Privacy Policy

Last Updated: November 2025

Your Privacy Matters: This Privacy Policy explains how BGO s.r.o. ("we", "us", "our") collects, uses, stores, and protects your personal information when you use PromoPilot. We are committed to protecting your privacy and ensuring the security of your data in compliance with GDPR and applicable privacy laws.

1. About This Policy

This Privacy Policy applies to the PromoPilot platform ("Service"), a marketing campaign management and AI-powered creative generation platform. By using our Service, you consent to the data practices described in this policy.

1.1 Data Controller

The data controller responsible for your personal information is:

BGO s.r.o.
Identification Number (IČO): 19173661
Registered in the Czech Republic
Email: info@promopilot.com
Website: https://promopilot.com

1.2 Scope

This policy covers all data processing activities related to PromoPilot, including our website, web application, API services, and any related services we provide.

2. Information We Collect

2.1 Information You Provide Directly

When you register and use our Service, we collect the following information:

Data Type Purpose Legal Basis (GDPR)
Email Address Account creation, authentication, communication Contract performance
Password Account security (stored as encrypted hash) Contract performance
First Name, Last Name Account personalization, communication Contract performance
Payment Information Credit purchases, billing (processed by Stripe) Contract performance
Campaign Data Campaign creation, AI processing, asset generation Contract performance
Brand Materials Brand analysis, style guide generation Contract performance
Marketing Content Strategy generation, creative asset production Contract performance

2.2 Information We Collect Automatically

2.3 Information from Third-Party Services

Important: We do NOT use client-side tracking cookies, analytics cookies (like Google Analytics), or any third-party advertising trackers. All analytics are performed server-side for your privacy.

3. How We Use Your Information

3.1 Service Delivery

3.2 Service Improvement

3.3 Communication

3.4 Legal Compliance

4. Third-Party Services & Data Processing

We use the following third-party services to operate PromoPilot. These services may process your data as described below:

4.1 Cloud Infrastructure

4.2 AI & Machine Learning Services

We send your campaign data, brand materials, and content to the following AI services for processing:

AI Data Processing Notice: When you use PromoPilot, your campaign content, brand materials, and prompts are sent to AI services for processing. These services may temporarily process your data to generate outputs but do not use your data to train their models without separate consent agreements.

4.3 Payment Processing

4.4 Data Processing Locations

Your data may be processed in the following locations:

5. Data Security

We implement industry-standard security measures to protect your personal information:

5.1 Technical Security Measures

5.2 Organizational Security Measures

5.3 Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities within 72 hours as required by GDPR.

6. Data Retention

6.1 Retention Periods

We retain your personal information for the following periods:

Data Type Retention Period Reason
Active Account Data Duration of account + 90 days after deletion Service provision, legal compliance
Campaign Data Duration of account + 90 days after deletion Service provision, data recovery
Generated Assets Duration of account + 90 days after deletion Service provision, download access
Payment Records Duration of account + 90 days after deletion Financial reporting, tax compliance
Security Logs 90 days Security monitoring, fraud prevention
System Logs 90 days Debugging, performance monitoring
Analytics Data (Aggregated) Indefinitely (anonymized) Service improvement, business analytics

6.2 Account Deletion

When you delete your account:

Data Recovery Window: Within 90 days of account deletion, you may contact us to restore your account. After 90 days, all data is permanently deleted and cannot be recovered.

7. Your Privacy Rights (GDPR)

As a user in the European Union, you have the following rights under GDPR:

7.1 Right of Access

You have the right to request a copy of all personal data we hold about you. To exercise this right, contact us at info@promopilot.com with subject line "Data Access Request".

7.2 Right to Rectification

You can update your personal information (name, email, password) directly in your account settings. For other corrections, contact us at info@promopilot.com.

7.3 Right to Erasure ("Right to be Forgotten")

You can delete your account at any time through your account settings. This will permanently delete all your personal data within 90 days. For immediate deletion, contact us at info@promopilot.com.

7.4 Right to Restrict Processing

You can request that we limit how we process your personal data. Contact us at info@promopilot.com to exercise this right.

7.5 Right to Data Portability

You can export your campaign data, brand materials, and generated assets at any time through the application interface. For a complete data export, contact us at info@promopilot.com.

7.6 Right to Object

You can object to certain types of processing, including:

7.7 Right to Withdraw Consent

Where we process data based on your consent, you can withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.

7.8 Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

7.9 Response Time

We will respond to all requests within 30 days. If we need more time, we will inform you of the delay and the reason.

8. Cookies & Tracking

8.1 Essential Cookies Only

PromoPilot uses only essential cookies necessary for the Service to function. We do NOT use:

8.2 Authentication Cookies

We use the following essential cookies:

8.3 Server-Side Analytics

All usage analytics are performed server-side and do not involve client-side tracking. We analyze:

This data is aggregated and anonymized for analytics purposes.

9. Marketing Communications

9.1 Current Status

We currently do NOT send marketing emails. We only send:

9.2 Future Marketing Communications

In the future, we may offer optional marketing communications to inform you about:

9.3 Your Marketing Preferences

Before we send any marketing communications, we will:

9.4 How to Opt Out

If we introduce marketing emails in the future, you can opt out:

10. AI-Generated Content & Privacy

10.1 How AI Processes Your Data

When you use PromoPilot's AI features, your data is processed as follows:

10.2 AI Provider Policies

Our AI service providers have committed to the following:

10.3 Your Content Ownership

Sensitive Information: Do not include sensitive personal data, confidential business information, or trade secrets in your campaigns unless necessary for the service. We cannot control how AI models process this information.

11. Data Sharing & Disclosure

11.1 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

11.2 When We Share Data

We share your data only in the following circumstances:

11.3 Anonymized Data

We may share aggregated, anonymized data that cannot identify you personally for:

12. Children's Privacy

PromoPilot is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16.

If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information immediately.

If you believe we have collected information from a child under 16, please contact us at info@promopilot.com.

13. International Data Transfers

PromoPilot operates globally and may transfer your data across international borders:

13.1 Primary Data Location

13.2 Transfers Outside the EU

Some AI processing services are located outside the EU:

13.3 Your Rights

You have the right to request information about international data transfers and the safeguards in place. Contact us at info@promopilot.com for details.

14. Changes to This Privacy Policy

14.1 Policy Updates

We may update this Privacy Policy from time to time to reflect changes in:

14.2 Notification of Changes

When we make material changes to this policy, we will notify you by:

14.3 Your Consent

Your continued use of PromoPilot after we publish changes constitutes your acceptance of the updated policy. If you disagree with changes, you may delete your account.

15. Contact Us & Data Protection Officer

15.1 Privacy Inquiries

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email: info@promopilot.com
Subject Line: Privacy Inquiry - [Your Request Type]
Website: https://promopilot.com

15.2 Data Controller

BGO s.r.o.
Identification Number (IČO): 19173661
Registered in the Czech Republic
Company Registry

15.3 Response Time

We aim to respond to all privacy inquiries within:

15.4 Supervisory Authority

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority. For Czech Republic users:

Úřad pro ochranu osobních údajů (ÚOOÚ)
Office for Personal Data Protection
Website: https://www.uoou.cz

16. Additional Information

16.1 Related Policies

This Privacy Policy should be read in conjunction with:

16.2 Language

This Privacy Policy is provided in English. In the event of any conflict between different language versions, the English version shall prevail.

16.3 Severability

If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.


Summary of Key Points

Quick Reference:

  • ✅ We collect only data necessary to provide the Service
  • ✅ Your data is encrypted and securely stored in the EU
  • ✅ We do NOT use tracking cookies or sell your data
  • ✅ AI processing is performed by GDPR-compliant providers
  • ✅ You can export or delete your data at any time
  • ✅ All data is deleted within 90 days of account closure
  • ✅ We currently do NOT send marketing emails
  • ✅ Full GDPR compliance with all privacy rights honored