Legal
Effective Date: August 26, 2026 · Replaces the version of December 9, 2025
Effective Date: August 26, 2026
Table of Contents
The AI CMO is operated by ROGA AI LIMITED, a company registered in Gibraltar under Company No. 125994, Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA ("we", "us", "our"). This notice explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it, and what your rights are.
The AI CMO is a business service: an AI marketing platform used by companies, agencies and marketing professionals. Being a business service does not mean no personal data is involved. We process the personal data of the people who use the platform, of the people who visit theaicmo.com, and – on behalf of our customers – of our customers' own customers, subscribers and website visitors. Section 2 explains which of those applies to you, because it changes who is responsible for what.
We process personal data under the General Data Protection Regulation as it applies in Gibraltar (the Gibraltar GDPR and the Data Protection Act 2004) and, where our customers or the people concerned are in the European Economic Area or the United Kingdom, under the EU GDPR and the UK GDPR. Using the Services is not, by itself, consent to anything: every purpose in this notice rests on a specific legal basis, set out in Section 4, and where that basis is consent it is asked for separately and can be withdrawn as easily as it was given.
We are the controller of your account, billing, usage and support data. Sections 3–4 describe it.
We are the controller of the data our own website collects: see Section 12 for cookies and analytics.
Our customers bring their own data into the platform – contact lists, purchase and behavioural events from their shops and websites, and the visitors of any website where they install our SDK. For that data the customer is the controller and we are its processor. We process it only on the customer's documented instructions, under our Data Processing Agreement (theaicmo.com/dpa), which sets out the subject matter, purposes, categories of data, security measures, sub-processors, assistance, audits and deletion. The Data Processing Agreement is expressly incorporated into this Privacy Policy and forms part of our agreement with every customer on whose behalf we process personal data; for personal-data processing it prevails over this notice. The customer's own privacy notice, its cookie or consent banner, and the way it installs and configures our SDK are the customer's responsibility; our responsibility is to describe honestly what the tools do (Sections 3.5, 5, 6 and 12) and to give the customer the controls and the assistance it needs to comply.
If you want to exercise your rights over data one of our customers holds about you, contact that customer. If you contact us instead, we will pass your request to the customer without undue delay and act on its instructions (Section 11.3).
Briefs, prompts, brand profiles, uploaded files, connected data and the marketing content the platform produces (articles, e-mails, ads, strategies, reports). This content is yours. It may contain personal data of your own customers – a name in an e-mail, an order in an uploaded list – and where it does, we process that data as your processor (Section 2.3). Please do not put special-category data (health, beliefs, sexual orientation and the like) into the platform unless we have agreed to it in writing. We do not use your content to train AI models (Section 5).
When you connect a platform through OAuth, we access only the data the scopes you grant allow, for the purpose of the feature you connect it to. Typically: Google Analytics (traffic, behaviour and conversion data), Google Ads (campaigns, spend and performance), Meta, LinkedIn, X and YouTube (pages, posts, engagement, publishing), Mailchimp and other e-mail platforms (audiences and campaign statistics), Shopify and other shops (orders, products, customers), WordPress and other CMSs (publishing). Connection tokens are held for us, encrypted, by Nango or Pipedream; we never see or store your passwords for those platforms. You can disconnect any platform at any time from your Connections page or from the platform's own security settings, and disconnecting ends our access at once.
A customer may install our SDK on its website. The SDK records page views, sessions, navigation paths, clicks, scroll depth, time on page, form interactions (not the values typed into forms), device and browser type, referrer and campaign source, and – when the customer's own systems tell it to – conversions, sign-ups and purchases. Each visitor is given a pseudonymous identifier stored in a first-party cookie or local storage. Until the customer identifies the visitor, the identifier is not linked to a name; once the customer's site calls the SDK's identify function (for example after a login), the identifier is linked to that customer's own customer identifier or e-mail address. Pseudonymous identifiers of this kind are personal data and we treat them as such: they are not anonymous.
For this data the customer is the controller and we are its processor (Section 2.3). The SDK ships with a consent mode in which nothing is loaded or recorded until the visitor has opted in through the customer's consent banner; the customer decides whether and how to obtain consent under the laws that apply to it, and configures the SDK accordingly. Behavioural data is processed by PostHog, in the EU or the United States as the customer chooses per site.
Where we are the controller (Sections 2.1 and 2.2):
| Purpose | Legal basis |
|---|---|
| Providing the Services: your account, generating content, running the tools you use, connecting platforms, support | Performance of our contract with you (Terms of Service) |
| Billing, invoicing, tax and accounting records | Contract; legal obligation |
| Keeping the Services secure: authentication, abuse and fraud prevention, logging, incident response | Legitimate interests (security and integrity of the Services); legal obligation |
| Understanding how the platform is used, fixing errors, improving features (aggregated product analytics) | Legitimate interests (improving the Services); on theaicmo.com only with your cookie consent |
| Service notices: changes to the Services, this notice, security or billing matters | Contract; legal obligation |
| Marketing communications about The AI CMO | Consent, or legitimate interests for existing customers about similar services – with an unsubscribe in every message |
| Establishing, exercising or defending legal claims; complying with law and lawful requests | Legitimate interests; legal obligation |
Where we are a processor (Section 2.3), we use the data for one purpose only: performing the Services the customer has configured, on its instructions. The legal basis for that processing is the customer's to establish; we do not process our customers' customers' data for our own purposes, and we do not sell personal data.
To generate content the platform sends the relevant parts of your brief, brand profile and connected data to AI model providers – Anthropic, OpenAI and Google, routed through OpenRouter, and Replicate and OpenAI for images and video – and receives the output. The providers are our sub-processors (Section 7) and process the request only to produce the response.
The AI CMO does not make decisions about individuals that produce legal effects or similarly significant effects. It does something narrower: on a customer's instructions it groups a customer's contacts and visitors into segments, scores them (for example "likely to buy again"), and personalises marketing messages and website content for them. That is profiling in the GDPR sense, and it is the customer's processing, carried out by us as processor.
We are established in Gibraltar. The application database and authentication run in the European Union (Stockholm). Several sub-processors, including the AI model providers, process data in the United States. Where personal data originating in the EEA, the United Kingdom or Gibraltar is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant) or, for recipients certified under the EU–US Data Privacy Framework, on that certification, together with the supplementary measures described in Section 10. Copies of the transfer mechanisms in use are available to customers on request.
| Information | Retention |
|---|---|
| Account, profile and team data | While the account is active; deleted within 30 days of account deletion or a verified deletion request |
| Content you provide and content generated for you | While the account is active; deleted within 30 days of termination, unless you export or ask us to return it first |
| Customer data processed as processor (contacts, events, SDK data) | For the term of the customer's agreement and the retention the customer configures; on termination, returned or deleted at the customer's choice within 30 days; purged automatically once a subscription has lapsed for 30 days |
| Consent, unsubscribe and suppression records | Kept as evidence for as long as the underlying obligation exists – a suppression stays in force so the person stays excluded |
| Connection tokens for platforms you connect | Until you disconnect the platform or delete your account; removed from the token store within 48 hours |
| AI requests at model providers | Not retained by us beyond the output stored in your account; at providers, at most 30 days for abuse monitoring, or zero retention on enterprise terms |
| Server, access and security logs | Up to 90 days |
| Backups | Encrypted; deleted data ages out of backups within 90 days |
| Billing and tax records | As long as tax and accounting law requires (typically 7 years) |
Details of the deletion process, what may be retained under a legal obligation, and how to make a request are on our Data Deletion Request page.
We operate a security programme under SOC 2 Type II and GDPR-aligned policies covering information security, access control, encryption, vendor management, incident response, business continuity and data retention. The measures that matter most to you:
Our Trust Center, with the status of the SOC 2 Type II examination and the policies in force, is at trust.inc/roga-ai-limited. A fuller description of the technical and organisational measures is Annex II of the Data Processing Agreement. No method of transmission or storage is perfectly secure; if you believe your account has been compromised, contact us at once.
Under the GDPR you have the right to:
Write to privacy@theaicmo.com. We may need to verify your identity. We answer within one month; for complex requests we may extend by up to two further months and will tell you why. Requests are free unless clearly unfounded or excessive.
The customer is the controller of your data and the one to answer your request. If you write to us, we forward your request to the customer without undue delay, do not act on it without the customer's instruction unless the law requires us to, and give the customer the technical help it needs – exports, deletion, restriction, and an explanation of any profiling – so that it can answer you within the legal time limit.
The Services are for businesses and professionals and may not be used by anyone under 18. We do not knowingly collect personal data from children; if we learn that we have, we delete it. Our customers are responsible for the age rules that apply to their own audiences.
We update this notice when our practices, the law or our sub-processors change. Each version is dated at the top and archived, so you can see what applied at any time. For material changes – a new purpose, a new category of data, a new sub-processor for customer data – we notify account owners by e-mail before the change takes effect and, for customers under a Data Processing Agreement, as that agreement provides.
ROGA AI LIMITED
Registered in Gibraltar, Company No. 125994
Unit G02, Eurocity, Europort Avenue
Gibraltar GX11 1AA
Privacy requests: privacy@theaicmo.com
Data Protection Officer: dpo@theaicmo.com
Security: security@theaicmo.com
Customers who need a signed Data Processing Agreement, the sub-processor notification list, or copies of transfer mechanisms: write to privacy@theaicmo.com.