the risks to which information and its systems are exposed; measures shall be proportionate to the risk they address and must be justified. Risks identified in the processing of personal data shall also be taken into account.
  • Prevention, detection, response and preservation: by implementing preventive actions against incidents, minimizing detected vulnerabilities, preventing threats from materializing and, when they do, providing an agile response to restore information or services, ensuring secure preservation of information.
  • Lines of defense: the organization’s security strategy is designed and implemented in layers.
  • Continuous monitoring and periodic reassessment: the organization implements means to detect and respond to anomalous activities or behaviors, as well as others that allow continuous assessment of the security status of assets. There will also be a continuous improvement process for the periodic review and update of security measures according to their effectiveness and the evolution of risks and protection systems.
  • Security by default and by design: systems must be designed and configured to ensure security by default. Systems shall provide the minimum functionality necessary to deliver the service for which they were designed.
  • Separation of duties: pursuant to this principle, the functions of the Security Officer and the System Owner shall be separated.

Regulatory framework

The main regulations affecting this Policy are:

  • Royal Decree 311/2022 of 3 May, regulating the National Security Framework (ENS).
  • Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2), on measures for a high common level of cybersecurity across the Union.
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), laying down harmonized rules on artificial intelligence.
  • Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act).
  • Organic Law 3/2018 of 5 December on Personal Data Protection and guarantee of digital rights.
  • Regulation (EU) 2016/679 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • Royal Decree 1007/2023 (Verifactu Regulation), on requirements for billing IT systems to prevent record alteration.
  • Law 18/2022 (Crea y Crece Law), regulating the mandatory use of electronic invoicing in commercial transactions between companies and self-employed persons.
  • Information Security standards, especially the latest versions of ISO/IEC 27001 and ISO/IEC 27002, as well as ISO/IEC 27034 (Application security).

Security organization

Taking into account the provisions of the ENS, the organization establishes the following actions to organize Information Security:

  • It shall designate security roles: Service Owner(s), Information Owner, Security Officer, System Owner and Data Protection Officer.
  • It shall establish an advisory and strategic body for decision-making on Information Security. This body shall be called the Information Security Committee.

Definition of ENS-related roles and responsibilities

Information Owner (RINF) and Service Owner (RSERV)

The functions of the Information and Service Owners shall be:

  • Establish the security requirements applicable to information (information security levels) and to Services (service security levels), within the framework set out in Annex I of the ENS Royal Decree, and may request a proposal from the Security Officer taking into account the System Owner’s opinion.
  • Decide on access rights to information and services.
  • Accept residual risk levels affecting information and services.
  • Inform the Security Officer of any change regarding the Information and Services under their responsibility, especially the addition of new Services or Information. The Security Officer shall report such changes to the Information Security Committee at its next meeting.
  • They have ultimate responsibility for the use made of certain services and information and, therefore, for their protection.

Security Officer (RSEG)

The functions of the Security Officer shall be:

  • Maintain and verify the appropriate security level of the Information handled and of the electronic Services provided by the information systems.
  • Promote training and awareness on information security.
  • Designate those responsible for carrying out the risk analysis and Statement of Applicability, identify security measures, determine required configurations and prepare system documentation.
  • Approve the Statement of Applicability based on the security measures required under Annex II of the ENS, in a separate document.
  • Provide advice for determining the System Category, in collaboration with the System Owner and/or ICT Security Committee.
  • Participate in preparing and implementing security improvement plans and, where applicable, continuity plans, and validate them.
  • Manage external or internal system reviews.
  • Manage certification processes.
  • Escalate to the Security Committee the approval of changes and other system requirements.
  • Approve security procedures that form part of the Regulatory Framework (and are not within the Committee’s remit) and inform the Committee of modifications made during the current period.
  • Participate in drafting, within the Information Security Committee, the Information Security Policy for approval by Management.
  • Coordinate with the Committee Secretary the calling of meetings and preparation of the agenda: call meetings, prepare topics with timely information for decision-making, and draft meeting minutes.
  • Is responsible for the direct or delegated execution of Committee decisions.

System Owner (RSIS)

The functions of the System Owner shall be:

  • Develop, operate and maintain the information system throughout its lifecycle, preparing the necessary operating procedures.
  • Define the topology and management of the Information System, establishing usage criteria and available services.
  • Halt access to information or service delivery if aware of serious security deficiencies.
  • Ensure that specific security measures are properly integrated within the general security framework.
  • Provide advice for determining the System Category, in collaboration with the Security Officer and/or Information Security Committee.
  • Participate in preparing and implementing security improvement plans and, where applicable, continuity plans.
  • Coordinate the system security administrator’s functions: management, configuration and updating of security hardware and software; management of user authorizations and privileges, including activity monitoring; approve configuration changes; ensure strict compliance with controls and procedures; supervise installations, modifications and improvements; monitor security status; inform the Security Officer of anomalies, compromises or vulnerabilities; and collaborate in investigating and resolving security incidents.

Data Protection Officer (DPO)

The functions of the Data Protection Officer shall be:

  • Inform and advise the organization and users involved in processing of their obligations under applicable Data Protection regulations.
  • Supervise compliance with security regulations and the organization’s internal data protection policies, including allocation of responsibilities, awareness and training of staff involved in processing operations, and related audits.
  • Provide requested advice on data protection impact assessments and supervise their implementation.
  • Cooperate with the Spanish Data Protection Agency when required, acting as the point of contact on data processing matters.
  • Perform their duties with attention to the risks associated with processing operations: gather information to determine processing activities; analyze and verify compliance; inform, advise and issue recommendations; supervise the record of processing activities; advise on data protection by design and by default; advise on impact assessments; prioritize activities based on risk; and advise the Controller on areas to audit, training and operations requiring more resources.

Information Security Committee

The organization has established an Information Security Committee composed of a Chair, a Secretary and Members. These members are classified as permanent or non-permanent according to whether participation is mandatory:

Permanent members:

  • Chair.
  • Security Officer.
  • System Owner.

Non-permanent members:

  • Service Owners.
  • Information Owner.
  • Data Protection Officer.
  • Organization representatives and external specialists from the public or private sector whose presence is necessary or advisable due to their experience or connection with the matters discussed.
  • Advisors deemed appropriate for the topics at hand (with voice but without vote).

Information and Service Owners shall be called by the Chair according to the matters to be discussed, representing the different ICT security areas. Each area shall be represented by one voting member, without prejudice to several representatives attending.

The Data Protection Officer shall participate with voice but without vote in Committee meetings when personal data processing matters are discussed, and whenever their participation is required. In any case, if a matter is put to a vote, the Data Protection Officer’s opinion shall always be recorded in the minutes.

The Committee Secretary shall issue meeting notices and take minutes. Persons whom the Chair deems appropriate may attend sessions as advisors.

Security Committee roles

  • Chair: CEO
  • Secretary: Head of Operations and Alliances
  • Members: CEO, CFO, CTO, Head of Product Engineering, CPO and Head of Operations and Alliances
  • System Owner: Head of Product Engineering
  • Security Officer: CPO
  • Data Protection Officer: external provider (Govertis)
  • Information Owner: CEO, CFO, CTO, Head of Product Engineering, CPO and Head of Operations and Alliances
  • Service Owner: Head of Product Engineering and Head of Operations and Alliances

Security Committee powers

The functions of the Security Committee shall be:

  • Address the concerns of Senior Management and the different departments.
  • Regularly report the status of information security to Senior Management.
  • Promote continuous improvement of the Information Security Management System.
  • Develop the evolution strategy regarding information security.
  • Promote periodic audits to verify compliance with the organization’s security obligations.
  • Approve information security documentation.
  • Remain permanently informed of the regulations governing ENS Conformity Certification, including accreditation and certification rules, guides, manuals, procedures and technical instructions.
  • Remain permanently informed of the list of accredited Certification Bodies and certified public and private organizations.
  • Remain permanently informed of security certification schemes with which the Public Administration has mutual recognition arrangements or agreements.
  • Propose guidelines and recommendations, to be recorded in the corresponding Committee meeting minutes, to which the Chair shall give a full response.
  • Coordinate the efforts of the different areas on information security to ensure they are consistent, aligned with the agreed strategy, and to avoid duplication.
  • Address Information Security concerns from the Administration and the different areas, regularly reporting the status of information security to Management.
  • Resolve responsibility conflicts that may arise between different officers and/or departments, escalating cases where it lacks sufficient authority to decide.
  • Advise on information security whenever required.
  • Review the Information Security Policy prior to approval by the Superior Body.

Meeting frequency and adoption of resolutions

  • The Information Security Committee shall meet at least once a year, without prejudice to more frequent meetings as needed to fulfill its purposes and powers.
  • In any case, meetings shall be called by the Chair, through the Secretary, on the Chair’s initiative or by a majority of permanent members.
  • Decisions shall be adopted by consensus of the permanent members.

Appointment and conflict resolution

  • The creation of the Information Security Committee, the appointment of its members and the designation of the Officers identified in this Policy shall be carried out through an initial constitutive record.
  • Named roles shall be renewed annually automatically. Departures or changes in designated roles shall be communicated to the Committee and the established channels followed to appoint the new officer.
  • As regulated in Article 13.3 of the ENS Royal Decree, there shall be no hierarchical dependence between the RSEG and the RSIS, except for justified exceptions, which shall entail compensatory measures to ensure the purpose of the separation of duties principle.
  • When a conflict arises between the security requirements established in this Policy and operational or business needs, any officer may escalate it to the Information Security Committee for resolution. The Committee shall decide by consensus and the decision shall be documented in the minutes of the corresponding session.
  • In situations of operational urgency where the Committee cannot be convened immediately, the Security Officer may adopt a provisional measure, which must be documented and submitted for ratification by the Committee at the next ordinary or extraordinary session.

Processing of personal data

AIRFLOWS processes personal data as described in the Record of Processing Activities. AIRFLOWS shall assess the risks related to the personal data processed and propose an action plan to remediate risks that exceed the authorized threshold.

The risk analysis shall be reassessed periodically, with advice and supervision from the Data Protection Officer, and in any case when high-risk processing is detected, carrying out an impact assessment where appropriate. Implementation of the risk treatment plan shall be coordinated with that of the ENS, as well as with other security procedures or rules derived from data protection obligations, especially regarding control of service providers or response to incidents and/or security breaches.

Risk management

All systems subject to this Policy shall carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis shall be repeated:

  • Regularly, at least once a year.
  • When there are changes in the information handled.
  • When there are changes in the services provided.
  • When a serious security incident occurs.
  • When serious vulnerabilities are reported.
  • When there are modifications to the data protection risk analysis or impact assessments.

To harmonize risk analyses, the Information Security Committee shall establish a reference valuation for the different types of information handled and the different services provided. The Security Committee shall foster the availability of resources to meet the security needs of the different systems, promoting horizontal investments.

Data protection risks shall be taken into account, with the opinion of the Data Protection Officer; risk treatment plans shall also be coordinated.

The Statement of Applicability (SoA) sets out the detail of National Security Framework controls applicable to the AIR FLOWS DATA PLATFORM SL information system, pursuant to Annex II of Royal Decree 311/2022, together with their applicability justification and maturity level.

Development of the Information Security Policy

This Information Security Policy shall be complemented by more specific documents (security standards, procedures and technical instructions) that help carry out what is proposed.

The body of rules shall be developed at three levels:

  • First regulatory level: consisting of this Information Security Policy.
  • Second regulatory level: consisting of security standards derived from the above, aiming to indicate the correct use of specific aspects of the information security management system.
  • Third regulatory level: consisting of security procedures, guides and technical instructions. These are documents that, in compliance with the Information Security Policy, determine the actions or tasks to be performed in carrying out a process.

Management is responsible for approving the Information Security Policy, and the Information Security Committee is the body responsible for approving and disseminating the organization’s other documents, as established in Article 12 of the ENS Royal Decree.

Any change to it shall be disseminated to all affected parties.

Staff obligations

All members of AIRFLOWS are obliged to know and comply with this Information Security Policy and the standards, procedures or guides that develop it. It is the responsibility of AIRFLOWS, through the Security Committee and the people area, to provide the means necessary for the information to reach those affected.

All members of AIRFLOWS shall attend an information security awareness session at least once a year. A continuous awareness program shall be established for all AIRFLOWS members, particularly new joiners.

Persons with responsibility for the use, operation or administration of ICT systems shall receive training for the secure handling of systems to the extent needed to perform their work. Training shall be mandatory before assuming a responsibility, whether it is their first appointment or a change of role or responsibility.

Third parties

When AIRFLOWS provides services to other entities or handles their information, they shall be made aware of this Information Security Policy, without prejudice to data protection obligations if it acts as a processor in providing said services, and channels shall be established for reporting and coordination between the respective Security Committees and procedures for responding to security incidents. In addition, the Security Officer (or their delegate) shall be the Point of Contact (POC).

When AIRFLOWS uses third-party services or discloses information to third parties, they shall be made aware of this Security Policy and the Security Regulations applicable to those services or information, without prejudice to other data protection obligations. When contracting service providers or acquiring products, the contractor’s obligation to comply with the ENS shall be taken into account.

When acquiring rights to use cloud assets, the requirements set out in the security measures of Annex II and the development Guides shall be taken into account.

Such third party shall be subject to the obligations established in said regulations, and may develop its own operating procedures to meet them, so that AIRFLOWS can supervise them or request evidence of compliance, including second- or third-party audits. Specific incident reporting and resolution procedures shall be established and channeled through the POC of the third parties involved and, when personal data is affected, also through the Data Protection Officer. Third parties shall ensure that their staff are adequately security-aware, at least to the same level established in this Policy or as specifically required in the contract.

When any aspect of the Policy cannot be satisfied by a third party as required in the preceding paragraphs, the Security Officer shall issue a report specifying the risks incurred and how they will be treated. Approval of this report by the affected Information and Service Owners shall be required before contracting begins or, where applicable, before award. The report shall be forwarded to the organization’s representative, who must authorize continuation of the third-party contracting process, assuming the risks identified.

When the organization acquires, develops or deploys an Artificial Intelligence system, in addition to complying with applicable regulations, it shall have a report from the Security Officer, who shall consult the Information and Service Owners and, where necessary, the System Owner; the Data Protection Officer shall also issue their opinion.

Security incident management

AIRFLOWS shall have a procedure for the agile management of security events and incidents that pose a threat to information and services.

This procedure shall be integrated with others related to security incidents under other sectoral rules such as personal data protection or others affecting the organization, in order to coordinate the response from different perspectives and notify the relevant supervisory bodies without undue delay and, when necessary, the State Security Forces or the courts.

Approval and entry into force

This Information Security Policy is effective from its approval date on 24 June 2026, until it is replaced by a new Policy.