Data Privacy Policy

last updated September 09, 2026

  • GENERAL INFORMATION

    This Privacy Notice for AITHEA GmbH ("we", "us", or "our") describes how and why we collect, store, use, disclose and otherwise process ("process") personal data when you use our services ("Services"), including when you:


    Visit our website at https://www.ai-thea.com or any website of ours that links to this Privacy Notice;

    Use our consulting services, digital marketplace and technology services, including Heliolus;

    Register for or use an account;

    Submit information through our forms or other digital services;

    Use our websites, platforms, products, features or tools;

    Engage with us in connection with consulting, training, compliance technology, vendor selection, RFPs/RFIs or related services;

    Participate in our marketing activities, webinars, events, training or other activities; or

    Engage with us in other related ways, including any marketing or events.


    Controller


    AITHEA GmbH

    Zeppelinstraße 73

    81669 Munich

    Germany


    Email: info@ai-thea.com


    website: www.ai-thea.com


    Where AITHEA determines the purposes and means of processing personal data for its own purposes, AITHEA GmbH is the controller within the meaning of the GDPR.


    Where AITHEA processes personal data solely on behalf of a customer and according to that customer's documented instructions, AITHEA may act as a processor. Further information is provided in the section "Controller and Processor Roles" below.


    AITHEA Services


    AITHEA GmbH specializes in providing expert advisory and consulting services in compliance and regulatory technology, with a strong focus on artificial intelligence (AI) solutions for financial crime compliance and trade compliance.


    Our key services include:


    1. Advisory Services: Tailored advisory on digital transfromation related to financial crime compliance and AI Compliance
    2. Training & Education: E-Learning Solutions on financial crime compliance and AI Compliance topics.
    3. Digital Services: Marketplace/directory with AI capabilities for the creation of self-assessments, automated vendor matching and efficiency tools to select and support decisions on technology vendors.


    Heliolus AI - vendor matchmaking platform


    Heliolus AI is a compliance technology platform owned and operated by AITHEA.


    Depending on the functionality used, Heliolus may process information relating to organisations, compliance requirements, technology requirements, technology vendors, assessments, searches, queries, workflows, documents and other information submitted by users or customers.


    Heliolus AI may use artificial intelligence,  and related technologies for functions including information extraction, document analysis, classification, search, matching, analysis, summarisation and recommendations.


    Where Heliolus is used by a customer to process personal data on the customer's behalf, the customer may act as controller and AITHEA may act as processor. Such processing is governed by the applicable Data Processing Agreement and the customer's documented instructions.


    AITHEA acts as controller for personal data that it processes for its own purposes, including account administration, customer relationship management, billing, service communications, platform security and other purposes described in this Privacy Notice.


  • SUMMARY OF KEY POINTS

    This summary provides key points from our Privacy Notice.


    What personal information do we process?


    When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.


    Do we process any sensitive personal information?


    Some of the information processed through our Services may constitute special categories of personal data under Article 9 GDPR, for example information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or information concerning a person's sex life or sexual orientation.


    AITHEA does not intentionally request special categories of personal data for ordinary website interactions.


    However, documents and other information uploaded to Heliolus by users or customers may contain personal data, including special categories of personal data. Where such processing takes place on behalf of a customer, the customer is responsible for determining the applicable legal basis and appropriate safeguards, and AITHEA processes such data in accordance with the customer's documented instructions and the applicable Data Processing Agreement.


    Do we collect any information from third parties?


    We may collect information from public databases, marketing partners, social media platforms, business partners, service providers, and other outside sources where permitted by applicable law.


    How do we process your information?


    We process your information to provide, improve, and administer our Services, communicate with you, provide and operate Heliolus, support compliance technology assessments, maintain security and prevent fraud, conduct business and marketing activities where legally permitted, and comply with legal obligations.


    We process personal data only where at least one legal basis under applicable data protection law applies.


    In what situations and with which types of parties do we share personal information?


    We may share information in specific situations and with specific categories of third parties, including technology and service providers necessary to operate our Services.


    How do we keep your information safe?


    We have appropriate organisational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.


    What are your rights?


    Under the GDPR, you may have rights regarding your personal information, including the right of access, rectification, erasure, restriction of processing, data portability, objection to certain processing, withdrawal of consent and rights concerning solely automated decision-making, where applicable.


    How do you exercise your rights?


    You can exercise your data protection rights by contacting us at info@ai-thea.com. We will consider and act upon your request in accordance with applicable data protection law. For Heliolus AI you may use the self-service to delete your data under your account settings.

  • 1. WHAT INFORMATION DO WE COLLECT?

    Personal information you disclose to us


    In Short: We collect personal information that you provide to us.


    We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, participate in activities on the Services, use Heliolus, submit forms, or otherwise contact us.


    The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use.


    The personal information we collect may include:

    • names;
    • phone numbers;
    • email addresses;
    • mailing addresses;
    • company or organisation information;
    • job titles;
    • professional roles;
    • usernames;
    • passwords or authentication information;
    • contact preferences;
    • billing addresses;
    • payment-related information;
    • information contained in enquiries and communications;
    • information relating to compliance and regulatory requirements;
    • information relating to technology vendors and solutions;
    • RFI/RFP information;
    • assessment criteria and evaluation information;
    • documents and other information uploaded to Heliolus;
    • searches, queries and other inputs submitted to Heliolus;
    • information generated through assessments, workflows, classifications, matches and recommendations; and
    • other information that you voluntarily provide to us.

    All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.


    Sensitive Information


    We do not intentionally request special categories of personal data for ordinary website interactions.


    However, information submitted to Heliolus, including documents uploaded by users or customers, may contain special categories of personal data.


    Where AITHEA processes such data on behalf of a customer, the customer is responsible for determining the purposes and legal basis for the processing and for ensuring that appropriate safeguards are in place. AITHEA processes such information only in accordance with the customer's documented instructions and the applicable Data Processing Agreement.


    Payment Data


    We may collect data necessary to process your payment if you choose to make purchases, such as payment-related information.


    Payment card data is handled and stored by Stripe, where applicable. AITHEA does not intentionally store complete payment card details where these are processed directly by Stripe.


    You may find Stripe's privacy notice at:


    https://stripe.com/privacy


    Information automatically collected


    In Short: Some information, such as your Internet Protocol (IP) address and/or browser and device characteristics, is collected automatically when you visit our Services.


    We automatically collect certain information when you visit, use, or navigate the Services.


    This information may include:


    • IP address;
    • browser and device characteristics;
    • operating system;
    • language preferences;
    • referring URLs;
    • device name;
    • country or approximate location;
    • information about how and when you use our Services;
    • pages and files viewed;
    • searches;
    • features used;
    • date/time stamps;
    • error reports;
    • hardware settings;
    • device and application identification numbers;
    • internet service provider and/or mobile carrier; and
    • other technical information.

    This information is primarily needed to maintain the security and operation of our Services, and for internal analytics and reporting purposes.


    Like many businesses, we also collect information through cookies and similar technologies.


    You can find out more about this in our Cookie Policy.


    Log and Usage Data


    Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files.


    Depending on how you interact with us, this log data may include your IP address, device information, browser type and settings, and information about your activity in the Services, such as date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take.


    Device Data


    We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services.


    Depending on the device used, this device data may include your IP address or proxy server, device and application identification numbers, location, browser type, hardware model, internet service provider, mobile carrier, operating system and system configuration information.


    Location Data


    We may derive an approximate location from technical information such as your IP address where necessary for security, service operation, analytics or other permitted purposes.


    We do not require precise geolocation data for ordinary use of our website.


    Information collected from other sources


    In Short: We may collect limited data from public databases, marketing partners, social media platforms, business partners and other outside sources.


    In order to enhance our ability to provide relevant services and maintain our business records, we may obtain information about you from other sources, such as public databases, joint marketing partners, affiliate programs, data providers, social media platforms and other third parties, where permitted by applicable law.


    This information may include:


    • mailing addresses;
    • job titles;
    • email addresses;
    • phone numbers;
    • professional information;
    • business information;
    • intent data or user behaviour data;
    • IP addresses;
    • social media profiles;
    • social media URLs; and
    • other publicly available or business-related information.

    Such information may be used for business development, marketing, event promotion, vendor research, professional networking and other legitimate business purposes, subject to applicable law.

  • 2. HOW DO WE PROCESS YOUR INFORMATION?

    In Short: We process your information to provide, improve, and administer our Services, communicate with you, operate Heliolus, maintain security and prevent fraud, and comply with law. We may also process your information for other purposes with your consent.


    We process your personal information for a variety of reasons, depending on how you interact with our Services, including:


    To facilitate account creation and authentication and otherwise manage user accounts


    We may process your information so you can create and log in to your account, as well as keep your account in working order.


    To deliver and facilitate delivery of services to the user


    We may process your information to provide you with the requested service.


    To provide Heliolus functionality


    We may process information submitted to Heliolus to provide functions including compliance technology discovery, vendor and solution research, requirements gathering, technology assessments, document processing, information extraction, classification, search, matching, analysis, summarisation, recommendations and workflow management.


    To respond to user inquiries/offer support to users


    We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.


    To send administrative information to you


    We may process your information to send you details about our products and services, changes to our terms and policies, and other similar information.


    To fulfil and manage your orders


    We may process your information to fulfil and manage your orders, payments, returns, and exchanges made through the Services.


    To enable user-to-user communications


    We may process your information if you choose to use any of our offerings that allow for communication with another user.


    To request feedback


    We may process your information when necessary to request feedback and to contact you about your use of our Services.


    To send you marketing and promotional communications


    We may process the personal information you send to us for our marketing purposes where permitted by applicable law and in accordance with your marketing preferences.


    Where consent is required, we will obtain consent before sending the relevant marketing communications.


    You can opt out of our marketing emails at any time.


    To deliver targeted advertising to you


    Where applicable and where the required consent has been obtained, we may process information to develop and display personalised content and advertising tailored to your interests, location, and other relevant characteristics.


    The use of cookies and similar technologies for these purposes is subject to the requirements of § 25 TDDDG and, where personal data is processed, the GDPR.


    To protect our Services


    We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.


    To identify usage trends


    Where legally permitted, we may process information about how you use our Services to better understand how they are being used so we can improve them.


    Where analytics technologies require consent under applicable law, they will only be activated after the relevant consent has been obtained.


    To determine the effectiveness of our marketing and promotional campaigns


    Where legally permitted and, where required, with your consent, we may process information to understand the effectiveness of our marketing and promotional campaigns.


    To save or protect an individual's vital interest


    We may process your information when necessary to save or protect an individual's vital interest, such as to prevent harm, where permitted by applicable law.



  • 3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

    In Short: We only process your personal information when we have a valid legal reason to do so under applicable law.


    The General Data Protection Regulation (GDPR) requires us to explain the legal bases on which we rely to process personal data.


    Depending on the circumstances, we may rely on the following legal bases under Article 6(1) GDPR:


    Consent


    We may process your information if you have given us permission to use your personal information for one or more specific purposes.


    You can withdraw your consent at any time.


    For cookies and similar technologies, consent can be withdrawn or changed through our consent preference centre.


    Performance of a Contract


    We may process your personal information when this is necessary to fulfil our contractual obligations to you, including providing our Services or taking steps at your request prior to entering into a contract with you.


    Legal Obligations


    We may process your information where necessary to comply with our legal obligations, such as cooperating with a law enforcement body or regulatory agency, exercising or defending our legal rights, or retaining information where required by law.


    Legitimate Interests


    We may process your information where this is necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by your interests or fundamental rights and freedoms.


    Our legitimate interests may include:


    • operating and securing our Services;
    • managing customer and business relationships;
    • improving our products and Services;
    • diagnosing technical problems;
    • preventing fraud and misuse;
    • maintaining appropriate business records;
    • conducting limited business development activities where permitted by law;
    • measuring the effectiveness of business activities where legally permitted; and
    • establishing, exercising or defending legal claims.

    Where we rely on legitimate interests, we consider the nature of the processing and its impact on your rights and freedoms.


    Vital Interests


    We may process your information where necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.


    Controller and Processor Roles


    AITHEA may act as either a data controller or a data processor, depending on the processing activity.


    AITHEA acts as controller where it determines the purposes and means of processing personal data for its own purposes.


    Examples include:


    • website operation;
    • account administration;
    • customer relationship management;
    • billing;
    • service communications;
    • marketing;
    • events and training;
    • security;
    • operation of Heliolus for AITHEA's own purposes; and
    • compliance with legal obligations.

    AITHEA acts as processor where it processes personal data on behalf of a customer and according to that customer's documented instructions.


    Where AITHEA acts as processor, the customer generally remains the controller responsible for determining the purposes and legal basis of the processing.


    Such processing is governed by the applicable Data Processing Agreement.


  • 4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

    In Short: We may share information in specific situations described in this section and/or with specific categories of third parties.


    Vendors, Consultants, and Other Third-Party Service Providers


    We may share your data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work.


    Where such providers process personal data on our behalf, we enter into appropriate contractual arrangements as required by applicable data protection law.


    Depending on the service, these providers may include:


    • AI platforms;
    • cloud computing and hosting services;
    • communication and collaboration tools;
    • data analytics services;
    • payment processors;
    • performance monitoring tools;
    • sales and marketing tools;
    • social networks;
    • user account registration and authentication services;
    • form and survey providers;
    • consent-management services;
    • security and fraud-prevention services; and
    • other technical service providers necessary to operate our Services.

    Usercentrics


    We use Usercentrics for consent management and to manage and document your preferences regarding cookies and other technologies that require consent.


    Usercentrics may process technical information and information relating to your consent choices.


    Google Analytics


    We use Google Analytics to track and analyse the use of our Services and to understand website performance and usage trends.


    Google Analytics may process information such as IP address, device and browser information, online identifiers and information relating to interactions with our website.


    Where consent is legally required, Google Analytics is activated only after the applicable consent has been obtained through our consent management platform.


    Further information about Google's privacy practices can be found in Google's privacy documentation.


    Data privacy policy: https://policies.google.com/privacy


    Jotform


    We use Jotform for online forms, registrations, surveys and other submission functionality.


    Where you submit information through a Jotform form, Jotform may process the information contained in your submission on our behalf.


    Depending on the form, this may include your name, email address, company, professional information and other information that you voluntarily provide.


    LinkedIn


    We use LinkedIn for professional networking, business communication and, where applicable, marketing, advertising and campaign measurement.


    Depending on the functionality used, LinkedIn may process professional information, interaction data and advertising or campaign measurement information.


    Where LinkedIn tracking technologies are used on our website, they are activated only where the applicable consent has been obtained.


    Data Privacy Policy: https://www.linkedin.com/legal/privacy-policy


    Cloudflare


    We use Cloudflare for website and service infrastructure, security, traffic protection and related technical functions.


    Cloudflare may process technical information including IP addresses, request information, browser information and security-related information in order to provide these functions and detect or mitigate malicious or automated traffic.


    Data privacy policy


    Stripe


    We use Stripe for payment processing and related payment services.


    Payment information may be processed by Stripe where applicable.


    Data privacy policy


    OpenAI and Anthropic


    We use AI services provided by OpenAI and Anthropic for certain AI-enabled functionalitywithin Heliolus AI, to summarise, draft and write reports, generate RFP drafts and extract information from documents. 


    Depending on the functionality used, inputs, outputs, documents, extracted information and other information submitted to an AI-enabled feature may be processed by the relevant AI service provider.


    Such processing is carried out to provide the relevant functionality and in accordance with applicable contractual and data protection requirements.


    AI models are not trained by customer data. More information can be found here.


    Data Privacy Policy Open AI

    Data Privacy Policy Anthrophic


    Business Transfers


    We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.


    Business Partners


    We may share your information with our business partners where necessary to offer you certain products, services, demonstrations, partnerships or other business activities, subject to applicable law.



  • 5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

    We may use cookies and other tracking technologies to collect and store information.


    We may use cookies and similar tracking technologies, such as web beacons and pixels, to gather information when you interact with our Services.


    Some technologies are necessary to provide the Services, maintain security, prevent misuse, save preferences and support basic site functions.


    Other technologies may be used for analytics, marketing or other optional purposes.


    Where the storage of information on or access to information already stored on your device requires consent under § 25 TDDDG, we obtain the required consent before activating the relevant technology.


    Where personal data is processed, the applicable legal basis under the GDPR also applies.


    You can change or withdraw your consent at any time through our Privacy Settings / Consent Preference Centre.


    Specific information about the technologies used, their purposes, providers and retention periods is set out in our Cookie Policy.


    Google Analytics


    We use Google Analytics to track and analyse the use of the Services.


    Where the relevant processing requires consent, Google Analytics is activated only after the applicable consent has been obtained through our consent management platform.



  • 6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

    We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.


    As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products").


    These tools are designed to enhance your experience and provide innovative solutions.


    The terms in this Privacy Notice govern your use of the AI Products within our Services.


    Use of AI Technologies


    We provide certain AI Products through third-party service providers ("AI Service Providers"), including Anthropic and OpenAI.


    Depending on the functionality used, your input, output, documents, extracted information and other personal information may be processed by these AI Service Providers to enable your use of our AI Products for the purposes described in this Privacy Notice.


    Our AI Products - Heliolus AI only


    Our AI Products are designed for functions including:


    • AI insights;
    • information extraction;
    • document analysis;
    • analysis;
    • summarisation; and
    • recommendations.

    How We Process Your Data Using AI


    Separation of Account and Business Information


    Personal information associated with a Heliolus user account, such as the user's name, email address, login credentials, account details, user permissions and billing information, is not submitted to or processed by the AI functionality of Heliolus.


    AI processing is limited to business-related information required to provide the relevant Heliolus functionality. This may include information such as the company name, company characteristics, compliance and technology requirements, information about the organisation's existing technology environment, information about technology vendors and solutions, and information or inputs relating to the company that the user submits for analysis.


    Where documents or other information are submitted for AI-assisted processing, only information necessary for the relevant Heliolus functionality is processed by the applicable AI service provider. Users should avoid submitting personal information that is not necessary for the relevant assessment or analysis.


    Where business information contains personal data, such data may nevertheless constitute personal data under applicable data protection law. The fact that information relates to a business or organisation does not, by itself, exclude it from the scope of the GDPR. 


    Privacy recommendation for document uploads


    To minimise the processing of personal data, we recommend anonymising or removing personal information from documents before uploading them for the Heliolus self-assessment, where this information is not necessary for the assessment. This may include names, email addresses, telephone numbers, signatures and other information that identifies an individual.


    Please only upload information that is necessary for the self-assessment.


    Automated Decision-Making


    Unless expressly stated otherwise and permitted by applicable law, we do not use solely automated decision-making based on personal data to make decisions that produce legal effects or similarly significantly affect individuals within the meaning of Article 22 GDPR.


    Heliolus may generate automated classifications, matches, insights or recommendations. These outputs are intended as decision-support information and should be reviewed and validated by the user.



  • 7. HOW LONG DO WE KEEP YOUR INFORMATION?

    We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.


    We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law, such as tax, accounting or other legal requirements.


    The applicable retention period depends on the nature and purpose of the processing.


    Examples include:


    account information: for the duration of the account and an appropriate period thereafter;

    customer and contractual records: for the duration of the contractual relationship and applicable statutory retention periods;

    accounting and tax information: for the applicable statutory retention period;

    marketing information: until withdrawal of consent, valid objection or the expiry of the applicable retention period;

    enquiry information: for as long as necessary to handle the enquiry and related business or legal requirements;

    security and technical logs: for the period reasonably necessary for the relevant security purpose;

    Heliolus customer data: in accordance with the applicable customer agreement and Data Processing Agreement; and

    uploaded Heliolus documents: in accordance with the relevant functionality, customer configuration and contractual arrangements.


    When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise such information or, if this is not possible, securely store the personal information and isolate it from any further processing until deletion is possible.


  • 8. HOW DO WE KEEP YOUR INFORMATION SAFE?

    We aim to protect your personal information through a system of organisational and technical security measures.


    We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process.


    Depending on the service and risks involved, these measures may include access controls, authentication, encryption, logging, backups, security monitoring, segregation of environments and contractual controls over service providers.


    However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.


    Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk.


    You should only access the Services within a secure environment.

  • 9. DO WE COLLECT INFORMATION FROM MINORS?

    We do not knowingly collect data from or market to children under 18 years of age.


    Our Services are primarily directed at businesses and professional users.


    We do not knowingly solicit data from or market to children under 18 years of age.


    If we learn that personal information from a person under 18 years of age has been collected, we will take reasonable measures to delete such data from our records where legally required.


    If you become aware of data we may have collected from children, please contact us at info@ai-thea.com.

  • 10. WHAT ARE YOUR PRIVACY RIGHTS?

    Under the GDPR, you have rights that allow you greater access to and control over your personal information.


    Depending on the circumstances and applicable law, you may have the following rights:


    Right of access


    You have the right to obtain confirmation as to whether personal data concerning you is being processed and, where applicable, access to that personal data and information about the processing.


    Right to rectification


    You have the right to request correction of inaccurate personal data and completion of incomplete personal data.


    Right to erasure


    You may have the right to request deletion of your personal data where the requirements of Article 17 GDPR are met.


    Right to restriction of processing


    You may have the right to request restriction of processing in the circumstances provided for by Article 18 GDPR.


    Right to data portability


    Where the requirements of Article 20 GDPR are met, you have the right to receive personal data concerning you in a structured, commonly used and machine-readable format and to transmit that data to another controller.


    Right to object


    You have the right to object to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR where the conditions of Article 21 GDPR are met.


    You have an unconditional right to object to the processing of your personal data for direct marketing purposes.


    Right to withdraw consent


    Where processing is based on your consent, you have the right to withdraw your consent at any time.


    Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.


    Rights concerning automated decision-making


    Where applicable, you have the right under Article 22 GDPR not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, subject to the exceptions provided by law.


    You can make a request by contacting us using the contact details provided below.


    We will consider and act upon any request in accordance with applicable data protection law.


    Withdrawing your consent


    If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time.


    You can withdraw your consent by contacting us or updating your preferences through our consent preference centre.


    Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.


    Opting out of marketing and promotional communications


    You can unsubscribe from our marketing and promotional communications at any time by clicking the unsubscribe link in the emails that we send or by contacting us using the details provided below.


    You will then be removed from the relevant marketing lists.


    However, we may still communicate with you, for example, to send you service-related messages necessary for the administration and use of your account, respond to service requests, or for other non-marketing purposes.


    Account Information


    If you would at any time like to review or change information in your account or terminate your account, you can use the relevant account settings where available or contact us at info@ai-thea.com.


    Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases, subject to applicable legal and legitimate retention requirements.


    We may retain some information to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms and/or comply with applicable legal requirements.


    Cookies and similar technologies


    Most web browsers are set to accept cookies by default.


    You can usually choose to set your browser to remove cookies and reject cookies.


    However, browser settings do not replace the consent controls available through our consent preference centre where consent is legally required.


    You can change or withdraw your consent at any time through our Privacy Settings / Consent Preference Centre.


    For further information, please see our Cookie Policy.





  • 11. CONTROLS FOR DO-NOT-TRACK FEATURES

    Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected.


    At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised.


    As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.


    Where applicable, your cookie and tracking preferences are managed through our consent preference centre.


    If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

  • 12. DO WE MAKE UPDATES TO THIS NOTICE?

    Yes, we will update this notice as necessary to stay compliant with relevant laws.


    We may update this Privacy Notice from time to time to reflect changes to our Services, processing activities, service providers, technical infrastructure or applicable legal requirements.


    The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice.


    If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification where appropriate.


    We encourage you to review this Privacy Notice periodically to remain informed about how we protect your information.

  • 13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

    If you have questions or comments about this Privacy Notice, you may email us at info@ai-thea.com or contact us by post at:


    AITHEA GmbH

    Zeppelinstraße 73

    81669 Munich

    Germany


    AITHEA GmbH is the controller for personal data that it processes for its own purposes as described in this Privacy Notice.


    Where AITHEA processes personal data solely as a processor on behalf of a customer, the relevant customer is the controller for that processing and the applicable Data Processing Agreement governs AITHEA's processing.




  • 14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

    Depending on applicable data protection law, you may have the right to request access to the personal information we collect from you, information about how we have processed it, correction of inaccurate information, restriction or deletion of your personal information, data portability, or withdrawal of consent where applicable.


    To exercise your rights, please contact us at:


    info@ai-thea.com


    We may need to verify your identity before processing your request.


    We will respond within the applicable statutory period.

  • RIGHT TO LODGE A COMPLAINT

    If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority.


    For AITHEA GmbH's establishment in Bavaria, the competent supervisory authority is:


    Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

    Promenade 18

    91522 Ansbach

    Germany


    You may also contact another competent supervisory authority where permitted under applicable data protection law.

  • THIRD-PARTY SERVICE PROVIDERS

    We use selected third-party service providers to operate our websites and Services, manage consent, process forms, analyse website usage, manage customer relationships, process payments, provide security and infrastructure, and provide AI-enabled functionality.


    The providers currently used or identified for these purposes include:


    • Usercentrics - Consent Management
    • Google Analytics - Website analytics
    • Jotform - contact forms and submissions
    • Linkedin - Professional networking, marketing and advertising/campaign management and measurement
    • OpenAI -AI-enabled functionality (Heliolus AI only)
    • Anthrophic - AI-enabled functionality (Heliolus AI only)
    • Stripe - Payment Processing (Heliolus AI only)
    • Cloudflare - website security and Infrastructure
    • Million Labs - IT Management Heliolus AI
    • Fly.io - data server and hosting(Frankfurt cloud)
    • Supabase - Frankfurt location

    Where these providers process personal data on behalf of AITHEA, appropriate contractual and organisational safeguards are implemented as required by applicable law.


    Where AITHEA acts as processor for a customer, the applicable Data Processing Agreement governs the processing of customer data.


    For Heliolus specific data privacy policy please visit https://heliolusapp.ai-thea.com/privacy-security



  • INTERNATIONAL DATA TRANSFERS

    Where personal data is transferred to recipients located outside the European Economic Area, AITHEA ensures that an appropriate transfer mechanism under Chapter V GDPR is in place where required.


    Depending on the circumstances, this may include:


    • an adequacy decision of the European Commission;
    • Standard Contractual Clauses adopted by the European Commission; or
    • another legally recognised transfer mechanism.

    Where required, appropriate supplementary safeguards will be implemented.


    The applicable transfer mechanism may differ depending on the service provider and processing activity.

  • LINKS FROM THIRD PARTIES

    Occasionally, we may at our own discretion offer products or services from third parties on our website. These third-party websites have separate, independent privacy policies. We therefore assume no responsibility or liability for the content and activities of these linked websites. Nevertheless, we try to protect the integrity of our website and welcome any feedback about these websites.

  • ONLINE PRESENCE ON SOCIAL NETWORKS

    We maintain an online presence on social networks in order to communicate there with customers and prospective customers, among other things, and to inform them about our products and services.


    User data is generally processed by the respective social networks for market research and advertising purposes. In this way, usage profiles can be created that are based on users' interests. For this purpose, cookies and other identifiers are stored on users' computers. Based on these usage profiles, advertising is then displayed, for example, within the social networks as well as on third-party websites.


    As part of operating our online presences, it is possible that we may access information such as statistics on the use of our online presences, which are provided by the social networks. These statistics are aggregated and may include, in particular, demographic information and data on interaction with our online presences and the posts and content distributed through them. For details and links to the social network data that we, as the operator of the online presences, may access, please see the list below.


    The legal basis for the data processing is Art. 6(1) sentence 1 lit. a and b GDPR, in order to stay in contact with our customers, inform them, and carry out pre-contractual measures with future customers and prospective customers.


    For the legal bases of the data processing carried out by the social networks under their own responsibility, please refer to the privacy notices of the respective social network. The links below also provide further information on the respective data processing and on options for objecting to it.


    We would also like to point out that data protection concerns can be raised most effectively with the respective provider of the social network, since only these providers have access to the data and can take appropriate action directly. Below you will find a list with information on the social networks in which we maintain online presences:


    Facebook (United States of America and Canada: Facebook Inc., 1601 Willow Road, Menlo Park, California 94025, United States of America; all other countries: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).  Operation of the Facebook fan page under joint controllership on the basis of an Agreement on the Joint Processing of Personal Data (the so-called Page Insights Supplement to the controller). Information on the processed Page Insights data and contact options for data protection concerns: https://www.facebook.com/legal/terms/information_about_page_insights_data         Privacy policy: https://www.facebook.com/about/privacy/                                                                    

    Opt-out: https://www.facebook.com/settings?tab=ads and https://www.youronlinechoices.com


    Google/YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).                                     

    Privacy policy: https://policies.google.com/privacy  

    Opt-out: https://www.google.com/settings/ads


    LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland). Operation of the LinkedIn company page under joint controllership on the basis of an Agreement on the Joint Processing of Personal Data (the so-called Page Insights Joint Controller Addendum). Information on the processed Page Insights data and contact options for data protection concerns: https://legal.linkedin.com/pages-joint-controller-addendum          

    Privacy policy: https://www.linkedin.com/legal/privacy-policy                                                                             Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

  • YOUR RIGHTS

    When we process your personal data, you are considered a data subject under the GDPR and, following successful identification, you have the following rights against us:


    • Right of access (Article 15 GDPR, Section 34 BDSG)
    • Right to erasure (Article 17 GDPR, Section 35 BDSG)
    • Right to rectification (Article 16 GDPR, Section 34 BDSG)
    • Right to restriction of processing (Article 18 GDPR)
    • Right to data portability (Article 20 GDPR)
    • Right to withdraw your consent at any time (Article 7(3) GDPR)
    • Right to object (Article 21 GDPR).

    To exercise the rights described here, you can send a request at any time using this form.


    You may at any time file a complaint with a supervisory authority regarding the collection and processing of your personal data by AITHEA. You may contact the data protection authority of your place of residence, which will then forward your request to the competent authority.

  • DATA PROTECTION CONTACT

    For questions concerning the processing of personal data or to exercise your rights, please contact:


    AITHEA GmbH

    Zeppelinstraße 73

    81669 Munich

    Germany


    Email: dataprivacy@ai-thea.com


    If a statutory obligation to appoint a Data Protection Officer applies to AITHEA, the relevant contact details will be provided here.

  • CONTACT

    AITHEA GmbH

    Zeppelinstraße 73

    81669 Munich

    Germany


    Email: dataprivacy@ai-thea.com

  • UPDATES

    We reserve the right to update this privacy policy from time to time. In the event that we make material changes that limit your rights or AITHEAS' obligations under this privacy policy, we will publish a clear notice in this section of this privacy policy informing users when it is updated.