Privacy policy.
Last updated: July 2026. This policy explains which personal data AImplement.io processes, why, on which legal basis, how long we keep it, and which rights you have under the GDPR (AVG).
1. Controller
The controller for data processed through this website is AImplement.io, established at High-Tech Systems Park, Hengelo, the Netherlands, Contact: hello@aimplement.io. For data our digital employees process on behalf of clients, AImplement.io acts as a processor under a separate data processing agreement (DPA); that processing is governed by the client's own privacy policy.
2. Data we process, purposes and legal bases
We process the following categories of personal data:
a. Contact form data. Name, company name, business email address and the message you submit. Purpose: responding to your request, preparing and scheduling an introduction call. Legal basis: performance of pre-contractual measures at your request (art. 6(1)(b) GDPR).
b. Business communication. Email correspondence and call notes if we enter a business relationship. Purpose: performance of the agreement and account management. Legal basis: performance of a contract (art. 6(1)(b)) and legitimate interest (art. 6(1)(f)).
c. Website analytics. Aggregated usage data via Google Analytics 4 (pages viewed, interaction events such as CTA clicks and AI Scan completions, approximate location at city level, device type). Purpose: measuring and improving the website. Legal basis: consent (art. 6(1)(a)), requested via the cookie notice. IP anonymization is enabled.
d. AI Scan answers. The AI Scan runs entirely in your browser. Your answers are not transmitted to or stored by us unless you subsequently share them with us yourself.
e. Get started / onboarding application. When you use “Get started” (app.aimplement.io) we process your name, business email address, company name, and the answers you give during onboarding (the work you want to automate, who is involved, the boundaries you set). To prepare a recommendation we read the publicly available website of your email domain, or a website address you enter yourself, and analyse its text. For sign-in we use a one-time login link instead of a password; we store only a hashed version of that link and a hashed IP address to limit abuse. Access runs through that email address, so if it is a shared mailbox (for example info@), everyone with access to it can reach the account and the data in it. Purpose: preparing a concrete proposal for a digital employee at your request. Legal basis: performance of pre-contractual measures at your request (art. 6(1)(b) GDPR); the hashed IP address for abuse prevention rests on our legitimate interest (art. 6(1)(f)).
3. Recipients and processors
We do not sell personal data and do not share it with third parties for their own marketing. We use a limited set of processors, each bound by a data processing agreement: Vercel (website hosting); Google Ireland Ltd. (Analytics, loaded only after you accept cookies); Contentsquare (Hotjar, behavioural analytics, loaded only after you accept cookies); Anthropic PBC (the AI model that analyses website text and drafts the recommendation in “Get started”); Supabase (database and storage for sign-ups and onboarding answers); and Resend (delivery of the one-time login link). Website content and onboarding answers are sent to Anthropic solely to generate your recommendation and are not used to train its models. Where data is transferred outside the EEA (e.g. to Google LLC, Vercel, Anthropic or Resend in the US), transfers rely on the EU, US Data Privacy Framework and/or Standard Contractual Clauses.
4. Retention periods
Contact form submissions that do not lead to a business relationship are deleted no later than 12 months after our last contact. Sign-ups made through “Get started” that do not lead to a business relationship are deleted no later than 3 months after your last activity; you can also delete this data yourself at any time from your account (Profile → Delete my data), which immediately removes your sign-up, your onboarding answers and any connections, including their encrypted keys. Data related to an agreement is kept for the duration of the agreement plus the statutory retention period (7 years for administrative records under Dutch tax law). Analytics data is retained for a maximum of 14 months.
5. Security
We apply appropriate technical and organizational measures: encrypted transport (TLS), least-privilege access, scoped credentials per system, logging of access, and contractual confidentiality obligations for everyone who handles personal data on our behalf.
6. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time (without affecting processing before withdrawal). If you signed up through “Get started”, you can erase everything we hold about you directly from your account (Profile → Delete my data). For any other request, email hello@aimplement.io; we respond within one month. You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
7. Changes
We may update this policy. The current version is always published on this page with the date of last revision.