Privacy Policy
Last updated: Oct 6, 2026
Amio s.r.o.
Bartoškova 1411/20, Nusle, 140 00 Praha 4, Czech Republic
Company ID: 06177794
VAT ID: CZ06177794
Privacy contact: privacy@amio.io
1. Scope and our role
This Privacy Policy explains how Amio s.r.o. (“Amio”, “we”, “us” or “our”) processes personal data for purposes that Amio determines itself, meaning where Amio acts as a controller. It covers our website, business and sales contacts, customer account and support contacts, billing and legal administration, recruitment, security and related business operations. It also covers conversations with Amio’s own AI demo or website assistant where Amio determines the purposes of that processing; this is distinct from customer-deployed experiences governed by the DPA.
When Amio processes personal data contained in Customer Data on a customer’s documented instructions, Amio acts as a processor or, where the customer itself acts as a processor, as a subprocessor. That processing is governed by our Data Processing Agreement (“DPA”) and the customer’s instructions. The customer is responsible for its own privacy notices and legal basis for that processing. This Privacy Policy is a transparency notice and does not amend the Agreement or DPA.
Our website and direct services are intended for business and professional users and are not directed to children.
Where applicable data-protection law requires Amio to appoint a local representative, we will make that representative’s contact details available to affected individuals and supervisory authorities in the manner required by applicable law, including through our website or other applicable privacy information.
2. Personal data we process, why, legal basis and retention
Website, security and service telemetry
Data may include IP address, browser and device information, timestamps, security and access logs, cookie choices, website interactions and service-usage telemetry associated with an identifiable user.
Purpose: operate, secure, troubleshoot and improve our website and services; prevent fraud and misuse; understand performance and usage; and, where we enable them, measure marketing campaigns, conversions and advertising effectiveness.
Legal basis: our legitimate interests in operating a secure, reliable and effective B2B service; consent where applicable law requires consent for non-essential analytics, advertising, marketing cookies or similar technologies.
Retention: identifiable website-interaction and website or marketing analytics records are retained for up to two years from collection. Cookie Settings describes device-storage durations, which may differ from server-side retention. Routine identifiable service security logs and telemetry are subject to a maximum configured retention period of 30 days from collection. Actual periods are set according to the relevant operational and security purpose and may be shorter; Amio may adjust them within this maximum as needs change. The maximum also applies to routine copies and archives controlled by Amio. Expired records are removed through the relevant provider’s normal automated deletion cycle. Particular records needed to investigate a specific incident or technical issue may be retained until that investigation is completed or the issue is resolved; any further retention is limited to the legal-retention rules below.
Customer account, business-contact and support data
Data may include name, work email, telephone number, company, role, account identifiers, authentication/account information, communications, support history and relevant service-usage information.
Purpose: create and administer accounts, provide and support the service, communicate about the business relationship, secure accounts, manage access and resolve issues.
Legal basis: our legitimate interests in administering a B2B customer relationship and providing support; performance of a contract or steps requested before a contract where the individual is personally a party; and legal obligations where applicable.
Retention: active account and relationship records are retained until the relevant account is closed or the business relationship ends. Support records are retained while the relevant support matter remains open. After those purposes end, retention is limited to relevant billing, contractual, security or other records covered by the legal-retention rules below.
Enquiries, demos, sales and permitted marketing
Data may include name, work contact details, employer/company, job role, communications, content and attachments you submit to Amio’s own AI demo or website assistant, associated technical session information, meeting or event information, interests relevant to Amio’s services, and information about the source of the contact.
Purpose: respond to enquiries, generate and deliver responses through Amio’s own AI demo or website assistant, provide requested demonstrations, arrange demos, manage prospective-customer relationships, maintain our CRM, conduct relevant B2B sales activity and send marketing communications where permitted by law.
Legal basis: our legitimate interests in responding to requested enquiries, providing requested B2B demonstrations and website assistance, and developing and managing B2B relationships; steps requested before entering a contract where applicable; and consent where consent is required. A GDPR legitimate interest does not by itself authorize an electronic marketing message where separate electronic-marketing rules require consent or another specific permission.
Retention: enquiry, demo, prospective-customer and marketing records are retained for up to two years from collection, and use for marketing ends earlier if you object or withdraw consent where applicable. If you become a customer, records needed for the resulting account or business relationship are retained under the separate criteria above. After an opt-out, we may retain only a minimal suppression record identifying the contact and preference while needed to prevent renewed marketing contrary to that preference. Separate legal-retention requirements apply only to the relevant records under the rules below.
Billing, accounting, contracts and legal compliance
Data may include business contact details, billing information, invoices, payment and transaction records, contract records, tax information and correspondence relevant to legal or compliance matters.
Purpose: billing and collections, accounting and tax compliance, contract administration, audits, corporate recordkeeping, legal compliance and establishing, exercising or defending legal claims.
Legal basis: compliance with legal obligations; our legitimate interests in financial administration, governance and protection of legal rights; and contract performance where the individual is personally a party.
Retention: under current Czech law, accounting documents and books are generally retained for five years from the end of the accounting period to which they relate; financial statements and annual reports for ten years from the end of that accounting period; and VAT tax documents for ten years from the end of the tax period in which the relevant supply occurred. Contractual and other legal records follow the legal-retention rules below. A longer period applies only where a specific statutory requirement or relevant unresolved tax, audit or legal matter requires continued retention.
Recruitment
Data may include identification and contact details, CV and application information, qualifications, experience, interview notes and recruitment communications.
Purpose: assess applications, communicate with candidates, make hiring decisions and comply with employment-related legal obligations.
Legal basis: steps taken at the candidate’s request before entering an employment or other engagement; our legitimate interests in recruitment and recordkeeping; and legal obligations where applicable.
Retention: recruitment records are retained until the application is withdrawn, the candidate is rejected or the relevant hiring process concludes. If the candidate is hired, records required for the employment or engagement relationship are retained under the applicable employment, contractual and statutory recordkeeping requirements. Otherwise, further retention is limited to relevant records under the legal-retention rules below. Where we lawfully retain records for future opportunities, the period or end condition is provided in the information for that separate purpose; that use ends earlier following withdrawal of consent or a successful objection, where applicable.
Business partners, suppliers and professional contacts
Data may include name, work contact details, company, role, contractual or commercial communications, and information necessary to manage the relationship.
Purpose: manage supplier, adviser and business-partner relationships, procurement, due diligence, invoices, security, compliance and legal matters.
Legal basis: our legitimate interests in operating and protecting our business; legal obligations; and contract performance where the individual is personally a party.
Retention: active supplier and business-partner relationship records are retained until that relationship ends. Afterwards, only relevant accounting, tax, contractual, audit or other legal records are retained under the statutory periods and legal-retention rules described above.
Legal-retention rules for the categories above: after the ordinary purpose ends, we retain only records needed for a specific legal obligation or to establish, exercise or defend a legal claim. Records supporting a legal claim are retained until expiry of its applicable limitation period, calculated from the statutory starting point and including any lawful suspension or extension. If relevant proceedings are pending, necessary records may be retained until their final resolution and any lawful enforcement period. The general Czech civil limitation period is three years from the applicable statutory starting point; a different period applies where the relevant law or a valid agreement provides one. We delete or irreversibly anonymise personal data when no applicable purpose or lawful retention ground remains.
Where information is required to create or secure an account, administer a contract, process billing, respond to a request or comply with law, failure to provide it may prevent us from providing the relevant service, completing the transaction or responding to the request. Other information is generally optional.
Amio does not currently use the personal data covered by this Privacy Policy to make solely automated decisions that produce legal effects or similarly significant effects for individuals.
3. Where we obtain personal data
We obtain personal data directly from you when you contact us, create or use an account, request a demo, communicate with support, enter into a business relationship, attend a meeting or event with us, or apply for a role.
We may also obtain business-contact data indirectly from your employer or another organization you represent, publicly available professional or business sources (including professional networking platforms), business-information, enrichment or lead-data providers, referrals, event organizers, business partners and other lawful business sources relevant to developing or managing a B2B relationship. The particular sources used may vary over time.
Where applicable law requires source information for data obtained indirectly, we will provide the specific source from which the personal data originated where possible, including whether the source was publicly accessible. Where the specific source cannot reasonably be provided, we will provide information about the nature or category of the source, within the period required by law.
Where applicable law requires us to provide information because we obtained personal data indirectly, we will provide this Privacy Policy and any additional required source or processing information within a reasonable period and no later than one month after obtaining the data, or earlier at our first communication with you or first disclosure to another recipient, as applicable. We may provide the information by sending a direct link to the relevant notice. An exception to individual notice applies only where the conditions in applicable law are met; website publication alone does not replace individual notice unless the law permits it.
4. Who receives personal data
We disclose controller personal data only where reasonably necessary for the purposes described above, including to categories of recipients such as:
- cloud, hosting, infrastructure, security, IT, and AI-model or inference service providers;
- analytics, product-analytics, website, advertising and marketing-technology service providers where used;
- CRM, communications and customer-support providers;
- payment, billing and financial service providers;
- recruitment or HR service providers where used;
- accountants, auditors, lawyers, insurers and other professional advisers;
- competent public authorities where disclosure is required or permitted by law; and
- parties involved in a merger, acquisition, financing, reorganization or sale of all or part of our business, subject to appropriate confidentiality and legal safeguards.
This section concerns personal data for which Amio acts as controller. Processing of Customer Personal Data on a customer’s behalf is governed by the DPA. The DPA describes how customers receive and access Amio’s current subprocessor list and receive advance notice of additions or replacements. That list concerns processing on customers’ behalf and does not replace the controller-recipient and international-transfer information in this Privacy Policy.
5. International transfers
The service providers we use for controller processing, including website hosting, analytics, CRM, scheduling, business email and collaboration, customer support and billing, may process personal data outside the European Economic Area (“EEA”). Relevant non-EEA destinations include the United Kingdom, United States and Singapore. Certain providers operate global processing or support networks, with additional locations identified in their processing-location information linked below. The processing of a particular record depends on the service and features used. European hosting does not by itself exclude access or onward processing outside the EEA.
For transfers from the EEA to the United Kingdom, we rely on the European Commission’s adequacy decision. For transfers to U.S. recipients covered by a valid EU-U.S. Data Privacy Framework certification, we rely on the Commission’s adequacy decision for that framework, only to the extent the certification covers the recipient and the relevant data. For other restricted transfers, including transfers to recipients in Singapore or to U.S. recipients not covered by that framework, we use the European Commission’s 2021 Standard Contractual Clauses with any required supplementary measures. The provider information below describes the safeguards applicable to the relevant services. Where UK or Swiss data-protection law applies to a transfer, the required UK transfer terms or Swiss adaptations also apply.
Provider processing-location and transfer information is available for Vercel (website hosting); Google advertising and analytics; PostHog (analytics); Ahrefs (web analytics); Attio (CRM); Google Workspace locations and transfer terms (email and collaboration); Calendly (scheduling); Plain (support); and Stripe (billing and payments). These resources describe provider processing arrangements; they do not mean every provider or location is involved in every individual’s interaction with Amio. You may contact privacy@amio.io for information about a relevant transfer and to obtain a copy of the applicable safeguards, with any necessary redactions to protect confidential information or other individuals’ personal data.
6. Security
We maintain technical and organisational measures designed to provide a level of security appropriate to the risk. Security measures evolve with our services, technology and risks. Contractual security commitments concerning Customer Personal Data are governed by the Agreement and DPA rather than by additional promises in this Privacy Policy.
7. Your privacy rights
Subject to the conditions and exceptions in applicable data-protection law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- receive certain personal data in a portable format;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing; and
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
You may exercise applicable rights by contacting privacy@amio.io. We may need information reasonably necessary to verify your identity and locate the relevant data. We may retain information where required or permitted by law, including records necessary to comply with legal obligations, establish or defend legal claims, or maintain a suppression record following a marketing opt-out.
If your request concerns personal data that Amio processes only on behalf of an Amio customer, please contact that customer first. Depending on the circumstances, the customer may be the controller or may itself act as a processor for another controller. Amio will assist customers as required by the DPA and applicable law.
You also have the right to lodge a complaint with the supervisory authority competent for your processing. The Czech supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), uoou.gov.cz.
8. Cookies and similar technologies
We use cookies and similar technologies for necessary website functionality and, where permitted, for analytics or marketing. Where applicable law requires consent for non-essential cookies or similar technologies, we use those technologies only after the required consent has been obtained. You can manage applicable choices through our cookie controls. More information is provided in our Cookies Policy.
9. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our processing, services or applicable law. Editorial or non-material updates may take effect when the updated version is published.
Where applicable law requires advance notice, a new legal basis, consent or other action before a material change in processing can take effect, we will take that action before applying the change to the affected processing. Publication of an updated policy does not by itself create a new legal basis for processing.
10. Contact
Amio s.r.o.
Bartoškova 1411/20, Nusle, 140 00 Praha 4, Czech Republic
Company ID: 06177794
VAT ID: CZ06177794
Email: privacy@amio.io
Website: amio.io