Privacy Policy
Version 1.5 · Last updated 22 September 2026
This Privacy Policy explains how Shpat Radoniqi B.I. ("AIA", "we", "us") collects, uses, and protects personal data when you use the AIA platform. We act as a data controller for your account data, and as a data processor for the message data you connect to the platform. This policy is written to align with the General Data Protection Regulation (GDPR) and the data protection law of the Republic of Kosovo.
1. Who we are
The data controller is Shpat Radoniqi B.I., registered at Rruga Agim Radoniqi 16, 30000 Pejë, Republic of Kosovo. For any privacy question or to exercise your rights, contact us at info@aiaplatform.ai.
2. What data we collect
- Account data: your name, email address, password (stored only as a secure hash), and business/workspace name.
- Connected-account data: when you connect an email or messaging account (Gmail, Outlook, WhatsApp, Slack, Facebook, Instagram), we access the messages, contacts, and metadata needed to provide the unified inbox and AI features. If you connect a calendar (Google Calendar, Microsoft Outlook Calendar), we also access your events and free/busy times so the scheduling features can see when you are available.
- Content you provide: knowledge-base documents, agent configurations, and workflow definitions.
- Usage and technical data: log data, IP address, browser/device information, and actions taken in the app.
- Cookies and similar technologies: see the "Cookies" section below.
3. How we use your data and our legal bases
We process personal data to provide and operate the service (performance of a contract), to secure and improve the platform (our legitimate interests), where you have given consent (such as optional cookies), and to comply with legal obligations.
- Provide the unified inbox, classification, and AI-assisted responses.
- Send replies from your connected account, and update the original message in that account — marking it read and applying an "AIA" label — so that account and your AIA inbox agree on what has been handled. We write to a connected account only when you act: a reply you approve and send, or a read/unread change you make in AIA. We never modify messages you have not acted on.
- Create events on your connected calendar when you schedule a meeting through the platform.
- Authenticate you and keep your account secure.
- Provide support and send service-related communications.
- Detect, prevent, and address abuse, fraud, or technical issues.
4. AI processing
To classify messages and generate suggested responses, message content and relevant context may be sent to our AI provider, Anthropic (Claude API). This processing happens to provide a core feature of the service. We do not sell your data, and we configure our AI processing for business use only.
5. Third-party processors
We rely on the following categories of sub-processors to deliver the service. Each is bound by data-protection terms:
- Anthropic — AI message classification and response generation.
- Google (Gmail / Google Workspace) and Microsoft (Outlook / Microsoft Graph) — email integration.
- Meta (WhatsApp Business, Facebook, Instagram) and Slack — messaging integration.
- Cloud hosting and infrastructure providers (e.g. Railway), including managed PostgreSQL and Redis.
6. International transfers
Some of our processors are located outside Kosovo and the European Economic Area. Where data is transferred internationally, we rely on appropriate safeguards such as the European Commission Standard Contractual Clauses or an adequacy decision.
7. Data retention
We keep personal data for as long as your account is active and as needed to provide the service. What happens when you stop using part of the service depends on the action you take. In every case below, the one exception is data we must keep to meet a legal obligation: that data stays protected under this policy and is deleted as soon as the obligation ends.
- Disconnecting an integration stops us receiving new data from that platform and deletes the access token we had stored for it. Messages already delivered to your inbox are kept so your history stays intact, until you ask us to delete them.
- Archiving a message removes it from your active inbox but does not erase it. Archived messages are retained on the same terms as the rest of your history.
- Asking us to delete your data erases the associated messages and conversations from our live systems, together with what our agents derived from them — calendar entries, extracted leads, and sentiment and issue records. A deletion request sent by a connected platform such as Meta is actioned automatically and immediately, and returns a confirmation code you can use to check that it completed. A request you send us directly is carried out by hand: we complete it without undue delay, and within one month at the latest.
- Closing your account takes effect immediately: you are signed out everywhere, no further sign-in is possible, and you are removed from your workspace. Content that belongs to a shared workspace — messages, conversations, and the knowledge base — stays with that workspace, because the colleagues you shared it with still rely on it. To have that content erased as well, ask us using the contact details in this policy and we will action it as described above.
- Backups exist so we can recover from failure. They are overwritten on a rolling schedule rather than edited, so data erased from our live systems can still appear in a backup until that backup expires. We never restore erased data back into our live systems.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time.
- To exercise any of these rights, contact info@aiaplatform.ai.
- You also have the right to lodge a complaint with the Information and Privacy Agency of the Republic of Kosovo (IPA).
9. Security
We use technical and organisational measures to protect personal data, including encryption of stored credentials, encrypted transport (HTTPS), role-based access control, and tenant isolation. No method of transmission or storage is completely secure, but we work to protect your data and review our measures regularly.
10. Cookies
We use strictly necessary cookies to keep you signed in and to operate the platform; these do not require consent. If we introduce analytics or marketing cookies in the future, we will request your consent first via the cookie banner, and you can change your choice at any time.
11. Google user data
AIA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
This covers the Gmail and Google Calendar data you allow AIA to access when you connect a Google account:
- We use it only to provide the features you see in AIA: bringing your messages into the unified inbox, classifying them and drafting suggested replies, sending the replies you approve, marking handled messages read and labelling them "AIA", and showing and creating calendar events for scheduling.
- We transfer it only as needed to provide those features — for example to our AI provider, Anthropic (see section 5) — or to comply with applicable law.
- We do not sell it and do not use it for advertising.
- We do not use it to develop, improve, or train generalised AI or machine-learning models.
- Our staff do not read it unless you ask us to (for example, for support), it is needed for security purposes such as investigating abuse, it is needed to comply with applicable law, or it has been aggregated and anonymised for internal operations.
12. Children
The platform is intended for business use and is not directed at children under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the version and date shown at the top of this page and, where appropriate, notify you.
14. Contact
Questions about this policy or our data practices can be sent to info@aiaplatform.ai.