We respect your privacy. This document describes what personal data we collect, on what legal basis, how long we retain it, and the rights you have as a data subject. It applies to aicolabs.io and any sub-domain we operate.
1. Who we are
Aico Labs s.r.o., a company registered in Slovakia, with its registered seat at Palánok 4605/1, 949 01 Nitra, Slovenská republika. Company registration number: 57638799, tax ID: 2122864942.
Where this Policy uses "we", "us", or "our", it refers to Aico Labs s.r.o..
2. Roles under GDPR
We act as data controller for the personal data we collect directly when you visit our websites, contact us, or sign up to receive product updates.
When a Customer uses the Service to process the personal data of its own End Users (for example, candidates in a recruitment workflow), the Customer is the data controller and we act as the data processor. The Customer's privacy notice covers that data and we process it under a written data processing agreement.
3. What data we collect
On our public marketing sites (aicolabs.io and its sub-domains) we collect only the data you voluntarily submit to us. This typically includes the email address and message body you provide through the /get intake form or direct email contact, and your name when you give it to us.
We do not run third-party analytics, marketing pixels, or session replay on our public sites. We do not set non-essential cookies. The functional cookies our sites use are described in our Cookies Policy.
4. What data we process as processor
In our role as data processor for our Customers we process the personal data the Customer submits into a process. This may include candidate names, contact details, identification numbers, document scans, responses to structured intake questions, and similar.
We process that data only on documented instructions from the Customer. We do not access Customer data beyond what is necessary to operate, secure, and maintain the Service, and only Customer-authorised staff can do so.
5. Legal basis
Our legal basis for processing depends on the activity in question.
- Direct submissions (contact form, email, signed agreements) — processing is necessary for the performance of a contract, or at your request prior to entering into one (Art. 6(1)(b) GDPR).
- Compliance with legal obligations such as invoice retention and tax recordkeeping (Art. 6(1)(c) GDPR).
- Legitimate interest in operating, securing, and improving the Service (Art. 6(1)(f) GDPR).
- Consent where we ever ask for it, for example when you opt in to a product newsletter (Art. 6(1)(a) GDPR).
- Cookie consent (Art. 6(1)(a) GDPR) — when you make a choice in the cookie banner on a public site, we record that decision in an audit log together with an opaque identifier and the version of this policy you agreed to. The audit entry is the proof required by Art. 7(1) GDPR that consent was given, and by Art. 7(4) GDPR that the data subject was able to meaningfully choose.
6. Sub-processors
We use a small set of sub-processors to operate the Service. For each of them a written data processing agreement is in place. The list below reflects the providers who may process personal data on our behalf.
- Vercel Inc., San Francisco, USA — hosting of the public marketing sites and web application edge runtime. Vercel acts under its own DPA, built on Standard Contractual Clauses for transfers outside the EEA.
- Convex Cloud, hosted in the United States — application database, functions, and authentication backplane for the platform. Data we receive from web forms and from authenticated users flows through Convex. Transfer to the United States is covered by Standard Contractual Clauses and by Convex's own DPA, available on request.
- Resend, US-based email provider — transactional mail, including the magic-link messages we send to Users and End Users. Resend processes the recipient email address and message content under their standard DPA.
- Stripe Payments Europe Ltd., Dublin, Ireland — billing. When a Customer pays an order, Stripe processes the payment instrument and the billing details we receive from the Customer. Stripe Payments Europe acts as our EEA sub-processor for billing data.
- Better Auth — authentication framework integrated into our Convex backend. Sessions, credentials, and the audit trail of sign-ins are processed through it. Better Auth itself does not receive personal data beyond what is needed for the session.
7. Retention
Direct submissions to us: we retain contact-form submissions and email correspondence for as long as we have an active business relationship with you, plus 30 days after the relationship ends, unless a longer retention is required by tax or accounting law.
Customer data processed through the Service: we retain it for the lifetime of the Customer's account. When the account is closed, we delete the data within 30 days, except for copies we are required to keep for legal or accounting purposes, which we keep for the statutory minimum period.
8. Your rights
As a data subject you have the right to request access to your personal data, to have it corrected or erased, to restrict its processing, to object to processing, to data portability, and to lodge a complaint with a supervisory authority.
Requests sent to the contact address below are handled without undue delay and at the latest within 30 days. We may extend that period by up to 60 days where the request is complex or repeated and we notify you of the extension.
9. Security
Personal data is processed in environments with technical and organisational measures proportionate to the nature of the data and the risks involved. Access to Customer data is limited to staff who need it to deliver the Service and is logged.
Where we become aware of a personal data breach affecting your data, we will notify the competent supervisory authority within 72 hours and, where the breach is likely to result in a high risk to your rights, we will also notify you without undue delay.
10. Children
Our Service is not directed to children. We do not knowingly process personal data of children under the age of 16. If you believe a child has submitted data through the Service, contact us so we can delete it.
11. International transfers
We keep personal data we process as controller in the European Economic Area. Where a sub-processor transfers data outside the EEA — most notably Convex Cloud, which hosts our application database in the United States — we rely on Standard Contractual Clauses (Commission Decision 2021/914) and on the supplementary technical and organisational measures that the specific transfer requires.
For these transfers, we have assessed that the destination provides an adequate level of protection for the data in question, or that the safeguards put in place by the sub-processor (encryption in transit and at rest, access controls, vendor-side DPA on file) make the transfer compliant. Customers and End Users may request a copy of the safeguards by writing to the contact address below.
12. Changes to this policy
We may update this Privacy Policy. Material changes will be announced at least 30 days before they take effect and the version number will be bumped. The previous version remains available on request.
13. Contact
For privacy questions, write to hello@aicolabs.io.