Chapter I — General provisions
This Privacy Policy governs the processing of personal data in connection with AI Scan, a service operated by UAB "Taikomasis dirbtinis intelektas" (company code 304845429, registered office in the Republic of Lithuania, address Architektų g. 9, Lazdijų k., Lazdijų r.) ("AAI Labs," "we"). It supplements the AAI Labs company Privacy Policy available at www.aai-labs.com/en/privacy-policy; for matters specific to AI Scan, this policy governs. We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Lithuanian law.
The service, in brief: a company (the "Client") commissions a scan of its operations. An AI agent conducts short conversational interviews with the Client's employees, and, where the Client elects to enable them, the service additionally draws on internal materials the Client makes available to it (the "context layers", described in Chapter V). The resulting analysis is delivered to the Client as a report on a web platform.
Chapter II — Controller and processor roles
AI Scan involves distinct categories of data subject whose data is governed by different roles. Identifying which applies to you determines how your rights are exercised.
- Clients (the purchasing company and the individuals using the platform on its behalf): AAI Labs is controller of account, contact, billing and platform-usage data.
- Employees of a Client whose data is processed through the interviews or the context layers: the Client is the controller and AAI Labs acts as processor on the Client's documented instructions, under a written data processing agreement ("DPA") concluded before any such processing begins. The Client determines that the scan occurs, its purpose, and the lawful basis for processing its workforce's data; AAI Labs executes the scan on the Client's behalf.
This allocation is definitive for the purposes of this policy and is mirrored in the DPA between AAI Labs and each Client, signed in AI Scan platform. Where the two documents address the same matter, they are drafted to be consistent.
Chapter III — Interview data
What is processed. The content of conversations between the employee and the AI Scan agent, together with the participant's role and department.
Role and basis. The Client is controller and determines the purpose and lawful basis; AAI Labs processes only on the Client's documented instructions.
Pseudonymisation. Responses are separated from directly identifying information at the point of collection; analysis is conducted against a participant identifier and role/department rather than a name. Illustrative quotations, where used, are de-identified. We do not represent that anonymity is absolute: within a small team a particular example may remain recognisable.
Incidental special-category data. The conversational format means a participant may volunteer information falling within Article 9 GDPR. The agent is instructed not to solicit such data and to minimise it; responsibility for the lawful basis of any incidental processing rests with the Client as controller.
Chapter IV — Client, account and billing data
Name, work email, company, role and platform-usage data of platform users are processed to provide and secure the service, under Article 6(1)(b) and 6(1)(f) GDPR. Where payment is taken, transaction data is processed under Article 6(1)(b) and 6(1)(c). Online purchases are handled by our merchant of record, Paddle (Paddle.com Market Limited and its affiliates), which acts as an independent controller of the payment data it collects; Paddle processes your card details and we do not receive or store them. Retention follows the periods in our company policy for service and accounting records.
Chapter V — The context layers (optional, Client-enabled)
Where the Client elects, AI Scan can enrich its understanding of the Client's organisation by drawing on two sources of internal material. Both are optional, disabled by default, and enabled only by an authorised Client administrator through the process in Chapter VI.
(a) Communication context layer. With Client authorisation, the service reads messages from channels the Client designates within its workplace communication tools (for example, Slack or Microsoft Teams). This is strictly limited to channels that are shared/open within the Client's organisation; it does not access private channels, direct messages, or private groups.
(b) Document context layer. With Client authorisation, the service reads materials from document and knowledge sources the Client designates (for example, shared drives or wiki/knowledge-base pages). This is strictly limited to materials shared broadly within the Client's organisation and does not access privately-restricted files.
An important characterisation. Material that is broadly shared within the Client's organisation is internal data with a limited organisational audience, it is not "public" data, and the individuals who created it may reasonably have expected it to remain within the organisation. Enabling a context layer means an external processor (AAI Labs) reads that internal material on the Client's instruction. Because of this, the context layers carry heightened responsibilities, addressed in Chapter VI.
Role, basis and minimisation. For both layers the Client is controller and AAI Labs is processor. Personal data within the ingested material is pseudonymised for analysis on the same basis as interview data, and identifying information is not transmitted to sub-processors as part of the analysis. The layers are used to understand organisational structure, responsibility allocation and workflows, not to profile or evaluate individuals, and the agent is instructed accordingly.
Chapter VI — Authorisation of the context layers: the two-gate process and allocation of responsibility
Because the context layers involve an external processor reading internal organisational material, AI Scan applies a two-gate authorisation process before either layer is enabled. This process exists to verify that the Client has the authority and lawful basis to authorise the processing.
Gate one: authorised administrator. A context layer can be enabled only by a Client administrator who confirms they are authorised to act for the Client in doing so.
Gate two: scope confirmation and compliance attestation. Before enablement, the administrator must designate the specific channels or sources in scope and must confirm, on the Client's behalf, that the Client has satisfied its own obligations as controller, including having a lawful basis for the processing, having provided any required notice to its workforce, and having completed any consultation required under applicable law (including, where applicable, works-council or employee-representative consultation).
Allocation of responsibility. The Client, acting through its administrator, determines what is placed in scope. The Client is responsible, as controller, for ensuring that the material it exposes to the service is material it is entitled to process and to have processed on its behalf, and for the consequences of designating in-scope any material that ought not to have been exposed. The Client warrants the accuracy of its authorisation and the fulfilment of its controller obligations, and indemnifies AAI Labs against claims arising from a breach of those warranties, on the terms set out in the DPA.
The limit of that allocation, stated honestly. This allocation governs the relationship between the Client and AAI Labs. It does not diminish AAI Labs' own obligations as a processor under the GDPR, nor does it affect any rights a data subject holds against either the Client or AAI Labs under the GDPR. AAI Labs processes context-layer data only on the Client's documented instructions, applies the minimisation and pseudonymisation measures described above, and will decline or cease processing that it is instructed to carry out in a manifestly unlawful manner.
Chapter VII — AI models and sub-processors
AI Scan uses third-party large language model providers as sub-processors to conduct interviews and analyse data. We select providers offering EU data-processing arrangements and appropriate contractual protection, and directly identifying information is not transmitted to them as part of the analysis. A current list of sub-processors (i.e. LLM providers, hosting, communication/messaging infrastructure and payment processing) is maintained as part of our processing documentation and is available upon request.
Chapter VIII — Transfers outside the EU
Where processing involves personal data leaving the European Union, we undertake to meet Articles 44–49 GDPR, relying on an adequacy decision or standard contractual clauses with appropriate supplementary measures as required.
Chapter IX — Third-party disclosure
Personal data may be provided to: sub-processors delivering the service (each under a DPA, only as necessary); our merchant of record, Paddle, in connection with the sale, payment processing, and tax compliance and invoicing for online purchases; the Client, in respect of the analysis it commissions as controller; and competent authorities, courts or law enforcement where required by law.
Chapter X — Cookies and analytics
Cookies are small text files stored on your device when you visit a website. Similar technologies, such as browser local storage, work the same way. They let a site function, stay secure, and help us understand how visitors use it. This chapter describes the cookies and similar technologies used on scan.aai-labs.com.
Categories we use:
- Strictly necessary. Required for the site to load and stay secure. Set automatically by our hosting and security provider. They do not require consent and cannot be switched off, but we disclose them here.
- Analytics (statistics). Help us understand how visitors use the site so we can improve it. Set only after you accept through our cookie banner. If you decline, nothing is stored on your device and no analytics data is collected. You can withdraw consent at any time through the cookie settings on the site, which stops further collection.
We do not use advertising or marketing cookies, and we do not sell personal data.
Strictly necessary (set automatically by Cloudflare, our hosting and security provider):
| Cookie | Purpose | Provider | Duration |
|---|---|---|---|
__cf_bm | Bot management and bot detection to protect the site. | Cloudflare | ~30 minutes |
cf_clearance | Records that a visitor passed a security challenge. Set only if a visitor is challenged. | Cloudflare | Up to 24 hours (session) |
Analytics (set only after you accept, via PostHog):
Before you accept, PostHog runs in memory only. It sets no cookie and writes nothing to your device. Once you accept, it sets the following:
| Cookie / storage | Purpose | Provider | Type | Duration |
|---|---|---|---|---|
ph_phc_..._posthog | Stores an anonymous device/user ID (distinct_id), session ID, and feature-flag state. | PostHog | Cookie | ~12 months |
ph_phc_..._posthog | Same values as above, held in browser storage. | PostHog | Local storage | Until browser storage is cleared |
We use PostHog (hosted in the EU) to understand how visitors use the site. After you accept, PostHog records: page views and page exits; clicks and interactions with buttons and forms; and a set of custom events covering our main calls to action (for example, booking a scan, requesting pricing, logging in, and contacting us). It also collects technical properties automatically, including approximate location derived from your IP address (country, region, city), browser, operating system, device type, referring page, page address, and any campaign tags in the link you arrived through.
Where you submit a contact or booking form, we associate the information you provide, including your email address, name, and company, with your analytics record, so we can connect an enquiry to the visit it came from. Your email address is used as the identifier for this record.
The legal basis for analytics is your consent under Article 6(1)(a) GDPR. You can withdraw it at any time through the cookie settings on the site.
For how we handle the personal data you submit through forms once we receive it, see Chapter IV.
Chapter XI — Rights of data subjects
You hold the GDPR rights to be informed, of access, rectification, erasure, restriction, objection, portability, and not to be subject to solely automated decisions with legal or similarly significant effect.
Exercising them depends on role. Clients exercise their rights with us directly. Employees whose interview or context-layer data is processed should direct requests concerning that data to their employer as controller; AAI Labs, as processor, will assist the employer in responding, and will route any request received directly to the appropriate controller. Requests concerning data for which AAI Labs is controller may be made to us directly.
We respond within one month, extendable by two further months for complex or numerous requests. You may complain to the State Data Protection Inspectorate of the Republic of Lithuania, your local supervisory authority, or a court.
Chapter XII — Contact
Questions or requests concerning personal data in connection with AI Scan may be addressed to our data protection officer at hello@aai-labs.com. Email requests should be electronically signed for identification. Employees with questions about why a scan or context layer was authorised should contact their employer.