Aiomize

Privacy Policy

Last updated

This policy describes Aiomize's website and optimization service. The website provides product information and a customer portal. Subscription checkout is currently disabled.

Who is responsible

Qleerly AI AB (reg. no. 559595-0246), Rombäck 481, 841 74 Fränsta, Sweden is responsible for the personal data described here. Contact [email protected] for privacy requests.

Information processed

DataPurpose
Company details, contact name, contact email and optional phone numberMaintain a customer profile, deliver sign-in links and communicate about the software.
Registered website addresses and ownership verificationIdentify authorized websites and confirm permission to manage them.
Public website content, scan results and findingsAssess technical and content issues and produce optimization suggestions.
Approved changes, snapshots and delivery recordsApply changes safely, support rollback and document work.
Plan, usage and audit recordsEnforce access limits, maintain security and record service activity.
IP addresses and request information in server access logsOperate the website, diagnose failures and detect abuse.
Connection credentials, where you authorize an integrationDeliver approved changes to the connected platform.

Why we process data

We process customer data to provide the service and fulfill our agreement. Security and operational logs support our legitimate interest in running a reliable service. Legal records are retained where required by law. Optional marketing requires consent.

AI providers and integrations

When an AI feature is used, relevant website content and instructions may be processed through OpenRouter by the selected model provider. Visitors using an embedded Qleerly chatbot have their question and customer-provided business information sent to the selected provider. The portal records the model, time and usage cost, not the visitor question or answer. Providers have their own retention and processing policies; do not include confidential or sensitive information in material intended for AI processing unless you have a suitable legal basis and authorization.

Customer-authorized website platforms process the data necessary for their integration. Subject to domain approval, Paddle will process payments when checkout is enabled; it is currently not loaded by this website. We do not store payment card numbers.

Google sign-in and customer API keys

If you choose Google sign-in, Google processes the authentication request and provides your account identifier and verified email address. We store the Google account identifier to link future sign-ins to your customer account. Temporary cookies named aig and aigl support the sign-in and account-linking process and expire after fifteen minutes. You can also sign in by email.

Customer API keys provide read-only access to the customer profile. Key secrets are shown only when created and stored as hashes. Keep them in server-side environment configuration; they can be revoked from the portal. Contact details are not automatically included in the public chatbot context.

Cookies and analytics

The public information pages do not set application cookies and do not load Google Analytics, Meta advertising pixels or Paddle checkout scripts. Server logs may still record requests. The customer portal uses an HttpOnly, Secure, SameSite authentication cookie named aip, valid for up to thirty days. Sign-in links expire after fifteen minutes and can be used only once. Email addresses are processed by Resend to deliver the links. The public pages do not use advertising or analytics cookies.

Retention and security

Customer data is kept while needed to provide the service, meet legal obligations and maintain security. The configured optimization history periods are three months for Start, twelve for Pro, twenty-four for Business and thirty-six for Enterprise. Other records, including backups, may have different retention requirements. Contact us for account closure or deletion requests.

We use encrypted transport and restrict access to customer information. Website scans and reports are associated with the customer profile that owns them. Customer sign-in links are stored as hashes; server-side sessions identify the authenticated account.

International processing

External providers may process information outside the European Economic Area. Where required, applicable transfer safeguards must support that processing. Contact us for information about providers relevant to your service.

Your rights

You may request access, correction, deletion, restriction or portability of your personal data, and object to processing where applicable. You may withdraw consent for optional processing. Write to [email protected]; we respond within one month, subject to applicable legal exceptions.

You can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), or your local supervisory authority.

Changes and contact

This page is updated when data processing changes. Material changes affecting customers will be communicated. Contact: [email protected].