Privacy policy

This Privacy Policy explains how ROIFORCIO GmbH processes personal data in connection with the Pitch Avatar service, and sets out the information required by Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).

1. Controller and contact details

1.1. The controller is ROIFORCIO GmbH, FN 461562v, 15/62 Wallgasse, 1060 Vienna, Republic of Austria.

1.2. Contact for all matters, including data protection matters and the exercise of data subject rights: info@roi4cio.com. A request concerning personal data should be marked “data protection” in the subject line so that it is routed without delay. We have not appointed a data protection officer, as the conditions of Article 37(1) GDPR are not met; the contact point above answers all data protection enquiries.

1.3. Where we process personal data contained in the content uploaded by a business customer, that customer is the controller and we act as processor on its behalf, under our Data Processing Agreement. In that case the customer’s own privacy notice applies to the data subjects concerned, and this Policy describes our role as processor only.

2. What we process, why, and on what legal basis

Processing

Data

Purpose

Legal basis

Retention

Account registration and provision of the Service

Name, job title, e-mail address, organisation, account credentials, subscription and configuration data

Creating and administering the account, providing the contracted functionality, authentication

Art. 6(1)(b) — performance of the contract

For the term of the account and 30 days thereafter; billing-related records as below

Content uploaded and generated

Documents, presentations, links, prompts, images, audio and video, voice samples, avatars, generated outputs

Generating the outputs requested by the user and maintaining the user’s knowledge base

Art. 6(1)(b); where the content contains data of third parties, the customer’s own basis under its Data Processing Agreement

Until deleted by the user; on termination, 30 days for export plus 60 days for deletion

Audience interaction

Views, engagement and interaction data relating to presentations, questions put to the Chat-avatar, contact data voluntarily supplied by a viewer

Delivering the presentation, operating the Chat-avatar, providing analytics to the user who deployed the content

Art. 6(1)(b) towards the user; as processor on the customer’s behalf towards the viewer

For the term of the account, unless deleted earlier

Billing and taxes

Billing name and address, VAT number, transaction data (card data are processed by the Merchant of Record, not by us)

Invoicing, collection, accounting and tax compliance

Art. 6(1)(b) and Art. 6(1)(c) — legal obligation (§ 132 BAO, § 212 UGB)

7 years from the end of the calendar year concerned

Support and correspondence

Contact data, content of the enquiry, technical diagnostic data

Answering enquiries, resolving incidents

Art. 6(1)(b) and Art. 6(1)(f) — legitimate interest in answering enquiries

3 years from closure of the enquiry

Security, logging and abuse prevention

IP address, device and browser data, access and security logs, records of suspected misuse

Securing the Service, preventing fraud and misuse, enforcing the Acceptable Use Policy

Art. 6(1)(f) — legitimate interest in the security and integrity of the Service; Art. 6(1)(c) where reporting is required by law

12 months; longer where required for an investigation or a legal claim

Analytics and improvement of the Service

Usage and device data, in aggregated or pseudonymised form

Understanding how the Service is used and improving it

Art. 6(1)(a) — consent, where set by cookie or equivalent technology; otherwise Art. 6(1)(f)

Up to 14 months

Marketing communications

Name, e-mail address, organisation, engagement with communications

Sending information on our products and offers

Art. 6(1)(a) — consent; or § 174(3) TKG 2021 for our own similar products to existing customers, with an opt-out in every message

Until withdrawal of consent or objection

Establishment and defence of legal claims

The data relevant to the claim

Asserting, exercising or defending legal claims

Art. 6(1)(f) — legitimate interest in the defence of claims

Until expiry of the applicable limitation period (in general 3 years, up to 30 years)

Compliance with sanctions and export control

Identification data of the customer and, where applicable, of its beneficial owners

Screening against sanctions and restricted-party lists

Art. 6(1)(c) — legal obligation

For the term of the relationship and 5 years thereafter

2.1. Where processing is based on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal. Where processing is based on our legitimate interest, you may object to it under Article 21 GDPR.

2.2. Providing the data marked as necessary at registration and at purchase is a contractual requirement; without it the account cannot be created and the Service cannot be provided. Providing any other data is voluntary.

2.3. We do not sell personal data.

3. Processing in connection with the AI features

3.1. The Service includes artificial intelligence features (the Chat-avatar, AI presenters and avatars, voice generation and cloning, video translation and dubbing). The content you upload and the prompts you submit are processed to generate the requested outputs and, where applicable, to maintain a retrieval-augmented generation knowledge base within your account.

3.2. Certain generative capabilities are performed by third-party providers of general-purpose AI models acting as our processors and listed in Section 6. The input necessary to generate a response is transmitted to the relevant provider on a need-to-process basis.

3.3. Content processed through the retrieval-augmented generation system is hosted within the European Union, is not used to train publicly available or general-purpose AI models, and is not shared with other customers. We have contracted for that restriction with the providers concerned.

3.4. Voice and likeness. Voice samples, facial images and video recordings submitted for the creation of an avatar, a synthetic voice or a translated recording are processed solely to produce the output requested by the user. They are not used to identify or authenticate any natural person and are not processed for the purpose of uniquely identifying a natural person; they therefore do not constitute biometric data within the meaning of Article 4(14) GDPR and are not processed under Article 9 GDPR. We do not compare a submitted voice or image against any reference sample.

3.5. The user who submits a voice sample or an image of another person must hold that person’s documented consent, as required by the Acceptable Use Policy. Such material is retained in the user’s account for re-use until it is deleted by the user, and in any event in accordance with the Data Processing Agreement.

3.6. The outputs generated by the Service carry a machine-readable marking identifying them as artificially generated or manipulated, as described in the Synthetic Content Marking Policy.

3.7. We do not use the AI features to take decisions producing legal effects concerning a natural person or similarly significantly affecting them; no automated individual decision-making within the meaning of Article 22 GDPR takes place.

4. Special categories of data

4.1. The Service is not intended for the processing of the data referred to in Article 9(1) GDPR. Users must not upload such data and must not use the Service for the identification or authentication of natural persons without our prior written agreement.

5. Cookies and similar technologies

5.1. We use technically necessary cookies to operate the website and to maintain a session; these are set on the basis of § 165(3) TKG 2021 and Article 6(1)(f) GDPR. Analytics and preference cookies are set only with your consent, given through our cookie banner, which you may withdraw at any time through the same banner or through your browser settings.

6. Recipients and processors

6.1. We disclose personal data only to the recipients necessary for the purposes set out above: our processors listed below, our professional advisers bound by confidentiality, and public authorities where required by law.

Recipient

Purpose

Role

Location / safeguard

Amazon Web Services

Hosting infrastructure, including the retrieval-augmented generation environment

Processor

European Union (Frankfurt); SCC where applicable

Microsoft Azure

Cloud computing and ancillary services

Processor

European Union region; SCC where applicable

OpenAI

Natural language processing and generation

Processor

United States; SCC; no training on customer content

Salesforce / HubSpot

Customer relationship management, support and marketing communications

Processor

SCC

FastSpring (Bright Market, LLC)

Payment processing as Merchant of Record

Independent controller in respect of payment data

United States; SCC

Google Analytics

Website and product analytics

Processor

SCC; set only with consent

Matomo

Product analytics

Processor

European Union

Stonly

In-product user guidance and help content

Processor

European Union

6.2. This list is kept up to date and supersedes any inconsistent earlier statement, including any statement that hosting is limited to a single provider. Business customers are notified of changes to the list in accordance with the Data Processing Agreement.

7. International transfers

7.1. Personal data are stored within the European Economic Area. Where a transfer to a third country is necessary — in particular to a provider established in the United States — it takes place on the basis of an adequacy decision under Article 45 GDPR or of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 under Article 46 GDPR, supplemented where necessary by additional measures identified in a transfer impact assessment. A copy of the safeguards applied may be obtained at info@roi4cio.com.

8. Security

8.1. We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS 1.2 / 1.3) and at rest (AES-256), role-based access control and multi-factor authentication for administrative access, logical separation of customer environments, logging, regular vulnerability scanning and continuous monitoring, backup and restoration procedures, and staff confidentiality undertakings and training. The measures applicable to processing on behalf of business customers are set out in Annex II to the Data Processing Agreement.

8.2. Upon becoming aware of a personal data breach we notify the competent supervisory authority in accordance with Article 33 GDPR and, where the conditions of Article 34 GDPR are met, the data subjects concerned. Business customers are notified within 48 hours, as provided in the Data Processing Agreement.

9. Retention

9.1. We retain personal data for the periods set out in Section 2. Where a retention period has expired, the data are deleted or irreversibly anonymised, save where their retention is required by law or necessary for the establishment, exercise or defence of legal claims. Data contained in backup media are deleted in accordance with the backup rotation cycle, which does not exceed 90 days.

10. Your rights

10.1. You have the right to obtain confirmation as to whether we process personal data concerning you and access to those data (Article 15 GDPR), to obtain rectification (Article 16), erasure (Article 17) and restriction of processing (Article 18), to data portability (Article 20), to object to processing based on our legitimate interest, including profiling (Article 21), and to withdraw consent at any time (Article 7(3)).

10.2. Requests may be addressed to info@roi4cio.com. We answer without undue delay and in any event within one month, which may be extended by two further months where necessary, in which case we inform you of the extension and of its reasons. We verify the identity of the person making the request before acting on it.

10.3. Where the personal data concerned are contained in content uploaded by a business customer, we act as processor and forward the request to that customer, who is the controller and responsible for answering it.

10.4. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The competent authority for ROIFORCIO GmbH is the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).

11. Sources of data not obtained from you

11.1. Where we do not obtain the data from you directly, they originate from the business customer or user who uploaded the content in which they are contained, from a person who sent you a presentation created with the Service, from our authorised partners and resellers in connection with a purchase made through them, or from publicly accessible sources used for sanctions and restricted-party screening. The categories of data concerned and the purposes of their processing are those set out in Section 2.

12. Children

12.1. The Service is intended for professional and business use and is not directed at persons under 18 years of age. We do not knowingly process the personal data of such persons and delete them upon becoming aware of them.

13. Changes to this Policy

13.1. We may update this Policy. The current version is published on this page with its effective date. Where a change materially affects the processing of your personal data, we notify registered users by e-mail not less than 30 days before it takes effect, in accordance with Section 13 of the Terms of Use.