Privacy & Cookies Policy

Last updated: 15 August 2026

1. Who we are

Botto Digital OÜ is the entity responsible for processing your personal data within the scope described in this policy.

A company incorporated under Estonian law, registration no. 16918390, VAT EE102710227, with its registered office at Lõõtsa tn 5 // Sepapaja tn 4, 11415 Tallinn, Estonia.

Contact for data protection matters: hello@aip.cards.

This policy applies to the aip.cards website and to the app.aip.cards application (hereinafter, "AIP Cards").

2. In what capacity we process your data

Our role changes depending on the processing, and this determines your rights and to whom you should address them.

We are the data controller when we decide the purposes and the means: for billing and invoicing, for physical card orders, for the AIP Community and for service communications.

We are the data processor when we operate the tool on your behalf: the contacts you scan and your CRM are yours, and we process them only in accordance with your instructions. In that case, the data controller is you.

3. What data we process, for what purpose and on what basis

3.1 Scanned contacts and CRM (we are the processor)

We process the business cards you scan and the contacts you create: name, job title, company, email, phone, social networks, your notes and the image of the card.

Purpose: to scan business cards (optical reading by artificial intelligence) and to manage professional contacts on your behalf.

Basis: that of the controller, namely your legitimate interest in managing professional contacts (art. 6.º/1/f).

Retention: for as long as you keep the contact. Deleting the contact or the account deletes this data by cascade.

3.2 Assistant and messages generated by artificial intelligence (we are the processor)

We process the data of your own card and your own CRM (deals, appointments, projects) to generate summaries, answers to questions about your data and drafts of follow-up messages.

Basis: that of the controller, namely your legitimate interest in managing your contacts and your CRM (art. 6.º/1/f), as a compatible purpose (art. 6.º/4).

Artificial intelligence works only on the data already held in your card and your CRM. It does not perform enrichment from external sources, it does not profile and it does not make decisions about people. The messages generated are drafts: nothing is sent without a person reviewing and deciding.

Retention: the summary is associated with the contact and is deleted together with it.

3.3 AIP Community and synergy suggestions (we are the controller)

If you join the Community, we process the data of your own professional profile: field, activity, description of what you do, company, job title, LinkedIn address and Telegram identifier.

Purpose: a contact directory between members, and suggestions generated by artificial intelligence of people who may be relevant for you to meet.

Basis: your consent (art. 6.º/1/a), collected upon joining and revocable at any time (art. 7.º/3), without prejudice to the rest of the service.

Your email and phone number are never shown to other members. Contact between members takes place via LinkedIn or Telegram. There is no bulk export of the directory, and the Terms prohibit the automated collection of members' data.

Each suggestion is identified as generated by artificial intelligence. It is a suggestion, not a decision: it does not trigger any automated contact nor produce any legal effect on you (art. 22.º not applicable).

Retention: for as long as you are a member with an active membership. When you leave, the published fields and the suggestions involving you are deleted on both sides.

3.4 Purchases, invoicing and physical card (we are the controller)

We process the account email, the name and the billing address, the tax number, the company and the country. For the physical card, we also process the name and the shipping address and the name to be engraved.

Purpose: to charge, to issue and to keep the invoice, and to produce and deliver the card.

Basis: the performance of the contract (art. 6.º/1/b) for charging and delivery, and the legal obligation (art. 6.º/1/c) for the invoice and its retention.

The data of your payment card (number and security code) are entered directly into Stripe's secure environment and never pass through our servers.

The provision of the name, tax number and billing address is a legal and contractual requirement: without this data it is not possible to issue the invoice or to complete the purchase (art. 13.º/2/e).

Retention: invoices and records of transactions are kept for 10 years, the period required by the VAT One Stop Shop (OSS) regime for cross-border sales within the European Union (art. 369.º-K of Directive 2006/112/EC). The shipping data lose their basis after delivery and are anonymised when you delete the account.

3.5 Service communications (we are the controller)

We send operational notifications: low balance alert, summary of new synergy suggestions and project sharing notice.

Basis: performance of the contract and legitimate interest in providing the service (art. 6.º/1/b and f).

These are transactional communications, they are not marketing. The synergy summary has its own toggle in the Settings, and the email contains only the count and a link, never other people's data.

3.6 Public card and visits to the card (we are the processor)

Your card is published at its own address on the Internet, so that anyone you show it to, or who taps it with the NFC card, can open it without installing anything. The choice to publish is presented to you beforehand, and what is published is what you put on the card. The page can be found by search engines. You can unpublish the card at any time in the application, and publish it again whenever you wish: once unpublished, the address stops responding.

The data published on the card is yours and your responsibility, as set out in the Terms and Conditions. You decide what you publish and you are the controller of that processing; we host and serve the page on your behalf.

When someone opens your card, or clicks one of its buttons, we record that moment so that we can show you the card's statistics. For each visit we store the date and time, whether it was an opening or a click, which button was used, the visitor's browser and operating system, the page they came from and a code computed from their Internet address — the address itself is not stored as it was received. In your statistics and in the export of your data, these records appear under the name taps.

This recording is based on prior consent, included in the Terms and Conditions. We do not use cookies for it: the card page neither places nor reads anything on the device of whoever opens it. We do not use these records for advertising, for profiling or to make automated decisions.

Retention: 24 months from each visit. If you delete your account, the records of your card are deleted before that. They are kept in the database in the European Union and on the server in Germany, with the safeguards described in sections 4 and 5. Your rights and how to exercise them are set out in sections 8 and 9.

4. Whom we rely on (sub-processors)

To provide the service we rely on suppliers that process personal data on our behalf, under sub-processing agreements (art. 28.º). The list in force is the one published on this page.

Sub-processorFor whatWhere it processesTransfer safeguard
Hetzner Online GmbHHosting of the app.aip.cards application and of the server where your data is processedGermany (European Union)European Union entity; processing within EU territory
SupabaseDatabase and storage (contacts, profiles, orders, invoices)Project in the EU (Frankfurt, eu-central-1); entities in the USA and in SingaporeStandard Contractual Clauses (Module 2 and Module 3) and the United Kingdom addendum, with a documented transfer impact assessment. No Data Privacy Framework
Stripe Payments Europe, LtdPayments (packs, AI pass, physical card)Ireland (EU entity); flows to the USAPrincipal relationship within the EU. Transfers to Stripe, LLC (USA) under the 2021 Standard Contractual Clauses (Modules 1, 2 and 3)
Google (Gemini API)Artificial intelligence: reading of the cards and generation of summaries and suggestionsUSAData Privacy Framework (Google LLC, active) and Standard Contractual Clauses. Paid service: your data is not used to train models
SendPulse Inc.Sending of the service emails and of the invoices and credit notesUSA and Ukraine2021 Standard Contractual Clauses. No Data Privacy Framework and no EU entity; transfer covered by a documented impact assessment, with residual risk assessed as low
Make (Celonis)Orchestration of the service notifications (low balance, synergy summary, project sharing) and of the responses of the Community botOrganisation in the EU (Dublin); entity in the USAData Privacy Framework and Standard Contractual Clauses (Module 2). The execution logs are configured not to retain the contents containing personal data
Titan Solution Ltd SEZCHosting of our contact email, through which we process your requestsUnited StatesStandard Contractual Clauses. No Data Privacy Framework; transfer covered by a documented impact assessment
HostingerHosting of the aip.cards websiteEuropean Union and, for some services, third countriesStandard Contractual Clauses (Modules 2 and 3)

We may update this list when we add or replace a supplier. The version in force is always the one published on this page.

Services that process your data as independent controllers

Some services we use do not process your data on our behalf: they process it as autonomous controllers, under their own privacy policies, over which we have no control.

Telegram, if you choose to take part in our Community through that channel. Telegram is a company independent of us, and what it does with your data is governed by its own policy. What we do with what you write to us through the bot is described in the Privacy Policy of the AIP Community Bot.

The European Commission's VIES service, to validate tax identification numbers, where the law requires it.

Companio, the company that provides our accounting services, based in Estonia, to which we send the invoices and credit notes for accounting purposes and for the legal retention of tax records. Companio processes that data as an autonomous controller, in fulfilment of its own legal obligations and under a duty of professional confidentiality, and is governed by its own privacy policy.

5. Transfers outside the European Union

Some of the suppliers above process data outside the European Economic Area, mainly in the United States.

These transfers rely on Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) and, where the supplier is certified, on the Data Privacy Framework. In cases where there is no adequacy decision or certification, we have assessed the transfer and documented the supplementary measures applied.

6. Artificial intelligence: what we do and what we do not do

We use artificial intelligence to read business cards, to summarise information, to answer questions about your own data, to draft messages and to suggest connections in the Community.

All content generated by artificial intelligence is identified as such in the application.

We do not use artificial intelligence to make automated decisions that produce legal effects on you or that significantly affect you (art. 22.º). We do not profile from external sources. The models we use are in paid services, with a sub-processing agreement, and are not trained with your data.

7. Security

Access to the data is authenticated and limited to the account holder, with isolation enforced at the database level.

Images are protected by temporary and revocable links. Access credentials are managed outside the source code, in protected configuration. Payments are processed in Stripe's environment, and the amount to be charged is always determined by our server, never by the browser.

8. Your rights

You have the right to access your data, to rectify it, to request its erasure, to restrict or object to the processing, and to obtain a portable copy (art. 15.º to 22.º). Where the processing is based on consent, you may withdraw it at any time (art. 7.º/3), without affecting the lawfulness of the prior processing.

In the application, you can directly exercise access and portability through the export of your data, and erasure through the deletion of the account, in "My Data and Privacy".

Erasure removes your contacts, profiles, images, community data and shipping data. The legally required billing data (name, tax number, billing address and amounts) are kept in full in the invoices for the tax period, because the law requires it (art. 17.º/3/b); only the data without a tax function, such as the shipping address, are deleted or anonymised.

For any request, write to hello@aip.cards. We respond within one month (art. 12.º/3).

If the data in question are contacts that another user scanned, that user is the controller and we act on their behalf; we forward your request and provide assistance.

9. Complaints

You may lodge a complaint with a supervisory authority.

The lead authority of the controller is the Estonian one, Andmekaitse Inspektsioon (AKI, aki.ee).

You may also lodge a complaint with the authority of your country of residence. In Portugal, the Comissão Nacional de Proteção de Dados (CNPD, cnpd.pt).

10. Changes to this policy

We may update this policy, in particular when we change supplier or add features. The date of the last update is at the top. Substantial changes are communicated in the application.

11. Cookies

The aip.cards website uses cookies organised by categories. On entry, a cookie bar allows you to accept, refuse or configure each category. The strictly necessary cookies are always active, because the site does not work without them; any analytics or marketing cookie is only placed after your consent, which you may withdraw at any time.

Strictly necessary (always active): WordPress session and operation cookies (for example wordpress_test_cookie), the store's cart cookie where applicable (woocommerce_cart_hash) and the cookie that records your consent preference.

Analytics and statistics (only with consent): they help us understand how the site is used, so that we can improve it.

Marketing and advertising (only with consent): they allow campaigns to be measured and personalised.

Whenever we activate an analytics or marketing service, we indicate in this section the supplier and the specific cookie, and that service remains blocked until you consent in the cookie bar. As at the date of this policy, only strictly necessary cookies are active. You may manage or delete cookies at any time in the cookie bar and in the browser settings.