Privacy Policy

Last updated: June 12, 2026

Copilote AI Business ("we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store and protect personal data when you use our platform.

This policy is designed to comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP/nDSG).

1. Data Controller

  • Data controller: the operator of the Copilote AI Business service — legal identity published on our Legal Notice page
  • Email: hello@copilotebusiness.ai

2. Data We Collect

a) Account data

Name, email address, password (stored hashed), restaurant name, business type, city/location, language preference.

b) Restaurant business data

Menu items and pricing, customer lists you import (names, emails, phone numbers), visit history, review data, campaign performance.

c) Payment data

Processed by Stripe. We never store card numbers. We retain subscription status, plan, currency and invoice records.

d) Usage data

Login timestamps, feature usage, campaigns launched, reports generated and pages visited — measured primarily through our own first-party analytics; product analytics tools (PostHog) run only with your consent (see Cookie Policy).

e) Communication data

Email and SMS delivery logs (sent/failed status). We do not read the content of your customer communications beyond what is needed to operate the service.

3. How We Use Your Data

  • To provide and operate the Platform services
  • To generate AI-powered diagnostics, recommendations, campaigns and reports
  • To process payments and manage subscriptions
  • To send transactional emails (reports, notifications, account and billing updates)
  • To improve the Platform, its models and its performance
  • To comply with legal obligations

4. Legal Basis for Processing (GDPR)

  • Contract performance: processing needed to provide the services you subscribed to
  • Legitimate interest: security, fraud prevention, first-party service measurement and improvement
  • Consent: optional analytics cookies and marketing communications (where required)
  • Legal obligation: tax and accounting records, regulatory compliance

5. Processors and Data Sharing

We share data only with the following categories of processors, under data-processing agreements:

  • Stripe — payment processing (PCI-DSS compliant)
  • Twilio SendGrid — email delivery
  • Twilio — SMS delivery
  • MongoDB — database hosting
  • PostHog — product analytics (only if you consent to analytics cookies)
  • AI model providers (incl. OpenAI) — generation of diagnostics, recommendations and campaign content, accessed through secured infrastructure
  • Cloud hosting provider — application hosting

We do not sell your personal data. A Data Processing Agreement (DPA) for business customers is available on request at hello@copilotebusiness.ai.

6. Data Retention

  • Account data: while your account is active + 30 days after deletion
  • Restaurant customer data: while your account is active + 30 days
  • Payment and invoice records: 10 years (Swiss commercial-law retention requirements)
  • Analytics data: up to 24 months

7. Your Rights

Under the GDPR and the Swiss FADP you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interest
  • Withdraw consent at any time

To exercise these rights, contact hello@copilotebusiness.ai. We respond within 30 days.

8. Data Security

We apply appropriate technical and organisational measures: encryption in transit (TLS), encrypted storage, access controls, secured authentication (JWT), audit logging and regular security reviews.

9. International Data Transfers

Some processors are located in the United States (e.g. Stripe, Twilio SendGrid, AI model providers). Transfers are covered by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by the GDPR and the Swiss FADP.

10. Children

The Platform is not intended for individuals under 18. We do not knowingly collect data from minors.

11. Changes

We may update this Privacy Policy. Material changes are communicated by email. Continued use constitutes acceptance.

12. Contact and Complaints

Privacy enquiries: hello@copilotebusiness.ai.

If you believe your rights have been infringed, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.

We use essential cookies to run this site. With your consent, we also use analytics cookies to improve the product. Cookie Policy