Legal information
Privacy Policy
Last updated: 9 August 2026
1. Data controller
AI-AO is the controller for the processing described here. Contact us at info@ai-ao.net or by phone at +46 700 95 83 27.
2. Data we process
- Bookings: name, email address, organization, phone number, selected meeting, and message.
- Member accounts: display name, email address, securely protected password, and account and login information.
- Comments: comment text, account, time, and moderation status.
- Open_H assistant: prompts, chat history, generated answers, retrieved document passages, ontology relationships, citations, edits, ratings, feedback, and usage information such as message, token, and cost totals.
- Technical and safety data: IP address, timestamps, browser information, authentication, rate-limit, error, audit, and security records required to operate and protect the service.
- Social sign-in: if enabled, we may receive your name, email address, and a unique identifier from your chosen provider.
Do not enter personal, confidential, or protected information into Open_H unless you are authorised to use it for this purpose.
3. Purposes and legal basis
- Managing booking requests and communication before a potential engagement: steps prior to a contract and legitimate interests.
- Creating accounts and providing comments and Open_H, including retrieval, citations, chat history, and user-requested edits: performance of the Terms of Use.
- Measuring permitted usage, diagnosing errors, securing the service, preventing abuse, and improving reliability: performance of the service and legitimate interests.
- Meeting legal obligations such as accounting or authority requirements: legal obligation.
- Social sign-in data is processed when you actively choose a provider and approve its sign-in flow.
Open_H supports users with information and drafting. We do not use it to make solely automated decisions about people that produce legal or similarly significant effects.
4. Recipients and providers
Data may be processed by providers that assist with server operation, backups, email delivery, authentication, AI generation, and embeddings. Open_H may send a prompt and selected retrieved context to the AI and embedding providers configured by the administrator. PII masking is applied before external AI processing where configured, but it cannot guarantee detection of every sensitive value. Email is currently delivered through Google. We do not sell personal data.
Some providers may process data outside the EU/EEA. Where this occurs, processing must be supported by an applicable adequacy decision or other GDPR safeguards.
5. Retention
- Booking and contact data is normally retained for no more than 24 months after the latest contact, unless a contract or legal duty requires longer retention.
- Member accounts and associated assistant history are retained while the account is active. A user can delete individual chats and may request account deletion, subject to records that must be retained for security, disputes, or law.
- Approved comments may remain while the article is published. Rejected and pending comments are normally deleted within 12 months.
- Security and server logs are normally retained for no more than 90 days unless an incident requires longer investigation.
7. Your rights
You may have rights to information, access, correction, deletion, restriction, portability, and objection. Contact us by email to exercise your rights. We may need to verify your identity. You may also complain to the Swedish Authority for Privacy Protection (IMY).
8. Security and changes
We use access controls, encrypted HTTPS communication, password hashing, backups, and restricted administrative access. No internet service is entirely risk-free. This policy may be updated when the service or legal requirements change; the date above shows the latest version.
