Skip to content

Privacy Policy

Last updated: 6 September 2026

Translation Notice: This English translation was produced with the assistance of artificial intelligence (LLM) and is provided for informational purposes only. In the event of any discrepancy between the English and Slovak versions, the Slovak version shall prevail. The relationship is governed by the law of the Slovak Republic.

The legally binding version is available at: /sk/legal/privacy

Effective from: 5 September 2026 · replaces the version of 14 August 2026 (version 2.2)

Change from the version of 14 August 2026: the section “Website measurement” has been added (anonymous event counts on our own infrastructure, with no cookies, retained for 60 days) and the contact addresses have been updated to the aiprioritymap.com domain.

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”), together with Act No 18/2018 Coll. on the protection of personal data (the “Data Protection Act”), requires the controller to tell the data subject what their personal data will be used for — including where that data was not obtained from the data subject directly.

2.1 Controller

DDN Consulting s.r.o., registered office Bodíky 222, 930 31 Bodíky, IČO 55 879 128, registered in the Commercial Register of the Slovak Republic kept by Okresný súd Trnava, Section: Sro, File No. 55445/T

General enquiries: [email protected]

Data protection enquiries: [email protected]

2.2 What We Collect

What we process depends on the service:

  • Paid services, such as the AI Foundation Audit: company identification details (name, company registration number, tax number, registered office); contact details for the contact person (name, email, telephone); process data, meaning the information about company processes supplied during the audit; and technical data (IP address, browser type, cookies).
  • Free online tools, such as the EU AI Act Documentation Pack: the contact email entered when the output is requested, together with the details about the company's systems or activities that the user enters in the questionnaire. These tools are designed not to require personal data beyond that contact email, and users are asked not to enter personal data or confidential information in free-text fields.
  • Outreach to prospective customers: as set out in the separate “Prospective customer data” section below.
  • AI visibility reports: the business details and questions you enter in the order questionnaire (business name, market, competitors and claims), the answers the AI assistants return about your business, and the report generated from them. Please do not enter personal data or confidential information in free-text fields.
  • Free AI Answer Check: what we store is the business name and category you typed, the town and offering you confirmed, the result of the check, and the run IDs of the answers behind it. The town and offering are stored inside the question we asked, word for word. The website address is stored as its domain only, never the full address, together with a one-way hash of that domain. We do not keep the assistants' answers in the check record — the check is stored as its result, not as text. The result document the check composes for you does quote the answers word for word; it is kept for 24 hours so we can hand you the same document again, and is then deleted. To prevent abuse we count requests against the IP address of your connection in the server's memory only, for one minute and for one day; no IP address, and no fingerprint of one, is written to our database. If you ask us to email the result, or to run the check for you the next day, we store your email address. Ask for the same business again within 24 hours and we show you the stored result instead of running a new check. We keep the check record for 60 days, we build no profile from it, and we do not sell it; an email address you give us also enters our contact records, which we keep until you unsubscribe.
  • Website measurement: counts of anonymous events on our own website, such as a page being viewed or a checkout being started. Each count records only the name of the event, the time, the language, the name of the page, the presentation variant and, where relevant, the product and the checkout step. We set no cookies, place nothing on your device and read nothing from it, and we record no identifier, no IP address and nothing you type. These counts are held on our own infrastructure and kept for 60 days.

The audit does NOT collect: financial statements or accounting data; personal data belonging to the company's own customers; internal trade secrets or commercial strategy; system credentials such as passwords and API keys; or employee data such as salaries and personal details.

2.3 Purpose of Processing

  • Supplying the service — carrying out the audit and generating the output
  • Invoicing and tax obligations
  • Communicating with the Client about the service
  • Operating and supporting the free AI Answer Check, and investigating abuse of it — for 60 days after a check, our own staff can open an internal, authenticated, read-only view of an individual check record: the business name, the question we asked word for word, and the result. Our legitimate interest is keeping the free check working, being able to answer your questions about it, and protecting it from abuse. No decision about you is taken from this view, we do not contact you because of it, and we build no profile from it.
  • Improving our service and checking that our own measurement method is accurate — for the paid AI visibility reports only, we use aggregated or pseudonymised review-label records that contain no answer text and no business names. This does not extend to the free AI Answer Check, whose check records are described above.
  • Checking the quality of what we deliver before we send it

2.4 Legal Basis

  • Article 6(1)(b) GDPR — performance of the contract
  • Article 6(1)(c) GDPR — legal obligation (invoicing, tax)
  • Article 6(1)(f) GDPR — legitimate interests (improving the service, direct B2B marketing, operating and supporting the free AI Answer Check and investigating abuse of it)

2.5 Retention

Retention periods differ by purpose and by service:

  • Audit process data (AI Foundation Audit): 90 days after the report is delivered, then erased or anonymised automatically.
  • Questionnaire inputs and the stored AI answers (AI visibility reports): 60 days after the report is delivered, then erased. Review-label records kept to verify our method contain no answer text and no business names, and are anonymised when the underlying order data is erased.
  • Questionnaire inputs and generated outputs from the free tools, such as the EU AI Act Documentation Pack (other than the AI Answer Check, which has its own line below): 12 months from generation, then erased or anonymised; aggregated statistics that identify no one may be kept longer. Within that period the output can also be re-opened and refreshed through the link sent by email; once the period ends, that option lapses.
  • AI Answer Check (free tool): the check record — the business name and category, the town and offering, the domain and its hash, the result and the run IDs — 60 days from the check, then erased. The result document that quotes the answers: 24 hours. An email address given for the result or for a next-day run: 60 days in the check record; where it also enters our contact records, the “contact details and marketing consent” line below applies.
  • Invoices and accounting records: 10 years, as required by law.
  • Contact details and marketing consent: until consent is withdrawn.
  • Data from outreach to prospective customers: 6 months where there is no response; details below.

2.6 Your Rights as a Data Subject

As a data subject you have the following rights:

— to be told whether providing personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, whether you are obliged to provide it, and what the consequences of not providing it may be.

— to be told the source your personal data came from where it was not obtained from you, and, where relevant, whether it came from publicly accessible sources.

— to obtain confirmation from the controller as to whether it is processing personal data concerning you and, if so, to access that data and to receive the accompanying information: the purpose of the processing, the categories of data, the recipients, the retention period, the existence of the rights to rectification, erasure, restriction and objection, and the source of the data.

— to rectification: to have inaccurate personal data concerning you corrected by the controller without undue delay, and incomplete data completed.

— to erasure, the right to be forgotten, on the conditions in Article 17 GDPR. This right cannot be exercised effectively where the processing is necessary, in particular, for the establishment, exercise or defence of legal claims.

— to restriction of processing, on the conditions in Article 18 GDPR.

— to object to processing based on the controller's legitimate interests; in the case of direct marketing you may object at any time.

— to data portability, on the conditions in Article 20 GDPR.

— to withdraw consent at any time where the processing is based on consent; withdrawal does not affect the lawfulness of processing carried out beforehand.

— to lodge a request or complaint with a supervisory authority. The supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, Bratislava. Where the processing concerns a data subject in the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), ico.org.uk. For data subjects in the EU/EEA the Office for Personal Data Protection of the Slovak Republic has jurisdiction, or, where applicable, the supervisory authority in the member state of the data subject's habitual residence.

2.7 Processors and Third Parties; AI Tools

Data is NOT used to train AI models and is NOT passed to third parties for marketing.

In supplying the services the Provider uses the following categories of processor and technical tool: (i) a provider of an artificial-intelligence model, to generate the text of the outputs; (ii) a provider of AI-assisted office tools, to draft and process text; and (iii) a tool for finding and selecting contacts when approaching prospective customers. These processors handle personal data under a data processing agreement and solely for the purpose of supplying the service. Email is handled on the Provider's own email infrastructure within the aiprioritymap.com domain.

The Provider:

  • does not use Client input data to train AI models, and requires the same undertaking from its processors by contract;
  • enters no personal data into AI tools beyond what supplying the service requires, in line with its internal policy on the use of AI;
  • ensures that where a processor handles personal data outside the European Economic Area (EEA), the transfer rests on a European Commission adequacy decision or on standard data protection clauses under Article 46 GDPR.

Human review. Some deliverables are checked by a person before we send them: a reviewer at AI Priority Map reads the AI answers stored for your order and confirms that each mention we counted really refers to your business. The reviewer records only a verdict — no notes — and no copy of your answers leaves our systems. We keep those verdicts, without your business name or any answer text, to measure how accurate our own method is. This processing is based on Article 6(1)(f) GDPR (our legitimate interests). You can object at any time by emailing [email protected], and we will delete the verdicts recorded for your order.

2.8 Transfers to Third Countries

In supplying its services the controller does not transfer personal data to third countries or to international organisations, except where one of the processors — the AI tools described in section 2.7 — handles data outside the EEA; in that case the transfer rests on an adequacy decision or on standard data protection clauses under Article 46 GDPR. Email is handled by the controller on its own email infrastructure within the aiprioritymap.com domain.

Prospective Customer Data

If AI Priority Map contacted you by email without your having given us your details directly, this section explains how we process that data and what rights you have, in accordance with Article 14 of the UK GDPR and the EU GDPR.

Controller. DDN Consulting s.r.o., Bodíky 222, 930 31 Bodíky, Slovakia (IČO 55 879 128), operating the AI Priority Map brand. Data protection contact: [email protected].

What we hold. Your name, job title, work email address, employer, the public source where we found your details, and the business signal relevant to your role that prompted us to get in touch. We hold no special categories of personal data.

Purpose. Relevant business-to-business outreach about our service, addressed to the appropriate decision-maker in your organisation.

Legal basis. Legitimate interests under Article 6(1)(f) in relevant direct marketing of our professional services between businesses (recital 47). We have carried out a legitimate interests assessment, dated 21 June 2026; a summary is available on request.

Source. Public company websites, public professional profiles, and the UK Companies House register. Some work email addresses are derived with standard tools from standard patterns rather than copied from a published page.

Use of AI tools in outreach. We use an AI-assisted tool to find and select relevant contacts. The outreach itself — writing and sending the message — is not generated by artificial intelligence; a person does it. The AI tool therefore only supports contact research: it holds no automated conversation with you and takes no automated individual decisions producing legal effects concerning you or similarly significantly affecting you. You may object at any time and are entitled to human intervention — write to [email protected].

Recipients. Email is handled on our own email infrastructure within the aiprioritymap.com domain. We do not sell your data and do not pass it to third parties for marketing.

Retention. If you do not respond to our approach, we erase or block your record within 6 months. If you object, we keep a minimal record — email address, date, and the note “objected” — indefinitely, solely so that we can honour that objection (Article 6(1)(c) / Article 17(3)(b)).

Your rights. Access, rectification, erasure, restriction, portability where it applies, and — for direct marketing — an absolute right to object. To opt out, reply to our email with the word “remove” or contact us at [email protected]; we stop processing immediately and permanently.

Complaints. You may complain to a supervisory authority — the UK Information Commissioner's Office (ico.org.uk) or the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk).

(For recipients in the United Kingdom: the UK GDPR as amended by the Data (Use and Access) Act 2025. For recipients in the EU/EEA: Regulation (EU) 2016/679, the GDPR.)

Need help? Contact us at info [at] aiprioritymap [dot] com