Need to know.
What the platform knows about you, why it knows it, and when it forgets — across the free tools, the client portal and everything between. Written under Articles 13 and 14 of the GDPR.
01The controller
Someone answers, by name.
The controller — the one who answers for your data — is AiB Solutions OOD, Sofia, Bulgaria. One address reaches us for everything in this notice: legal@aib.solutions. Inside a client engagement we act as processor instead: client materials are handled on the client’s written instructions under a GDPR Article 28 agreement, and the client remains controller of what they entrust to us.
02Free tools
Checked, not remembered.
The free tools work without sign-in and keep no history of what you check. What you type or upload travels only to the source that answers it and nowhere else — for VAT numbers, the European Commission’s VIES service; for the AI-powered tools, the AI engine named under the tool (Google Gemini, with OpenAI standing by), which reads it once to produce your result — and, for the invoice reader, Google Cloud Vision, which reads the rendered pages of a photo or scan once so each field can be marked where it was found. An uploaded document is processed in memory and never stored by us, and its result is not cached; other definitive answers may sit in a cache for about fifteen minutes so repeats are instant. To keep the tools standing, requests are counted per IP address — our legitimate interest in preventing abuse; the counting windows last from minutes up to a day and their rows are swept within the month. A VAT number or an invoice can identify a person, which is why all of the above is written down here.
03The portal
An account is what it says.
A portal account processes exactly what an account needs: name, email, a password stored only as a hash, and the sign-in and activity records security and auditing require. The legal bases are the contract that gives you the account and our legitimate interest in keeping the platform safe. Account data lives while the account does; audit trails live with the workspace they protect.
04Billing
Kept because the law says so.
Invoices carry what Bulgarian tax law itself prescribes — names, addresses, identification numbers. The legal basis is legal obligation, and the same law sets the shelf life: accounting documents are kept for the statutory periods, typically five to ten years, and an erasure request cannot shorten what statute requires us to hold.
05Client work & logs
Custodians, not owners.
Documents and records a client routes through their tools remain the client’s — we process them only on instructions, under the Article 28 agreement. Where an AI model reads a document it does so through a commercial API whose contract forbids training on that content; a field the model can’t be sure about is flagged, never guessed, and no decision with legal effect for you is taken by a machine alone. Run logs exist for developers’ eyes, are scrubbed of secrets, and are removed when a client’s data is wiped.
06Recipients & transfers
Few hands, all named.
We sell nothing, share nothing for advertising, and run no analytics trackers — these pages call no third-party scripts at all. Data reaches only the services that physically run the platform: Stripe for card payments (your card never touches our servers), Cloudflare object storage on an EU-jurisdiction endpoint, Render hosting in Frankfurt, and the mail service that delivers the platform’s messages. Where any provider processes outside the EEA, it does so under the GDPR’s transfer safeguards.
07Cookies
Three cookies, no followers.
The platform sets at most three small cookies, all first-party and all strictly necessary: the session that keeps you signed in, the CSRF token that protects forms from forgery, and the note that remembers you have seen the cookie notice. Nothing follows you across the web — which is why the bottom-left notice informs rather than asks: the law requires consent only for cookies a site could live without, and we set none of those. Names, jobs and lifetimes are on the cookie notice page.
08Your rights
Your data answers to you.
The GDPR gives you access, rectification, erasure, restriction, portability and objection — one email to legal@aib.solutions exercises any of them, and we verify identity before anything moves. Where processing rests on legitimate interest, you may object on grounds of your particular situation; where the law mandates keeping (section 04), the mandate wins. If you believe we have it wrong, the supervisory authority is the Commission for Personal Data Protection (cpdp.bg — 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia); complaining costs nothing. This notice is versioned like the terms — the date at the top names the wording you read.
Something this notice didn’t answer?
Write to usEffective 6 August 2026 · AiB Solutions OOD · Sofia