Trust

Privacy Policy

This notice explains what personal data we process, why, how it is protected, and what your rights are.

This is a draft to be reviewed by legal counsel before final publication. Items marked in [BRACKETS] will be completed and confirmed before publication.

Last updated: 16 July 2026

Who we are

Aye Matey is a service provided by Mainostoimisto Kaksi Oy (business ID [BUSINESS ID]). Our website address is https://www.ayematey.fi.

Data controller:
Mainostoimisto Kaksi Oy (auxiliary trade name Aye Matey)
[STREET ADDRESS, POSTAL CODE, CITY]
[EMAIL FOR PRIVACY MATTERS, e.g. tietosuoja@ayematey.fi]

Two roles: controller and processor

In the Aye Matey service, personal data is processed in two different roles. Understanding this helps you know who to contact in matters concerning your own data.

1. When you visit ayematey.fi or are our customer, Mainostoimisto Kaksi Oy is the controller of your personal data. This notice describes that processing.

2. When you chat with an Aye Matey receptionist on one of our customers’ websites, that company is the controller of your personal data and Mainostoimisto Kaksi Oy acts on its behalf as a processor. In that case, the primary privacy information can be found in that company’s own privacy notice. Processing is agreed with our customers in a data processing agreement (DPA).

What data we collect and why

Customer accounts and use of the service

When you create an Aye Matey account, we collect and process: your name, email address, company name and contact details, login information, and the settings and configuration of the service.

Purpose: providing the service, account management, customer support and service-related communication. Legal basis: contract.

Billing

Payments are processed by our payment partner Stripe. We do not store payment card details in our own systems. For invoicing, we process the company’s billing details and payment history. Legal basis: contract and statutory obligations (incl. accounting legislation).

Contact requests and demo bookings

When you contact us or book a demo, we process the contact details you provide and the content of your message in order to respond to you. Legal basis: legitimate interest or pre-contractual measures.

Receptionist conversations on our customers’ websites (as processor)

When a website visitor chats with the Aye Matey receptionist, the system stores the content of the conversation and any contact details the visitor voluntarily provides (e.g. name, email, phone number), together with a description of their need.

Purpose: responding to the conversation, qualifying the need, booking appointments and responding to contact requests on our customer’s behalf. The data is not used for marketing or disclosed to third parties for marketing.

Visitors are always told that they are talking to an AI assistant.

Where data is stored and how it is protected

We store data (such as conversations, leads, bookings and settings) in our systems on servers located in the EU.

Personal data (incl. contact details and conversation content) is protected with encryption in the database, not only in transit. Access to the data is restricted to people who need it to provide the service, deliver customer support or maintain security, and processing is subject to confidentiality obligations.

For generating AI responses, we use a carefully selected technology partner under a data processing agreement (DPA). Processing may take place outside the EU under appropriate transfer safeguards, including the EU Standard Contractual Clauses. The partners are listed under Subprocessors below.

How long we keep data

Customer account data is kept for the duration of the customer relationship and deleted or anonymised within a reasonable time after it ends, unless legislation (e.g. accounting law) requires longer retention.

For personal data in receptionist conversations, our customer can set a retention period after which personal data is anonymised automatically. [CONFIRM: default retention period for new licences, e.g. 24 months; must be implemented in the product before promising this.] After anonymisation, statistics remain without personal data. Data is also deleted on request.

Subprocessors

We use the following subcontractors (processors of personal data or their sub-processors) in providing the service:

Subprocessor Purpose Location/notes
[HOSTING PARTNER] Server environment and data storage EU
Google (Gemini API) Generating AI responses Global service; processing under a DPA
Stripe Payment processing
Google (Calendar API) / Microsoft (Graph API) Calendar integration for bookings Only when authorised by the customer
Meta (WhatsApp Business / Instagram) Messaging channels, if enabled by the customer
[OTHERS: email service, analytics etc.]

[CONFIRM the list against SubprocessorService: all subprocessors, not only the LLM.]

An up-to-date subprocessor list is available on request and as part of the data processing agreement.

Calendar integration (Google and Microsoft)

Our customers’ specialists can connect their own Google or Microsoft calendar for bookings using OAuth 2.0.

What permissions we request (Google):

  • Reading the calendar list (calendar.readonly)
  • Free/busy times (calendar.freebusy)
  • Creating, updating and deleting events (calendar.events)

How we use the data: solely to display available times and to save bookings made through the receptionist. Tokens and calendar identifiers are stored encrypted.

What we do not do: we do not read, analyse or store the contents of other events in the calendar, and we do not disclose calendar data to third parties.

Disconnecting: the specialist can disconnect the calendar connection at any time, in which case the tokens are removed from the system.

The application complies with the Google API Services User Data Policy (Limited Use): calendar data is used only for booking and availability display purposes and is not transferred to other applications.

Processing of Google Workspace Data and Artificial Intelligence

1. Data Protection Mechanisms

All data processed via Google Workspace APIs (specifically Google Calendar) is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Access to user data is strictly limited to real-time system queries required to perform user-requested actions.

2. Data Retention and Deletion

Information retrieved from Google Calendar is processed in real-time only for the duration of the request and is not permanently stored in our databases. If a user disconnects the application or requests account deletion, all associated Google authentication tokens and temporary session data are immediately and permanently removed from our systems.

3. AI Model Training Prohibition & Limited Use

User data received from Google Workspace APIs (including calendar events and details) will never be used, transferred, or sold to train, retrain, or improve third-party or generalized artificial intelligence or machine learning (AI/ML) models.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Your rights

You have the right to:

  • know what personal data we process about you, and receive a copy of it
  • request rectification or erasure of your data
  • restrict or object to processing as provided by law
  • transfer the data you have provided to another controller
  • lodge a complaint with a supervisory authority (in Finland, the Office of the Data Protection Ombudsman)

The right to erasure does not apply to data that we must retain for statutory, administrative or security reasons.

If your question concerns a conversation on one of our customers’ websites, we will forward the request to the correct controller where necessary. You can also contact that company directly.

Contact in privacy matters: [EMAIL].