Privacy
Privacy Policy — Smart Hotline AI (ai.smart-hotline.com)
_Draft v1 — Phase 0. Review before real payments go live._
Last updated: 2026-10-10
1. Who we are
Smart Hotline AI, operated by Smart Hotline, is the data controller for personal data processed via ai.smart-hotline.com. Contact: support@smart-hotline.com.
2. What we collect
- Account data: email address and a password stored only as a salted hash. We do not ask for names or payment data during the test period.
- Usage data: the URLs you submit for audits and monitoring, audit results, monitor status history, and entitlements (which services your account can use).
- Technical data: standard server logs (IP address, timestamps, user agent) kept for security and abuse prevention.
3. Why we process it (legal bases)
- Providing the service you request (contract).
- Security, fraud and abuse prevention (legitimate interest / legal obligation).
- Improving the service (legitimate interest), using aggregated, non-identifying data.
4. What we do NOT do
- We do not sell your data.
- We do not run cross-site tracking or advertising cookies. Analytics, if enabled, is privacy-preserving (no cross-site user tracking).
- We do not store payment card data (payments, when introduced, are handled entirely by our payment provider acting as merchant of record).
5. Sub-processors
We host on Cloudflare (edge hosting, storage, database) and use transactional email infrastructure for account emails. Each provider processes data only to deliver our service. The current list of sub-processors is available on request.
6. Retention
Account and usage data are kept while your account is active. Deleted accounts are purged from production within 30 days; backups may persist up to 90 days. Server logs are kept up to 30 days.
7. Your rights (GDPR)
You may access, correct, export, or delete your personal data, object to processing, or request restriction. Email support@smart-hotline.com — we respond within 30 days. You may also lodge a complaint with your local data protection authority.
8. Security
Data is encrypted in transit (TLS) and at rest. Passwords are hashed (PBKDF2). Access to production data is restricted and logged.
9. Children
The services are not intended for anyone under 16.
10. Changes
We may update this policy; material changes will be announced on the Site.
11. International transfers
Data is processed on Cloudflare's global network; transfers outside the EEA rely on standard contractual clauses or equivalent safeguards.