Privacy Statement
This statement explains how Kaleos d.o.o. ("we") processes personal data in connection with the emio.ai website and the Emio.ai service (together, the "Service"), in line with the EU General Data Protection Regulation (GDPR, Reg. 2016/679) and Slovenian data protection law (ZVOP-2).
1. Website
When you visit emio.ai we process: server log data (IP address, user agent, request, timestamp) for security and operation (Art. 6(1)(f) GDPR, legitimate interest); a language preference stored locally in your browser (no cookies; no tracking, advertising or analytics). Logs are retained up to 30 days.
If you email us, we process your email address and message content to respond (Art. 6(1)(f) GDPR). Correspondence is retained as long as necessary for the matter, then deleted.
2. Service (document processing)
When you use the Service to extract data from documents, those documents and the resulting outputs ("Customer Data") may contain personal data of you or third parties. With respect to such personal data:
- You are the controller; we act as your processor (Art. 28 GDPR) under our Data Processing Agreement, which governs purposes, instructions, security, sub-processors and deletion.
- We process Customer Data only to provide the Service and on your documented instructions.
- We do not use Customer Data to train models for other customers.
- Customer Data is stored in the EU/EEA. We do not transfer it to third countries without a valid GDPR transfer mechanism.
- Retention is configured by you: by default documents are processed transiently and deleted after processing; if you opt to save data, it is kept until you delete it or your contract ends.
You are responsible for ensuring you have a lawful basis to submit personal data to the Service and for informing affected data subjects.
3. Recipients and sub-processors
We use vetted EU-based infrastructure and software sub-processors strictly to operate the Service. A current list is available on request to web@kaleos.ai.
4. Security
We apply appropriate technical and organisational measures (encryption in transit, access controls, logging, least-privilege, backups) to protect personal data against unauthorised access, loss or alteration.
5. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing, and to data portability. Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. To exercise these rights, write to web@kaleos.ai. For Customer Data processed on a customer's behalf, please contact that customer (the controller); we will forward requests where required.
You also have the right to lodge a complaint with the Slovenian supervisory authority, Informacijski pooblaščenec (www.ip-rs.si), or with the authority of your EU country of residence.
6. Changes
We may update this statement. The "Last updated" date above reflects the current version.