Privacy
What we collect, and what we don't.
This site sets no cookies and runs no analytics. The only personal data we hold is what you send us when you get in touch.
- 1. Who we are
- 2. What we collect and why
- 3. Cookies and tracking
- 4. Who else your data reaches
- 5. How long we keep it
- 6. Information about your business during a project
- 7. Your rights
- 8. Security
- 9. Changes to this policy
- 10. How to reach us
1. Who we are
Aivonto.com is an AI consultancy and implementation company based in the Netherlands. For the data described on this page, the controller is Aivonto.com, reachable at the email address below.
You can reach us about anything on this page at Aivonto.com@gmail.com.
2. What we collect and why
When you contact us
The contact form on this site asks for your name, email address, company and message. We use those details for one purpose: to answer you and, if it goes further, to plan the work. The legal basis is taking steps at your request before entering into a contract, and our legitimate interest in responding to business enquiries.
If you email us directly, we hold whatever you choose to put in that email, for the same purpose.
When you visit the site
Our hosting provider records standard server information for every request: your IP address, the page requested, the time, and the browser and operating system you use. That is a normal part of serving a website securely and the legal basis is our legitimate interest in keeping the site running and protected. We do not use it to build a profile of you.
What we do not collect
- No accounts, so no usernames or passwords.
- No payment details are taken through this website.
- No special categories of personal data, and nothing about children.
- No newsletter list and no marketing emails unless you ask us to send you something.
3. Cookies and tracking
This website sets no cookies. There is no analytics, no advertising, no tracking pixel, no session storage and no fingerprinting script. That is also why you are not being asked to accept anything.
Every file this site needs, its fonts, styling and animation code, is served from our own domain. Nothing is fetched from an external font service or a public content delivery network, so opening a page does not announce your visit to anyone but our hosting provider.
4. Who else your data reaches
We keep this list as short as we can. At present it is:
- Our hosting provider, which stores the site and processes the server information described above.
- Our form provider, which delivers messages submitted through the contact form to our inbox. Your message passes through their systems on the way to us.
- Our email provider, which holds our correspondence with you.
Some of these providers operate outside the European Economic Area. Where that is the case, transfers are covered by the European Commission's standard contractual clauses or an equivalent safeguard.
We do not sell personal data, and we do not share it with anyone for their own marketing.
5. How long we keep it
- Enquiries that do not lead to work: kept for up to two years, so we have context if you come back to us, then deleted.
- Correspondence with clients: kept for the duration of the project and afterwards for as long as we may need it to answer questions about the work.
- Invoices and related records: kept for seven years, because Dutch tax law requires it.
- Server logs: kept for a short period by the hosting provider and then rotated out.
6. Information about your business during a project
An Audit means looking at how your business actually works. That usually involves seeing documents, systems and processes that contain personal data about your staff, your customers or your suppliers. Two things follow from that.
First, for that data you are the controller and we act as a processor on your instructions. What we may do with it is set out in the written agreement for the project, including a data processing agreement where one is required. This privacy policy does not govern that relationship.
Second, we ask for the narrowest access that lets us do the work, and we prefer anonymised or sample data wherever it is enough to understand a process.
7. Your rights
Under the GDPR you can ask us to:
- tell you what personal data we hold about you, and give you a copy,
- correct it if it is wrong,
- delete it,
- restrict what we do with it,
- hand it to you or another provider in a portable format,
- stop processing it where we rely on legitimate interest.
Email Aivonto.com@gmail.com and we will respond within one month. There is no charge. If you are not satisfied with how we handle it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
8. Security
The site is served over HTTPS. Access to our email and files is protected by strong authentication, and access to anything belonging to a client is limited to the people working on that project. No system is perfect, and we will not claim otherwise. If a breach affects your data and presents a risk to you, we will tell you and the supervisory authority within the periods the GDPR sets.
9. Changes to this policy
If what we do with data changes, this page changes with it, and the date at the top is updated. Material changes will be described here rather than quietly folded in.
10. How to reach us
Questions about this policy, or about anything we hold on you, go to Aivonto.com@gmail.com. Our registered details are listed on the terms page.