Privacy Policy

Last updated: April 12, 2026

Copilote IA Business ("Company", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our AI-powered restaurant revenue optimization platform.

This policy complies with the General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (nDSG/FADP), and other applicable data protection laws.

1. Data Controller

  • Company: Copilote IA Business
  • Registered office: Geneva, Switzerland — full registered address available on request via hello@copilotebusiness.ai
  • Email: hello@copilotebusiness.ai

2. Data We Collect

a) Account Data

Name, email address, password (hashed), restaurant name, business type, location.

b) Restaurant Business Data

Menu items, pricing, customer lists (names, emails, phone numbers), visit history, Google rating and review count, campaign performance data.

c) Payment Data

Processed by Stripe. We do not store credit card numbers. We retain subscription status, plan details, and invoice records.

d) Usage Data

Login timestamps, feature usage, campaigns launched, reports generated, pages visited (via PostHog and Google Analytics).

e) Communication Data

Email delivery logs (sent/failed status), SMS delivery logs. We do not read the content of your customer communications.

3. How We Use Your Data

  • To provide and operate the Platform services
  • To generate AI-powered campaigns, recommendations, and reports
  • To process payments and manage subscriptions
  • To send operational emails (reports, notifications, account updates)
  • To improve our AI algorithms and platform performance
  • To comply with legal obligations

4. Legal Basis for Processing (GDPR)

  • Contract performance: Processing necessary to provide the Platform services you subscribed to
  • Legitimate interest: Analytics, security, fraud prevention, and service improvement
  • Consent: Marketing communications and cookie tracking (where required)
  • Legal obligation: Tax records, regulatory compliance

5. Data Sharing

We share data only with the following categories of processors:

  • Stripe — Payment processing (PCI DSS compliant)
  • SendGrid (Twilio) — Email delivery
  • Twilio — SMS delivery
  • MongoDB Atlas — Database hosting
  • PostHog — Product analytics
  • OpenAI — AI campaign generation (data processed per OpenAI's data processing terms)

We do not sell your data to third parties.

6. Data Retention

  • Account data: retained while your account is active + 30 days after deletion
  • Restaurant customer data: retained while your account is active + 30 days
  • Payment records: retained for 7 years (Swiss tax requirements)
  • Analytics data: retained for 24 months

7. Your Rights (GDPR)

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Delete your data ("right to be forgotten")
  • Restrict processing of your data
  • Port your data to another service
  • Object to processing based on legitimate interest
  • Withdraw consent at any time

To exercise these rights, contact hello@copilotebusiness.ai. We will respond within 30 days.

8. Data Security

We implement appropriate technical and organizational measures, including encryption in transit (TLS/SSL), encrypted storage, access controls, regular security audits, and secure authentication (JWT tokens).

9. International Data Transfers

Data may be transferred to processors in the United States (Stripe, SendGrid, OpenAI). These transfers are governed by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR.

10. Children's Privacy

The Platform is not intended for use by individuals under 18. We do not knowingly collect data from minors.

11. Changes

We may update this Privacy Policy. Material changes will be communicated via email. Continued use constitutes acceptance.

12. Contact & Complaints

For privacy inquiries: hello@copilotebusiness.ai

If you believe your rights have been violated, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.