Privacy & Cookie Policy
Personeo is provided by Good Vibes Software s.r.o., Streďanská 2661/53B, 955 03 Topoľčany, Slovakia, Company ID 54906466, registered in the Commercial Register maintained by the Municipal Court of Nitra, section Sro, insert 58337/N.
In this policy, “Personeo”, “we”, “us” and “our” refer to Good Vibes Software s.r.o.
This Privacy & Cookie Policy explains how we collect, use, store, share and protect personal data when you visit our website, communicate with us or use the Personeo platform.
Personeo is primarily a business to business service. Depending on the context, Good Vibes Software s.r.o. may process personal data either as a data controller or as a data processor acting on behalf of a customer.
If you have any questions about this policy or the processing of personal data, contact us at hello@personeo.ai.
1.Our role under data protection law
When Personeo acts as a controller
Good Vibes Software s.r.o. generally acts as a data controller when we determine why and how personal data is processed for our own business purposes.
This may include personal data relating to:
- visitors to our public website
- people who request a demo or contact us
- prospective customers and business contacts
- partners and partner contacts
- customer administrators and commercial contacts
- account and authentication information required to operate Personeo
- billing and invoicing
- security and operational information required to protect and operate the service
- communications with our sales, customer success, implementation and support teams
When Personeo acts as a processor
When an organization provides Personeo to its employees, contractors or other users for training purposes, the organization will normally determine why the training data is processed.
In this situation, the organization normally acts as the data controller and Personeo acts as its data processor.
Data processed on behalf of customers may include:
- roleplay conversations and transcripts
- roleplay scores
- AI generated feedback
- training history
- usage and adoption information
- skill and performance analytics
- roleplay configurations and evaluation criteria
- customer provided training materials
- custom roleplay content
- voice recordings where recording has been explicitly enabled
We process this information according to the customer's instructions, the applicable agreement and, where relevant, a Data Processing Agreement.
If you use Personeo through your employer or another organization and your request concerns training data controlled by that organization, you should normally contact that organization first.
Personeo will assist its customers with valid data subject requests where required by applicable law and our contractual obligations.
2.Personal data we collect
The personal data we process depends on how you interact with Personeo.
Website visitors
When you visit our public website, we may process information including:
- IP address
- browser type and version
- device information
- operating system
- language settings
- approximate geographic information derived from technical data
- referring page
- pages visited
- date and time of access
- website interaction information
- analytics information where analytics consent has been provided
Google Analytics is used only on the public Personeo marketing website.
Google Analytics is not used within the authenticated Personeo application.
Demo requests, prospective customers and business contacts
If you request a demo, contact us, attend a meeting or otherwise communicate with our team, we may process:
- name and surname
- business email address
- phone number where provided
- company
- job title or business role
- country
- information included in your message or enquiry
- meeting history
- communication history
- information about your organization's needs, training processes and potential Personeo use case
We may also receive professional contact information from:
- your organization
- authorized Personeo partners
- event organizers
- referrals
- legitimate publicly available business sources
We currently manage sales and business communications primarily through Google Workspace and Gmail.
Personeo user accounts
When you create or use a Personeo account, we may process:
- name and surname
- email address
- organization
- workspace and team membership
- user role and permissions
- authentication information
- session information
- language and account preferences
- account activity
- security events
- technical and operational logs
Training and roleplay data
When Personeo is used for training, the platform may process:
- roleplay transcripts
- user responses
- roleplay scores
- AI generated coaching feedback
- training history
- skill development information
- practice activity
- usage information
- adoption analytics
- roleplay configuration
- roleplay evaluation criteria
- training materials provided by the customer
This information will normally be processed on behalf of the organization providing Personeo to the user.
Voice data
Personeo supports voice based AI roleplays.
By default, raw voice audio is processed transiently in order to provide the voice conversation and is not persistently stored by Personeo.
Where a customer explicitly enables voice recording, audio may be stored as part of that customer's configuration.
In such cases, access and retention are governed by the customer's agreed configuration, policies and contractual requirements.
Transcripts created from voice conversations may be stored as part of the training session according to the applicable customer retention settings.
Service and security logs
To operate and protect Personeo, we may process service and security log information such as:
- IP address
- timestamps
- authentication events
- browser and device information
- request metadata
- application errors
- service availability information
- security events
- access events
These logs are used to maintain service reliability, troubleshoot technical issues, detect unauthorized access and protect Personeo and its customers.
Standard Personeo operational and security logs are normally retained for up to 30 days.
Support and business communications
If you communicate with our sales, customer success, implementation or support teams, we may retain your communication and related information where necessary to:
- respond to your request
- provide support
- manage our relationship
- implement Personeo
- resolve technical or commercial issues
- maintain an appropriate record of our communication
Billing information
Enterprise customers are normally billed by invoice.
We may process:
- company name
- billing address
- company identification information
- VAT information
- billing contact details
- invoice information
- payment status
- transaction references
- information required for accounting and tax purposes
Where online card payment is available, Stripe may be used to process payments.
Personeo does not need to store full payment card information when payment is processed by Stripe.
Stripe may process payment information as an independent controller for certain activities under its own privacy terms.
3.Purposes and legal bases for processing
We process personal data only where we have an appropriate legal basis under applicable data protection law.
Depending on the context, the following legal bases may apply.
Contract and pre contractual steps
We may process personal data where necessary to:
- provide Personeo
- create and manage user accounts
- provide customer support
- process a demo request
- discuss a potential project
- prepare a proposal
- take steps requested before entering into a contract
- fulfil our contractual obligations
We rely on Article 6(1)(b) GDPR where processing is necessary to perform a contract with the individual or to take steps at their request before entering into a contract. For users accessing Personeo through an organization, account administration and related processing may instead be based on legitimate interests or carried out on behalf of the Customer, depending on the context.
Legitimate interests
We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the rights and interests of the individual.
Our legitimate interests may include:
- managing B2B customer and partner relationships
- responding to business enquiries
- developing our business
- improving Personeo
- protecting our systems
- preventing unauthorized access and abuse
- maintaining service availability and reliability
- investigating technical or security incidents
- maintaining appropriate business records
Where we rely on legitimate interests, we consider the nature of the information, the purpose of the processing and the reasonable expectations of the individuals concerned.
Legal obligations
We may process personal data where necessary to comply with legal obligations, including:
- accounting requirements
- tax requirements
- regulatory obligations
- legally valid government requests
- obligations arising under applicable law
Consent
Where required, we rely on consent for activities such as:
- non essential website analytics
- certain marketing communications
- other optional processing requiring consent under applicable law
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
4.How we use personal data
We may use personal data for the following purposes:
- providing and operating Personeo
- authenticating users
- managing accounts and access
- providing AI roleplays and coaching
- delivering customer support
- implementing customer projects
- processing demo requests
- preparing commercial proposals
- managing customer and partner relationships
- processing invoices and payments
- monitoring service reliability
- protecting Personeo against security threats
- investigating incidents
- complying with legal obligations
- improving our services
- understanding usage and adoption
- communicating relevant product and service information
- analyzing public website usage where consent has been provided
Where Personeo acts as a processor, customer training data is used only in accordance with the customer's instructions and applicable agreement.
5.Artificial intelligence and model training
Personeo uses artificial intelligence to provide functionality including:
- AI roleplay conversations
- realtime voice interactions
- transcription
- roleplay evaluation
- coaching feedback
- training analytics
Our primary production AI provider is OpenAI.
For supported production processing:
- Personeo uses enterprise API services
- customer data training is disabled
- Zero Data Retention is configured for applicable OpenAI processing
- supported production AI processing uses an EU data processing path
Personeo does not use customer roleplay conversations, transcripts or training content to train OpenAI models.
Customer data is not used to build general purpose AI models.
AI generated feedback
AI generated scores, feedback and recommendations are designed to support training and coaching.
They should be interpreted within the context of the relevant training exercise and the success criteria configured for that roleplay.
Personeo is not designed to autonomously make employment decisions.
Personeo does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
Personeo is not intended to be used for:
- autonomous hiring decisions
- candidate selection
- employee termination decisions
- determining employment eligibility
- workplace surveillance
- emotion recognition
- biometric categorization
Organizations using Personeo remain responsible for appropriate human oversight and for determining how training results are used within their organization.
6.Cookies and similar technologies
This section also serves as the Personeo Cookie Policy.
We use a limited number of cookies and similar browser technologies.
Necessary cookies and browser storage
Personeo may use first party cookies or browser storage that are necessary for:
- authentication
- maintaining user sessions
- security
- user preferences
- core website functionality
- core application functionality
Where these technologies are strictly necessary to provide a service requested by the user, they do not require consent under applicable law.
Analytics cookies
We use Google Analytics on the public Personeo marketing website.
Google Analytics helps us understand:
- website traffic
- which pages visitors view
- how visitors navigate the website
- general website engagement
- website performance
Google Analytics is not used inside the authenticated Personeo application.
Analytics cookies are only used where permitted by applicable law and, where required, after the visitor has provided consent.
Cookie categories
| Category | Provider | Purpose | Legal basis |
|---|---|---|---|
| Necessary | Personeo | Authentication, sessions, security and core functionality | Necessary to provide the requested service |
| Analytics | Google Analytics | Public website analytics and website improvement | Consent where required |
Advertising and tracking
Personeo does not currently use advertising pixels or third party advertising tracking technologies within the authenticated Personeo application.
We do not sell personal data for advertising purposes.
Managing cookies
Where cookie controls are available, you may use them to accept, reject or change your preferences for non essential cookies.
You may also control cookies through your browser settings.
You may withdraw analytics consent at any time.
Withdrawal does not affect processing that was lawfully carried out before consent was withdrawn.
7.Service providers and subprocessors
We use selected third party providers to operate and support Personeo.
Hetzner
Purpose: Infrastructure hosting, data storage and backups.
Primary processing location: Germany, European Union.
OpenAI
Purpose: AI inference, realtime voice processing and transcription.
For supported Personeo production processing, customer data training is disabled and applicable processing is configured with Zero Data Retention and an EU data processing path.
Better Stack
Purpose: Monitoring, logging and service observability.
Only operational and security information necessary for these purposes is intended to be included in standard monitoring telemetry.
Customer conversation content is not included in standard Better Stack telemetry.
Cloudflare
Purpose: Authoritative DNS services.
Cloudflare is not used as the production application proxy or application CDN for Personeo.
Purpose: Google Workspace and Gmail for business communication and lead management. Google Analytics for analytics on the public Personeo website.
Stripe
Purpose: Optional online payment processing.
Stripe may act as an independent controller for certain payment processing activities under its own privacy terms.
A current overview of our infrastructure, security and data processing practices is available on our Security & Trust page.
8.Sharing personal data
We do not sell personal data.
We may share personal data only where necessary and appropriate.
This may include sharing information with:
- service providers that help us operate Personeo
- subprocessors acting on our behalf
- authorized Personeo partners involved in providing services to a customer
- our professional advisers where necessary
- authorities where disclosure is required by applicable law
- parties involved in establishing, exercising or defending legal claims
- parties involved in a merger, acquisition, restructuring or similar business transaction, subject to appropriate safeguards
Where Personeo acts as a processor, personal data may also be shared according to the customer's documented instructions.
Access to customer data by Personeo personnel is limited to situations where access is necessary to operate, support, secure or troubleshoot the service and is subject to internal access controls.
9.International data transfers
Personeo is designed around European infrastructure and data processing.
Our primary production infrastructure is hosted in Germany within the European Union.
Supported production AI processing is configured to use an EU processing path.
Some providers used for business communications, website analytics, payments or other supporting services may process limited personal data outside the European Economic Area depending on their configuration and corporate structure.
Where personal data is transferred outside the EEA and no adequacy decision applies, we use or rely on legally recognized safeguards where required.
These may include Standard Contractual Clauses approved by the European Commission and other safeguards available under Chapter V of the GDPR.
10.Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected, taking into account contractual, operational and legal requirements.
Customer training data
Retention of customer production and training data is configurable according to customer requirements and the applicable agreement.
This may include:
- transcripts
- training history
- scores
- feedback
- usage analytics
- training materials
- roleplay data
Customer data may be deleted according to the customer's instructions, supported deletion functionality or the applicable agreement.
User account data
Account information is generally retained while the relevant account or customer relationship remains active.
When an account is deleted, relevant data is removed from active systems subject to technical, contractual and legal requirements.
Residual copies may remain temporarily in backups until the normal backup retention period expires.
Voice recordings
Raw voice audio is not persistently stored by default.
If voice recording is explicitly enabled by a customer, recordings are retained according to the customer's configured or agreed retention requirements.
Operational and security logs
Standard operational and security logs are normally retained for up to 30 days.
Backups
Standard backups containing customer data are retained for a maximum of 30 days.
Data deleted from active systems may therefore remain temporarily within encrypted backup copies until those backups expire according to the normal retention cycle.
Prospective customers and business leads
Where you contact Personeo about a potential business relationship but do not become a customer, we normally retain relevant business contact information and sales communications for up to 24 months after the last meaningful interaction.
We may delete the information earlier upon request where legally appropriate.
We may retain specific information for longer where:
- a customer relationship is established
- continued retention is necessary for legal claims
- applicable law requires retention
- another valid legal basis applies
Customer and partner relationship information
Business communication and contact information may be retained for the duration of the relevant customer or partner relationship and for a reasonable period afterwards where required for legitimate business, contractual or legal purposes.
Billing and accounting records
Invoices and related accounting, tax and transaction records are retained for the periods required by applicable law.
Website analytics
Website analytics information is retained according to our Google Analytics configuration and applicable consent settings.
11.Security
We use technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss or destruction.
Depending on the system and data involved, these measures include:
- encrypted transmission using TLS
- encryption of sensitive data at rest
- encrypted backups
- role based access controls
- multi factor authentication for privileged access
- named privileged accounts
- controlled production access
- logging of privileged access
- separation of production and non production environments
- security monitoring
- incident response procedures
- vulnerability management
- change management controls
- penetration testing
- backup and recovery procedures
Production data is not used in development or staging environments.
More information about our security practices is available on our Security & Trust page.
No internet based service can guarantee absolute security. We continuously review and improve our security measures based on risk and the nature of the service.
12.Your rights under GDPR
Where the GDPR applies and Personeo acts as the controller of your personal data, you may have the following rights.
Right of access
You may request confirmation of whether we process your personal data and obtain access to that data and related information.
Right to rectification
You may request correction of inaccurate personal data or completion of incomplete information.
Right to erasure
You may request deletion of personal data in circumstances provided by applicable law.
Right to restriction of processing
You may request restriction of processing in circumstances provided by applicable law.
Right to data portability
Where applicable, you may request personal data in a structured, commonly used and machine readable format or request its transfer to another controller.
Right to object
You may object to processing based on legitimate interests in circumstances provided by applicable law.
You may object to direct marketing at any time.
Right to withdraw consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Automated decision making
You have rights relating to certain decisions based solely on automated processing that produce legal or similarly significant effects.
Personeo is not designed to make such decisions about users.
Right to lodge a complaint
You have the right to lodge a complaint with a competent data protection supervisory authority.
To exercise your rights in relation to data controlled directly by Personeo, contact hello@personeo.ai.
We may need to verify your identity before completing a request.
We will respond within the timeframe required by applicable law.
13.Data controlled by your organization
If your employer, customer organization or another organization provides you access to Personeo, that organization will normally be the controller for your training related personal data.
This may include:
- roleplay transcripts
- training history
- roleplay scores
- AI feedback
- usage information
- adoption information
- skill and performance analytics
Requests concerning this information should normally be directed to the organization that provided your access to Personeo.
Personeo will support that organization in responding to valid requests where required under the applicable Data Processing Agreement and data protection law.
14.Marketing communications
We may communicate with existing and prospective business contacts regarding Personeo, our services and relevant business information where permitted by applicable law.
Where consent is required, we will rely on consent.
Where applicable law permits legitimate interest based B2B communication, our legitimate interest is to develop relevant professional relationships and communicate about services that may reasonably be relevant to the recipient's professional role.
You may opt out of non essential marketing communications at any time.
Opting out of marketing does not prevent us from sending necessary service, security, contractual or administrative communications.
15.Children
Personeo is a professional training platform intended for business and organizational use.
Personeo is not intended for children.
We do not knowingly collect personal data from children through the normal operation of the service.
If you believe that a child has provided personal data to Personeo inappropriately, contact us at hello@personeo.ai.
We will review the request and take appropriate action where required.
16.Legal requests and protection of rights
We may preserve or disclose personal data where reasonably necessary to:
- comply with applicable law
- respond to a legally valid request from a competent authority
- comply with a court order
- investigate fraud or unlawful activity
- protect Personeo, our customers or users
- enforce our contractual rights
- establish, exercise or defend legal claims
We will assess such requests in accordance with applicable law.
17.Business transfers
If Good Vibes Software s.r.o. is involved in a merger, acquisition, restructuring, financing, sale of assets or similar transaction, relevant personal data may be transferred as part of that transaction.
Any such transfer will remain subject to applicable data protection law and appropriate confidentiality and security requirements.
18.Changes to this policy
We may update this Privacy & Cookie Policy when:
- our services change
- our processing activities change
- our providers change
- our technology changes
- applicable legal requirements change
The latest version will be published on this page together with the date of the most recent update.
Where a material change requires additional notice or consent under applicable law, we will provide that notice or request consent as appropriate.
19.Contact
For questions about this Privacy & Cookie Policy, our privacy practices or personal data processed directly by Personeo, contact:
Good Vibes Software s.r.o.Streďanská 2661/53B955 03 TopoľčanySlovakiaCompany ID: 54906466 Email: hello@personeo.ai20.Supervisory authority
If you believe your personal data has been processed in violation of applicable data protection law, you have the right to contact a competent supervisory authority.
For Good Vibes Software s.r.o. in Slovakia:
Office for Personal Data Protection of the Slovak Republic