Your Data, Your Rights

Privacy Policy

AiDome is built on the principle that your data belongs to you — and only you. This policy explains what personal data we collect, why we collect it, and how we protect it.

Last updated: February 2026  |  Data Controller: AiDome Technologies OÜ

Data Controller

Company: AiDome Technologies OÜ

Registered in: Estonia (EU)

Email: privacy@aidometech.ai

Website: aidometech.ai

Applicable law: General Data Protection Regulation (EU) 2016/679, Estonian Personal Data Protection Act (Isikuandmete kaitse seadus)

Lead Supervisory Authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — aki.ee

What Personal Data We Collect

We collect only the data necessary to provide our services and improve your experience. Here is a complete overview of the personal data we process, organized by context.

✉️ Contact Form

When you submit our contact form, we collect:

  • Your name
  • Your email address
  • Your message content
📊 Analytics (Marketing Website)

With your consent, Google Analytics collects:

  • Pages visited and time spent
  • Referral source (how you found us)
  • Device type and browser
  • Approximate geographic location (country/city level)
🔧 Technical Data (Automatic)

Our servers automatically collect:

  • IP address (anonymized where possible)
  • Browser type and version
  • Operating system
  • Access timestamps

Why We Process Your Data

Every data processing activity has a specific purpose and a legal basis under GDPR Article 6.

Purpose Data Involved Legal Basis (Art. 6 GDPR) Retention
Respond to your inquiries Name, email, message Consent Art. 6(1)(a) Until request is fulfilled, max 12 months
Provide PRISM platform access Name, email, password, usage data Contract Art. 6(1)(b) Duration of account + 30 days after deletion
Process documents in PRISM User-uploaded documents, AI interactions Contract Art. 6(1)(b) Until user deletes or account closes
Improve website experience Analytics data (anonymized) Consent Art. 6(1)(a) 26 months (Google Analytics default)
Ensure website security IP address, access logs Legitimate Interest Art. 6(1)(f) 90 days
Legal compliance As required by law Legal Obligation Art. 6(1)(c) As required by applicable law

PRISM Platform — Data Sovereignty

PRISM is designed from the ground up with data sovereignty as its core principle.

All documents, conversations, and AI-generated content within PRISM remain on EU-based infrastructure. No data is sent to third-party AI providers (OpenAI, Google, Anthropic, etc.). PRISM uses self-hosted, open-source language models running on dedicated GPU instances.

Where PRISM Data Lives

🇪🇺 Scaleway — Paris, France

All PRISM infrastructure is hosted by Scaleway in their fr-par-1 data center (Paris, France), within the European Union.

  • GPU instances (AI model inference)
  • Application servers
  • PostgreSQL database
  • Qdrant vector database
  • Object storage (S3-compatible)
🔒 Tenant Isolation

Every PRISM user's data is completely isolated from other users:

  • Separate database partitions per tenant
  • Isolated vector collections per agent
  • Encrypted storage at rest
  • No cross-tenant data access — ever

What PRISM Does NOT Do

  • We do NOT send your documents to external AI providers
  • We do NOT use your data to train AI models
  • We do NOT share your data with third parties
  • We do NOT store data outside the European Union
  • We do NOT retain data after you delete your account (except as required by law)

Marketing Website Hosting

Our marketing website (aidome.tech) is hosted by Hostinger International Ltd., with servers in the European Union. Hostinger acts as a data processor for the technical data (server logs, IP addresses) generated when you visit our website.

Hostinger privacy policy: hostinger.com/privacy-policy


Third-Party Services

We use a limited number of third-party services. Each one is listed here with its purpose and data handling.

Service Purpose Data Shared Location Legal Basis
Google Analytics 4 Website usage statistics Anonymized browsing data EU (Google Ireland Ltd.) Consent
Hostinger Website hosting Server logs, IP addresses EU Legitimate Interest
Scaleway PRISM platform hosting Platform data (encrypted) EU (Paris, France) Contract

No data transfers outside the EU. All our service providers process data within the European Economic Area. We do not transfer personal data to countries outside the EU/EEA. Google Analytics uses IP anonymization by default in GA4 and processes EU data through Google Ireland Limited.

Your Rights Under GDPR

You are always in control of your personal data

👁️ Right of Access Art. 15

You can request a copy of all personal data we hold about you, free of charge, in a commonly used format.

✏️ Right to Rectification Art. 16

You can ask us to correct or update any inaccurate or incomplete personal data we hold about you.

🗑️ Right to Erasure Art. 17

You can request we delete your personal data. We will comply unless we have a legal obligation to retain it.

⏸️ Right to Restrict Processing Art. 18

You can ask us to limit how we use your data while a concern is being resolved.

📦 Right to Data Portability Art. 20

You can receive your data in a structured, machine-readable format and transfer it to another service.

Right to Object Art. 21

You can object to processing based on legitimate interest. We will stop unless we have compelling grounds.

↩️ Right to Withdraw Consent Art. 7(3)

Where we rely on consent, you can withdraw it anytime. This does not affect prior lawful processing.

🤖 Right Regarding Automated Decisions Art. 22

You have the right not to be subject to decisions based solely on automated processing that affect you significantly.

How to Exercise Your Rights

Send your request to privacy@aidometech.ai

We will respond within 30 days as required by GDPR. We may ask you to verify your identity before processing your request. All requests are free of charge unless manifestly unfounded or excessive.

How We Protect Your Data

Security is not an afterthought — it's our architecture

Encryption at Rest & in Transit

All data is encrypted using industry-standard protocols. TLS 1.3 for transit, AES-256 for storage. Database connections are encrypted end-to-end.

Tenant Isolation

PRISM enforces strict multi-tenant isolation. Each user's data is partitioned at the database, vector store, and storage level. No user can access another user's data.

Access Controls

Role-based access control (RBAC) ensures only authorized personnel can access infrastructure. All access is logged and auditable.

No Third-Party AI Processing

PRISM uses self-hosted, open-source language models. Your documents and conversations are never sent to OpenAI, Google, Anthropic, or any other external AI provider.

Supervisory Authority

AiDome Technologies OÜ is registered in Estonia. Our lead supervisory authority is:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Website: aki.ee
Email: info@aki.ee

Under Art. 77 GDPR, you also have the right to lodge a complaint with the data protection authority in your country of residence. For example, if you are based in Italy, you may contact the Garante per la protezione dei dati personali at garanteprivacy.it.

Privacy Is Our Foundation

Questions about how we handle your data? We're here to help. Transparency isn't just policy — it's how we build trust.

Contact Us

This privacy policy may be updated periodically to reflect changes in legislation or our data practices. We encourage you to review this page regularly. The "Last updated" date at the top indicates the most recent revision.