Privacy Policy
Privacy Policy
Last updated: 29 July 2026
This policy explains how AIE MEDIA D.o.o. (“Asheard”, “we”) processes personal data when you visit asheard.com/, use the Asheard application at app.asheard.com, or contact us. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Slovenian data-protection law. We are the controller for the processing described here. Contact: hello@asheard.com.
1. Data we process
Account data — name, email address, password (stored hashed), workspace name, language preference; provided by you at registration. Billing data — plan, subscription status, invoices, and country for VAT purposes; payment card details are collected and processed directly by our merchant of record, Paddle, and never reach our servers. Content you enter — domains, keywords, prompts, brand and competitor names, team-member emails you invite. Usage and technical data — log data such as IP address, browser type, pages viewed, and actions performed, used for security and to operate the Service. Support communication — emails you send us.
Monitoring data produced by the Service (search positions, AI answers, cited sources) relates to the domains and brands you choose to track; where such content incidentally contains personal data (for example a personal name in a search result), we process it solely to provide the Service to you.
2. Purposes and legal bases
We process personal data: to provide the Service and perform our contract with you (Art. 6(1)(b) GDPR) — accounts, monitoring, notifications, support; to comply with legal obligations (Art. 6(1)(c)) — accounting and tax records; and for our legitimate interests (Art. 6(1)(f)) — securing the Service, preventing abuse, and improving the product using aggregated usage data. Where we send product news by email, we do so to existing customers under legitimate interest with an opt-out in every message, or otherwise based on your consent (Art. 6(1)(a)), which you can withdraw at any time.
3. Cookies
The application uses strictly necessary cookies for login sessions and security (no consent required). The marketing site uses no advertising cookies. If we introduce analytics that require consent, a cookie banner will ask for it first.
4. Recipients of data
We share personal data only with service providers who process it on our behalf under data-processing agreements, limited to what each needs: Paddle (payment processing and invoicing, as merchant of record — an independent controller for payment data), EU-based hosting and infrastructure providers, an email-delivery provider (transactional emails such as password resets and alerts), and the search-data and AI-model providers whose systems we query to produce your monitoring results — queries sent to them contain the keywords and prompts being checked, not your account identity. We do not sell personal data and do not use it for third-party advertising.
5. International transfers
Our primary infrastructure is located in the EU. Where a provider processes data outside the EU/EEA, we rely on adequacy decisions or the European Commission’s Standard Contractual Clauses.
6. Retention
Account and workspace data is kept while your account is active and deleted within 90 days after account deletion, except invoices and records we must keep under accounting and tax law (currently up to 10 years in Slovenia). Server logs are kept for up to 12 months for security. Monitoring history is deleted together with the workspace.
7. Your rights
You have the right to access, rectify, and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting prior processing. To exercise any right, email hello@asheard.com; we respond within one month. You also have the right to lodge a complaint with the Slovenian supervisory authority — Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si — or the authority of your habitual residence.
8. Security
We protect data with measures including encrypted connections (TLS), hashed passwords, role-based access inside workspaces, least-privilege access for our staff, and isolated per-tenant data. No system is perfectly secure; we will notify you and the supervisory authority of personal-data breaches as required by Art. 33–34 GDPR.
9. Children
The Service is intended for business use by adults. We do not knowingly process data of children under 15.
10. Changes
We will post updates to this policy here and, for material changes, notify you by email or in-app. The “Last updated” date above always reflects the current version.
