This policy explains how Annapolis Tour S.R.L. ("we", "ARIA") collects, uses, and protects personal data in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679).
1. Who the data controller is
ARIA is a service operated by Annapolis Tour S.R.L., a Romanian legal entity, CUI 38461850, registration no. J2017003056086, with its registered office at Str. Gheorghe Bariţiu nr. 18, Brașov, 500025. For the data of visitors to the ariaknows.com website, Annapolis Tour S.R.L. is the data controller.
For the data of the customers of the businesses that use ARIA at their front desk (for example, the guests of a hotel), that business is the data controller, and we are only the processor. The relationship is governed by a separate Data Processing Agreement (DPA).
2. What data we collect
From website visitors:
- IP address (for security and abuse prevention)
- Browser and device data (for optimising the website)
- Information you send us voluntarily through the contact forms or WhatsApp
From the customers of the businesses that use ARIA:
- The content of conversations with ARIA (text messages, transcripts of voice messages)
- Contact identifiers (telephone number, email, where provided)
- Conversation metadata (time, channel, detected language)
3. On what legal basis
Data is processed on the basis of:
- Consent (Art. 6.1.a GDPR): for the newsletter or direct marketing, if you subscribe
- Performance of a contract (Art. 6.1.b GDPR): in order to deliver the ARIA service to you
- Legitimate interest (Art. 6.1.f GDPR): for security, fraud prevention, and improving the product through aggregated metadata
4. How long we keep data
| Data type | Retention period |
|---|---|
| Customer conversations | 12 months rolling, or according to the client business's own policy |
| Technical logs | 30 days |
| IP addresses in analytics | 14 days |
| Billing data | 10 years (legal obligation) |
| Contact requests (email) | 2 years |
5. Who we transfer data to
Your data is not sold. We use it only inside ARIA and with specific, audited subprocessors. The full list of subprocessors is published in our DPA and includes at least: the hosting provider (Contabo, in the EU), the language model provider (Mistral AI, in the EU), the voice transcription provider (Soniox, on its European access point), and, for voice synthesis on telephone calls, ElevenLabs, in the USA, covered by standard contractual clauses.
No subprocessor has the right to use your data for any purpose other than delivering the service.
6. Where data is stored
In the European Union. See the Security page for technical details.
7. Your rights under the GDPR
You have the right to:
- Access the data we process about you (Art. 15)
- Correct inaccurate data (Art. 16)
- Erase your data ("the right to be forgotten", Art. 17)
- Restrict processing (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing (Art. 21)
- Lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP)
To exercise any of these rights, send an email to [email protected]. We reply within 30 days at the latest.
8. Cookies
We use cookies that are strictly necessary for the website to work (session, security). We do not use tracking or advertising cookies. We do not need a consent banner, because we do not use non-essential cookies.
9. Changes
This policy may be updated. The current version is dated at the top of the page. Material changes will be communicated by email to active customers at least 30 days before they take effect.
10. Contact
For any question relating to personal data: [email protected].
Translation
This page is an English translation of the Romanian original. In case of any discrepancy between the two versions, the Romanian version at ariaknows.com/confidentialitate prevails.