Перейти до вмісту

Privacy Policy — AI Advisory Board Course

Effective date: June 24, 2026 Revision date: 2026-10-07 Version: 2.0 (for the course.aiadvisoryboard.me platform)

This Privacy Policy describes how TOV «TU EVENT PARTNERS» (Ukrainian limited liability company; "we", "us", the "Provider", the "Controller") collects, uses, stores and discloses your information in connection with your use of the course.aiadvisoryboard.me platform and related services (the "Service").

1. Data controller

TOV «TU EVENT PARTNERS»

  • EDRPOU (company registration code): 43521211
  • Address: 5A Tershakovtsiv St., Lviv, Ukraine
  • Email: ceo@aiadvisoryboard.me

For B2B customers: when an organization provides us with personal data of its employees (students) to give them access, the Provider acts as a processor for that data and the customer organization acts as the Controller. The Provider is the Controller of its own service data (logs, analytics, technical metrics).

2. What data we collect

2.1. Account data

  • first name, last name;
  • email address;
  • interface language, time zone;
  • Telegram username and chat ID (if the user connected the Telegram bot @vibevodingbot);
  • Google account ID (if signing in via Google SSO).

2.2. Learning and activity data

  • progress through course modules (lessons viewed, homework completed, scores);
  • contents of homework and the final project;
  • history of conversations with the AI assistant;
  • session metadata: sign-in/sign-out time, IP address, browser type, device type.

2.3. B2B data (for employees of organizations)

  • role in the organization (Owner / Manager / Member / HR / Observer);
  • the fact of a seat being assigned/revoked by a manager;
  • participation in student replacements (as the replaced person or as the new participant).

2.4. Payment information

  • the fact of payment, amount, date, unique invoiceId;
  • payment method (bank / Monobank);
  • we do NOT store card numbers, CVV/CVC or other sensitive payment details — all processing takes place on the side of Monobank Acquiring (PCI DSS Level 1).

2.5. Automatically collected data

  • IP address (kept in activity logs for 90 days);
  • cookies and local storage (details in the Cookie Policy /legal/cookies);
  • analytics events (page views, clicks) in anonymized or pseudonymized form.

3. How we use data

3.1. Providing the Service:

  • authentication and authorization;
  • delivering course content and tracking progress;
  • generating AI answers to user questions;
  • sending reminders via the Telegram bot or email.

3.2. Managing a B2B organization:

  • showing the manager a team activity dashboard;
  • classifying students by status (active / newcomer / falling behind);
  • enforcing the replacement policy (Replace Policy — see Section 6).

3.3. Financial operations:

  • issuing invoices, processing payments and refunds;
  • bookkeeping in accordance with the requirements of Ukrainian tax law.

3.4. Support and improvement:

  • technical support for users;
  • fixing bugs, error monitoring (Sentry-like);
  • analytics to improve the course.

3.5. Security:

  • preventing fraud, abuse and brute-force attacks;
  • a detector of suspicious seat rotations (anti-abuse).

3.6. Legal bases for processing (GDPR / Law of Ukraine "On Personal Data Protection"):

Data categoryLegal basis
Account, activityPerformance of a contract (Art. 6(1)(b) GDPR)
Payment dataPerformance of a contract + legal obligation (fiscal)
AI chat historyPerformance of a contract + legitimate interest (improvement)
Analytics cookiesUser consent (cookie banner)
Replacement audit, anti-abuse hashesLegitimate interest (protecting the model, security)
Marketing emailsUser consent (opt-in)

4. Who has access to data

4.1. Within the Provider:

  • founder and CEO (full access);
  • technical team (with admin actions logged);
  • administrative assistant (Olha) — limited access to feedback and CRM, without the ability to change security settings.

4.2. Managers of customer organizations:

  • see data of their own employees only;
  • access is limited to email, name, learning progress, activity status;
  • do NOT see: a student's AI chat history, IP addresses, technical logs.

4.3. Subprocessors (third parties to which data is transferred in order to provide the Service):

SubprocessorPurposeData location
Hetzner Online GmbHServer and database hostingGermany (EU)
Monobank (Universal Bank)Payment gatewayUkraine
Anthropic, PBCPaid tier of the AI advisor for organizations (Claude API)USA (DPF/SCC)
OpenRouter Inc.Routing requests to AI models (including Gemini for "My Day")USA (DPF/SCC)
Telegram FZ-LLCNotification botUAE/global
Google LLCOAuth SSO, Google Calendar; AI features of "My Day" (Gemini 2.5 Flash)USA (DPF)
NVIDIA CorporationAI text processing in platform features via NVIDIA NIM (including CRM dossiers and role generation); not the AI features of "My Day"USA
OpenAIOnly when the user connects ChatGPT themselves; processed by OpenAI on the user's sideUSA
ResendTransactional emailUSA (DPF)
Perplexity AI Inc.Research (internal use)USA

Data Processing Agreements (DPAs) are in place with all subprocessors, and for transfers outside the EU — Standard Contractual Clauses (SCC) or DPF certification.

4.4. Public authorities: we disclose data only on the basis of an official request under the laws of Ukraine.

5. Retention periods

CategoryPeriod
Active user accountAs long as the account exists
Learning progress12 months after the organization's subscription ends
AI chat content90 days (then anonymized)
Activity logs (IP, User-Agent)90 days
Replacement audit log (B2BReplaceAudit)Indefinitely (see Section 6)
Anti-abuse email hashesIndefinitely (as long as the organization exists)
Payment documents (invoices, receipts)3 years (fiscal law requirement)
Database backups14 days (rolling)
Marketing email listsUntil consent is withdrawn

6. Special policy on student replacements (Replace Policy)

6.1. When a manager replaces a student in an organization:

  • The replaced person's personal data (email, name, progress) is anonymized 90 days after the actual replacement.
  • A cryptographic hash of the email salted per organization (sha256(email + per_org_salt)) is kept indefinitely.
  • An audit log record of the replacement itself (tier, organization ID, timestamp) is kept indefinitely.

6.2. The legal basis for keeping the hash and the audit log is the legitimate interest of the Provider in:

  • preventing abuse of the replacement feature (re-inviting replaced emails);
  • SOC 2 compliance (a recommended minimum of 12 months of audit log for digital services);
  • protecting the business model from circumvention of license limits.

6.3. The right to be forgotten (Art. 17 GDPR) is limited with respect to the hash:

  • the hash is a technically one-way transformation and does not allow the email to be recovered;
  • deleting the hash would harm the Provider's legitimate interests and our ability to protect the model;
  • we respond to "forget me" requests by deleting the personal data itself (email, name, progress), leaving only an unlinked hash.

6.4. If a customer organization ceases its activity, hashes associated with that organization may be deleted at the request of the organization's owner (sent to ceo@aiadvisoryboard.me).

7. International data transfers

7.1. Some subprocessors (Anthropic, OpenRouter, Telegram, Google) are located outside the EU/Ukraine.

7.2. Data is transferred to the USA on the basis of:

  • the EU-US Data Privacy Framework (DPF) — for certified companies;
  • the European Commission's Standard Contractual Clauses (SCC) — for the rest.

7.3. The user consents to such transfer to the extent necessary to provide the Service.

8. Data security

8.1. Technical measures:

  • traffic encryption (TLS 1.3);
  • passwords are stored as a bcrypt hash, never in plain text;
  • sessions — JWT with a limited lifetime (7 days) and HttpOnly + Secure + SameSite=Lax cookies;
  • isolated databases in Docker containers;
  • daily backups;
  • regular code security audits (cross-review by several AI models).

8.2. Organizational measures:

  • restricted access to the production environment (founder only);
  • logging of all admin actions with 12-month retention;
  • internal data processing rules binding on the team.

8.3. In the event of a data breach:

  • the User will be notified within 72 hours (GDPR Art. 33-34 requirement);
  • the notice will be published on the Service's main page and sent by email/Telegram.

9. Your rights

9.1. As a data subject, you have the right:

  • of access — to receive a copy of your data that we process;
  • to rectification — to update inaccurate or outdated data yourself via /cabinet/settings or by contacting us;
  • to erasure (right to be forgotten) — with exceptions for the replacement audit log (Section 6.3) and fiscal documents (Section 5);
  • to restriction of processing — to suspend certain types of processing;
  • to data portability — to receive data in a machine-readable format (JSON);
  • to object — to processing based on legitimate interest;
  • to withdraw consent — for marketing messages and non-essential cookies;
  • to lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or another EU supervisory authority.

9.2. To exercise your rights, contact ceo@aiadvisoryboard.me — we will respond within 30 calendar days.

10. AI processing

10.1. The Provider uses the following AI processors depending on the feature:

  • Google LLC via OpenRouter Inc. — AI features of "My Day": advisor, chat, voice, agent and summaries. The model is Gemini 2.5 Flash (fallback — Gemini 2.5 Flash-Lite); texts pass through OpenRouter (USA) and Google. Personal AI advice — with the user's consent; the manager's advisor analyzes the records available to the manager without separate consent from the subordinate.
  • Voice in "My Day": primary recognition is performed by the browser's SpeechRecognition; as the app's voice input notice states, in Chrome and Edge the voice is recognized by Google and the audio does not reach our server. The fallback server path sends audio to Google via OpenRouter with consent to AI; the app does not store audio, the bytes live in the request's memory.
  • NVIDIA Corporation (NVIDIA NIM) — text processing in platform features, including CRM dossiers and role generation. This route is not used for the AI features of "My Day".
  • Anthropic, PBC (Claude API) — the paid tier of the AI advisor for organizations.
  • OpenAI — only when the user connects ChatGPT themselves via MCP; processing happens on the user's side and the calls are paid for by OpenAI. Access can be revoked in "Connections".

Beyond "My Day", AI processing is used to generate answers in the chat assistant, analyze homework (with consent) and for automatic classifications (student status, question type).

The "My Day" routine map is computed from the records themselves without an AI model, so it works without Gemini and without enabling AI advice. Hosting the server in the EU does not mean that AI data is processed only in the EU.

The models used in "My Day" are listed at aiadvisoryboard.me/en/my-day/models.

10.2. The User acknowledges that:

  • text entered into the AI chat is transferred to third-party AI providers;
  • terms of data retention and use depend on the respective provider and route; statements about the Claude API do not automatically extend to all of the processors listed;
  • AI can make mistakes — the user makes critical decisions (legal, medical, financial) on their own.

10.3. It is prohibited to enter into the AI chat:

  • trade secrets of other persons;
  • personal data of third parties without their consent;
  • illegal, offensive or harmful content.

11. Cookies

Details are in the Cookie Policy (/legal/cookies).

12. Children

The Service is not intended for persons under 16. If we learn that we have collected data of such a person without the consent of their legal representatives, we will delete it without delay.

13. Changes to this Policy

13.1. We may update this Policy. The "Version" date at the top of the document reflects the latest update.

13.2. We will notify you of material changes (new data categories, new subprocessors, changes in processing purposes):

  • via a banner in the Service;
  • by email to the account address;
  • in the Telegram bot (if connected).

13.3. Continued use of the Service after the Policy is updated means acceptance of the new version.

14. Website visitor analytics (B2B)

We use our own visitor analytics system to better understand which companies and previously known contacts are interested in our business products. The basis for processing is legitimate interest within B2B marketing.

What data is processed:

  • First-party cookie vis_id — a technical browser identifier (contains no personal data) so that one visit is not counted twice. Kept for up to 13 months.
  • Technical visit data — pages viewed, referrer, UTM tags, device type, visit time.
  • IP address — used temporarily to determine the country and (for organizations with their own networks) an approximate company name. We delete the raw IP address within 30 days. Long-term analytics relies only on derived data (company domain, network type).
  • Visits via personal links — if you followed a personalized link from our email, we may associate the visit with your email address to continue a conversation already started. The tokens themselves are stored only as a cryptographic hash.

Visitors from the EU/EEA are NOT tracked by default (the country is determined using the GeoLite2 database). We also respect the Global Privacy Control (GPC) signal — if your browser sends it, no identification is performed.

What we do NOT do: we do not sell or transfer this data to third parties; we do not send automated messages based on analytics results (any communication is prepared and checked by a human); we do not track your activity outside our websites.

Your rights: you can request deletion of your data by writing to ceo@aiadvisoryboard.me — we will delete all records associated with your email address.

14a. Chrome extension for employees ("AI Advisory Board Call Cockpit")

The extension is intended only for AI Advisory Board employees and is distributed via a direct link (it cannot be found by searching the Chrome store). In short: it reads a personal access token from the connection page on our website, stores it locally in the browser (chrome.storage), asks our server once a minute for upcoming meetings and shows a notification before they start. No data is transferred to third parties; pages of other websites are not read.

The full text (permissions with justification, storage, deletion) is a separate document referenced by the Chrome Web Store listing: Privacy Policy of the "AI Advisory Board Call Cockpit" extension. It is the single source of truth for the extension; this paragraph remains here only as a pointer.

15. Contacts

For privacy questions, exercising data subject rights, complaints and requests, write to: ceo@aiadvisoryboard.me

Optional channel: Telegram @vibevodingbot (for authorized users — questions are routed to the Provider automatically).