ARIOS
Terms Data & Compliance Contact

Legal

Privacy Policy

Last updated: 20 July 2026 · Effective date: 20 July 2026

Terms & Conditions Privacy Policy Data & Compliance

This policy explains what personal data Pangratis AI collects through the ARIOS website and platform, why, how we protect it, and the rights you have. We aim to collect as little personal data as possible. For a plain-language summary of what we store and where, see Data & Compliance.

Contents

  1. Who is responsible
  2. What we collect
  3. Why & legal basis
  4. Business-contact data
  5. AI & enrichment providers
  6. Google user data
  7. Cookies & analytics
  8. Who we share with
  9. International transfers
  10. How long we keep data
  11. Security
  12. Your rights
  13. Children
  14. Changes
  15. Contact

1.Who is responsible

The data controller is Eynur Ahmadov, trading as Pangratis AI, an individual established in Georgia at Ketevan Tsamebuli 24, Tbilisi, Georgia. (Pangratis AI LLC is in formation; this policy will be updated to name the company once it is registered.) You can reach us about privacy at sales@pangratis.com.

Where you upload data about your own business contacts into ARIOS, you are the controller of that data and we act as your processor. See section 4.

2.What we collect

CategoryExamplesSource
Waitlist / contact Email address, and any name or message you choose to give us via the waitlist or contact form You
Account & login Email address and an encrypted password (authentication only — we do not require your personal name to sign up) You
Content you enter Companies, business contacts, signals, notes, and opportunities you add to your workspace ("Your Content") You
Usage & technical IP address, device/browser type, pages viewed, timestamps, and diagnostic logs Automatic

What we do not collect: we do not store full payment-card numbers, and we do not require your government ID or special-category (sensitive) personal data. Please do not upload sensitive personal data into ARIOS.

3.Why we use data & legal basis

Where GDPR or similar law applies, we rely on these legal bases:

  • Contract — to create your account, provide ARIOS, and support you.
  • Legitimate interests — to secure, maintain, and improve the service, prevent abuse, and (for the waitlist) tell you about early access. We balance these against your rights.
  • Consent — for the newsletter/waitlist emails and any non-essential cookies; you can withdraw consent at any time.
  • Legal obligation — to comply with law and respond to lawful requests.

4.Business-contact data you add

ARIOS is a B2B tool. To do its job it stores information about the business contacts and companies you research — which can include names, job titles, employers, and professional/public profile links. For this data you are the controller and we are your processor: we process it only on your instructions to provide ARIOS.

You are responsible for having a lawful basis (such as your own legitimate interest in B2B outreach) to process that data, for honouring the rights of those contacts, and for responding to their requests. We will help you meet those obligations where the platform allows. We do not sell this data and do not use it to build our own marketing lists.

5.AI & enrichment providers

To generate briefs, drafts, and enrichment, ARIOS sends relevant content to third-party AI and data providers (for example an AI model provider, and company/contact-enrichment and company-logo providers). These providers process the data to return a result to you. We choose providers that offer appropriate safeguards and, where relevant, agree not to train their public models on your business data. AI output can be inaccurate and must be reviewed by you before use.

6.Google user data

If you connect a Google account, ARIOS requests only the access it needs and uses it only for the features you asked for.

  • Gmail metadata — sender, recipient, subject and date of messages, so ARIOS can show which partners you have corresponded with and when. ARIOS does not read the contents of your emails.
  • Gmail compose and send — to prepare a draft in your mailbox, and to send a message only when you explicitly click send. ARIOS never sends email automatically or in bulk.
  • Calendar (read-only) — upcoming events and attendees, to prepare you for meetings. ARIOS never creates, edits or deletes calendar entries.

Limited Use disclosure. ARIOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not use Google user data to train generalised AI or machine-learning models, we do not sell it, we do not transfer it except as necessary to provide or improve the features you requested, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data is aggregated and anonymised.

Access tokens are encrypted at rest. You can disconnect Google at any time from Settings, and you can revoke ARIOS's access directly in your Google account permissions.

7.Cookies & analytics

The website uses cookies and similar technologies that are strictly necessary to function, and may use limited analytics to understand traffic. The waitlist form is provided by our email provider (Brevo) and sets its own cookies when used. Where required by law, we ask for consent before setting non-essential cookies. You can control cookies through your browser settings.

8.Who we share data with

We do not sell your personal data. We share it only with:

  • Sub-processors that run the service on our behalf — cloud hosting, database and authentication, AI model, data-enrichment, and email/newsletter providers — under data-processing terms. A current list is available on request.
  • Authorities where required by law or to protect rights, safety, and security.
  • A successor in a merger, acquisition, or reorganisation, subject to this policy.

9.International transfers

We are based in Georgia and our providers may be in the EU, the US, or elsewhere, so your data may be transferred across borders. Where personal data is transferred from the EEA, UK, or other regulated regions, we use appropriate safeguards such as Standard Contractual Clauses or an adequacy decision where available.

10.How long we keep data

We keep personal data only as long as we need it, and we enforce these periods automatically rather than by intention:

DataKept forThen
Email metadata (sender, recipient, subject, date — never message contents)24 months from the message dateDeleted
Calendar events synced from Google12 monthsDeleted
Usage and provider logs12 monthsDeleted
Compliance audit log12 monthsArchived, not destroyed
Your Content (companies, contacts, signals, notes)While your workspace is active30 days to export after closure, then deleted
Waitlist emailUntil you unsubscribeDeleted

These periods are configured per workspace and applied by a scheduled job. If the law requires us to keep something longer, we will, and we will say so.

11.Security

We use technical and organisational measures appropriate to the risk — including encryption in transit, encryption of secrets at rest, access controls, server-side handling of AI keys, and workspace-level data isolation. No system is perfectly secure; we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.

12.Your rights

Depending on where you live (for example under the EU/UK GDPR or the California CCPA/CPRA), you may have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data, or delete it;
  • restrict or object to processing, including profiling;
  • data portability;
  • withdraw consent at any time (without affecting prior processing);
  • opt out of marketing emails via the unsubscribe link;
  • not be sold or discriminated against for exercising your rights — we do not sell personal data;
  • lodge a complaint with your data-protection authority.

To exercise a right, email sales@pangratis.com. We may need to verify your identity and will respond within the time the law requires. If your request is about data a customer holds in their workspace, we will refer you to that customer.

13.Children

ARIOS is not intended for anyone under 18, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

14.Changes

We may update this policy. We will change the "Last updated" date and, for material changes, provide additional notice where appropriate. Continued use after changes take effect means you accept the updated policy.

15.Contact

Privacy questions or requests: sales@pangratis.com, Eynur Ahmadov trading as Pangratis AI, Ketevan Tsamebuli 24, Tbilisi, Georgia.

ARIOS

Legal

Terms & Conditions Privacy Policy Data & Compliance

Company

About Contact

© Pangratis AI. ARIOS is a platform by Pangratis AI. All rights reserved.