Legal
Privacy Policy
This policy explains what personal data Pangratis AI collects through the ARIOS website and platform, why, how we protect it, and the rights you have. We aim to collect as little personal data as possible. For a plain-language summary of what we store and where, see Data & Compliance.
1.Who is responsible
The data controller is Eynur Ahmadov, trading as Pangratis AI, an individual established in Georgia at Ketevan Tsamebuli 24, Tbilisi, Georgia. (Pangratis AI LLC is in formation; this policy will be updated to name the company once it is registered.) You can reach us about privacy at sales@pangratis.com.
Where you upload data about your own business contacts into ARIOS, you are the controller of that data and we act as your processor. See section 4.
2.What we collect
| Category | Examples | Source |
|---|---|---|
| Waitlist / contact | Email address, and any name or message you choose to give us via the waitlist or contact form | You |
| Account & login | Email address and an encrypted password (authentication only — we do not require your personal name to sign up) | You |
| Content you enter | Companies, business contacts, signals, notes, and opportunities you add to your workspace ("Your Content") | You |
| Usage & technical | IP address, device/browser type, pages viewed, timestamps, and diagnostic logs | Automatic |
What we do not collect: we do not store full payment-card numbers, and we do not require your government ID or special-category (sensitive) personal data. Please do not upload sensitive personal data into ARIOS.
3.Why we use data & legal basis
Where GDPR or similar law applies, we rely on these legal bases:
- Contract — to create your account, provide ARIOS, and support you.
- Legitimate interests — to secure, maintain, and improve the service, prevent abuse, and (for the waitlist) tell you about early access. We balance these against your rights.
- Consent — for the newsletter/waitlist emails and any non-essential cookies; you can withdraw consent at any time.
- Legal obligation — to comply with law and respond to lawful requests.
4.Business-contact data you add
ARIOS is a B2B tool. To do its job it stores information about the business contacts and companies you research — which can include names, job titles, employers, and professional/public profile links. For this data you are the controller and we are your processor: we process it only on your instructions to provide ARIOS.
You are responsible for having a lawful basis (such as your own legitimate interest in B2B outreach) to process that data, for honouring the rights of those contacts, and for responding to their requests. We will help you meet those obligations where the platform allows. We do not sell this data and do not use it to build our own marketing lists.
5.AI & enrichment providers
To generate briefs, drafts, and enrichment, ARIOS sends relevant content to third-party AI and data providers (for example an AI model provider, and company/contact-enrichment and company-logo providers). These providers process the data to return a result to you. We choose providers that offer appropriate safeguards and, where relevant, agree not to train their public models on your business data. AI output can be inaccurate and must be reviewed by you before use.
6.Google user data
If you connect a Google account, ARIOS requests only the access it needs and uses it only for the features you asked for.
- Gmail metadata — sender, recipient, subject and date of messages, so ARIOS can show which partners you have corresponded with and when. ARIOS does not read the contents of your emails.
- Gmail compose and send — to prepare a draft in your mailbox, and to send a message only when you explicitly click send. ARIOS never sends email automatically or in bulk.
- Calendar (read-only) — upcoming events and attendees, to prepare you for meetings. ARIOS never creates, edits or deletes calendar entries.
Limited Use disclosure. ARIOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not use Google user data to train generalised AI or machine-learning models, we do not sell it, we do not transfer it except as necessary to provide or improve the features you requested, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data is aggregated and anonymised.
Access tokens are encrypted at rest. You can disconnect Google at any time from Settings, and you can revoke ARIOS's access directly in your Google account permissions.
9.International transfers
We are based in Georgia and our providers may be in the EU, the US, or elsewhere, so your data may be transferred across borders. Where personal data is transferred from the EEA, UK, or other regulated regions, we use appropriate safeguards such as Standard Contractual Clauses or an adequacy decision where available.
10.How long we keep data
We keep personal data only as long as we need it, and we enforce these periods automatically rather than by intention:
| Data | Kept for | Then |
|---|---|---|
| Email metadata (sender, recipient, subject, date — never message contents) | 24 months from the message date | Deleted |
| Calendar events synced from Google | 12 months | Deleted |
| Usage and provider logs | 12 months | Deleted |
| Compliance audit log | 12 months | Archived, not destroyed |
| Your Content (companies, contacts, signals, notes) | While your workspace is active | 30 days to export after closure, then deleted |
| Waitlist email | Until you unsubscribe | Deleted |
These periods are configured per workspace and applied by a scheduled job. If the law requires us to keep something longer, we will, and we will say so.
11.Security
We use technical and organisational measures appropriate to the risk — including encryption in transit, encryption of secrets at rest, access controls, server-side handling of AI keys, and workspace-level data isolation. No system is perfectly secure; we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.
12.Your rights
Depending on where you live (for example under the EU/UK GDPR or the California CCPA/CPRA), you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data, or delete it;
- restrict or object to processing, including profiling;
- data portability;
- withdraw consent at any time (without affecting prior processing);
- opt out of marketing emails via the unsubscribe link;
- not be sold or discriminated against for exercising your rights — we do not sell personal data;
- lodge a complaint with your data-protection authority.
To exercise a right, email sales@pangratis.com. We may need to verify your identity and will respond within the time the law requires. If your request is about data a customer holds in their workspace, we will refer you to that customer.
13.Children
ARIOS is not intended for anyone under 18, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
14.Changes
We may update this policy. We will change the "Last updated" date and, for material changes, provide additional notice where appropriate. Continued use after changes take effect means you accept the updated policy.
15.Contact
Privacy questions or requests: sales@pangratis.com, Eynur Ahmadov trading as Pangratis AI, Ketevan Tsamebuli 24, Tbilisi, Georgia.