SweetRouter
Privacy Policy
This Privacy Policy explains how OneClick AI Solutions s.r.o. processes personal data when you visit our website, use the SweetRouter console or call our API. It is available in English and Czech; if the versions differ, the English version prevails.
1. Who we are
The controller of your personal data is OneClick AI Solutions s.r.o., ID No. 23948353, with its registered office at Sokolovská 428/130, Karlín, 186 00 Praha 8, Czech Republic, registered in the Commercial Register under file no. C 435717, kept by the Municipal Court in Prague. You can contact us about privacy at sweetsrouter@gmail.com.
2. Scope
This policy covers personal data we process as a controller: data about our customers' account users, billing, support and the technical use of our service. When our customers send personal data of their own end users through the API (for example inside chat messages), we process it on the customer's behalf as a processor under our Data Processing Addendum; the customer is the controller of that data and its own privacy notice applies.
3. What we process, why, and for how long
- Account data: email address, hashed password (stored by our authentication provider), language preference, account settings. Purpose: creating and running your account and providing the service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Kept while your account exists and deleted within 30 days after it is closed, except where we must keep it by law.
- Billing data: top-up amounts, invoices, receipts, payment status and the customer identifier at our payment provider. Card details are handled by Stripe and never reach our servers. Purpose: payments, invoicing and accounting. Legal basis: contract and legal obligation (Art. 6(1)(b) and (c) GDPR). Kept for the period required by Czech accounting and tax law, currently up to 10 years.
- API call details: time, API key, model, status, number of input and output tokens, cost, request id, and an optional end-user identifier you choose to send. Purpose: billing, usage reporting in your console, security and abuse prevention. Legal basis: contract and legitimate interests (Art. 6(1)(b) and (f) GDPR). Kept for 30 days; daily usage totals without personal details are kept for accounting.
- Chat messages and replies: passed through to the AI model provider to generate the reply and returned to you. We do not store their text.
- Generated image and video files: stored for 24 hours so you can download them, then deleted.
- Technical and security data: IP address, user agent and request logs created by our hosting and infrastructure providers. Purpose: running, securing and debugging the service and enforcing rate limits. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). Kept for a short period, normally up to 30 days.
- Support communications: what you send us by email or Telegram. Purpose: answering your requests. Legal basis: contract and legitimate interests. Kept for up to 3 years after the matter is resolved.
We do not use your data or your end users' messages to train AI models, and we do not sell personal data.
4. Who receives your data
We use the following service providers, who process personal data on our behalf under data processing agreements:
- Supabase, Inc.: Database, authentication and file storage (EU (Frankfurt, Germany)).
- Vercel Inc.: Website and API hosting (EU (Frankfurt, Germany); company based in the USA).
- Upstash, Inc.: Rate limiting (API key identifiers and request counters) (EU region; company based in the USA).
- Third-party AI model inference provider: Generating chat replies from the messages you send (Singapore).
- Verda (DataCrunch Oy): Image and video generation (EU (Finland)).
- Google Ireland Limited (Gmail): Email correspondence with customers (EU; data may also be processed in the USA).
Stripe Payments Europe, Ltd. (Ireland) processes payments as an independent controller under its own privacy policy. We may also disclose data to authorities where the law requires it, and to professional advisers bound by confidentiality.
5. Transfers outside the EU
Some of our providers are located, or have parent companies, outside the European Economic Area, including in the USA and Singapore. Where personal data is transferred to a country without an EU adequacy decision, we rely on the European Commission's Standard Contractual Clauses or, for US companies certified under it, the EU-US Data Privacy Framework, together with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
6. Cookies
We use only cookies that are strictly necessary for the website to work: authentication cookies that keep you signed in to the console, and a cookie that remembers your language. We do not use analytics or advertising cookies, so no cookie consent is required.
7. Security
We protect personal data with appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, hashed API keys and passwords, least-privilege access, two-factor authentication on administrative accounts, and managed backups.
8. Your rights
Under the GDPR you have the right to access your personal data, have it corrected or deleted, restrict or object to its processing, and receive it in a portable format. Where processing is based on consent, you can withdraw it at any time. You can change your email or delete your account at any time in the console settings. To exercise your other rights, email us at the address in section 1. We will respond within one month.
You also have the right to lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz, or with the authority in the EU country where you live or work.
9. Children
Our service is intended for businesses and is not directed at children. We do not knowingly collect personal data of anyone under 18.
10. Changes
We may update this policy from time to time. We will publish the new version on this page with a new effective date and, for material changes, notify account holders by email or in the console.