Privacy Policy
Last Updated: December 20, 2025
AEOH.ai ("we," "us," or "our") respects your privacy and is committed to protecting the personal data we process. This Privacy Policy explains how we collect, use, and protect your information when you use our AI Engine Optimization analytics platform.
1. WHO WE ARE (DATA CONTROLLER)
For the purpose of the General Data Protection Regulation (GDPR), the Data Controller is:
2. WHAT DATA WE COLLECT
We collect minimal data necessary to provide our Service:
A. Input Data (Report Requests)
Data you provide when requesting a Report:
- Location: The geographic location you specify (e.g., "Warsaw, Poland")
- Industry: The business category you're researching (e.g., "Law Firms")
B. Payment Data
Transaction information processed via Stripe:
- Payment confirmation and transaction ID
- Billing email (if provided to Stripe)
- Note: We do not store credit card numbers—Stripe handles all payment data securely.
C. Technical Data
Automatically collected when you visit our website:
- IP address (for security and rate limiting)
- Browser type and device information
- Pages visited and timestamps
3. PUBLIC BUSINESS DATA
Our Reports contain information about businesses that is publicly available on the internet. This includes:
- Business names and addresses
- Website URLs
- Public reviews and ratings
- Information cited by AI models from public sources
We do not collect personal data about individual consumers. We aggregate publicly available business data as recommended by third-party AI systems.
4. HOW WE USE YOUR DATA
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Generate your Report | Location, Industry | Performance of Contract |
| Process payment | Payment Data (via Stripe) | Performance of Contract |
| Prevent fraud and abuse | IP Address, Technical Data | Legitimate Interest |
| Improve the Service | Aggregated usage patterns | Legitimate Interest |
5. AGGREGATED DATA USAGE
We may use anonymized, aggregated data from Reports to:
- Create market research and industry benchmarks
- Publish trend analyses (e.g., "Most popular search keywords in Warsaw")
- Improve our AI query methodology
- Develop new features and services
This aggregated data does not identify you personally or reveal the specific Reports you purchased.
6. THIRD-PARTY PROCESSORS
We share data with trusted third-party service providers to operate our Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Payment information |
| OpenAI | AI content generation | Search queries (Location + Industry) |
| Vercel | Website hosting | Technical data, IP addresses |
| Supabase | Database hosting | Report data, transactions |
All processors have appropriate data protection agreements in place.
7. DATA WE DO NOT COLLECT
For clarity, we do not collect:
- User accounts or login credentials (no account required)
- Personal names or contact information (unless voluntarily provided)
- Sensitive personal data (health, religion, political views, etc.)
- Data about individual consumers of the businesses in Reports
8. COOKIES
We use minimal cookies for:
- Essential: Maintaining your session during Report generation
- Functional: Remembering your preferences (language, etc.)
We do not use advertising or tracking cookies. You can block cookies in your browser settings.
9. DATA RETENTION
- Report Data: Stored indefinitely to allow you to access your purchased Reports
- Payment Records: Retained for 6 years (Polish tax law requirement)
- Technical Logs: Retained for 30 days for security purposes
10. YOUR RIGHTS (GDPR)
Under the GDPR, you have the right to:
- Request access to your personal data
- Request correction of inaccurate data
- Request erasure of your data ("Right to be forgotten")
- Object to processing of your data
- Request data portability
- Lodge a complaint with a supervisory authority
To exercise these rights, email us at privacy@aeoh.ai.
11. SECURITY
We implement industry-standard security measures:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest (database encryption)
- Secure payment processing via Stripe (PCI compliant)
- Regular security monitoring
12. INTERNATIONAL TRANSFERS
Some of our service providers are located outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
13. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this page periodically.
Contact Information
For privacy-related inquiries: