Legal

Privacy & Cookie Policy

Last updated: 2 October 2026

Personeo is provided by Good Vibes Software s.r.o., Streďanská 2661/53B, 955 03 Topoľčany, Slovakia, Company ID 54906466, registered in the Commercial Register maintained by the Municipal Court of Nitra, section Sro, insert 58337/N.

In this policy, “Personeo”, “we”, “us” and “our” refer to Good Vibes Software s.r.o.

This Privacy & Cookie Policy explains how we collect, use, store, share and protect personal data when you visit our website, communicate with us or use the Personeo platform.

Personeo is primarily a business to business service. Depending on the context, Good Vibes Software s.r.o. may process personal data either as a data controller or as a data processor acting on behalf of a customer.

If you have any questions about this policy or the processing of personal data, contact us at hello@personeo.ai.

1.Our role under data protection law

When Personeo acts as a controller

Good Vibes Software s.r.o. generally acts as a data controller when we determine why and how personal data is processed for our own business purposes.

This may include personal data relating to:

  • visitors to our public website
  • people who request a demo or contact us
  • prospective customers and business contacts
  • partners and partner contacts
  • customer administrators and commercial contacts
  • account and authentication information required to operate Personeo
  • billing and invoicing
  • security and operational information required to protect and operate the service
  • communications with our sales, customer success, implementation and support teams

When Personeo acts as a processor

When an organization provides Personeo to its employees, contractors or other users for training purposes, the organization will normally determine why the training data is processed.

In this situation, the organization normally acts as the data controller and Personeo acts as its data processor.

Data processed on behalf of customers may include:

  • roleplay conversations and transcripts
  • roleplay scores
  • AI generated feedback
  • training history
  • usage and adoption information
  • skill and performance analytics
  • roleplay configurations and evaluation criteria
  • customer provided training materials
  • custom roleplay content
  • voice recordings where recording has been explicitly enabled

We process this information according to the customer's instructions, the applicable agreement and, where relevant, a Data Processing Agreement.

If you use Personeo through your employer or another organization and your request concerns training data controlled by that organization, you should normally contact that organization first.

Personeo will assist its customers with valid data subject requests where required by applicable law and our contractual obligations.

2.Personal data we collect

The personal data we process depends on how you interact with Personeo.

Website visitors

When you visit our public website, we may process information including:

  • IP address
  • browser type and version
  • device information
  • operating system
  • language settings
  • approximate geographic information derived from technical data
  • referring page
  • pages visited
  • date and time of access
  • website interaction information
  • analytics information where analytics consent has been provided

Google Analytics is used only on the public Personeo marketing website.

Google Analytics is not used within the authenticated Personeo application.

Demo requests, prospective customers and business contacts

If you request a demo, contact us, attend a meeting or otherwise communicate with our team, we may process:

  • name and surname
  • business email address
  • phone number where provided
  • company
  • job title or business role
  • country
  • information included in your message or enquiry
  • meeting history
  • communication history
  • information about your organization's needs, training processes and potential Personeo use case

We may also receive professional contact information from:

  • your organization
  • authorized Personeo partners
  • event organizers
  • referrals
  • legitimate publicly available business sources

We currently manage sales and business communications primarily through Google Workspace and Gmail.

Personeo user accounts

When you create or use a Personeo account, we may process:

  • name and surname
  • email address
  • organization
  • workspace and team membership
  • user role and permissions
  • authentication information
  • session information
  • language and account preferences
  • account activity
  • security events
  • technical and operational logs

Training and roleplay data

When Personeo is used for training, the platform may process:

  • roleplay transcripts
  • user responses
  • roleplay scores
  • AI generated coaching feedback
  • training history
  • skill development information
  • practice activity
  • usage information
  • adoption analytics
  • roleplay configuration
  • roleplay evaluation criteria
  • training materials provided by the customer

This information will normally be processed on behalf of the organization providing Personeo to the user.

Voice data

Personeo supports voice based AI roleplays.

By default, raw voice audio is processed transiently in order to provide the voice conversation and is not persistently stored by Personeo.

Where a customer explicitly enables voice recording, audio may be stored as part of that customer's configuration.

In such cases, access and retention are governed by the customer's agreed configuration, policies and contractual requirements.

Transcripts created from voice conversations may be stored as part of the training session according to the applicable customer retention settings.

Service and security logs

To operate and protect Personeo, we may process service and security log information such as:

  • IP address
  • timestamps
  • authentication events
  • browser and device information
  • request metadata
  • application errors
  • service availability information
  • security events
  • access events

These logs are used to maintain service reliability, troubleshoot technical issues, detect unauthorized access and protect Personeo and its customers.

Standard Personeo operational and security logs are normally retained for up to 30 days.

Support and business communications

If you communicate with our sales, customer success, implementation or support teams, we may retain your communication and related information where necessary to:

  • respond to your request
  • provide support
  • manage our relationship
  • implement Personeo
  • resolve technical or commercial issues
  • maintain an appropriate record of our communication

Billing information

Enterprise customers are normally billed by invoice.

We may process:

  • company name
  • billing address
  • company identification information
  • VAT information
  • billing contact details
  • invoice information
  • payment status
  • transaction references
  • information required for accounting and tax purposes

Where online card payment is available, Stripe may be used to process payments.

Personeo does not need to store full payment card information when payment is processed by Stripe.

Stripe may process payment information as an independent controller for certain activities under its own privacy terms.

3.Purposes and legal bases for processing

We process personal data only where we have an appropriate legal basis under applicable data protection law.

Depending on the context, the following legal bases may apply.

Contract and pre contractual steps

Article 6(1)(b) GDPR

We may process personal data where necessary to:

  • provide Personeo
  • create and manage user accounts
  • provide customer support
  • process a demo request
  • discuss a potential project
  • prepare a proposal
  • take steps requested before entering into a contract
  • fulfil our contractual obligations

We rely on Article 6(1)(b) GDPR where processing is necessary to perform a contract with the individual or to take steps at their request before entering into a contract. For users accessing Personeo through an organization, account administration and related processing may instead be based on legitimate interests or carried out on behalf of the Customer, depending on the context.

Legitimate interests

Article 6(1)(f) GDPR

We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the rights and interests of the individual.

Our legitimate interests may include:

  • managing B2B customer and partner relationships
  • responding to business enquiries
  • developing our business
  • improving Personeo
  • protecting our systems
  • preventing unauthorized access and abuse
  • maintaining service availability and reliability
  • investigating technical or security incidents
  • maintaining appropriate business records

Where we rely on legitimate interests, we consider the nature of the information, the purpose of the processing and the reasonable expectations of the individuals concerned.

Legal obligations

Article 6(1)(c) GDPR

We may process personal data where necessary to comply with legal obligations, including:

  • accounting requirements
  • tax requirements
  • regulatory obligations
  • legally valid government requests
  • obligations arising under applicable law

Consent

Article 6(1)(a) GDPR

Where required, we rely on consent for activities such as:

  • non essential website analytics
  • certain marketing communications
  • other optional processing requiring consent under applicable law

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

4.How we use personal data

We may use personal data for the following purposes:

  • providing and operating Personeo
  • authenticating users
  • managing accounts and access
  • providing AI roleplays and coaching
  • delivering customer support
  • implementing customer projects
  • processing demo requests
  • preparing commercial proposals
  • managing customer and partner relationships
  • processing invoices and payments
  • monitoring service reliability
  • protecting Personeo against security threats
  • investigating incidents
  • complying with legal obligations
  • improving our services
  • understanding usage and adoption
  • communicating relevant product and service information
  • analyzing public website usage where consent has been provided

Where Personeo acts as a processor, customer training data is used only in accordance with the customer's instructions and applicable agreement.

5.Artificial intelligence and model training

Personeo uses artificial intelligence to provide functionality including:

  • AI roleplay conversations
  • realtime voice interactions
  • transcription
  • roleplay evaluation
  • coaching feedback
  • training analytics

Our primary production AI provider is OpenAI.

For supported production processing:

  • Personeo uses enterprise API services
  • customer data training is disabled
  • Zero Data Retention is configured for applicable OpenAI processing
  • supported production AI processing uses an EU data processing path

Personeo does not use customer roleplay conversations, transcripts or training content to train OpenAI models.

Customer data is not used to build general purpose AI models.

AI generated feedback

AI generated scores, feedback and recommendations are designed to support training and coaching.

They should be interpreted within the context of the relevant training exercise and the success criteria configured for that roleplay.

Personeo is not designed to autonomously make employment decisions.

Personeo does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

Personeo is not intended to be used for:

  • autonomous hiring decisions
  • candidate selection
  • employee termination decisions
  • determining employment eligibility
  • workplace surveillance
  • emotion recognition
  • biometric categorization

Organizations using Personeo remain responsible for appropriate human oversight and for determining how training results are used within their organization.

6.Cookies and similar technologies

This section also serves as the Personeo Cookie Policy.

We use a limited number of cookies and similar browser technologies.

Necessary cookies and browser storage

Personeo may use first party cookies or browser storage that are necessary for:

  • authentication
  • maintaining user sessions
  • security
  • user preferences
  • core website functionality
  • core application functionality

Where these technologies are strictly necessary to provide a service requested by the user, they do not require consent under applicable law.

Analytics cookies

We use Google Analytics on the public Personeo marketing website.

Google Analytics helps us understand:

  • website traffic
  • which pages visitors view
  • how visitors navigate the website
  • general website engagement
  • website performance

Google Analytics is not used inside the authenticated Personeo application.

Analytics cookies are only used where permitted by applicable law and, where required, after the visitor has provided consent.

Cookie categories

CategoryProviderPurposeLegal basis
NecessaryPersoneoAuthentication, sessions, security and core functionalityNecessary to provide the requested service
AnalyticsGoogle AnalyticsPublic website analytics and website improvementConsent where required

Advertising and tracking

Personeo does not currently use advertising pixels or third party advertising tracking technologies within the authenticated Personeo application.

We do not sell personal data for advertising purposes.

Managing cookies

Where cookie controls are available, you may use them to accept, reject or change your preferences for non essential cookies.

You may also control cookies through your browser settings.

You may withdraw analytics consent at any time.

Withdrawal does not affect processing that was lawfully carried out before consent was withdrawn.

7.Service providers and subprocessors

We use selected third party providers to operate and support Personeo.

Hetzner

Purpose: Infrastructure hosting, data storage and backups.

Primary processing location: Germany, European Union.

OpenAI

Purpose: AI inference, realtime voice processing and transcription.

For supported Personeo production processing, customer data training is disabled and applicable processing is configured with Zero Data Retention and an EU data processing path.

Better Stack

Purpose: Monitoring, logging and service observability.

Only operational and security information necessary for these purposes is intended to be included in standard monitoring telemetry.

Customer conversation content is not included in standard Better Stack telemetry.

Cloudflare

Purpose: Authoritative DNS services.

Cloudflare is not used as the production application proxy or application CDN for Personeo.

Google

Purpose: Google Workspace and Gmail for business communication and lead management. Google Analytics for analytics on the public Personeo website.

Stripe

Purpose: Optional online payment processing.

Stripe may act as an independent controller for certain payment processing activities under its own privacy terms.

A current overview of our infrastructure, security and data processing practices is available on our Security & Trust page.

8.Sharing personal data

We do not sell personal data.

We may share personal data only where necessary and appropriate.

This may include sharing information with:

  • service providers that help us operate Personeo
  • subprocessors acting on our behalf
  • authorized Personeo partners involved in providing services to a customer
  • our professional advisers where necessary
  • authorities where disclosure is required by applicable law
  • parties involved in establishing, exercising or defending legal claims
  • parties involved in a merger, acquisition, restructuring or similar business transaction, subject to appropriate safeguards

Where Personeo acts as a processor, personal data may also be shared according to the customer's documented instructions.

Access to customer data by Personeo personnel is limited to situations where access is necessary to operate, support, secure or troubleshoot the service and is subject to internal access controls.

9.International data transfers

Personeo is designed around European infrastructure and data processing.

Our primary production infrastructure is hosted in Germany within the European Union.

Supported production AI processing is configured to use an EU processing path.

Some providers used for business communications, website analytics, payments or other supporting services may process limited personal data outside the European Economic Area depending on their configuration and corporate structure.

Where personal data is transferred outside the EEA and no adequacy decision applies, we use or rely on legally recognized safeguards where required.

These may include Standard Contractual Clauses approved by the European Commission and other safeguards available under Chapter V of the GDPR.

10.Data retention

We retain personal data only for as long as necessary for the purpose for which it was collected, taking into account contractual, operational and legal requirements.

Customer training data

Retention of customer production and training data is configurable according to customer requirements and the applicable agreement.

This may include:

  • transcripts
  • training history
  • scores
  • feedback
  • usage analytics
  • training materials
  • roleplay data

Customer data may be deleted according to the customer's instructions, supported deletion functionality or the applicable agreement.

User account data

Account information is generally retained while the relevant account or customer relationship remains active.

When an account is deleted, relevant data is removed from active systems subject to technical, contractual and legal requirements.

Residual copies may remain temporarily in backups until the normal backup retention period expires.

Voice recordings

Raw voice audio is not persistently stored by default.

If voice recording is explicitly enabled by a customer, recordings are retained according to the customer's configured or agreed retention requirements.

Operational and security logs

Standard operational and security logs are normally retained for up to 30 days.

Backups

Standard backups containing customer data are retained for a maximum of 30 days.

Data deleted from active systems may therefore remain temporarily within encrypted backup copies until those backups expire according to the normal retention cycle.

Prospective customers and business leads

Where you contact Personeo about a potential business relationship but do not become a customer, we normally retain relevant business contact information and sales communications for up to 24 months after the last meaningful interaction.

We may delete the information earlier upon request where legally appropriate.

We may retain specific information for longer where:

  • a customer relationship is established
  • continued retention is necessary for legal claims
  • applicable law requires retention
  • another valid legal basis applies

Customer and partner relationship information

Business communication and contact information may be retained for the duration of the relevant customer or partner relationship and for a reasonable period afterwards where required for legitimate business, contractual or legal purposes.

Billing and accounting records

Invoices and related accounting, tax and transaction records are retained for the periods required by applicable law.

Website analytics

Website analytics information is retained according to our Google Analytics configuration and applicable consent settings.

11.Security

We use technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss or destruction.

Depending on the system and data involved, these measures include:

  • encrypted transmission using TLS
  • encryption of sensitive data at rest
  • encrypted backups
  • role based access controls
  • multi factor authentication for privileged access
  • named privileged accounts
  • controlled production access
  • logging of privileged access
  • separation of production and non production environments
  • security monitoring
  • incident response procedures
  • vulnerability management
  • change management controls
  • penetration testing
  • backup and recovery procedures

Production data is not used in development or staging environments.

More information about our security practices is available on our Security & Trust page.

No internet based service can guarantee absolute security. We continuously review and improve our security measures based on risk and the nature of the service.

12.Your rights under GDPR

Where the GDPR applies and Personeo acts as the controller of your personal data, you may have the following rights.

Right of access

Article 15 GDPR

You may request confirmation of whether we process your personal data and obtain access to that data and related information.

Right to rectification

Article 16 GDPR

You may request correction of inaccurate personal data or completion of incomplete information.

Right to erasure

Article 17 GDPR

You may request deletion of personal data in circumstances provided by applicable law.

Right to restriction of processing

Article 18 GDPR

You may request restriction of processing in circumstances provided by applicable law.

Right to data portability

Article 20 GDPR

Where applicable, you may request personal data in a structured, commonly used and machine readable format or request its transfer to another controller.

Right to object

Article 21 GDPR

You may object to processing based on legitimate interests in circumstances provided by applicable law.

You may object to direct marketing at any time.

Right to withdraw consent

Where processing is based on consent, you may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Automated decision making

Article 22 GDPR

You have rights relating to certain decisions based solely on automated processing that produce legal or similarly significant effects.

Personeo is not designed to make such decisions about users.

Right to lodge a complaint

You have the right to lodge a complaint with a competent data protection supervisory authority.

To exercise your rights in relation to data controlled directly by Personeo, contact hello@personeo.ai.

We may need to verify your identity before completing a request.

We will respond within the timeframe required by applicable law.

13.Data controlled by your organization

If your employer, customer organization or another organization provides you access to Personeo, that organization will normally be the controller for your training related personal data.

This may include:

  • roleplay transcripts
  • training history
  • roleplay scores
  • AI feedback
  • usage information
  • adoption information
  • skill and performance analytics

Requests concerning this information should normally be directed to the organization that provided your access to Personeo.

Personeo will support that organization in responding to valid requests where required under the applicable Data Processing Agreement and data protection law.

14.Marketing communications

We may communicate with existing and prospective business contacts regarding Personeo, our services and relevant business information where permitted by applicable law.

Where consent is required, we will rely on consent.

Where applicable law permits legitimate interest based B2B communication, our legitimate interest is to develop relevant professional relationships and communicate about services that may reasonably be relevant to the recipient's professional role.

You may opt out of non essential marketing communications at any time.

Opting out of marketing does not prevent us from sending necessary service, security, contractual or administrative communications.

15.Children

Personeo is a professional training platform intended for business and organizational use.

Personeo is not intended for children.

We do not knowingly collect personal data from children through the normal operation of the service.

If you believe that a child has provided personal data to Personeo inappropriately, contact us at hello@personeo.ai.

We will review the request and take appropriate action where required.

16.Legal requests and protection of rights

We may preserve or disclose personal data where reasonably necessary to:

  • comply with applicable law
  • respond to a legally valid request from a competent authority
  • comply with a court order
  • investigate fraud or unlawful activity
  • protect Personeo, our customers or users
  • enforce our contractual rights
  • establish, exercise or defend legal claims

We will assess such requests in accordance with applicable law.

17.Business transfers

If Good Vibes Software s.r.o. is involved in a merger, acquisition, restructuring, financing, sale of assets or similar transaction, relevant personal data may be transferred as part of that transaction.

Any such transfer will remain subject to applicable data protection law and appropriate confidentiality and security requirements.

18.Changes to this policy

We may update this Privacy & Cookie Policy when:

  • our services change
  • our processing activities change
  • our providers change
  • our technology changes
  • applicable legal requirements change

The latest version will be published on this page together with the date of the most recent update.

Where a material change requires additional notice or consent under applicable law, we will provide that notice or request consent as appropriate.

19.Contact

For questions about this Privacy & Cookie Policy, our privacy practices or personal data processed directly by Personeo, contact:

Good Vibes Software s.r.o.Streďanská 2661/53B955 03 TopoľčanySlovakiaCompany ID: 54906466 Email: hello@personeo.ai

20.Supervisory authority

If you believe your personal data has been processed in violation of applicable data protection law, you have the right to contact a competent supervisory authority.

For Good Vibes Software s.r.o. in Slovakia:

Office for Personal Data Protection of the Slovak Republic

dataprotection.gov.sk