Privacy policy
This Privacy Policy explains how ROIFORCIO GmbH processes personal data in connection with the Pitch Avatar service, and sets out the information required by Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).
1. Controller and contact details
1.1. The controller is ROIFORCIO GmbH, FN 461562v, 15/62 Wallgasse, 1060 Vienna, Republic of Austria.
1.2. Contact for all matters, including data protection matters and the exercise of data subject rights: info@roi4cio.com. A request concerning personal data should be marked “data protection” in the subject line so that it is routed without delay. We have not appointed a data protection officer, as the conditions of Article 37(1) GDPR are not met; the contact point above answers all data protection enquiries.
1.3. Where we process personal data contained in the content uploaded by a business customer, that customer is the controller and we act as processor on its behalf, under our Data Processing Agreement. In that case the customer’s own privacy notice applies to the data subjects concerned, and this Policy describes our role as processor only.
2. What we process, why, and on what legal basis
Processing | Data | Purpose | Legal basis | Retention |
Account registration and provision of the Service | Name, job title, e-mail address, organisation, account credentials, subscription and configuration data | Creating and administering the account, providing the contracted functionality, authentication | Art. 6(1)(b) — performance of the contract | For the term of the account and 30 days thereafter; billing-related records as below |
Content uploaded and generated | Documents, presentations, links, prompts, images, audio and video, voice samples, avatars, generated outputs | Generating the outputs requested by the user and maintaining the user’s knowledge base | Art. 6(1)(b); where the content contains data of third parties, the customer’s own basis under its Data Processing Agreement | Until deleted by the user; on termination, 30 days for export plus 60 days for deletion |
Audience interaction | Views, engagement and interaction data relating to presentations, questions put to the Chat-avatar, contact data voluntarily supplied by a viewer | Delivering the presentation, operating the Chat-avatar, providing analytics to the user who deployed the content | Art. 6(1)(b) towards the user; as processor on the customer’s behalf towards the viewer | For the term of the account, unless deleted earlier |
Billing and taxes | Billing name and address, VAT number, transaction data (card data are processed by the Merchant of Record, not by us) | Invoicing, collection, accounting and tax compliance | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation (§ 132 BAO, § 212 UGB) | 7 years from the end of the calendar year concerned |
Support and correspondence | Contact data, content of the enquiry, technical diagnostic data | Answering enquiries, resolving incidents | Art. 6(1)(b) and Art. 6(1)(f) — legitimate interest in answering enquiries | 3 years from closure of the enquiry |
Security, logging and abuse prevention | IP address, device and browser data, access and security logs, records of suspected misuse | Securing the Service, preventing fraud and misuse, enforcing the Acceptable Use Policy | Art. 6(1)(f) — legitimate interest in the security and integrity of the Service; Art. 6(1)(c) where reporting is required by law | 12 months; longer where required for an investigation or a legal claim |
Analytics and improvement of the Service | Usage and device data, in aggregated or pseudonymised form | Understanding how the Service is used and improving it | Art. 6(1)(a) — consent, where set by cookie or equivalent technology; otherwise Art. 6(1)(f) | Up to 14 months |
Marketing communications | Name, e-mail address, organisation, engagement with communications | Sending information on our products and offers | Art. 6(1)(a) — consent; or § 174(3) TKG 2021 for our own similar products to existing customers, with an opt-out in every message | Until withdrawal of consent or objection |
Establishment and defence of legal claims | The data relevant to the claim | Asserting, exercising or defending legal claims | Art. 6(1)(f) — legitimate interest in the defence of claims | Until expiry of the applicable limitation period (in general 3 years, up to 30 years) |
Compliance with sanctions and export control | Identification data of the customer and, where applicable, of its beneficial owners | Screening against sanctions and restricted-party lists | Art. 6(1)(c) — legal obligation | For the term of the relationship and 5 years thereafter |
2.1. Where processing is based on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal. Where processing is based on our legitimate interest, you may object to it under Article 21 GDPR.
2.2. Providing the data marked as necessary at registration and at purchase is a contractual requirement; without it the account cannot be created and the Service cannot be provided. Providing any other data is voluntary.
2.3. We do not sell personal data.
3. Processing in connection with the AI features
3.1. The Service includes artificial intelligence features (the Chat-avatar, AI presenters and avatars, voice generation and cloning, video translation and dubbing). The content you upload and the prompts you submit are processed to generate the requested outputs and, where applicable, to maintain a retrieval-augmented generation knowledge base within your account.
3.2. Certain generative capabilities are performed by third-party providers of general-purpose AI models acting as our processors and listed in Section 6. The input necessary to generate a response is transmitted to the relevant provider on a need-to-process basis.
3.3. Content processed through the retrieval-augmented generation system is hosted within the European Union, is not used to train publicly available or general-purpose AI models, and is not shared with other customers. We have contracted for that restriction with the providers concerned.
3.4. Voice and likeness. Voice samples, facial images and video recordings submitted for the creation of an avatar, a synthetic voice or a translated recording are processed solely to produce the output requested by the user. They are not used to identify or authenticate any natural person and are not processed for the purpose of uniquely identifying a natural person; they therefore do not constitute biometric data within the meaning of Article 4(14) GDPR and are not processed under Article 9 GDPR. We do not compare a submitted voice or image against any reference sample.
3.5. The user who submits a voice sample or an image of another person must hold that person’s documented consent, as required by the Acceptable Use Policy. Such material is retained in the user’s account for re-use until it is deleted by the user, and in any event in accordance with the Data Processing Agreement.
3.6. The outputs generated by the Service carry a machine-readable marking identifying them as artificially generated or manipulated, as described in the Synthetic Content Marking Policy.
3.7. We do not use the AI features to take decisions producing legal effects concerning a natural person or similarly significantly affecting them; no automated individual decision-making within the meaning of Article 22 GDPR takes place.
4. Special categories of data
4.1. The Service is not intended for the processing of the data referred to in Article 9(1) GDPR. Users must not upload such data and must not use the Service for the identification or authentication of natural persons without our prior written agreement.
5. Cookies and similar technologies
5.1. We use technically necessary cookies to operate the website and to maintain a session; these are set on the basis of § 165(3) TKG 2021 and Article 6(1)(f) GDPR. Analytics and preference cookies are set only with your consent, given through our cookie banner, which you may withdraw at any time through the same banner or through your browser settings.
6. Recipients and processors
6.1. We disclose personal data only to the recipients necessary for the purposes set out above: our processors listed below, our professional advisers bound by confidentiality, and public authorities where required by law.
Recipient | Purpose | Role | Location / safeguard |
Amazon Web Services | Hosting infrastructure, including the retrieval-augmented generation environment | Processor | European Union (Frankfurt); SCC where applicable |
Microsoft Azure | Cloud computing and ancillary services | Processor | European Union region; SCC where applicable |
OpenAI | Natural language processing and generation | Processor | United States; SCC; no training on customer content |
Salesforce / HubSpot | Customer relationship management, support and marketing communications | Processor | SCC |
FastSpring (Bright Market, LLC) | Payment processing as Merchant of Record | Independent controller in respect of payment data | United States; SCC |
Google Analytics | Website and product analytics | Processor | SCC; set only with consent |
Matomo | Product analytics | Processor | European Union |
Stonly | In-product user guidance and help content | Processor | European Union |
6.2. This list is kept up to date and supersedes any inconsistent earlier statement, including any statement that hosting is limited to a single provider. Business customers are notified of changes to the list in accordance with the Data Processing Agreement.
7. International transfers
7.1. Personal data are stored within the European Economic Area. Where a transfer to a third country is necessary — in particular to a provider established in the United States — it takes place on the basis of an adequacy decision under Article 45 GDPR or of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 under Article 46 GDPR, supplemented where necessary by additional measures identified in a transfer impact assessment. A copy of the safeguards applied may be obtained at info@roi4cio.com.
8. Security
8.1. We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS 1.2 / 1.3) and at rest (AES-256), role-based access control and multi-factor authentication for administrative access, logical separation of customer environments, logging, regular vulnerability scanning and continuous monitoring, backup and restoration procedures, and staff confidentiality undertakings and training. The measures applicable to processing on behalf of business customers are set out in Annex II to the Data Processing Agreement.
8.2. Upon becoming aware of a personal data breach we notify the competent supervisory authority in accordance with Article 33 GDPR and, where the conditions of Article 34 GDPR are met, the data subjects concerned. Business customers are notified within 48 hours, as provided in the Data Processing Agreement.
9. Retention
9.1. We retain personal data for the periods set out in Section 2. Where a retention period has expired, the data are deleted or irreversibly anonymised, save where their retention is required by law or necessary for the establishment, exercise or defence of legal claims. Data contained in backup media are deleted in accordance with the backup rotation cycle, which does not exceed 90 days.
10. Your rights
10.1. You have the right to obtain confirmation as to whether we process personal data concerning you and access to those data (Article 15 GDPR), to obtain rectification (Article 16), erasure (Article 17) and restriction of processing (Article 18), to data portability (Article 20), to object to processing based on our legitimate interest, including profiling (Article 21), and to withdraw consent at any time (Article 7(3)).
10.2. Requests may be addressed to info@roi4cio.com. We answer without undue delay and in any event within one month, which may be extended by two further months where necessary, in which case we inform you of the extension and of its reasons. We verify the identity of the person making the request before acting on it.
10.3. Where the personal data concerned are contained in content uploaded by a business customer, we act as processor and forward the request to that customer, who is the controller and responsible for answering it.
10.4. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The competent authority for ROIFORCIO GmbH is the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).
11. Sources of data not obtained from you
11.1. Where we do not obtain the data from you directly, they originate from the business customer or user who uploaded the content in which they are contained, from a person who sent you a presentation created with the Service, from our authorised partners and resellers in connection with a purchase made through them, or from publicly accessible sources used for sanctions and restricted-party screening. The categories of data concerned and the purposes of their processing are those set out in Section 2.
12. Children
12.1. The Service is intended for professional and business use and is not directed at persons under 18 years of age. We do not knowingly process the personal data of such persons and delete them upon becoming aware of them.
13. Changes to this Policy
13.1. We may update this Policy. The current version is published on this page with its effective date. Where a change materially affects the processing of your personal data, we notify registered users by e-mail not less than 30 days before it takes effect, in accordance with Section 13 of the Terms of Use.