Privacy Policy
Last Modified: 03-09-2026
Questa versione rivista della Privacy Policy & Compliance (GDPR) per AINETBusiness corregge tutte le criticità rilevate nell'analisi tecnica (in particolare la C4 e la C10).
Sono stati inseriti formalmente i dati identificativi completi di CONNEXT EOOD (incluso il numero di registrazione bulgaro EIK/BULSTAT: BG207748920), sono stati uniformati i canali di contatto ufficiali su dominio aziendale (eliminando la casella gratuita su Proton e il refuso), è stato integrato l'impegno alla fornitura del DPA (Data Processing Agreement ex art. 28 GDPR) per i clienti business e mappato correttamente il sub-responsabile del modulo di attivazione esterno.
Puoi copiare e incollare questo testo direttamente nella pagina della Privacy Policy del sito:
PRIVACY & COMPLIANCE (GDPR) – AINETBUSINESS
Last Updated: September 3, 2026
This Privacy Policy explains how AINETBUSINESS ("Platform", "we", "us", or "our"), operated by CONNEXT EOOD, processes personal information, how AI features operate, what data is stored, retention periods, and the security safeguards applied. This document is structured to ensure transparency under Regulation (EU) 2016/679 (GDPR) and related European data protection frameworks.
1. WHO WE ARE (DATA CONTROLLER) & CONTACT DETAILS
Data Controller: CONNEXT EOOD
Company Registration / EIK (BULSTAT): BG207748920
Registered Office: Dunav 35, Sofia Center, 1000 Sofia, Bulgaria
Official Corporate Email: info@connext-world.com
Privacy & GDPR Requests Contact: info@connext-world.com (Dedicated compliance channel)
If you submit a privacy or data subject request, please include:
The exact email address registered to your account.
The specific nature of your request (e.g., access, rectification, deletion, data portability).
Sufficient details to verify your identity securely, where strictly necessary.
2. SCOPE OF APPLICATION
This policy applies to:
The AINETBUSINESS website (ainetbusiness.com) and associated cloud platform.
Account registration, user authentication, license activation processes, and platform features.
Customer support communications, operational notices, and administrative interactions.
No Marketing Trackers / No Advertising Pixels: We do not deploy advertising trackers, profiling cookies, or marketing pixels. We do not sell or monetize personal data.
3. HOW AI FEATURES WORK (IMPORTANT NOTICE)
AINETBUSINESS functions strictly as a software orchestration layer connecting to external artificial intelligence engines (such as OpenAI or equivalent configured providers) to generate requested outputs.
No Proprietary Foundation Model: AINETBUSINESS does not provide a proprietary foundational AI model, nor does it develop or train its own AI models using customer prompts, inputs, or generated content.
Data Transmission to AI Engines: AI outputs are generated dynamically by selected third-party AI providers based on user inputs and the platform's request-optimization logic (formatting, structured prompts, and guardrails). Data transmitted is strictly limited to what is required to fulfill the user request.
User Responsibility & Content Warnings:
Do not submit unnecessary personal data.
Do not input sensitive or special categories of personal data (e.g., health, biometric, genetic, political opinions, religious beliefs, or sexual life), children's data, or confidential third-party information unless a lawful basis exists and it is strictly necessary for your professional use case.
You remain entirely responsible for the legality, compliance, and appropriateness of the content you submit to the Platform.
4. CATEGORIES OF DATA COLLECTED
Depending on your interaction with the Platform, we may process:
A) Account & Contact Data: Email address, secure authentication credentials, and optional profile details voluntarily provided (e.g., name, company name, billing data).
B) Technical & Security Logs: IP addresses (for security, rate-limiting, and anti-abuse), timestamps, device/browser technical identifiers, error logs, and security event logs. (Purpose: platform security, availability, and threat mitigation).
C) User Content (Prompts & Responses): Text entries, configuration parameters, and generated outputs transmitted to external AI providers to deliver core functionalities.
D) Support Communications: Messages, tickets, and technical details provided to resolve service issues.
E) Billing & Licensing Data: License codes, B2B company details, payment status, and transaction references. Payment card details (if applicable) are handled exclusively by certified external payment processors and are never stored on our servers.
5. PURPOSES OF PROCESSING & LEGAL BASES (GDPR)
We process personal data exclusively for legitimate, bounded purposes under the GDPR:
Service Delivery (GDPR Art. 6(1)(b) – Contractual Performance): Managing user accounts, delivering platform orchestration features, processing license activations, and providing customer support.
Security & Abuse Prevention (GDPR Art. 6(1)(f) – Legitimate Interest): Protecting the platform against unauthorized access, cyberattacks, fraud, and system misuse, ensuring infrastructure reliability and investigating security incidents.
Legal Compliance (GDPR Art. 6(1)(c) – Legal Obligation): Complying with mandatory accounting, tax, and commercial record-keeping laws, and responding to lawful orders from competent authorities.
Performance & Reliability Improvements (GDPR Art. 6(1)(f) – Legitimate Interest): Analyzing aggregated, non-identifiable technical metrics to optimize platform stability.
6. INFRASTRUCTURE HOSTING AND SUB-PROCESSORS
Infrastructure Hosting: The Platform infrastructure, operational storage, and database systems are hosted on servers provided by Contabo GmbH, ensuring localized processing within European data centers.
External AI Providers: When AI features are invoked, queries are routed to authorized third-party AI providers (e.g., OpenAI) under strict technical minimization limits.
License Activation Sub-processors: License validation and B2B onboarding data collected via dedicated activation interfaces (such as integrated form tools) are processed securely to validate physical license cards.
A complete, updated list of active sub-processors and data processing agreements (DPA) can be requested by business clients via info@connext-world.com.
7. OPENAI & EXTERNAL AI PROVIDERS – COMPLIANCE POSITION
AINETBUSINESS relies on enterprise-grade external AI providers that maintain robust security and privacy commitments:
Data Processing Addenda (DPA): Providers such as OpenAI offer DPAs supporting GDPR compliance and clarifying data controller/processor boundaries.
Data Confidentiality ("Zero Training"): Data sent to enterprise API endpoints is not utilized by default to train or improve foundational models, and strict data retention controls are enforced by the underlying providers.
Independent Audits: External providers maintain independent security certifications, including SOC 2 reports and ISO compliance frameworks.
8. INTERNATIONAL DATA TRANSFERS
Where data is processed or accessed outside the EEA, UK, or Switzerland (depending on underlying cloud or AI infrastructure configurations), transfers are governed by appropriate legal safeguards, including the Standard Contractual Clauses (SCCs) approved by the European Commission, combined with robust technical and organizational encryption measures.
9. DATA RETENTION SCHEDULE
We retain personal data only for the strict duration necessary to fulfill the purposes outlined in this policy:
Security and Technical Logs: Retained for a rolling period of 30 days, after which they are securely deleted or irreversibly anonymized.
System Backups: Retained on a rolling 10-day rotation cycle, after which older backup increments are automatically overwritten.
Account Data: Maintained for the active duration of the user account. Following account closure, essential data is retained solely as required to satisfy legal, tax, and anti-abuse obligations, and deleted thereafter.
Billing and Tax Records: Retained in accordance with mandatory statutory accounting retention periods.
Deletion Requests: Users may request account termination and data erasure at any time. We will execute deletion where technically and legally feasible.
10. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
We implement rigorous security controls to protect data against unauthorized access, alteration, disclosure, or destruction, including:
Strict access controls based on the principle of least privilege.
Secure password hashing and authentication mechanisms.
Data encryption in transit via robust Transport Layer Security (TLS/HTTPS).
Continuous security logging (retained for 30 days) and automated 10-day rolling backup protocols.
11. DATA SUBJECT RIGHTS UNDER THE GDPR
Subject to statutory exemptions under applicable law, data subjects possess the following rights:
Right of Access: Request confirmation of whether we process your data and obtain a copy.
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten"): Request deletion of personal data where applicable.
Right to Restriction: Request temporary suspension of data processing activities.
Right to Data Portability: Receive your data in a structured, commonly used format.
Right to Object: Object to processing based on legitimate interests.
Right to Lodge a Complaint: File a complaint with a competent European supervisory data protection authority.
To exercise any of these rights, business users and data subjects must contact our privacy team at info@connext-world.com. Business-to-Business DPA requests under Article 28 GDPR can also be submitted directly through this channel.
12. COOKIE POLICY
The Platform utilizes exclusively strictly necessary technical cookies required for basic website operation, session management, and user authentication. We do not deploy advertising cookies, tracking beacons, or marketing analytics pixels. Users can manage or block cookies directly via browser settings.
13. PROTECTION OF MINORS
The Platform is engineered exclusively for professional business use and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you become aware that a minor has submitted personal data, please contact us immediately so we can purge the records.
14. POLICY AMENDMENTS
We reserve the right to modify this Privacy Policy at any time. The "Last Updated" date at the top of this page indicates the effective date of the latest revision. Continued use of the Platform following the publication of modifications constitutes formal acceptance of the updated terms.
CONNEXT EOOD
Company Registration (EIK/BULSTAT): BG207748920
Registered Address: Dunav 35, Sofia Center, 1000 Sofia, Bulgaria
Contact: info@connext-world.com