Who is responsible
The controller of your personal data is the company that operates AIdoesAI (“we”):
- Company name
- Petite Tap s.r.o.
- Legal form
- Limited liability company (společnost s ručením omezeným)
- Registered office
- Stochovská 686/68, 161 00 Praha 6 – Ruzyně
- Company ID (IČO)
- 25332741
- Tax ID (DIČ)
- CZ25332741
- Commercial Register
- C 205218, kept by the Municipal Court in Prague
- info@aidoesai.com
Write to privacy@aidoesai.com about anything in this policy. We answer within one month.
What this policy covers
- The public website at aidoesai.com.
- The student platform at app.aidoesai.com, where invited people sign in and open tools.
- Tools on other aidoesai.com addresses that you open from the platform, such as monitor.aidoesai.com.
- Enquiries, bookings, and other contact with clients.
If your employer booked a class for you, they may also process your data under their own privacy policy.
Visiting the website
The public website sets no cookies. It runs no analytics, advertising, or social media plugins. Fonts and images load from our own server.
To deliver a page, our server receives your IP address, the page you ask for, and technical details your browser sends. Server logs may hold your IP address and the time of the request. We use them to run and protect the service and keep them for up to 14 days.
Platform accounts
The platform has no public registration. An administrator creates your account, usually because your organisation arranged access for a class. You do not have to give us your data, but without an email address we cannot give you access.
For each account we hold:
- Your email address and display name, from you or your organisation.
- Whether the account is enabled, and whether you are an administrator.
- Which tools you may open.
- Your sign-in links and sessions: when they were created, used, and ended. We store only a one-way hash of each link and session token, never the token itself.
- An activity record: sign-ins, failed sign-ins, changes to your account and tool access, and tool launches. It holds user identifiers, not email or IP addresses.
- Short-lived records that limit how often sign-in links can be requested. They hold a keyed hash of the email or IP address, never the address itself.
We email sign-in links through our email provider. Link tracking is off, so each link goes straight to app.aidoesai.com.
Tools
When you open a tool, the platform passes it a signed token that expires after two minutes. The token holds your user identifier, email address, display name, and the time your platform session ends. The tool uses it to start its own session.
A tool processes what you enter in it. Conversation Monitor keeps your conversations in its memory, not in a database. They are deleted when you delete them, when the tool restarts, and at the latest two hours after they were started.
Conversation Monitor currently shows prepared examples and sends nothing to an AI model provider. Before any tool sends what you enter to an AI model provider, we will name that provider in this policy and in the tool.
Clients and enquiries
When you email us or book a class, we process your name, work contact details, organisation, and what you write. We use them to answer, to prepare and deliver the class, and to invoice.
An organisation that books a class may send us the names and work email addresses of participants, so we can arrange the class and platform access.
In a class, participants work with third-party AI tools. Before the class, we agree with the organisation which data may go into them. By default, that is no personal data and no confidential data.
Purposes and legal bases
| Purpose | Legal basis under Article 6(1) GDPR |
|---|---|
| Delivering the website and the platform securely | (f) our legitimate interest in running a secure service |
| Providing platform access arranged for you | (b) contract, when you are a party to it; otherwise (f) our and your organisation’s legitimate interest in providing the agreed access |
| Activity records and sign-in limits | (f) our legitimate interest in security and accountability |
| Answering enquiries, preparing and delivering classes | (b) steps before a contract and its performance; (f) our legitimate interest, for contact people at client organisations |
| Invoicing and accounting | (c) legal obligations under tax and accounting law |
We do not sell personal data, use it for advertising, or make decisions about you by automated means alone.
Who processes data for us
These providers process personal data on our behalf and only on our instructions.
| Provider | Purpose | Data location |
|---|---|---|
| Hetzner Online GmbH, Germany | Servers for the website, platform, tools, and database | Helsinki, Finland |
| Resend, Inc., United States | Sending sign-in emails | Sent from Ireland; US company |
| Cloudflare, Inc., United States | Storing database backups | Eastern Europe (Cloudflare location hint, not guaranteed) |
| Nethost s.r.o., Czech Republic | Our mail server, which receives email sent to our aidoesai.com addresses | Czech Republic |
Where a provider handles data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework for certified companies or on the European Commission’s standard contractual clauses.
We disclose data to public authorities only when the law requires it.
How long we keep data
| Data | Kept for |
|---|---|
| Sign-in request limits | 24 hours |
| Server logs | Up to 14 days |
| Sign-in links | 30 days after they were created |
| Sessions | 30 days after they ended |
| Database backups | 30 days |
| Activity record | 12 months |
| Platform account | Until you or your organisation ask us to delete it, and no longer than 12 months after your last sign-in |
| Tool conversations | As described under Tools above |
| Enquiries and correspondence | 3 years after our last contact |
| Invoices and accounting records | As long as Czech tax and accounting law requires, usually up to 10 years |
When we delete an account, its sign-in links and sessions go with it, and the activity record no longer points to you. Deleted data leaves our backups within 30 days.
Your rights
You have the right to:
- get a copy of your personal data and information about how we use it;
- have inaccurate data corrected;
- have your data deleted;
- have processing restricted;
- receive data you gave us in a machine-readable format;
- object to processing based on our legitimate interest.
To use a right, write to privacy@aidoesai.com from the address linked to your account, or tell us how we can confirm it is you. We answer within one month.
You can also complain to the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz, or to the supervisory authority where you live or work.
Security
Every connection uses HTTPS. Our API has no public route; only our web application reaches it. A sign-in link works once and expires after 30 minutes. A session ends after 30 minutes without activity.
If a breach is likely to put your rights at high risk, we will tell you without undue delay.
Changes to this policy
We update this policy when what we do with personal data changes. The date at the top shows the current version. We tell platform users about significant changes by email or on the platform.