Account and organization information
Name, email address, date of birth, country or region, language, account type, business name, organizational role, age limit and guardian declaration.
Artificial Intelligence Operating SystemEffective: September 14, 2026 · Version: 2026-09-14-v6
Transparent terms of personal data management during the registration, use, AI tasks, communication and subsequent payment services of AIOS Business.
The Service Provider may only process data for a specific, legal purpose and to the extent necessary. The data management required for the operation of the account is not the same as the sending of advertising: only those who tick the separate, voluntary checkbox will receive a marketing message. Consent can be withdrawn at any time.
This information applies to visitors, registrants, users, company accounts and invited members of the AIOS Business website. The Service Provider acts according to the principles of legality, fair procedure, transparency, purposefulness, data economy, accuracy, limited storage capacity, integrity and confidentiality.
The data provided during registration can be used for the creation of the account and the workspace, the performance of the service, security, cost measurement and legal obligations. Registration does not mean permission to use data for an unlimited, unspecified purpose.
Name, email address, date of birth, country or region, language, account type, business name, organizational role, age limit and guardian declaration.
Version of accepted policies, date of acceptance and acknowledgment of AI risk, and status and date of marketing consent.
Function used, selected model, token and usage amount, cost, operation status and time; IP address, browser and device data may also appear in security logs.
Package, Balance, Amount, Currency, Transaction ID and Billing Receipts. Full bank card number and CVC/CVV code are not stored by AIOS Business.
Instructions, documents, images, sounds, videos, codes and responses generated from them. These may contain personal or business data only if uploaded legally.
Customer service enquiries, security and contractual notices, as well as newsletter and marketing communications with separate consent.
Recipient lists uploaded by the User, evidence of the source and legal basis of the addresses, sender, subject, message content, attachments, sending time, delivery, bounce, unsubscribe and complaint data; open and click events if set separately.
Own domain, brand and partner profile, referral ID, click and registration event, assigned customer, commission rule, settlement status, and bank or PayPal payment data stored encrypted and later only displayed masked.
Affiliate name or company name, address, e-mail address, country, language, partner ID, commission selection, payment method, billing information, referral events, as well as limited IP, device, session and security log data necessary to detect repeat or abusive registration.
| Target | Legal Basis | Save |
|---|---|---|
| Provision of account, workspace, subscription and requested functions | GDPR Article 6 (1) b) – performance of contract | Until the existence of the account, and then, as a rule, up to 30 days; further in case of legal dispute or mandatory retention |
| Age control and protection of minors | Contract, legal obligation and legitimate interest in secure service | Until the existence of the account and the necessary claim validation period |
| Executing an AI task and directing it to a model | GDPR Article 6 (1) b); a separate legal basis is required for special data | AIOS does not currently build a persistent conversation archive; the conditions of the selected AI service provider are applicable to service provider retention |
| Usage measurement, balance and abuse prevention | Fulfillment of contract, legitimate interest or legal obligation according to Article 6 (1) f) GDPR | The duration of the contract and the subsequent general claim enforcement period; for accounting data, the mandatory time |
| Invoicing, accounting and tax liability | GDPR Article 6 (1) c) – legal obligation | According to accounting and tax law rules, typically 8 years |
| Security and essential service notifications | Performance of a contract, legal obligation or legitimate interest | As long as the account exists; the associated log for the necessary time |
| Send advertising, offers and newsletters | GDPR Article 6 (1) a) – separate, voluntary and revocable consent | Until Unsubscribe; proof of consent until the end of the claim validation period |
| Technical provision of the newsletter and advertising campaign launched for the User's own recipients | Instruction of the User as data manager; AIOS Business as a data processor based on the service contract and data processing conditions. The legal basis for recipients is defined and verified by the User. | Until the User is deleted or for a maximum of 30 days following the termination of the account; proof of opt-out and consent may be retained for a limited period of time necessary for legal claims. |
| Operation of the User's own partner program, assignment of referrers and clients, accounting and payment records | Fulfillment of contract; documented instructions of the User operating the program; in the case of security and fraud prevention, legitimate interest according to GDPR Article 6 (1) f). | Until the existence of the partnership and settlement, and then for the period according to accounting, taxation and claim enforcement obligations |
| AIOS Affiliate registration, individual referral tracking, commission calculation, payment and abuse prevention | Fulfillment of contract; invoicing and taxation legal obligation; in case of fraud prevention and the exclusion of multiple assignment, legitimate interest according to GDPR Article 6 (1) f) | Until the affiliate relationship exists; for financial documents until the mandatory retention period; in the case of security flags and logs, for the proportionate time required for the investigation and claim validation |
Customer-operated program: in the partner program created for its own domain, the User defines the purpose, legal basis, information, remuneration and payment of the data management of partners and acquired customers. During the technical provision of the function, AIOS Business may act as a data processor within the framework of the documented instructions.
AIOS Affiliate Program: the operator of AIOS Business handles the data required for application, unique referral identification, commission settlement, payment, taxation, contact and fraud prevention as an independent data controller.
Data saving abuse prevention: the IP address, device, and session identifiers do not determine exclusion by themselves. By evaluating several signals together, the system can block obvious repetition or request a manual check. Unnecessary complete browsing history is not collected by AIOS Business.
Payment details: the entire bank account number, IBAN or PayPal ID can be stored encrypted and can only be displayed later on in a masked form on the authorized user interface. Bulk payment export can only be made for authorized operators, limited to the necessary data.
Mandatory notice: the registrant declares that he has read this information and requests to create an account. The primary legal basis for the data management required for this is the conclusion and performance of the contract, not a general, unlimited consent.
Voluntary Marketing Contribution: "I want AIOS Business news, offers and advertising materials" can be entered by checking a separate, empty by default checkbox. Refusing to do so is not an obstacle to registration and cannot cause a disadvantage in using the service.
Undo: consent can be revoked at any time, without reason or charge, by using the unsubscribe link in the sent message, in the account settings or support@aios-business.com. Revocation does not affect the legality of previous data management.
User's responsibility: the User is usually the data controller with regard to his own recipient list, campaign goal and message. He is obliged to inform the recipients properly, to verify the legal basis and, if necessary, the consent, to handle the requests of the data subjects, and to validate the opt-outs and objections without delay.
The role of AIOS Business: handles the data required to create, address, schedule, send and measure the results of the campaign according to the User's documented instructions. AIOS Business does not use the recipient list for its own advertising, profiling, sales or independent business purposes.
Shipping and measurement service providers: is actually sent, the sender, recipient, content, attachment and delivery metadata may be sent to the service provider connected by the User. Open or click measurement can only be activated if the legal basis and the conditions according to the rules of electronic communications have been provided by the User. The service provider's name, destination country and conditions are displayed before the connection is activated.
AIOS Business does not automatically transfer all data to all listed AI providers. The content of the task can only be sent to one or more service providers that the user chooses or that the AI-router designates to perform the given task. Transmission is limited to the necessary data, and the system indicates active model connections on the interface.
The User must avoid uploading unnecessary personal data, special data, business secrets, lawyer secrets, bank card data, passwords or other authentication data. You can only upload the data of a third party with a suitable legal basis and with information.
The conditions of external service providers apply to the data processing they carry out. AIOS' own information sheet and service provider documents should be read together. Before activating the service provider, the Service Provider is obliged to check the corresponding contractual, security and international data transfer guarantees.
Login and AI API task processing. According to OpenAI's business data protection commitment, API business data is not used for model training by default.
European Data Protection Directives · updated: June 4, 2026OpenAI Enterprise Privacy · Updated: January 8, 2026In EGT, only a connection that complies with the paid service conditions of Gemini API and Google's data processing conditions can be activated.
Google Privacy PolicyGemini API Data Usage Terms · 28 April 2026When using a commercial API, the data processing agreement and business terms apply; commercial client content cannot be used for model training.
Anthropic Privacy Policy · effective: July 8, 2026Anthropic Commercial TermsDeepSeek's own disclosure also indicates a Chinese data controller and storage in the People's Republic of China. The integration cannot be activated for personal data until the legal basis for data transfer according to the GDPR, guarantees and risk assessment have been verified.
DeepSeek Privacy Policy · updated: February 10, 2026In the case of business data processing, Mistral may act as a data processor; activation is preceded by a data processing agreement and service provider settings.
Mistral Privacy Policy · effective: July 27, 2026Mistral Commercial TermsA cloud and storage service provider cooperates in the technical operation of the website, database and file storage. Signing in will provide AIOS Business with your ChatGPT account's verified email address and name, if available. Email, CRM, ERP, accounting, analytics or other integrations can only access data after the user has explicitly connected and granted the necessary rights.
The list of current actual data processors and sub-data processors is updated by the Service Provider when it activates a new service. Based on legislation, data may be forwarded to authorities, courts or other authorized bodies.
When Gmail newsletter sending is connected, AIOS Business requests only OpenID and email identity plus the gmail.send permission needed to send messages initiated by the user. The verified email address identifies the sender, and Gmail tokens are used solely to send messages approved by the user in AIOS. AIOS does not request access to read, download, modify or delete messages, drafts, contacts or Drive files.
OAuth tokens are encrypted, isolated by organization and user, cannot be displayed again, and may be used only by the server-side Gmail sending process. Only the sender, recipients, subject, content and attachments needed for the requested send are transferred to Google. AIOS does not sell Google user data or use it for advertising, profiling, credit decisions or AI-model training. The connection can be removed in AIOS, access can be revoked in the Google Account, and stored credentials are deleted when the connection or account is deleted.
AIOS uses two isolated Microsoft flows. Microsoft sign-in or registration for an AIOS account uses OAuth 2.0 Authorization Code with PKCE and OIDC and only openid, profile, email and User.Read; it does not create a Microsoft 365 data connection and no access or refresh token is retained. The separate Microsoft 365 Connector uses openid, profile, email, offline_access and User.Read, with individually selected Files.Read, Mail.Read, Calendars.Read and Contacts.Read permissions and, for work or school accounts, Chat.Read and Sites.Read.All. Files.ReadWrite, Mail.Send and Calendars.ReadWrite are optional. Selecting them never performs an action. The technical Microsoft scope of Files.ReadWrite and Calendars.ReadWrite can be broader than the actions AIOS exposes, but AIOS provides no delete operation. AIOS never asks for or stores a Microsoft password.
AIOS binds accounts using the Microsoft tenant and object identifiers; an existing AIOS account is never linked solely because its email matches a Microsoft email. Search terms and the necessary access token are sent to Microsoft Graph and permitted results are shown in the current task. Ordinary Connector search terms and result contents are not retained; this does not apply to separately selected Company Knowledge sources. Company Knowledge synchronizes only OneDrive or SharePoint files, or direct folder contents, explicitly selected by the user. Supported text, metadata and provenance links are stored in the AIOS knowledge store; unsupported or oversized Office formats are catalogued as metadata only. Sending mail, creating a calendar event and saving a OneDrive draft each require a complete preview, a short-lived one-use approval bound to the browser and session, AIOS password confirmation and a separate execution command. On successful or failed execution, AIOS immediately replaces the complete preview with a content-free marker. The digest, status, limited result or error code and security events may be retained for no more than 30 days; an unexecuted preview may also remain for no more than 30 days. A bounded hourly maintenance job deletes the record and its events at the 30-day boundary, with an additional deletion check on the next action; deletion is retried after a transient storage failure. Account or Connector deletion starts immediate removal. AIOS does not sell this data or use it for advertising, credit decisions or AI-model training.
Connector access and refresh tokens are encrypted, isolated by organization and user, cannot be displayed again and are used only server-side. ID tokens are never stored persistently. Security events may contain fixed identifiers, event type, outcome, error code and timestamp, but never tokens. A selected Company Knowledge source can be removed separately; its stored AIOS document and index are deleted only when no other active selection references them. Disconnecting the Connector deletes its credential and associated Microsoft knowledge sources; consent can also be revoked in the Microsoft account. Deleting the AIOS account removes Microsoft identity bindings, connection data, knowledge sources and logs.
Microsoft Privacy Statement · Work or school account permissions · Personal account permissions
Bank card payment is currently not activated. Upon activation, the entire card number, expiration date and CVC/CVV code are managed on the secure interface of the selected payment service provider with appropriate security certification. AIOS only records the transaction ID, amount, currency, status and billing data required for payment. The name and data management information of the payment service provider is displayed when the payment is activated, before the payment.
The Service Provider protects data with risk-proportionate technical and organizational measures, such as encrypted data transmission, access control, organizational workspace separation, logging, API keys treated as secret variables, authorization review, backup and incident management procedures.
Only authorized persons and contractual data processors can access personal data, only to the extent necessary for their tasks and under confidentiality. No internet system can promise absolute, risk-free security; the Service Provider therefore constantly evaluates and develops protection measures.
Isolation of workspace content. During normal use, the content of the User's workspace can only be viewed by the User and the workspace members authorized by him. The Service Provider's employees do not read or use the content stored in the workspace for business purposes. At the same time, the system technically processes the data to perform the service, and the content required to perform the selected task can be forwarded to a data processor or AI service provider according to this information.
Exceptionally, only to the extent necessary, with appropriate authorization, confidentiality and, if possible, logging, an authorized person may access the content, if this is required by the technical support requested by the User, the investigation of a security incident, the prevention of abuse, system recovery or a mandatory statutory or official provision. Such access may not be used for advertising, profiling, or the utilization of the User's content for independent business purposes.
Server-side preservation and workflow continuity do not replace the User's own backup. The regular export of important completed works and documents is recommended, because data loss due to server, backup storage, network or software errors, power outages, cyber attacks, external service provider errors or force majeure cannot be completely excluded in any IT system.
If a data processor handles data outside the European Economic Area, the transfer can only be made in accordance with Chapter V of the GDPR, such as a compliance decision, appropriate guarantees, general contract terms and, if necessary, a data transfer impact assessment. If adequate protection cannot be ensured, the given integration will not be activated or restricted by the Service Provider.
The data subject can request information and access, request the correction or deletion of their data, the limitation of data management and - if the conditions for this are met - the storage of their data; you can object to data processing based on legitimate interest and withdraw your consent. The application is submitted by support@aios-business.com. As a general rule, the Service Provider will respond within one month and, if necessary, can verify the applicant's identity.
The registered user can initiate the permanent deletion of his account and workspace in the Settings menu of the account. After confirmed deletion, the contents of the account and the active workspace cannot be restored. This does not affect the data that the Service Provider is obliged to keep for a limited period of time due to a legal obligation, legal demand or documentation of a security incident.
Complaints can be made a National Data Protection and Freedom of Information Authority (1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.), you can also apply to the relevant court. A data subject living in another country can also contact the supervisory authority of his place of residence.
The service cannot be used by persons under the age of 13. If the given country stipulates a higher digital age limit, the higher age limit applies. Under the age of 18, permission from a parent or legal representative is required. If the Service Provider becomes aware that a child's data has been entered into the system without authorization, it will take the necessary measures immediately.
The AI router may choose a model based on technical considerations, and the security system may indicate abuse or budget overruns. AIOS Business does not make exclusively automated decisions with legal effect or similarly significant effect on a natural person. Such a decision requires human review and a separate legal basis.
Cookies and similar technologies required for the operation and secure login of the service can be used. Non-necessary analytical or advertising cookies can only be activated after prior, separate consent. The technical logs serve the purpose of operation, troubleshooting, fraud and attack prevention and can only be kept for as long as necessary.
The Service Provider investigates, documents and takes mitigation measures for incidents affecting the security of personal data. If notification or stakeholder information is required according to the GDPR, it will be completed within the legal deadline.
The Service Provider may modify the information in the event of a change in legislation, service provider, integration or operation. The user is informed of the significant change in the account or by e-mail. If consent is required for data management for a new purpose, it is requested separately; previous acceptance cannot be automatically extended to a new purpose.