The big reveal | March 19Introduction of first AI maturity model for knowledge workersRegister now
Aibility Logo Black
Superpowered Pro
Learn AI skills
For Teams
About Us
Česká republika — Čeština
United States — English
Start Free Assessment
Superpowered ProLearn AI skillsFor TeamsAbout UsLog inStart Free Assessment

PRIVACY POLICY

Data controller: Aibility, s. r. o., Company ID: 10684395, registered office at Drobného 555/49, Ponava, 602 00 Brno ("we").

Contact details of the controller: podpora@aibility.cz, Drobného 555/49, Ponava, 602 00 Brno

In this document, we would like to inform you about how we process your personal data, the purposes of processing, the lawfulness of processing, the retention period, and your rights in connection with the processing of personal data. The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR") and in accordance with other data protection regulations.

All information about us and our services and products can be found on our website www.aibility.cz ("website").

  1. Scope of Personal Data

Regardless of which of our services or products you use, we will process the following personal data about you:

  • Identification data, such as your first and last name (or organisation name and your role, if you use our services on behalf of a company).
  • Contact data, namely your email address and telephone number.
  • Order and payment data, such as the selected product/service (e.g. webinar, subscription), order identifier, date and time, price, payment method, payment confirmation, tax document, and related data for complaints/withdrawal from contract.
  • Billing data, namely address, company name, Company ID, VAT ID.
  • Supplementary data, namely additional information about you that we may request, such as seniority, field of work, job position, team membership, in connection with the services we provide.
  • Data on the use of our services and outputs, such as AI skills test results, participation and interactions at webinars/workshops, provided materials, or feedback.
  • Communication data, i.e. information about communication with you, such as emails, chats, etc.
  • Cookie data, i.e. data obtained from cookies and similar technologies that we use. For more information on their use, please read the cookies policy available on our website.
  • Photographs and video recordings from events, where we produce them (typically from offline workshops/hackathons or selected courses) — always depending on the specific event and the information provided on-site.

Specifically, we may also process the following personal data as data controllers, provided that you use the Aimee services ("platform"):

  • Account and platform access data, in particular login credentials (email when signing in via magic link / OAuth), account identifiers, data provided by the authentication provider (e.g. OAuth provider identifier), account settings and preferences, and data on activity within the account.
  • Identification and profile data, in particular first and last name (or first name), profile photo (if provided via OAuth or uploaded by you), and other data entered in the profile or during onboarding.
  • Data on the use of our services and outputs, in particular queries and inputs you provide when using the platform.
  • Onboarding and contextual data for service configuration, in particular professional role and responsibilities, information about the team and company (to the extent you provide), preferences for AI assistance (e.g. language/style), use case scenarios and goals (e.g. areas of development, expectations and coaching focus).
  • Content of coaching conversations and interactions, in particular messages, prompts and queries you enter into Aimee, the course and history of conversations, and metadata related to interactions (e.g. time sent, conversation continuity).
  • Feedback and evaluation data, in particular your ratings, comments, reactions to responses, and information provided in satisfaction surveys or problem reporting.
  • Service usage data, in particular pages visited and features used, time spent in the service, click and navigation patterns, and information about the course of feature usage.
  • Technical data about device and connection, in particular device type, browser type, operating system, language settings, IP address, and derived approximate location (typically at the city/country level).
  • Operational and security logs and diagnostic data, in particular error messages, logs, diagnostics and data for incident resolution, including performance data (e.g. API response times and application performance metrics).
  • Analytical and statistical data, in particular data on user behaviour and feature usage, aggregated statistics and analytical identifiers used for measuring and improving the service (e.g. through analytics tools such as Mixpanel).
  1. Purposes of Personal Data Processing

Your personal data is processed for the purposes described below. For each processing purpose, you will also find the scope of personal data processed and the retention period for personal data.

Processing related to the Aimee platform

Below you will find specific purposes relating to the processing of personal data in connection with the Aimee platform.

  1. Performance of the mutual contractual relationship (account creation and provision of the Aimee service)

We process personal data in order to provide you with the Aimee platform, i.e. to create and manage a user account, grant you access to the platform, and provide you with digital consultation/AI coaching features (including processing your queries and prompts and generating outputs). This purpose also includes basic operational communication necessary for the provision of the service (e.g. login link via email, registration confirmation, technical notifications related to the account).

For this purpose, we process your Order and payment data, Account and platform access data, Identification and profile data, Onboarding and contextual data for service configuration, and Content of coaching conversations and interactions.

The legal basis for this processing is the performance of a contract between you and us and the necessity to take steps at your request prior to entering into a contract. Where you order the service on behalf of a company, the processing is based on legitimate interest related to the necessity of communicating with the contact person and ensuring the provision of functionalities.

Data is processed for the duration of the contractual relationship (for the duration of the active account) and for a reasonable period after its termination, typically up to 3 years, unless it is necessary in a particular case to retain the data longer (e.g. for the protection of legal claims).

  1. Personalisation of the platform service and customisation of user experience

We process your personal data in order to adapt the functioning of Aimee to your needs, in particular based on your provided preferences, goals, use case scenarios, and the course of your service usage (e.g. communication style, thematic focus, continuation of previous interactions, and feature settings).

For this purpose, we process your Onboarding and contextual data for service configuration, Content of coaching conversations and interactions, Service usage data, and Feedback and evaluation data.

The legal basis for this processing is the performance of a contract (where personalisation is part of the service provided) and/or our legitimate interest in providing a meaningful and effective service and increasing its utility value.

Data is processed for the duration of the account. Certain partial information (e.g. settings and preferences) is processed until changed or deleted, but no longer than for the duration of the account and subsequently typically up to 3 years after its termination.

  1. Provision of customer support and communication with users

We process personal data for the purpose of providing customer support, handling your queries and requests, resolving technical issues, and communicating with customers (e.g. responding to bug reports, processing requests, providing instructions).

For this purpose, we process your Contact and Identification data, Communication data, and where applicable, Account and platform access data, and to the necessary extent also Operational and security logs and diagnostic data.

The legal basis for this processing is our legitimate interest in providing support and handling your queries; in some cases, the legal basis may also be the performance of a contract, particularly with regard to processing contractual claims within the scope of support and communication.

Personal data will be processed for the time necessary to handle the request and subsequently for a reasonable period, typically a maximum of 1 year, unless it is necessary to retain them longer (e.g. for the protection of legal claims).

  1. Operation of the platform, security, and prevention of misuse

We process your personal data to ensure the proper functioning of Aimee, its stability, security, and to prevent and detect fraudulent or harmful conduct (e.g. unauthorised access, attacks, account misuse), including maintaining technical logs, performance monitoring, and error diagnostics.

For this purpose, we process your Technical data about device and connection, Operational and security logs and diagnostic data, Technical monitoring and tracing data, and to the necessary extent also Account and platform access data and Service usage data.

The legal basis for this processing is our legitimate interest in the secure and reliable operation of the platform and the protection of our systems and users.

Data is generally processed for the period necessary to ensure security and operation, typically no more than 12 months (for certain security incidents, the period may be longer depending on the severity and the need for investigation).

  1. Analytics and platform improvement

We process your personal data to understand how users utilise Aimee and to improve features and user experience (e.g. measuring engagement, feature usage, evaluating aggregated statistics).

For this purpose, we process your Service usage data, Analytical and statistical data, and to a limited extent also Technical data about device and connection.

The legal basis for this processing is our legitimate interest in the development and optimisation of the service. Where analytics are carried out through cookies or similar identifiers in the website environment, the legal basis may also be your consent given via the cookie banner (depending on the specific settings).

Personal data is processed for the period necessary to fulfil the purpose, typically no more than 12 months, or until withdrawal of consent (where relevant).

Processing related to the provision of services in general and in connection with visiting the website

Below are the processing purposes that are general to any services we offer and in connection with visiting the website.

  1. Provision of services (Live workshops, AI skills test, AI Edu Stream, webinars, and other services offered on the website)

We use your personal data in particular to provide you with the given service and to deliver it. In this regard, this may involve processing necessary to ensure a subscription, ensure participation in our event, registration, communication before and after the provision of the service, sending materials, outputs, and ensuring further follow-up communication related to the service provided.

In such a case, we will process your Identification data, Contact data, Order and payment data, Supplementary data, Data on the use of our services and outputs, and Communication data.

The legal basis for this processing is the performance of a contract between you and us and the necessity to take steps at your request prior to entering into a contract. Where you order the service on behalf of a company, the processing is based on legitimate interest related to the necessity of communicating with the contact person and ensuring the provision of functionalities.

Personal data will be processed for the time necessary to provide the service and for a maximum of 3 years from the provision of the service.

  1. Taking photographs and other recordings

In some cases, for example when organising offline events and workshops, or during online events, we may take photographs and recordings. These may subsequently be published on our website, in commercial communications, or on social media.

For this purpose, we process Photographs and video recordings from events.

The legal basis for this processing is your consent, which you grant during registration for our events.

Your personal data will be processed for as long as they remain available on the platforms where they were published, but for no longer than 15 years from their publication.

  1. Contact forms

The website also contains a contact form through which you can contact us, for example if you wish to order certain services or if you have any questions.

In such a case, we will process your Identification data, Contact data, Communication data, and where applicable, information about the type of service you are interested in.

The legal basis for this processing is our legitimate interest in ensuring mutual communication and handling your queries. If a contractual relationship is subsequently established, personal data may be used for the purpose of fulfilling contractual obligations.

Personal data will be processed for the time necessary to handle your query, or for other purposes if relating to the performance of a contract.

  1. Internal records, statistics, and protection of our rights

Regardless of which of our services you use (including the Aimee platform), we may process your data for the purpose of maintaining internal records, recording payments made, producing statistical reports, protecting our rights and legal claims, and ensuring that we can defend against any claims you may raise.

For this purpose, we process your personal data as set out in Part A of this privacy policy, always to the extent necessary to ensure and implement the protection of our legal claims.

The legal basis for this processing is our legitimate interest in maintaining internal records, statistics, and protecting our rights. Data is processed for the duration of limitation periods, which is typically 10 years from the occurrence of the events from which the limitation period is calculated.

  1. Fulfilment of legal obligations

We may also process your personal data in order to fulfil our legal obligations, particularly in the area of tax and accounting. For each order, we must issue an invoice, maintain accounting records, remit taxes, and fulfil other obligations required by law. At the same time, we need to be prepared to cooperate with state authorities where we are obliged to do so by law. For example, in connection with the fulfilment of obligations under consumer protection legislation.

For this purpose, we process in particular your Identification data, Contact data, Order and payment data, and Billing data.

The legal basis for this processing is the fulfilment of our legal obligations. Data is processed for the period stipulated by legal regulations. For example, in the area of accounting and tax, this period is up to 10 years, taking into account possible audits.

  1. Sending commercial communications

We may also use your personal data to send you offers of our services and other commercial communications.

For this purpose, we process your Identification data (where known to us) and Contact data.

The legal basis for this processing is:

  • Our legitimate interest in direct marketing, provided that you are our customer and have not objected to the sending of commercial communications.
  • Your consent, provided that you subscribe to our newsletter via the website.

Your personal data will be processed until you object to the sending of commercial communications, which you can do in each individual email. However, for no longer than 3 years from the sending of the last newsletter.

Processing related to cookies (whether on the website or on the platform)

  1. Operation of the website/platform and security (necessity)

We process your personal data to ensure the functioning of the website and the platform and to ensure security. The processing of your personal data may thus also serve to ensure that the website works as you expect, that everything is displayed correctly, and that browsing is secure.

For this purpose, we process your Cookie data, to the extent of strictly necessary cookies.

The legal basis for this processing is our legitimate interest in the proper functioning and secure operation of the website. Data is generally processed for the duration of your visit to the website, and for no longer than 1 year from its collection.

  1. Traffic measurement and website improvement

We process your personal data for the purpose of measuring traffic, creating statistics and reports on the use of the website, and improving its functionality and user experience (e.g. evaluating which pages are most visited, how users navigate the website, and where errors or ambiguities occur).

For this purpose, we process your Cookie data, to the extent of analytical cookies (typically device/browser identifiers, approximate location derived from IP address, visit and interaction information, technical parameters).

A specific list of cookies is provided in the list of recipients (see below).

The legal basis for this processing is your consent (given via the cookie banner / settings). Data is processed for the period according to the settings of the individual cookies, generally no longer than 1 year (or until withdrawal of consent), unless otherwise stated in the cookie banner.

  1. Marketing and advertising effectiveness measurement

We process your personal data for marketing purposes, in particular to measure the effectiveness of advertising campaigns, attribute conversions, limit repeated ad impressions (frequency capping), and to display personalised advertising based on your activity on the website.

For this purpose, we process your Cookie data, to the extent of marketing cookies (typically online identifiers, visit and conversion data, technical identifiers, and where applicable, hashed identifiers).

A specific list of cookies is provided in the list of recipients (see below).

The legal basis for this processing is your consent. Data is processed for the period according to the settings of the individual cookies, generally no longer than 1 year (or until withdrawal of consent), unless otherwise stated in the cookie banner.

  1. Functional cookies for support and communication

We process your personal data for the purpose of providing customer support and communication (e.g. via chat widget), including maintaining communication context, pre-filling certain data, and evaluating basic support metrics.

For this purpose, we process your Cookie data, to the extent of functional cookies (typically session identifier, chat settings, device/browser information, and chat interaction data).

A specific list of cookies is provided in the list of recipients (see below).

The legal basis for this processing is your consent, unless the cookies are strictly necessary for the technical provision of a function you have requested. Data is processed for the period according to the settings of the individual cookies, generally no longer than 1 year (or until withdrawal of consent), unless otherwise stated in the cookie banner.

  1. Sharing of Personal Data

Your personal data may be shared with recipients listed in this list.

Where we share your personal data with controllers and processors in third countries (outside the EEA), we do so only where such persons provide adequate safeguards as set out in Article 44 et seq. of the GDPR.

  1. Your Rights Regarding Processing and How to Exercise Them

You have the right to (i) request access to your personal data; (ii) withdraw your consent; (iii) request rectification of your personal data; (iv) request erasure of your personal data; (v) request restriction of processing of your personal data; (vi) request portability of your personal data; (vii) object to the processing of your personal data; or (viii) lodge a complaint with the competent supervisory authority.

For all matters related to the processing of your personal data, whether it concerns a question, the exercise of rights, the submission of a complaint to us, etc., you may contact us via the email address stated at the beginning of this document.

  1. Right of access

You have the right to obtain from us confirmation as to whether or not your personal data is being processed.

If we process your personal data, you also have the right to request access to information about the purpose and scope of processing, the recipients of data, the processing period, the right to rectification, erasure, restriction of processing and to object to processing, the right to lodge a complaint with the supervisory authority, and the sources of personal data (this information is already provided in this document).

You may also request a copy of the personal data being processed. The first copy is provided free of charge; further copies may be subject to a fee. The scope of data provided may be limited so as not to infringe the rights and freedoms of other persons.

  1. Right to withdraw consent

You have the right to withdraw your consent to the processing of personal data at any time. However, withdrawal of consent does not affect the lawfulness of processing prior to such withdrawal, and will not result in the termination of processing of personal data that has already been anonymised.

  1. Right to rectification

You have the right to request from us the rectification of inaccurate personal data concerning you. Depending on the purpose of processing, you may also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

  1. Right to erasure (right to be forgotten)

You have the right to request the erasure of your personal data in cases where:

  • your personal data is no longer necessary for the purposes for which it was collected or processed;
  • you withdraw the consent on which the processing was based, and there is no other legal ground for the processing;
  • you object to the processing and there are no overriding legitimate grounds for the processing, or you object to the processing for the purposes of direct marketing;
  • the personal data has been processed unlawfully.

However, you cannot exercise this right where processing is necessary for compliance with our legal obligations or tasks carried out in the public interest, or for the establishment, exercise, or defence of legal claims.

  1. Right to restriction of processing

You have the right to request restriction of processing of your personal data in cases where:

  • you contest the accuracy of your personal data; in such a case, you may request restriction of processing for the period during which the accuracy of the personal data is verified;
  • the processing is unlawful and instead of erasure you request restriction of processing of the personal data;
  • your personal data is no longer necessary for the purposes for which it was collected or processed, but you require it for the establishment, exercise, or defence of legal claims;
  • you have objected to the processing of personal data; in such a case, you may request restriction of processing for the period during which it is verified whether our legitimate interests prevail.
  1. Right to data portability

You have the right to receive a copy of your personal data that we process by automated means on the basis of your consent or for the performance of a contract. We will provide such data in a commonly used and machine-readable format to you or to a controller designated by you, where technically feasible. The scope of data provided may be limited so as not to infringe the rights and freedoms of other persons.

  1. Right to object

You have the right to object to the processing of your personal data that we process on the basis of our legitimate interest. We will cease processing your data unless there are overriding legitimate grounds for the processing or unless the processing is necessary for the establishment, exercise, or defence of legal claims, or if you object to the processing for the purposes of direct marketing.

  1. Right to lodge a complaint

In addition to the possibility of exercising your rights with our company, you may also lodge a complaint with the competent supervisory authority, which is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), with its registered office at Pplk. Sochora 27, 170 00 Praha 7.

  1. Changes to this privacy policy

We are entitled to amend this privacy policy from time to time, so please review it regularly. Any changes to this document will be published on our website.

SUPERPOWERED PRO™

The Methodology

Free Assessment

Full Certificate

Results & Reports

FOR TEAMS

Team Assessment

AI Adoption Programs

Book a Demo

ABOUT US

About Aibility

Team

Contact

© Copyright 2026. All Rights Reserved.

Terms & Conditions

Privacy Policy

Cookie Settings

Sub-processors

Whistleblower Policy