Account an organization data
Name, email address, date a birth, country or region, language, account type, business name, organizational role, age limit an guardian statement.
Artificial Intelligence Operating SystemEffective: September 14, 2026 · Version: 2026-09-14-v6
Transparent terms a personal data management during di registration, use, AI tasks, communication an subsequent payment services a AIOS Business.
Di Service Provider may only process data fi a specific, legal purpose an to di extent necessary. Di data management weh yuh need fi di operation a di account a nuh di same as di sending a advertising: only dem who tick di separate, voluntary checkbox ago receive a marketing message. Consent can be withdrawn at any time.
Dis information apply to visitors, registrants, users, company accounts an invited members a di AIOS Business website. Di Service Provider act according to di principles a legality, fair procedure, transparency, purposefulness, data economy, accuracy, limited storage capacity, integrity an confidentiality.
Di data weh yuh provide during registration can be used fi di creation a di account an di workspace, di performance a di service, security, cost measurement an legal obligations. Registration nuh mean permission fi use data fi an unlimited, unspecified purpose.
Name, email address, date a birth, country or region, language, account type, business name, organizational role, age limit an guardian statement.
Version a accepted policies, date a acceptance an acknowledgement a AI risk, an status an date a marketing contribution.
Function used, selected model, token an usage amount, cost, operation status an time; IP address, browser an device data maita also appear inna security logs.
Package, balance, amount, currency, transaction ID an billing receipts. Full bank card numba an CVC/CVV code no store by AIOS Business.
Inschrokshan, dakiument, imij, soun, vidio, kuod ah rispans we jinariet frah dem. Dem may contain personal or business data only if uploaded legally.
Customer service enquiries, security an contractual notices, as well as newsletter an marketing communications wid separate consent.
Recipient lists weh di User upload, evidence regarding di source an legal basis a di addresses, sender, subject, message content, attachments, sending time, delivery, bounce, unsubscribe an complaint data; open an click events if set separately.
Own domain, brand an partner profile, referral ID, click an registration event, assigned customer, commission rule, settlement status, as well as bank or PayPal payment data stored encrypted an later only displayed masked.
Affiliate name or company name, address, e-mail address, country, language, partner ID, commission selection, payment method, billing information, referral events, as well as limited IP, device, session and security log data necessary fi detect repeated or abusive registration.
| Purpose | Legal basis | Preservation |
|---|---|---|
| Provision a account, workspace, subscription an requested functions | GDPR Article 6 (1) b) – contract performance | Til di egzistans a di akount, an den, az a jinaral ruul, op tu 30 die; further in case a legal dispute or mandatory retention |
| Age control an protection a minors | Contract, legal obligation an legitimate interest inna secure service | Til di existence a di account an di necessary claim enforcement period |
| Executing an AI task an directing it to a model | GDPR Article 6 (1) b); a separate legal basis is required fi special data | AIOS no currently build a persistent conversation archive; di conditions a di selected AI service provider dem applicable to service provider retention |
| Usage metering, balance an abuse prevention | Fulfillment a contract, legitimate interest or legal obligation according to GDPR Article 6 (1) f) | Di duration a di contract an di subsequent general claim enforcement period; fi accounting data, di mandatory time |
| Invoicing, accounting an tax liability | GDPR Article 6 (1) c) – legal obligation | According to accounting an tax law rules, typically 8 years |
| Security an Essential Service Notices | Performance of a contract, legal obligation or legitimate interest | Until di existence a di account; di associated log fi di necessary time |
| Sen advertising, offers an newsletters | GDPR Article 6 (1) a) – separate, voluntary an revocable consent | Til yuh unsubscribe; proof a consent until di end a di claim validation period |
| Technical provision a di newsletter an advertising campaign weh did launch fi di User's own recipients | Instruction of di User as a data controller; AIOS Business as a data processor based pan di service contract an data processing conditions. Di legal basis fi recipients is determined an verified by di User. | Til di User get delete or fi a maximum a 30 days afta di termination a di account; proof a opt-out an consent can be kept fi a limited period a time necessary fi legal claims. |
| Operation a di User's own partner program, assignment a referrers an clients, accounting an payment records | Performance of Contract; documented instructions a di User weh a operate di program; inna di case a security an fraud prevention, legitimate interest according to GDPR Article 6 (1) f). | Until di existence a di partnership an settlement, an den fi di period according to accounting, taxation an claim enforcement obligations |
| AIOS Affiliate registration, unique referral tracking, commission calculation, payment an abuse prevention | Contract performance; invoicing an taxation legal obligation; legitimate interest according to Article 6 (1) f) GDPR in case of fraud prevention and exclusion of multiple assignment | Until di affiliate relationship exist; fi financial documents until di mandatory retention period; inna di case a security indicators an logs, fi di proportionate time weh yuh need fi di examination an claim validation |
Customer-operated program: inna di partner program weh mek fi it own domain, di User determine di purpose, legal basis, information, remuneration an payment a di data management a partners an acquired customers. Durin di technical provision a di function, AIOS Business can act as a data processor widin di framework a di documented instructions.
AIOS Affiliate Program: AIOS Business operator handle di data weh yuh need fi application, unique referral identification, commission settlement, payment, taxation, contact an fraud prevention as an independent data controller.
Data saving abuse prevention: di IP ajres, divais ah seshan aidentifai no disaid exkluujan bai dehself. By evaluating several signals together, di system can block obvious repetition or request a manual check. Unnecessary complete browsing history is not collected by AIOS Business.
Payment details: di entire bank account numba, IBAN or PayPal ID can be stored encrypted an can only appear inna mask form later pan di authorized user interface. Bulk payment export can only be made fi authorized operators, limited to di necessary data.
Mandatory acknowledgement: di registrant declare seh him read dis information an request di creation a one account. Di primary legal basis fi di data management weh yuh need fi dis a di conclusion an fulfillment a di contract, not a general, unlimited consent.
Voluntary Marketing Contribution: "Request AIOS Business news, offers and advertising materials" can be entered by checking a separate, empty by default check box. Refusing fi do so a nuh obstacle to registration an cyaan cause a disadvantage inna using di service.
Withdrawal: at consent can be revoked at any time, widout reason or charge, by using di unsubscribe link inna di sent message, inna di account settings or support@aios-business.com. Revocation no affect di legality a previous data management.
User's responsibility: di User is usually di data manager wid regard to him own recipient list, campaign goal an message. Im oblige fi inform di recipients properly, fi verify di legal basis an, if necessary, di consent, fi handle di requests a di data subjects, an fi validate di opt-outs an objections widout delay.
Di role a AIOS Business: handle di data weh yuh need fi mek, address, schedule, send an measure di results a di campaign according to di User's documented instructions. Di recipient list nuh use by AIOS Business fi it own advertising, profiling, sales or independent business purposes.
Shipping an measurement service providers: pan actual sending, di sender, recipient, content, attachment an delivery metadata maita sen tu di service provider weh di User connect. Open or click measurement can only be activated if di legal basis an di conditions according to di rules a electronic communications have been provided by di User. Di service provider's name, destination country an conditions dem display before di connection get activate.
AIOS Business nuh automatically transmit all data to all listed AI providers. Di content a di task can only be sen to one or more service providers weh di user choose or weh di AI-router designate fi perform di given task. Transmission is limited to di necessary data, an di system indicate active model connections pan di interface.
Di User haffi avoid uploading unnecessary personal data, special data, business secrets, lawyer secrets, bank card data, passwords or other authentication data. Yuh can only upload di data a one third party wid a suitable legal basis an wid information.
Di conditions a external service providers apply to dem data processing. AIOS' own information sheet an service provider documents shuda be read tugeda. Bifuo yuh activate di service provider, di Service Provider haffi check di corresponding contractual, security an international data transfer guarantees.
Login an AI API task processing. According to OpenAI's business data protection commitment, API business data is not used fi model training by default.
European Data Protection Directives · updated: June 4, 2026OpenAI Enterprise Privacy · updated: January 8, 2026Inna di EGT, only a connection weh comply wid di paid service conditions a di Gemini API an di data processing conditions a Google can be activated.
Google Privacy PolicyGemini API Data Usage Terms · April 28, 2026Wen yuh a use a commercial API, di data processing agreement an di business conditions govern; commercial client content cyaan be used fi model training.
Anthropic Privacy Policy · Effective: July 8, 2026Anthropic Commercial TermsDeepSeek dem own notice also seh a Chinese data controller handle di data and dat storage can happen inna di People's Republic of China. Di integration cyaan activate fi personal data until di GDPR legal basis fi transfer, safeguards and risk assessment all verify.
DeepSeek Privacy Policy · updated: February 10, 2026Inna di case a business data processing, Mistral maita act as a data processor; activation is preceded by a data processing agreement an service provider settings.
Mistral Privacy Policy · effective: July 27, 2026Mistral Commercial TermsA cloud an storage service provider cooperate inna di technical operation a di website, database an file storage. Signing in will provide AIOS Business wid yuh ChatGPT account's verified email address an name, if available. Email, CRM, ERP, accounting, analytics or ada integrations can only access data afta di user explicitly connect an grant di necessary rights.
Di list a current actual data processors an sub-data processors get update by di Service Provider wen it activate a new service. Based pan legislation, data may be forwarded to authorities, courts or other authorized bodies.
When Gmail newsletter sending is connected, AIOS Business requests only OpenID and email identity plus the gmail.send permission needed to send messages initiated by the user. The verified email address identifies the sender, and Gmail tokens are used solely to send messages approved by the user in AIOS. AIOS does not request access to read, download, modify or delete messages, drafts, contacts or Drive files.
OAuth tokens are encrypted, isolated by organization and user, cannot be displayed again, and may be used only by the server-side Gmail sending process. Only the sender, recipients, subject, content and attachments needed for the requested send are transferred to Google. AIOS does not sell Google user data or use it for advertising, profiling, credit decisions or AI-model training. The connection can be removed in AIOS, access can be revoked in the Google Account, and stored credentials are deleted when the connection or account is deleted.
AIOS uses two isolated Microsoft flows. Microsoft sign-in or registration for an AIOS account uses OAuth 2.0 Authorization Code with PKCE and OIDC and only openid, profile, email and User.Read; it does not create a Microsoft 365 data connection and no access or refresh token is retained. The separate Microsoft 365 Connector uses openid, profile, email, offline_access and User.Read, with individually selected Files.Read, Mail.Read, Calendars.Read and Contacts.Read permissions and, for work or school accounts, Chat.Read and Sites.Read.All. Files.ReadWrite, Mail.Send and Calendars.ReadWrite are optional. Selecting them never performs an action. The technical Microsoft scope of Files.ReadWrite and Calendars.ReadWrite can be broader than the actions AIOS exposes, but AIOS provides no delete operation. AIOS never asks for or stores a Microsoft password.
AIOS binds accounts using the Microsoft tenant and object identifiers; an existing AIOS account is never linked solely because its email matches a Microsoft email. Search terms and the necessary access token are sent to Microsoft Graph and permitted results are shown in the current task. Ordinary Connector search terms and result contents are not retained; this does not apply to separately selected Company Knowledge sources. Company Knowledge synchronizes only OneDrive or SharePoint files, or direct folder contents, explicitly selected by the user. Supported text, metadata and provenance links are stored in the AIOS knowledge store; unsupported or oversized Office formats are catalogued as metadata only. Sending mail, creating a calendar event and saving a OneDrive draft each require a complete preview, a short-lived one-use approval bound to the browser and session, AIOS password confirmation and a separate execution command. On successful or failed execution, AIOS immediately replaces the complete preview with a content-free marker. The digest, status, limited result or error code and security events may be retained for no more than 30 days; an unexecuted preview may also remain for no more than 30 days. A bounded hourly maintenance job deletes the record and its events at the 30-day boundary, with an additional deletion check on the next action; deletion is retried after a transient storage failure. Account or Connector deletion starts immediate removal. AIOS does not sell this data or use it for advertising, credit decisions or AI-model training.
Connector access and refresh tokens are encrypted, isolated by organization and user, cannot be displayed again and are used only server-side. ID tokens are never stored persistently. Security events may contain fixed identifiers, event type, outcome, error code and timestamp, but never tokens. A selected Company Knowledge source can be removed separately; its stored AIOS document and index are deleted only when no other active selection references them. Disconnecting the Connector deletes its credential and associated Microsoft knowledge sources; consent can also be revoked in the Microsoft account. Deleting the AIOS account removes Microsoft identity bindings, connection data, knowledge sources and logs.
Microsoft Privacy Statement · Work or school account permissions · Personal account permissions
Bank card payment no activate now. Wen yuh activate, di entire card numba, expiration date an CVC/CVV code dem manage pan di secure interface a di payment service provider weh yuh select wid appropriate security certification. AIOS only record di transaction ID, amount, currency, status an billing data weh yuh need fi payment. Di name an data management information a di payment service provider is displayed wen di payment is activated, before di payment.
Di Service Provider protect data wid risk-proportionate technical an organizational measures, such as encrypted data transfer, access control, organizational workspace separation, logging, API keys treated as secret variables, authorization review, backup an incident management procedures.
Only authorized persons an contractual data processors can access personal data, only to di extent necessary fi dem tasks an unda confidentiality. No internet system can promise absolute, risk-free security; di Service Provider therefore constantly evaluate an develop protection measures.
Separation of workspace content. Durin normal use, di contents a di User's workspace can only be viewed by di User an di workspace members authorized by him. Di Service Provider's employees dem nuh read or use di content weh dem store inna di workspace fi business purposes. At di siem taim, di system technically process di data fi perform di service, an di content weh yuh need fi perform di selected task can be forwarded to a data processor or AI service provider according to dis information.
Exceptionally, only to di extent necessary, wid appropriate authorization, confidentiality an, if possible, logging, an authorized person may access di content, if dis is necessary fi technical support requested by di User, investigation of a security incident, prevention of abuse, system restoration or mandatory statutory or official provision. Such access may not be used fi advertising, profiling, or di utilization a di User's content fi independent business purposes.
Server-side preservation an di continuity a work processes no replace di User's own backup. Di regular export a important completed works an documents is recommended, cause data loss due to server, backup storage, network or software errors, power outages, cyber attacks, external service provider errors or force majeure cyaan be completely excluded in any IT system.
If a data processor handle data outside di European Economic Area, di transmission can only be carried out wid a solution according to Chapter V a di GDPR, such as a compliance decision, appropriate guarantees, general contractual conditions an, if necessary, a data transfer impact assessment. If adequate protection cyaan be ensured, di given integration naa go be activated or restricted by di Service Provider.
Di data subject can request information an access, request di correction or deletion a dem data, di limitation a data management an - if di conditions fi dis meet - di storage a dem data; yuh can object to data processing based pan legitimate interest an widdraw yuh consent. Di application is submitted by support@aios-business.com. As a general rule, di Service Provider ago respond widin one month an, if necessary, can verify di applicant's identity.
Di registered user can initiate di permanent deletion a him account an workspace himself inna di Settings menu a di account. Afta yuh confirm di delete, di contents a di account an di active workspace kyaahn get restore. Dis no affect di data weh di Service Provider obliged fi keep fi a limited period a time due to a legal obligation, legal demand or documentation a security incident.
A complaint can be mek a Nashinal Data Protekshan an Friidom a Infamieshan Aatariti (1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.), yuh can also apply to di relevant court. A data subject weh live inna anodda country can also contact di supervisory authority a him place a residence.
Di sorvis no fi yuuz bai piipl anda di iej a 13. Ef di gien konchri stipulate a ai dijital iej limit, di ai iej limit aplai. Anda di age a 18, permission fram a parent or legal representative is required. If di Service Provider get aware seh a pikni data get put inna di system widout authorization, it ago tek di necessary measures immediately.
Di AI-router can select a model based pan technical considerations, an di security system can indicate abuse or budget overruns. AIOS Business no mek exclusively automated decisions wid legal effect or similarly significant effect pan a natural person. Such a decision require human review an a separate legal basis.
Cookies an similar technologies necessary fi di operation a di service an secure login can be used. Non-necessary cookies fi analytical or advertising purposes can only be activated afta prior, separate consent. Di technical logs dem serve di purpose a operation, troubleshooting, fraud an attack prevention an can only be kept fi as long as necessary.
Di Service Provider investigate, document an tek mitigation measures fi incidents weh affect di security a personal data. If notification or stakeholder information is required according to di GDPR, it will be completed widin di legal deadline.
Di Service Provider may amend di information inna di event a changes inna legislation, service providers, integration or operations. Di user get informed a di significant change inna di account or by e-mail. If consent is required fi data management fi a new purpose, it is requested separately; previous acceptance cyaan be automatically extended to a new purpose.