Privacy Policy

Last updated: 2 July 2026 · Factual corrections: 1 August 2026

At a glance

  • Controller: Alethe s.r.o., Sládkova 1728/17, 360 01 Karlovy Vary, Czech Republic, IČO 09531025, registered in the Commercial Register kept by the Regional Court in Plzeň, Section C, Insert 39786
  • Contact: info@alethe.eu
  • Data Protection Officer (DPO): Not appointed — we do not meet the Art. 37 GDPR thresholds (we do not engage in large-scale systematic monitoring or large-scale processing of special-category data). Privacy queries: info@alethe.eu.
  • Main purpose of processing: Operate the Alethe AI agent platform (app.alethe.eu) and deliver AI automation services to business clients under contract.
  • Supervisory authority for complaints: Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, https://uoou.gov.cz

1. Who we are

Alethe s.r.o. (referred to as "we", "us", "our") operates the Alethe AI agent platform at app.alethe.eu and the public website at alethe.eu. We are the data controller for personal data processed via these properties. Our registered office is Sládkova 1728/17, 360 01 Karlovy Vary, Czech Republic. You can contact us at info@alethe.eu.

This Privacy Policy covers data we process as Controller — visitors to our marketing site, users we contact directly, and the admin / billing accounts our business customers use to log into Alethe. Personal data we process as Processor on behalf of a business customer (their leads, their customers, their members, their employees handled through Alethe) is governed by our Data Processing Agreement (DPA) — see Section 13 below.

2. What data we collect

CategoryExamplesSource
Account dataemail, name, hashed password, organisation nameYou provide at signup
Usage datapages visited, features used, agent turns, API calls, timestampsAutomatic via logs / activity bus
Billing dataname, billing address, VAT ID, last 4 digits of cardYou provide at checkout; full card data held by Stripe
Communication datamessages you send via support, sales emails, chat with our marketing assistantYou provide
Device & technical dataIP address (truncated for analytics), browser, OS, device typeAutomatic
AI interaction contentprompts you send to AI agents, AI responses returned to you, attached filesYou / your end-users provide (see DPA for B2B end-user data)
Integration credentials (encrypted)API keys you configure for connected services (Stripe, Meta, Shopify, etc.)You provide; encrypted at rest with AES-256-GCM

We do not intentionally collect special-category data (Art. 9 GDPR — health, biometric, political opinion, religion, ethnic origin, etc.). If you submit such data via free-text fields or AI chats, we treat it under heightened security but do not solicit it.

3. Why we process it (purposes + legal basis)

PurposeLegal basis (Art. 6 GDPR)Notes
Provide the Alethe platformContract (Art. 6(1)(b))Without this data we cannot deliver the service
Billing & paymentContract + legal obligation (CZ tax law)10-year retention for invoices
Service security, abuse detection, fraud preventionLegitimate interest (Art. 6(1)(f))Balancing test on file; contact us for details
Product analyticsConsent (Art. 6(1)(a))Only with cookie consent; opt-out anytime
Marketing pixel (advertising measurement/audiences)Consent (Art. 6(1)(a))Meta Pixel on the marketing site alethe.eu only; loaded only after Marketing consent — see Section 12
Marketing emailsConsent (Art. 6(1)(a))Only if you opted in; unsubscribe in every email
AI features (chat with AI agents, content generation)Contract (Art. 6(1)(b)) for core features; Consent for optional analytics on AI usageSee AI Transparency Notice
Legal compliance (subpoena, tax)Legal obligation (Art. 6(1)(c))

4. How long we keep it (retention)

Data categoryRetentionReason
Account dataDuration of account + 30 days after deletionAccount recovery + dispute window
Billing records / invoices10 yearsCzech accounting and VAT law
Server logs30 daysSecurity + debugging
Backups30 days rollingDisaster recovery
Support communications3 yearsService quality + dispute resolution
AI conversation historyDefault: lifetime of the chat / configurable per organisation. B2B customers can delete chats anytime.
Cached third-party contact data90 daysBounded staleness + GDPR-friendly cap (internal data-protection assessment; summary available on request)
Analytics data (Google Analytics 4, marketing site only)Up to 14 monthsGA4 retention setting; collected only with Analytics consent
Marketing pixel cookies (Meta Pixel _fbp / _fbc, marketing site only)Up to ~90 days (cookie lifetime) / consent-boundCollected only with Marketing consent; stops when consent withdrawn
Marketing listUntil you unsubscribe

When the retention period ends we delete or anonymise the data.

5. Who we share it with (recipients + subprocessors)

We share personal data only with:

  • Subprocessors acting on our instructions — full list with country of processing on our Subprocessors page
  • Authorities when legally required (court order, regulator request) — we will notify you unless legally prohibited
  • Analytics (marketing site alethe.eu only, consent-gated): Google LLC — Google Analytics 4 (United States; DPF + 2021 SCCs; loaded only after you give Analytics consent)
  • Marketing pixel (marketing site alethe.eu only, consent-gated): Meta Platforms Ireland Ltd. and Meta Platforms, Inc. — Meta Pixel, loaded only after you give Marketing consent. For the pixel's collection and transmission of your data on alethe.eu, we and Meta act as joint controllers (CJEU C-40/17 Fashion ID); Meta's privacy policy: https://www.facebook.com/privacy/policy/
  • No data brokers under any circumstances; other than the consent-gated Meta Pixel on the marketing site, no advertising networks — app.alethe.eu shares data with no advertising or analytics tracker

Top-line subprocessor categories (full list on our Subprocessors page):

  • Hosting: Hostinger (EEA datacenter)
  • Payments: Stripe Payments Europe Ltd (Ireland) + Stripe Inc. (US, DPF + 2021 SCCs)
  • AI model providers: OpenRouter, OpenAI, Anthropic, Google (Gemini), Groq, Perplexity (all US — 2021 SCCs)
  • Media generation: fal.ai — including models fal forwards to a further third-party host — and, on direct APIs, Google (Imagen), OpenAI (image endpoints), Black Forest Labs and Ideogram
  • Research and scraping: Brave Search, Serper, Apify, Jina AI, Zyte, Linkup, YouTube
  • Code execution (only when an agent runs code): E2B
  • Error tracking: a self-hosted, Sentry-protocol-compatible endpoint on our own VPS (not a third-party subprocessor); Telegram for internal ops alerts when a superadmin enables it
  • Integrations (only if you enable them): Meta (Facebook/Instagram), Shopify, Slack, Google Workspace, Apollo, Hunter, AliExpress

We require a Data Processing Agreement meeting Art. 28(3) GDPR to be in place with a subprocessor before it receives personal data from the platform. Data processing agreements are in place with subprocessors across that list, and we are working through the remainder. We publish the status per subprocessor rather than as a single blanket claim: rows on our Subprocessors page marked ⚠ DPA gap have no Art. 28 agreement in place yet and are fenced to non-personal-data use until one is executed. That page is updated as each agreement is executed.

6. International transfers

Where we transfer personal data outside the EEA we rely on:

  • Adequacy decisions of the European Commission (currently includes UK, Switzerland, Canada commercial, Japan, Israel, NZ, S. Korea, Uruguay, and others — see the Commission's adequacy-decisions list).
  • EU-US Data Privacy Framework (DPF) for transfers to DPF-certified US recipients (verify active status at https://www.dataprivacyframework.gov).
  • 2021 Standard Contractual Clauses (SCCs) signed with the recipient otherwise, with parallel SCCs maintained as fallback for DPF-certified recipients pending Schrems III resolution.

For each non-EEA transfer we conduct a Transfer Impact Assessment documenting destination country law and supplementary measures (encryption, EU-held keys where applicable).

7. Your rights under GDPR

You have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure ("right to be forgotten") (Art. 17)
  • Restriction of processing (Art. 18)
  • Portability of data to another controller (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time, where consent is the basis (Art. 7(3))
  • Not be subject to automated decision-making producing legal effects (Art. 22)

To exercise any right, email info@alethe.eu. We respond within 30 days (extendable by 60 days for complex requests, with notice).

8. Automated decision-making

We do not use automated decision-making producing legal or similarly significant effects on you within the meaning of Art. 22 GDPR. AI agents on the platform produce outputs based on your instructions, but the decision to act on those outputs is taken by you or your authorised users, not by the AI.

If we ever introduce a feature that would constitute Art. 22 decision-making (e.g. automated account suspension based on risk scoring with legal effect), we will update this section and offer a human-review right.

9. Cookies

See our separate Cookie Policy for details on cookies and similar technologies.

10. AI features

This service includes AI-powered features (chat with agents, content generation, classification, recommendations). For full details on what the AI does, your role in interactions with it, how AI-generated content is marked, and our role under the EU AI Act (we are a deployer of third-party models, not a provider), see our separate AI Transparency Notice.

We do not use your conversations or content to train shared AI models. That is our promise about what Alethe does.

It is not a promise we can make for every provider. Where an AI provider offers an API-tier training opt-out we apply it (OpenAI, Anthropic and Google default to opt-out for API customers). We do not hold a negotiated no-training commitment with every provider — in particular, our media-generation supplier's no-training commitment engages only under an enterprise contract we do not currently hold, and its self-serve terms permit use of anonymised or aggregated derivatives. We will not agree to a provider using your content in identifiable form to train, and we name the providers on our Subprocessors page.

11. B2B customer data — controller vs processor

Alethe is a two-shape data processor:

  • (a) Data we process as Controller: your admin account, your billing, our direct relationship with you. This Privacy Policy governs that data.
  • (b) Data we process as Processor on behalf of B2B customers: the leads, contacts, customers, members, or employees that our business customers bring into the platform to work with via AI agents — including personal data your agents acquire via in-platform data-acquisition tools (web scraping, contact lookup). For all of it you are the Controller: you remain responsible for the lawful basis and for informing the people concerned (GDPR Art. 14) — see the Acceptable Use Policy §6A. That processing is governed by our Data Processing Agreement (DPA) — see Section 13.

If you are an end-user (member, customer, lead) whose data was loaded into Alethe by one of our business customers, that customer is the Controller of your data. Contact that organisation first for any GDPR request. We will assist them — and you — but the primary controller relationship is with them.

11a. Meta Platform Data (connected Facebook, Instagram & Threads accounts)

When you connect your Facebook Page, Instagram professional account, Threads profile, or Meta Ads account to Alethe, we receive data from Meta's APIs ("Platform Data") strictly to operate the service for you:

  • What we receive: page/profile metadata, the content you publish or schedule through Alethe, comments on your posts and ads, your ad account structure (campaigns, ad sets, ads, audiences), and performance insights.
  • Why we process it: solely to provide the features you use — planning and publishing content, creating and managing your ad campaigns, reading your insights, and moderating comments — on your instruction and for your own accounts.
  • How it is protected: access tokens are encrypted at rest (AES-256-GCM), scoped to your organisation with row-level isolation, and used only for the assets you connected.
  • What we never do: we do not sell Platform Data, do not share it with third parties beyond the subprocessors needed to run the service (Section 5), do not use it for our own advertising, and do not build profiles unrelated to the service you requested.
  • Deletion: disconnect the integration in the app, remove the Alethe app in your Facebook settings (this triggers Meta's signed data-deletion callback to us), or email us — full steps in the Data Deletion Instructions. Access tokens are deactivated and cryptographically erased immediately.
  • Roles: for Platform Data relating to your connected accounts we act as your processor (Section 11(b)); you remain the controller of your pages, ads and audiences.

12. Marketing site and contact forms

The public marketing site at alethe.eu collects:

  • Contact form submissions (name, email, message) — kept until the conversation closes + 12 months
  • Newsletter signups (email, consent timestamp) — kept until you unsubscribe
  • Google Analytics 4 (Google LLC, United States; DPF + 2021 SCCs) — with your prior Analytics consent only; IP anonymisation enabled; analytics data retained up to 14 months
  • Meta Pixel (Meta Platforms Ireland Ltd. and Meta Platforms, Inc.) — with your prior Marketing consent only; cookies _fbp / _fbc (~90 days). For the pixel's data collection on alethe.eu, we and Meta are joint controllers for the collection and transmission stage (CJEU C-40/17 Fashion ID); Meta's own processing is governed by its privacy policy: https://www.facebook.com/privacy/policy/

app.alethe.eu (the platform) sets no analytics or marketing trackers.

You can unsubscribe from any marketing email via the link in the footer or by emailing info@alethe.eu.

13. Business customer DPA

If you are a B2B customer onboarding to Alethe, that processing is governed by our Data Processing Agreement (provided at onboarding; request a copy at info@alethe.eu). It is offered pre-signed.

14. Complaints

You can lodge a complaint with your local supervisory authority. Ours (for the Czech operating entity) is:

If you live in another EU member state, you can also complain to your local DPA.

15. Changes to this policy

We update this policy when our processing changes. Material changes are notified by email to active account holders at least 30 days before they take effect. The "Last updated" date at the top of this document always reflects the current version.