Privacy notice
Last updated: [date to be completed]
This privacy notice explains how aiaiai handles personal data: which data we process, why, for how long, with whom we share it and what rights you have.
1. Who are we?
aiaiai is a service of AI-Studio, trading name of Contento GCV, company number BE 0715.660.258, with its registered office at Oude Leuvensestraat 77 box 3, 3300 Tienen, Belgium. You can reach us at hello@ai-studio.be.
It is important to distinguish between two roles:
- The company using aiaiai (our customer) decides which processes are captured and which employees make recordings. For the data in its environment (recordings, procedures, knowledge base), that company is the controller. AI-Studio acts as processor for that data, in accordance with the data processing agreement.
- AI-Studio is itself the controller for a limited amount of data we need to offer the service: administrators' account details, billing and contact details, and technical logs for security.
Are you an employee of a customer with a question about your recordings or data? Please contact your employer in the first instance. We will help them with it.
2. What data do we process?
- Account data: name, email address, password (stored encrypted), role and company details such as company name and sector.
- Recordings: video and audio recordings of work processes made by an employee themselves, including whatever can be seen or heard in them (screen, camera image, voice).
- Answers to follow-up questions: typed answers, and speech when you talk to Hannah in the browser or by phone.
- Structured output: processes, steps, decision points, procedures, knowledge base items and automation scores per process.
- Consent and audit data: the time at which consent for a recording was given, and an audit log of exports, deletions and validations.
- Technical data: data needed to run the service securely, such as session cookies and error logs.
3. Why do we process this data?
- To deliver the service: analysing recordings, asking follow-up questions and building procedures, the knowledge base and automation scores (performance of the contract with the customer).
- To manage accounts, enable sign-in and send transactional emails, such as invitations and password resets (performance of the contract).
- To secure the service, prevent misuse and detect errors (legitimate interest).
- To comply with legal obligations, for example accounting obligations (legal obligation).
The legal basis for recordings and their processing within a company is determined by the customer as controller. [To be completed/checked: relationship between consent per recording and the employer's legal basis.]
4. How do we protect your privacy in the product?
- Consent per recording. Explicit consent is requested before every recording; the time is logged.
- You choose what you record. An employee decides what to record and can delete a recording as long as the analysis has not yet started.
- Raw videos are deleted automatically after the retention period set by the company (30 days by default, adjustable from 1 to 365 days). The structured output (procedures, knowledge base) is retained.
- Sensitive data that happens to appear on screen is not carried over into the output.
- No scores or analyses per employee. We assess processes, never people. No rankings, performance scores or analyses per employee are produced.
- Strict separation per company. Each company has its own environment; access is enforced in the database with row level security.
- Audit log of exports, deletions and validations.
5. Where is your data stored?
The application runs on a dedicated server in the European Union. The database and file storage are hosted by Supabase, in the Frankfurt region (EU).
6. With whom do we share data?
We do not sell data. We only use the following service providers (sub-processors), and only to the extent necessary to deliver the service:
- Supabase — database, authentication and file storage (EU, Frankfurt).
- Google (Gemini API) — analysis of video recordings. Videos are deleted at Google after the analysis.
- Anthropic (Claude API) — text processing, such as structuring steps and processing answers.
- AskHannah — phone conversations with Hannah (Belgium).
- Resend — sending transactional emails.
Some of these service providers may process data outside the European Economic Area. [To be completed: for each sub-processor, the processing location and the transfer safeguard used, e.g. adequacy decision or standard contractual clauses.]
We may also disclose data where the law requires us to do so.
7. How long do we keep data?
- Raw video recordings: until the end of the retention period set by the company (30 days by default, 1 to 365 days).
- Structured output and account data: for as long as the company is a customer. An administrator can export all company data and delete the company. [To be completed: period within which data is permanently erased after deletion or termination of the contract, including from backups.]
- Billing data: for as long as the law requires.
- Technical logs: [retention period to be completed].
8. Cookies
We only use cookies that are strictly necessary for the service to work, such as a session cookie to keep you signed in and a cookie that remembers which company you are working in. [To be checked: full list of cookies at go-live.]
9. Your rights
You have the right to access your data, to have it rectified or erased, to have processing restricted, to object and to data portability. If your data sits in a company's environment, that company handles your request; we support it in doing so. For data for which AI-Studio itself is responsible, you can contact hello@ai-studio.be.
If you are not satisfied with how we handle your data, you can lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
10. Changes
We may amend this privacy notice. The date at the top shows when it was last updated. In the event of significant changes, we will notify our customers' administrators.