Legal

Privacy Policy

Effective Date: August 26, 2026 · Replaces the version of December 9, 2025

Privacy Policy

Effective Date: August 26, 2026

1. Who we are and what this notice covers

The AI CMO is operated by ROGA AI LIMITED, a company registered in Gibraltar under Company No. 125994, Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA ("we", "us", "our"). This notice explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it, and what your rights are.

The AI CMO is a business service: an AI marketing platform used by companies, agencies and marketing professionals. Being a business service does not mean no personal data is involved. We process the personal data of the people who use the platform, of the people who visit theaicmo.com, and – on behalf of our customers – of our customers' own customers, subscribers and website visitors. Section 2 explains which of those applies to you, because it changes who is responsible for what.

We process personal data under the General Data Protection Regulation as it applies in Gibraltar (the Gibraltar GDPR and the Data Protection Act 2004) and, where our customers or the people concerned are in the European Economic Area or the United Kingdom, under the EU GDPR and the UK GDPR. Using the Services is not, by itself, consent to anything: every purpose in this notice rests on a specific legal basis, set out in Section 4, and where that basis is consent it is asked for separately and can be withdrawn as easily as it was given.

2. Your data, or your customers' data: our role

2.1 You use The AI CMO (an account holder or a team member)

We are the controller of your account, billing, usage and support data. Sections 3–4 describe it.

2.2 You visit theaicmo.com

We are the controller of the data our own website collects: see Section 12 for cookies and analytics.

2.3 You are a customer, subscriber, website visitor or player of one of our customers

Our customers bring their own data into the platform – contact lists, purchase and behavioural events from their shops and websites, and the visitors of any website where they install our SDK. For that data the customer is the controller and we are its processor. We process it only on the customer's documented instructions, under our Data Processing Agreement (theaicmo.com/dpa), which sets out the subject matter, purposes, categories of data, security measures, sub-processors, assistance, audits and deletion. The Data Processing Agreement is expressly incorporated into this Privacy Policy and forms part of our agreement with every customer on whose behalf we process personal data; for personal-data processing it prevails over this notice. The customer's own privacy notice, its cookie or consent banner, and the way it installs and configures our SDK are the customer's responsibility; our responsibility is to describe honestly what the tools do (Sections 3.5, 5, 6 and 12) and to give the customer the controls and the assistance it needs to comply.

If you want to exercise your rights over data one of our customers holds about you, contact that customer. If you contact us instead, we will pass your request to the customer without undue delay and act on its instructions (Section 11.3).

3. Information we collect

3.1 Account and business information

  • Name, work e-mail address, password (stored only as a salted hash), phone number where you give it
  • Company name, industry, website, registration and VAT/tax identifiers, billing address
  • Payment details – handled by Stripe; we never receive or store full card numbers
  • Team membership, roles and seats within your organisation
  • Communications with us: enquiries, support conversations, feedback

3.2 Content you provide and content we generate

Briefs, prompts, brand profiles, uploaded files, connected data and the marketing content the platform produces (articles, e-mails, ads, strategies, reports). This content is yours. It may contain personal data of your own customers – a name in an e-mail, an order in an uploaded list – and where it does, we process that data as your processor (Section 2.3). Please do not put special-category data (health, beliefs, sexual orientation and the like) into the platform unless we have agreed to it in writing. We do not use your content to train AI models (Section 5).

3.3 Usage and technical information

  • Log data: IP address, browser type and version, time zone, the pages and features you use and when
  • Device information: device type, operating system, screen size
  • Service metering: credits consumed, generations run, messages sent, storage used
  • Performance and error data used to keep the Services running

3.4 Data from platforms you connect

When you connect a platform through OAuth, we access only the data the scopes you grant allow, for the purpose of the feature you connect it to. Typically: Google Analytics (traffic, behaviour and conversion data), Google Ads (campaigns, spend and performance), Meta, LinkedIn, X and YouTube (pages, posts, engagement, publishing), Mailchimp and other e-mail platforms (audiences and campaign statistics), Shopify and other shops (orders, products, customers), WordPress and other CMSs (publishing). Connection tokens are held for us, encrypted, by Nango or Pipedream; we never see or store your passwords for those platforms. You can disconnect any platform at any time from your Connections page or from the platform's own security settings, and disconnecting ends our access at once.

3.5 Website SDK data (collected on our customers' behalf)

A customer may install our SDK on its website. The SDK records page views, sessions, navigation paths, clicks, scroll depth, time on page, form interactions (not the values typed into forms), device and browser type, referrer and campaign source, and – when the customer's own systems tell it to – conversions, sign-ups and purchases. Each visitor is given a pseudonymous identifier stored in a first-party cookie or local storage. Until the customer identifies the visitor, the identifier is not linked to a name; once the customer's site calls the SDK's identify function (for example after a login), the identifier is linked to that customer's own customer identifier or e-mail address. Pseudonymous identifiers of this kind are personal data and we treat them as such: they are not anonymous.

For this data the customer is the controller and we are its processor (Section 2.3). The SDK ships with a consent mode in which nothing is loaded or recorded until the visitor has opted in through the customer's consent banner; the customer decides whether and how to obtain consent under the laws that apply to it, and configures the SDK accordingly. Behavioural data is processed by PostHog, in the EU or the United States as the customer chooses per site.

4. How we use it, and on what legal basis

Where we are the controller (Sections 2.1 and 2.2):

PurposeLegal basis
Providing the Services: your account, generating content, running the tools you use, connecting platforms, supportPerformance of our contract with you (Terms of Service)
Billing, invoicing, tax and accounting recordsContract; legal obligation
Keeping the Services secure: authentication, abuse and fraud prevention, logging, incident responseLegitimate interests (security and integrity of the Services); legal obligation
Understanding how the platform is used, fixing errors, improving features (aggregated product analytics)Legitimate interests (improving the Services); on theaicmo.com only with your cookie consent
Service notices: changes to the Services, this notice, security or billing mattersContract; legal obligation
Marketing communications about The AI CMOConsent, or legitimate interests for existing customers about similar services – with an unsubscribe in every message
Establishing, exercising or defending legal claims; complying with law and lawful requestsLegitimate interests; legal obligation

Where we are a processor (Section 2.3), we use the data for one purpose only: performing the Services the customer has configured, on its instructions. The legal basis for that processing is the customer's to establish; we do not process our customers' customers' data for our own purposes, and we do not sell personal data.

5. AI models and your content

To generate content the platform sends the relevant parts of your brief, brand profile and connected data to AI model providers – Anthropic, OpenAI and Google, routed through OpenRouter, and Replicate and OpenAI for images and video – and receives the output. The providers are our sub-processors (Section 7) and process the request only to produce the response.

  • What a request contains. Your brief, your brand profile, the connected campaign data the feature needs and the draft being written – not your customer records. Contact lists, event logs and the identifiers of your customers are never sent to a model provider. Two features send data about an individual without any identifier: the Customer 360 brief sends a person's purchase facts and the attributes you stored (never the e-mail, name or identifiers) to summarise them, and support classification sends the text of a support message to read its tone.
  • No training on your data. We do not use your content, your customers' data or the outputs generated for you to train or fine-tune AI models, ours or anyone else's. Our model providers are engaged under API terms that exclude the use of submitted content for training, and our OpenRouter account is configured to route only to providers that do not retain or train on inputs. The only exception is a customer that expressly agrees, in writing, to a training or fine-tuning arrangement on its own data.
  • Retention at providers. Providers may hold requests briefly for abuse monitoring under their API terms, typically for no more than 30 days, and then delete them. Customers on enterprise terms can require zero-retention routing.
  • Choice of model and region. The model used for a given feature is set by us and listed in our documentation. Customers on enterprise terms can fix the provider, the model and the processing region for their account in the Data Processing Agreement.
  • Outputs are yours. Generated content belongs to you under the Terms of Service; we store it in your account so you can use, edit and publish it.

6. Automated decisions, profiling and human oversight

The AI CMO does not make decisions about individuals that produce legal effects or similarly significant effects. It does something narrower: on a customer's instructions it groups a customer's contacts and visitors into segments, scores them (for example "likely to buy again"), and personalises marketing messages and website content for them. That is profiling in the GDPR sense, and it is the customer's processing, carried out by us as processor.

  • The customer decides what runs on its own. Every automated action – a send, a change to a campaign, a personalised page – runs under the approval rules the customer configures. A customer can require that a named person approves each action before it reaches anyone, and customers in regulated sectors are expected to.
  • Consent and suppression are enforced at send time. Marketing consent is recorded per person and per channel in a ledger; suppression lists, unsubscribes and self-exclusion lists supplied by the customer are checked on every send path, so a person who has opted out or excluded themselves is not contacted.
  • Special categories and vulnerable people. The platform does not infer special-category data and must not be instructed to. Customers whose marketing is subject to sector rules – gambling, financial services, health – remain responsible for the lawful basis of any profiling-based personalisation, including explicit consent where the law requires it, and for the assessments (such as a data protection impact assessment) that such processing calls for. We provide the information and assistance those assessments need.

7. How we share information; sub-processors

We do not sell, rent or trade personal data. We share it with the service providers below, which act on our instructions as sub-processors; with a platform you have chosen to connect; where the law requires it; and in a merger, acquisition or sale of assets, in which case we notify you before your data is transferred. Other than that, and other than what you publish or send through the platform yourself, we do not share your data or your customers' data with anyone.

7.1 Sub-processor register

The register is arranged by what each provider actually touches. Only the providers in group A hold or handle the customer data you load into the platform.

A. Hold or handle the customer data you load into the platform

Contacts, events, website visitors, players, and the messages sent to them. These are the sub-processors of Customer Personal Data in the sense of the Data Processing Agreement.

ProviderPurposeLocation of processing
SupabaseDatabase, authentication and file storage – contacts, consent and suppression records, journeys, generated contentEU (Stockholm, eu-north-1)
ClickHouse CloudAnalytics warehouse for event data, provisioned per customerEU or United States, per customer (dedicated EU cluster on enterprise terms)
PostHogBehavioural analytics for websites where the SDK is installed (visitor identifiers, page and interaction events)EU or United States, chosen per site
ResendE-mail delivery: recipient address and message content, only for the e-mails you sendUnited States

B. Infrastructure the application runs on

The application's code runs here and data passes through it encrypted; these providers have no standing access to customer data and hold none at rest.

ProviderPurposeLocation of processing
RailwayApplication servers (API, scheduled jobs)United States / EU
VercelWeb application hosting and content deliveryUnited States, global edge network
CloudflareContent delivery, DDoS protection; object storage for generated images and files (no customer records)Global

C. AI model providers – receive generation requests, not customer records

A request carries what a generation needs: your brief, brand profile, connected campaign data and the draft being written. Contact lists, event logs and identifiers are never sent (Section 5).

ProviderPurposeLocation of processing
OpenRouterRoutes requests to the model providers below; account configured to exclude providers that retain or train on inputsUnited States
AnthropicText generation (Claude models)United States
OpenAIText and image generation (GPT models)United States
GoogleText and image generation (Gemini models)United States / EU
ReplicateImage and video generationUnited States

D. Our own operations – your account, not your customers' data

Providers we use to run The AI CMO as a business. They see account holders' data, never the data you load about your customers.

ProviderPurposeLocation of processing
StripePayments, invoicing and subscription billingUnited States / EU
ResendService e-mail to account holders (sign-in, notices, digests)United States
PostHogProduct analytics for the application itself (which features are used)United States / EU
NangoOAuth connection broker and encrypted token storage for platforms you connectUnited States
PipedreamOAuth connection broker for selected platforms (tokens proxied server-side)United States
Google, Meta, LinkedIn, X, YouTube, Shopify, Mailchimp, WordPress and othersOnly when you authorise a connection: reading and publishing on your behalf within the scopes you grant – under your own account with themPer platform

Channels you run through your own provider account – SMS, WhatsApp, push, or an e-mail platform you connect – are your processors, not ours; the platform hands them the message and the recipient under your credentials.

Each sub-processor is bound by a written agreement imposing data-protection obligations equivalent to ours, and we check their security assurance (SOC 2 Type II or equivalent) before and during use. This register is the current one; when we add or replace a sub-processor we update it here, and customers under a Data Processing Agreement are notified in advance and may object as that agreement provides. The certifications each provider holds are listed on our Security page.

8. International data transfers

We are established in Gibraltar. The application database and authentication run in the European Union (Stockholm). Several sub-processors, including the AI model providers, process data in the United States. Where personal data originating in the EEA, the United Kingdom or Gibraltar is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant) or, for recipients certified under the EU–US Data Privacy Framework, on that certification, together with the supplementary measures described in Section 10. Copies of the transfer mechanisms in use are available to customers on request.

9. How long we keep information

InformationRetention
Account, profile and team dataWhile the account is active; deleted within 30 days of account deletion or a verified deletion request
Content you provide and content generated for youWhile the account is active; deleted within 30 days of termination, unless you export or ask us to return it first
Customer data processed as processor (contacts, events, SDK data)For the term of the customer's agreement and the retention the customer configures; on termination, returned or deleted at the customer's choice within 30 days; purged automatically once a subscription has lapsed for 30 days
Consent, unsubscribe and suppression recordsKept as evidence for as long as the underlying obligation exists – a suppression stays in force so the person stays excluded
Connection tokens for platforms you connectUntil you disconnect the platform or delete your account; removed from the token store within 48 hours
AI requests at model providersNot retained by us beyond the output stored in your account; at providers, at most 30 days for abuse monitoring, or zero retention on enterprise terms
Server, access and security logsUp to 90 days
BackupsEncrypted; deleted data ages out of backups within 90 days
Billing and tax recordsAs long as tax and accounting law requires (typically 7 years)

Details of the deletion process, what may be retained under a legal obligation, and how to make a request are on our Data Deletion Request page.

10. How we protect information

We operate a security programme under SOC 2 Type II and GDPR-aligned policies covering information security, access control, encryption, vendor management, incident response, business continuity and data retention. The measures that matter most to you:

  • Encryption: TLS 1.2 or higher for all data in transit; AES-256 encryption at rest for databases, the analytics warehouse, file storage and backups.
  • Tenant isolation: every customer's data is separated at the database level by row-level security policies; the analytics warehouse is provisioned per customer.
  • Access control: role-based access within your organisation; least-privilege, multi-factor-protected access for our staff; access reviewed quarterly and logged.
  • Secure development: code review, dependency and vulnerability scanning, and penetration testing for major releases and at least annually.
  • Resilience: encrypted backups with restore tests; a maintained business continuity plan.
  • Incident response: a documented process; where a personal data breach affects a customer's data we notify that customer without undue delay so it can meet its own 72-hour notification duty, and we notify the Gibraltar Regulatory Authority where the breach concerns data we control.
  • Vendors: critical providers must hold a current SOC 2 Type II report or equivalent, reviewed annually.

Our Trust Center, with the status of the SOC 2 Type II examination and the policies in force, is at trust.inc/roga-ai-limited. A fuller description of the technical and organisational measures is Annex II of the Data Processing Agreement. No method of transmission or storage is perfectly secure; if you believe your account has been compromised, contact us at once.

11. Your rights

11.1 What you can ask

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy
  • Rectify inaccurate or incomplete data
  • Erase your data where there is no longer a reason for us to keep it
  • Restrict processing while a question about it is resolved
  • Port the data you gave us to another provider in a machine-readable form
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent at any time where consent is the basis, without affecting processing before the withdrawal
  • Complain to a supervisory authority: the Gibraltar Regulatory Authority (gra.gi), or the authority of the EEA country or the UK where you live or work

11.2 How to ask

Write to privacy@theaicmo.com. We may need to verify your identity. We answer within one month; for complex requests we may extend by up to two further months and will tell you why. Requests are free unless clearly unfounded or excessive.

11.3 If you are a customer of one of our customers

The customer is the controller of your data and the one to answer your request. If you write to us, we forward your request to the customer without undue delay, do not act on it without the customer's instruction unless the law requires us to, and give the customer the technical help it needs – exports, deletion, restriction, and an explanation of any profiling – so that it can answer you within the legal time limit.

12. Cookies, the website SDK and consent

12.1 On theaicmo.com

Our website uses strictly necessary cookies and storage (sign-in, security, your settings, your consent choice) without asking, because the site cannot work without them. Analytics (Google Analytics, PostHog, our own visit measurement) and marketing (Google Ads conversion measurement) are off by default: nothing from those groups loads, and none of their cookies is set, until you turn them on in the cookie banner. "Accept all" and "Reject non-essential" are offered side by side, one click each, with per-category choices one click further. You can change or withdraw your choice at any time through Cookie settings in the footer; withdrawing switches the trackers off and removes their cookies. Your choice is stored with its scope, time, policy version and a consent identifier, and each grant, change and withdrawal is recorded on our side so we can show it was made. The full inventory – every cookie and storage item, its purpose, duration and recipient – is the Cookie Policy.

12.2 Inside the application

The application is a signed-in service and no banner is shown inside it. It uses cookies and local storage that are strictly necessary to keep you signed in and to remember your settings. Our own first-party measurement of how the application is used – which features are used and where they fail, tied to your account, never shared – and Vercel's cookieless page-view analytics run under our legitimate interest in running and improving the Services; you can object at any time by writing to privacy@theaicmo.com. Google tags, PostHog and our website SDK are never switched on by signing in: they run only with a consent you gave in the banner on our public pages, and stay off otherwise.

12.3 On our customers' websites

When a customer installs our SDK on its website, the identifiers and behavioural data described in Section 3.5 are collected for that customer. The consent banner on that site, the categories it offers and the record of the visitor's choice are the customer's; the SDK's consent mode holds all collection until the customer's banner reports consent, and its opt-out call stops it again. A customer that links the SDK's visitor identifier to a logged-in account, or uses it for direct marketing, does so under its own notice and lawful basis.

13. Children

The Services are for businesses and professionals and may not be used by anyone under 18. We do not knowingly collect personal data from children; if we learn that we have, we delete it. Our customers are responsible for the age rules that apply to their own audiences.

14. Changes to this notice

We update this notice when our practices, the law or our sub-processors change. Each version is dated at the top and archived, so you can see what applied at any time. For material changes – a new purpose, a new category of data, a new sub-processor for customer data – we notify account owners by e-mail before the change takes effect and, for customers under a Data Processing Agreement, as that agreement provides.

15. Contact

ROGA AI LIMITED

Registered in Gibraltar, Company No. 125994

Unit G02, Eurocity, Europort Avenue

Gibraltar GX11 1AA

Privacy requests: privacy@theaicmo.com

Data Protection Officer: dpo@theaicmo.com

Security: security@theaicmo.com

Customers who need a signed Data Processing Agreement, the sub-processor notification list, or copies of transfer mechanisms: write to privacy@theaicmo.com.