Legal

Privacy Policy

Last updated:

This Privacy Policy explains how Sen Balance Limited (“AOVA”, “we”, “us”) collects and uses personal data when you visit aova.app, use the AOVA dashboard, chat with an assistant on our website, or otherwise use our services. It also explains your rights under the EU General Data Protection Regulation (“GDPR”) and the Irish Data Protection Act 2018.

Chatting with a business's assistant? If you talk to an assistant built on AOVA by another business, for example on their website, Telegram or WhatsApp, that business decides how your messages are used. It is the controller of your data, and we process your messages only on its behalf under our Data Processing Addendum. Please read that business's privacy notice and send your requests to it. We will pass on any request we receive.

1. Who we are

The controller of the personal data described in this policy is Sen Balance Limited, registered in Ireland under company number 792973, with its registered office at 77 Camden Street Lower, Dublin, Dublin, D02 XE80, Ireland.

For any privacy question or to exercise your rights, email senlimitedie@gmail.com. We are not required to appoint a Data Protection Officer, and we have not done so. That email address reaches the person responsible for data protection at AOVA.

2. Personal data we collect

  • Account data: your email address and a password. We don't see your password: it is managed by our authentication provider (Amazon Cognito), which stores it only in a securely hashed form.
  • Billing data: your plan, purchases, invoices, credit balance and usage history. Stripe collects your payment details, such as your card, name and billing address, and gives us only limited information, such as the card brand, last four digits and payment status.
  • Content you add: documents, audio and video files and their transcripts, Knowledge Base content, assistant instructions and channel settings. Your files may contain personal data about you or other people.
  • Conversation data: the messages exchanged with your assistants, including tests in the dashboard. It also includes the identifiers of your end users that a channel provides, such as a Telegram chat ID or a WhatsApp phone number. For your end users' conversations we act as your processor (see section 3).
  • Messages to our own assistant: if you use the chat widget on aova.app, the messages you send it and the answers it gives.
  • Communications: emails and support requests you send us.
  • Technical data: IP address, browser and device type, pages requested, timestamps and error logs, recorded automatically by our servers and content delivery network for security and troubleshooting.
  • Analytics data, only if you consent: how you use our websites, such as pages viewed, clicks, sign-ups and purchases. This is collected through Google Analytics (see section 6).
  • Promotion data: if you arrive through a promo link, the promo code, so we can apply it to your account.

We collect this data from you directly, from your use of the Service, and from Stripe (payment status). You don't have to give us personal data, but we cannot create an account or process purchases without an email address.

3. Our role: controller and processor

We are the controller for data about our own customers and website visitors: account, billing, communications, technical and analytics data, and messages to our own assistant. For content you upload and for your end users' conversations with your assistants, we are your processor. We process that data only on your instructions under our Data Processing Addendum, and you, as controller, are responsible for informing your end users and having a lawful basis.

4. Why we use your data and our legal bases

PurposeLegal basis (GDPR Art. 6(1))
Creating and running your account; providing the Service, including answering questions with AI, transcribing media and delivering messages to your channels(b) performance of our contract with you
Taking payments, managing subscriptions and credits, applying promotions(b) contract
Service emails, such as verification codes, receipts, and notices of changes to the Service or these policies(b) contract; (c) legal obligation
Keeping accounting and tax records(c) legal obligation
Security, fraud and abuse prevention (for example stopping promo-code abuse), troubleshooting and enforcing our Terms(f) our legitimate interest in a secure, reliable service
Answering your questions and support requests(b) contract, or (f) legitimate interest if you are not yet a customer
Answering your questions through the assistant on aova.app(f) legitimate interest in helping visitors understand our product
Website analytics and measuring our advertising(a) consent, which you can withdraw at any time
Establishing, exercising or defending legal claims(f) legitimate interest

5. How AI processing works

  • AI models are accessed through Amazon Bedrock, run by Amazon Web Services. Under AWS's terms, prompts, documents and answers are not used to train models, and they are not shared with the model developers (such as Anthropic, Amazon or xAI).
  • We do not use your content or conversations to train AI models.
  • Most models run on AWS infrastructure in the EU. Some models are available only through AWS's global inference, which may process a request in an AWS region outside the European Economic Area. Currently this applies to xAI's Grok models. If you need all processing to stay in the EU, choose a different model.
  • We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

6. Cookies and similar technologies

Under the Irish ePrivacy Regulations (S.I. 336/2011), we use only strictly necessary storage without asking you. Analytics cookies are set only after you accept them in our cookie banner. You can change your choice at any time using the “Cookie settings” link in the footer.

NamePurposeDuration
aova_consentRemembers your cookie choice across aova.app sites (necessary)6 months
aova_promoKeeps the promo code from a promo link you followed, so it can be applied when you sign up (necessary for the offer you requested)30 days
aova-landing-lang (local storage)Remembers your language choice (necessary)Until cleared
Sign-in tokens (local storage)Keep you signed in to the dashboard (necessary)Until you sign out or the session expires
_ga, _ga_*Google Analytics 4: usage statistics and ad conversion measurement (consent only)Up to 2 years

Until you consent, we use Google's Consent Mode. In this mode Google may receive cookieless signals that do not identify you, which it uses to model aggregate statistics.

7. Who we share data with

We do not sell your personal data. We share it only with the following recipients:

  • Amazon Web Services EMEA SARL, our hosting provider, which processes data on our behalf. This covers storage, databases, authentication, email delivery, AI models (Amazon Bedrock) and transcription (Amazon Transcribe). Data is stored in the AWS Europe (Ireland) region.
  • Stripe Payments Europe, Limited (Ireland), our payment processor. For some processing, such as fraud prevention and regulatory compliance, Stripe acts as an independent controller under its own privacy policy.
  • Google Ireland Limited, for Google Analytics, only if you consent.
  • Messaging platforms you connect, such as Telegram and WhatsApp (Meta). When you connect a channel, messages pass through that platform under its own terms and privacy policy.
  • Professional advisers, such as lawyers and accountants, bound by confidentiality.
  • Authorities, such as the Revenue Commissioners, regulators, courts and law enforcement, where the law requires us to share data.
  • A buyer or successor, if our business is sold or reorganised, subject to this policy.

8. International transfers

We store data in the EU. Some recipients may process data outside the European Economic Area. Examples are Google and Stripe's US affiliates, and AWS global inference for the models described in section 5. Where that happens, the transfer is protected by an adequacy decision, such as the EU-U.S. Data Privacy Framework for certified companies, or by the European Commission's Standard Contractual Clauses with supplementary measures. You can ask us for a copy of the relevant safeguards at senlimitedie@gmail.com.

9. How long we keep data

DataRetention
Account dataWhile your account is open, then deleted within 30 days of closure
Content, Knowledge Bases and conversationsUntil you delete them, or within 30 days of account closure. Uploaded audio and video files are deleted once they are transcribed.
Invoices, payments and related records6 years after the end of the financial year, as Irish tax law requires
Technical and security logsUp to 90 days, unless needed to investigate an incident
Support emailsUp to 2 years after the matter is resolved
Messages to our own website assistantUp to 12 months
Analytics data (with consent)14 months in Google Analytics

10. Security

We protect personal data with appropriate technical and organisational measures. These include encryption in transit (TLS) and at rest, access restricted to authorised personnel on a need-to-know basis, separation of each customer's data, and monitoring and logging. No online service can be completely secure. If a personal data breach is likely to put your rights at risk, we will notify the Data Protection Commission and, where required, you.

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict our processing in certain circumstances;
  • receive data you provided to us in a portable format (data portability);
  • object to processing based on our legitimate interests;
  • withdraw your consent at any time, for example through “Cookie settings”. This does not affect processing that took place before you withdrew it.

To exercise these rights, email senlimitedie@gmail.com. We will reply within one month, which we can extend by two months for complex requests, and we may need to verify your identity first. Exercising your rights is free.

You also have the right to lodge a complaint with the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (dataprotection.ie), or with the supervisory authority in the EU country where you live or work. We would appreciate the chance to address your concern first.

12. Children

AOVA is not intended for anyone under 18, and we do not knowingly collect children's personal data for our own purposes. If you believe a child has given us personal data, contact senlimitedie@gmail.com and we will delete it.

13. Changes to this policy

We may update this policy. We will show the date of the latest version at the top of this page. If we make material changes, we will notify account holders by email before they take effect.