Effective date: 29 September 2026
1. Responsibility and scope
1.1 Contact
RMVG TECH, LDA, trading as aiwrness, is established at Avenida Miguel Fernandes, 28, 7800-396 Beja, Portugal, NIPC 519625862. Privacy and security requests: support@aiwrness.com. You may also write to us at that address.
1.2 Scope
This Policy covers our website, application, accounts, support, diagnostics and authorised integrations. Paid subscriptions at launch are offered only in the EU-27. It explains processing under the GDPR and applicable Portuguese law, including Law 58/2019 and electronic-privacy rules. Other mandatory local rules can still apply where their territorial and material conditions are met; see Section 12.6.
1.3 Our roles
We act as controller for our own account administration, billing, security, compliance, communications and the public free report described in Section 2.4. We act as processor for personal data in Customer workspaces and analyses processed on instructions, or as subprocessor for an agency’s client. The Terms of Service, Schedule A (DPA) governs that processing. Actual activities determine these roles.
1.4 Organisational accounts
Your employer, agency or other Customer determines its purposes and lawful basis for Customer-controlled data. Contact it about those decisions. You may also contact us: we handle requests within our responsibility and assist or refer Customer-controlled requests appropriately.
1.5 If you are analysed but are not our customer
If your professional profile, brand or public statements appear in our analyses because a Customer configured them, read Section 4.9 and the Notice to people we analyse. You can exercise rights directly with us even though you have no account.
2. When you visit our website
2.1 Information and purposes
We process connection information, such as IP address, browser/device details, requested pages and timestamps, to deliver the site, maintain security and investigate faults. Selected appearance preferences use browser storage.
2.2 External resources and legal basis
Necessary delivery and security processing relies on legitimate interests in operating a secure website. Cloudflare and relevant resource hosts are identified in the shared provider schedule.
Typefaces are served from our own infrastructure. The website does not send domains typed into the free-report form to an external favicon service. In the application, brand logos are resolved by our servers rather than your browser. Some application elements, including provider marks, flags and map data, may still load from external hosts that receive your IP address and technical request details. We are reviewing those resources for any consent requirement. A necessary-storage exemption applies only where its legal conditions are met. Section 2.5 explains browser storage.
2.3 Optional tracking
We currently use no optional advertising or behavioural analytics tool. If introduced, non-essential tracking will require prior consent where applicable, with refusal and withdrawal controls. Terms acceptance is not tracking consent. DNS-based Search Console verification does not itself add visitor tracking.
2.4 When you request a free report
The free report is a public diagnostic available before you have an account. For this processing we are the controller, not a processor for anyone else.
We process the brand, domain and answers you supply, your email address where you provide one, and the results of the AI analysis we run for you. The purposes are producing and delivering the report you requested, and, where you provided contact details, telling you about the paid Service.
The lawful basis is the pre-contractual step you requested under Article 6(1)(b) for producing the report, and our legitimate interest under Article 6(1)(f) in presenting our service to a professional who asked for a diagnostic. We have carried out and documented the balancing assessment for that interest, and you may object at any time under Section 12.2. Marketing by electronic means requires separate consent where the law requires it, under Section 6.2.
The analysis sends your brand and question context to the AI providers in the shared provider schedule, exactly as described in Section 4.3. If you do not later create an account, we keep the report and the associated contact details for 12 months and then delete them, or earlier on request. If you create an account, the records become part of that account.
2.5 Cookies and browser storage
Where a theme control is available, a theme preference may be stored in your browser if you change its appearance. The application uses browser storage for authentication, a remembered sign-in choice, workspace and display preferences, and temporary data needed for requested billing or report workflows. Cloudflare may set security or delivery values depending on the production configuration. We do not currently use optional advertising or behavioural analytics cookies. You can clear site storage in your browser; doing so may sign you out or reset preferences. We will complete and publish a separate production inventory before introducing optional tracking.
3. When you register or join a workspace
3.1 Account information
We process names, emails, account identifiers, settings, invitations, memberships, roles, sessions and authentication events. This enables account creation, sign-in, workspace access and service communications. Your organisation or another authorised user may supply invitation details.
3.2 Authentication
Supabase supports authentication and account storage. Optional Google/GitHub sign-in supplies authorised identity/profile fields, such as name, email, provider ID or avatar; we do not receive your password for those services. Remembered sign-in details and browser sessions are summarised in Section 2.5.
3.3 Legal basis and required fields
Processing necessary for an individual’s own professional contract relies on GDPR Article 6(1)(b). Organisational-user administration relies on legitimate interests under Article 6(1)(f) in supplying the Customer’s service. Required fields enable the account; without them, access may be unavailable. Optional profile details and marketing consent are not purchase conditions.
4. When you use analyses and integrations
4.1 Workspace data
We process configured brands, domains, descriptions, aliases, products, images, competitors, prompts, markets, languages, tags, events, notes and diagnostics. Records may concern users, business contacts, self-employed professionals, creators and people mentioned in supplied material or sources.
4.2 Answers and sources
Results include answers, provider payloads, citations, titles, URLs, reported queries, classifications, counts, timestamps, usage metadata and scores. Information comes from Customer inputs, AI/search providers and public-web sources, including professional profiles, news, forums and video services. AI statements may be inaccurate. Public availability does not establish unrestricted reuse rights.
4.3 AI recipients
Relevant providers receive the prompts and context needed for the requested function. For Google AI Overviews, SearchApi receives the search query and selected market/language parameters and returns any available overview and source links. OpenAI also performs suggestions and sentiment/product classification, including analysis of answers returned by other providers. Free diagnostics and prospect pitches also involve provider calls. The shared provider schedule identifies these services. Selecting tracked assistants does not necessarily disable supporting providers.
4.4 Instructions and training
For Customer-controlled personal data, we act under Schedule A to the Terms; the Customer must establish its lawful basis and give required notices. We do not independently train a general-purpose AI model on Customer Personal Data or authorise suppliers to do so. Supplier agreements and settings must support this restriction. Permitted service, safety and legal retention may still apply.
4.5 Permissions and external assistants
Workspace members receive access within their roles. A Customer-authorised assistant may receive data and perform permitted actions under its own account terms. Revocation stops future access once effective, not copies already received. Customers are responsible for their external report disclosures. We remain responsible for processing under our control.
4.6 Indirect collection
Where we independently control personal data obtained from another source, we provide GDPR Article 14 information within the required period: normally one month, or earlier where contact/disclosure requires it. Any exception needs a documented legal basis. Publishing this Policy alone does not establish an exemption from individual notification.
4.7 Automated processing
Metrics, classifications, quotas, payment status and permissions involve automated processing. Professional-profile monitoring may evaluate individuals. The Service is not intended for employment, credit or similarly significant decisions, and Customers are contractually prohibited from using it for those purposes under clause 4.8 of the Terms. Contact support for explanation, correction and human review where a decision materially affects you; GDPR Article 22 safeguards apply when its conditions are met.
4.8 Sensitive information and minimisation
Do not submit secrets, payment credentials or unnecessary sensitive/personal information. A selected market is an analysis parameter, not a claim that we collected your precise location. Technical logs may contain identifiers and limited request context; our independent security/reliability processing relies on legitimate interests, or legal obligations where applicable.
Collected source material — news, forums, public profiles and similar — can contain special-category data without our asking for it. We apply proportionate filtering and minimisation to that material, and assess, restrict or delete special-category data we identify. We do not treat the contractual prohibition on submitting such data as a sufficient control on its own.
4.9 People we analyse who are not our users
Analyses can concern named individuals who have no relationship with us: public professionals, creators, self-employed brand owners and people mentioned in answers or sources.
For data processed on a Customer’s instructions, that Customer is the controller and holds the Article 14 information duty, including any documented reliance on the disproportionate-effort exception in Article 14(5)(b). We support it in two ways that do not replace it: we publish the Notice to people we analyse as a general information measure, and we operate the mechanism below.
If you are one of those individuals, write to support@aiwrness.com. You do not need an account. Every request is reviewed by us case by case; there is no automated control. We will tell you what we can about the processing and identify the relevant controller. Where a valid objection under Article 21, or a correction or erasure right, is not acted on by the Customer within a reasonable period, where the Customer cannot be reached, or where you are affected across several customers, we remove or restrict the relevant records and exclude you from further analyses, under Schedule A, clause D6.3. We keep the minimum record needed to maintain that exclusion and lift it if the basis ceases.
5. When you pay for the Service
5.1 Billing information
We process billing names, professional status, addresses, country, tax identifiers, email, subscription/payment status, validation results, invoices, refunds and provider identifiers. Stripe collects payment credentials; our account forms do not collect full card numbers or security codes. We receive necessary transaction details and limited payment-method descriptors.
5.2 Purposes and legal bases
Payments and subscription administration rely on contract for an individual contracting party, or legitimate interests for organisational contacts. Required fiscal records and disclosures rely on applicable tax/accounting law under Article 6(1)(c). Missing required billing details may prevent purchase. Records and recipients are limited to the relevant purpose.
5.3 Recipients
Stripe, the invoicing service, accountants and legally entitled authorities receive necessary information. Their roles depend on the function, including independent payment/compliance responsibilities. Actual services and processing arrangements are identified in the shared provider schedule.
6. When you contact us or receive messages
6.1 Support and enquiries
We process your contact details, messages, supplied diagnostics and complaint/request records to respond, provide support and manage claims. The basis is requested pre-contractual steps where applicable, otherwise legitimate interests in assistance and protecting rights, or relevant legal obligations. Microsoft 365 Business handles business correspondence; system emails use Resend and relevant authentication/invoicing services.
6.2 Marketing choices
Optional promotional messages require consent where electronic-marketing law requires it. We keep necessary preference/consent records and provide withdrawal or unsubscribe controls. Requesting a free report, joining a workspace or accepting Terms does not itself provide marketing consent. Necessary security, billing and service notices remain separate.
6.3 Legitimate-interest assessment
Whenever we rely on legitimate interests, we assess necessity, proportionality, reasonable expectations and individual rights, and record that assessment. You may object under Section 12. A contract with a company does not automatically provide the contractual basis for all employees’ data.
7. Recipients and shared provider schedule
7.1 Authorised recipients
Access is limited to personnel, advisers, workspace members and providers needing data for their authorised purposes. The Service Providers and Subprocessors schedule is our common reference for infrastructure, communications, AI/search, payments, external resources, locations and processing roles.
7.2 Other disclosures
Courts, regulators and legally entitled recipients may receive necessary records. Genuine corporate transactions may involve limited disclosures to advisers or counterparties with safeguards and required notices. We do not sell personal data or use Customer content for advertising audiences. A new purpose requires a valid basis and required information/choices before processing starts.
8. International processing
8.1 Locations
Our primary Supabase project is in a European region: eu-west-1 (Ireland). Other hosting, support, AI/search and integration operations may occur elsewhere, including the United States. Portuguese establishment does not mean all processing stays in Portugal or the EEA.
8.2 Safeguards
Transfers rely on an applicable adequacy decision within its scope, or on the EU Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914 — Module Three (processor to processor) where we pass Customer data to a subprocessor, Module Two (controller to processor) for data we control ourselves — with the required assessment and supplementary safeguards, or on another lawful mechanism.
For each recipient placed under an adequacy decision we record that the actual entity and the actual service are within its scope, checked on a date and re-verified whenever the provider schedule changes — Data Privacy Framework coverage is a status that can lapse, not a permanent fact. For each recipient relying on the standard clauses we hold a documented transfer impact assessment. A supplier DPA alone does not establish complete transfer coverage.
8.3 Specific qualifications
Resend states that Customer data is stored in the United States; European sending regions do not change that storage location. SearchApi processes search requests in the United States under its DPA and incorporated EU SCCs. Accepting this Policy is not blanket consent to international transfers.
8.4 Further information
Request the mechanism relevant to your data and copies of safeguards through support. We may proportionately redact confidential information and information affecting others’ rights.
9. Retention and deletion
9.1 Retention schedule
| Category | Retention rule |
|---|---|
| Personal account and profile | While needed for the account or continuing service; unnecessary active data deleted within 30 calendar days after closure, without undue delay, subject to specific lawful exceptions |
| Customer workspace and analysis history | During service and lawful instructions; 90 calendar days after ordinary paid access ends for retrieval/reactivation, then active deletion within 30 calendar days. Earlier valid deletion instructions prevail |
| Records marked for deletion | Ordinary access/processing stops when deletion begins; purge within 30 calendar days, except specific lawful retention. Separately retained history needs its own lawful purpose |
| Free report records where no account follows | 12 months from the report, then deletion; earlier on request or objection |
| Accounts without an active subscription | Reviewed after 12 months’ inactivity; 30 days’ notice before closure, then normal deletion rules. Accounts needed for active Customer workspaces are excluded |
| Routine security/error logs | Up to 90 days; longer only for documented incidents, investigations or legal duties |
| Support correspondence | Up to 24 months after closure; unnecessary attachments removed sooner; specific disputes assessed separately |
| Acceptance and rights-request evidence | Minimum necessary evidence for the applicable compliance or claims period, reviewed for continued need; no blanket retention of whole accounts |
| Service-level suppression records | While the suppression is maintained, limited to the identifiers needed to apply it; reviewed periodically and deleted when the basis ceases |
| Fiscal/accounting records | Generally 10 subsequent calendar years under applicable Portuguese rules, with the legal starting point and any specific longer duty or hold |
| Raw payment/reconciliation payloads | Up to 90 days after reconciliation, unless needed for an unresolved transaction, dispute or legal duty; minimum fiscal records kept separately |
| Supabase database backups | Under the current production setting, backup snapshots rotate out within 7 days. A copy of data deleted from the active database may therefore remain in a restricted backup for up to 7 further days; it is not used as an ordinary archive, and deletion is reapplied after restoration |
| AI/search provider files and state | Files under our control deleted within 7 days after successful ingestion and necessary retries. SearchApi may cache search results and log API usage under its own DPA and retention schedule; we do not claim that deleting our copy immediately removes its copy. Other response state, safety and legal records follow verified endpoint-specific arrangements |
9.2 Separate stages
Cancellation stops renewal; it does not itself request immediate erasure. Retrieval, active deletion and backup expiry are separate periods: for ordinary workspace closure, the periods are up to 90, 30 and 7 calendar days respectively, counted in sequence from the end of paid access. Earlier valid deletion instructions and shorter legal deadlines prevail; a valid erasure request does not wait for the 90-day retrieval period.
9.3 Owners and invited members
Personal-login closure does not itself terminate an organisation’s service or delete its prompts and shared history. Workspace records belong to the Customer, not to the individual who created them. Account deletion is handled by our support team on a verified request, not by a self-service control, and we assess and record the effect on Customer records before acting. We distinguish individual rights from authorised Customer instructions, including when an owner leaves. We assess removal of identifiers, specific content and any lawful continued retention. Workspace transfer is not a condition for exercising a valid personal-data right.
9.4 Prompts and answers
An answer is not automatically personal data about the user who ran it. It may identify that user or others, and activity links can also be personal data. Removing creator IDs does not necessarily anonymise content. Continuing Customer records remain subject to privacy rights, lawful purposes and the DPA.
9.5 Requests and legal holds
Request deletion through support without needing a particular in-app control or paid access. Verification is proportionate. For actual or reasonably anticipated disputes, we retain only relevant records for the necessary period, restrict use and reassess the hold.
10. Security
10.1 Measures
We apply risk-appropriate authentication, workspace permissions, database controls and secure communications. Support and administration access is limited to authorised operational needs. Our duties include supplier assessment and incident response.
10.2 Incidents
No system guarantees absolute security. Protect credentials and report suspected incidents to support. Where required, we notify authorities and affected individuals, or the relevant Customer when acting as processor.
11. Children
11.1 Eligibility and incidental data
Accounts are for adults acting professionally. The Service is not designed for children’s data. Report suspected inclusion to support for assessment and appropriate action. The age restriction does not remove protection for children mentioned incidentally.
12. Your rights
12.1 Access and control
Under the GDPR’s conditions, you may request access, a copy, correction, erasure, restriction and portability. Portability covers eligible data you supplied where automated processing relies on consent or contract; it does not cover every internal record.
12.2 Objection and withdrawal
You may object to legitimate-interest processing for reasons relating to your situation; processing stops unless the legal test permits continuation. You may always object to direct marketing and related profiling. Withdraw consent as easily as given, without affecting earlier lawful processing.
12.3 Request process
Contact support. We use proportionate identity/authority checks and do not routinely require identity-document copies. We normally respond within one month. Complexity or volume may justify up to two additional months, explained within the first month. Requests are normally free; fees or refusal require the GDPR’s conditions and an explanation.
12.4 Inaccurate AI information
Identify the relevant item or source. We assess correction, annotation, restriction or deletion within our control and involve the Customer/provider where appropriate. Clause 4.7 of the Terms describes the same procedure for any reported item. We cannot guarantee erasure from independent websites or third-party models’ underlying systems.
12.5 Complaints
Complain to Portugal’s CNPD or the EU supervisory authority for your habitual residence, work or alleged infringement. Prior contact with us is not required. Judicial remedies remain available.
12.6 Where you are outside the European Union
We sell only in the territories listed at checkout, currently the European Union, so this Policy is written around the GDPR and Portuguese law.
Another country’s data protection law can still reach us if it protects someone whose data appears in an analysis — for example a person named in an AI answer or in a cited source. Where that happens, we apply the rights in this Section and the process in Section 4.9, and we assess any additional local requirement on its own terms. Write to support@aiwrness.com and tell us where you are.
13. Changes and contact
13.1 Updates
We update the version and effective date when practices or duties change. Material changes receive appropriate direct notice. New consent is obtained where required; continued use is not consent to a new purpose.
13.2 Contact details
Privacy requests: support@aiwrness.com. Controller: RMVG TECH, LDA, Avenida Miguel Fernandes, 28, 7800-396 Beja, Portugal, NIPC 519625862.