1. Controller and contact
For account, website, billing, sales and support data, the controller is AIME ΤΕΧΝΟΛΟΓΙΚΕΣ & ΨΗΦΙΑΚΕΣ ΥΠΗΡΕΣΙΕΣ Ε.Ε., Ερμού & Λυκοβρύσεως 14, Αθήνα 14452, Greece, trading as AIME. Contact privacy@aime.gr. When a business customer directs processing of its appointment clients, review workflow, prospect information or other customer-controlled content, the customer may be controller and AIME may act as processor under the applicable DPA. Roles depend on the actual Product and use; a connected provider may have its own role and notice.
2. Data and sources
We receive account identity and contact details, billing profile and transaction records, support and sales messages, security/usage logs, consent preferences, and Product inputs and outputs. Bookr may process appointment, service, staff, availability, client contact, reminder and Calendar connection data. Review Responder may receive authorized Google Business Profile locations, reviews, ratings, reviewer names, replies, resource identifiers and performance metrics when the customer connects and initiates the relevant action, together with human/AI draft and approval history. QuickScan processes submitted website and competitor URLs, fetched public page material, PageSpeed results where configured, analyses and reports. NewsPilot Early Access may process request/contact data, selected topics and drafts if access is granted. Do not submit special-category or unrelated third-party data without a lawful basis and an appropriate Product arrangement.
3. Purposes and lawful bases
We process account and purchased-service data to perform the contract; billing and tax records to meet legal duties; security, abuse prevention and service reliability for legitimate interests; support and communications to respond to requests and perform service obligations; optional marketing/analytics only on the applicable consent or other lawful basis. For customer-controlled content, the customer determines the underlying legal basis and instructions where it is controller. We do not use Product inputs for a purpose incompatible with the contracted service merely because they are available.
4. Product integrations and AI
Stripe processes AIME payments and related customer data. Google Business Profile, Calendar and PageSpeed integrations are conditional on the Product, customer action and configured provider access. Review Responder requires the customer's ownership or authorization for a profile and explicit human publication; Google review Content is subject to provider restrictions. Performance information, if offered, depends on the enabled Google connection. AI-assisted drafting/analysis may send selected inputs to configured model providers; the specific Product determines which input is sent. Review AI outputs and avoid unnecessary sensitive personal data.
5. Recipients and international transfers
We share data only as needed with configured hosting, identity/database, payment, email, monitoring, rate-limit, analytics and AI providers, and with conditional Google integrations chosen by the customer. The current Provider Notice distinguishes configured processors from conditional connections; it does not establish an executed DPA for every provider. Some processing may occur outside the EEA. Where Chapter V GDPR applies, AIME must verify the relevant adequacy decision or contractual safeguards and supplementary measures for the actual data flow before launch. We do not sell personal data.
6. Marketing site consent and storage
Public marketing pages do not automatically hydrate a live account session. Necessary security functions may use storage. Optional Analytics, Marketing and Preferences storage activates according to the separate consent choices explained in the Cookie Policy. The consent decision is saved as the browser localStorage key aime_cookie_consent_v2, with timestamp and version; it is not an HTTP cookie and the current implementation does not enforce a fixed expiry. You may reopen settings and withdraw or change optional consent.
7. Retention and deletion
We retain account, service and customer-controlled data while needed to provide the selected service and for applicable contractual, security, tax or legal obligations. There is no single retention period for every Product or record. Google review data is subject to the provider's storage restrictions; AIME seeks to remove locally held review Content within an operational period shorter than the provider maximum and on disconnect, but we do not promise a permanent review archive. Deletion from active systems may be followed by backup rotation or lawful record retention. Ask for Product-specific retention details or deletion at privacy@aime.gr; we assess the request against the controller/processor role and obligations.
8. Rights and requests
Subject to applicable law, you may ask for access, rectification, erasure, restriction, portability, object to certain processing, and withdraw consent without affecting prior lawful processing. Use privacy@aime.gr; AIME currently handles such requests manually where no Product-native control is required. We may verify identity and, when acting as processor, direct or assist the relevant customer controller. We respond within GDPR time limits, including any lawful extension with notice. You may complain to the Hellenic Data Protection Authority or another competent supervisory authority.
9. Security and incidents
We use access controls, authenticated Product routes, transport encryption, tenant-scoped database policies where implemented, provider secret handling, logging and incident processes appropriate to the service. No system is risk-free. AIME investigates suspected incidents and makes required customer or authority notifications according to its role and applicable law. Product-specific controls and third-party terms remain subject to verification.
10. Changes
Material changes to this policy will be published with an updated date and, where required, additional notice. Contact privacy@aime.gr for a copy or questions.
