Personal data

Privacy Policy

This page sets out which personal data Tabtimize ApS processes, why we process it, who we share it with, and what rights you have.

Data controller
Tabtimize ApS
Company reg. no.
38975579
Version
2026-08-30
Updated
30 August 2026
In short
  • Your local AGM AI OS workspace and your business files stay on your own computer and are never sent to us.
  • We process the data needed for purchase, invoicing, licensing, course access, security and support.
  • Stripe handles the payment. We never receive your full card number, your CVC code or your bank login details.
  • No advertising, and no third party measures you. The course video and our own statistics only load once you say yes.
  • We do not send directly identifying customer or payment data to an AI service as part of internal analysis.
  • We do not make fully automated decisions that have legal effect or similarly significant consequences for you.

1. Who is the data controller?

Tabtimize ApS is the data controller for the processing described in this policy. AGM AI OS and AI Growth Minds are operated by the same legal entity.

Write to support@agm-ai-os.com about both the product and your personal data.

2. What does our responsibility cover?

Tabtimize ApS is the controller for processing connected with the website, purchase and payment, licence and course access, and support.

Your local files stay with you. AGM AI OS is installed on your own computer. Your workspace, your knowledge base, your business files, your prompts and your AI results are never sent to Tabtimize ApS.

When you connect AGM AI OS to an AI service or another external service yourself, that processing follows your own or your company’s agreement with the provider you chose. Tabtimize ApS does not receive what you send to that service and does not choose the provider for you.

3. What data do we process?

  • Contact and company details: name, email address, company name, billing address, country and company registration or VAT number.
  • Order and payment details: purchase date, product, amount, currency, discount, payment status, invoice and tax details, and transaction references.
  • Licence and activation details: licence data, a pseudonymous device identifier, product and software version, activation time and update entitlement.
  • Operational and security data: IP address, timestamps and the data needed about requests, errors and possible misuse of the service.
  • Course data: login and session data, plus the lessons you mark as completed yourself.
  • Communication: what you send to support, and the data we need in order to answer and resolve the matter.

The device identifier is generated automatically from a limited set of technical details about the device and is linked to the licence. We therefore treat it as personal data, not as anonymous information.

We do not ask for sensitive personal data. Please do not send health data, national identification numbers or other sensitive or confidential information to support unless it is strictly necessary and agreed with us in advance.

4. Where does the data come from, and is it required?

We receive data directly from you, automatically from your use of the website, the licence client and the course portal, and from Stripe in connection with the payment. If someone else in your company buys the licence for you, we may receive your work contact details from that company.

Contact, company, billing and payment details are required to complete the purchase and issue an invoice. Licence, device and version data are required to activate the licence, enforce the agreed machine count and deliver the right updates. Without this data we cannot deliver those functions.

Contacting support and marking lessons as completed are voluntary. You can unmark a lesson again and log out of the course portal.

If we receive your data from your company, we give you access to this policy no later than our first direct communication with you.

5. Purchase, payment and invoicing

When you choose to buy, you are sent to a checkout hosted by Stripe. Stripe collects the contact, company, billing and payment details required for payment, tax calculation and invoicing.

Tabtimize ApS never receives your full card number, your CVC code or your bank login details. We receive limited information about the transaction and the payment method for delivery, bookkeeping, refunds, prevention of misuse and handling of disputes.

The checkout page sits on Stripe’s own domain. Any cookies you meet there are set by Stripe under Stripe’s own privacy policy and cannot be read by us.

6. Licence, activation and updates

During activation and ongoing licence checks we process the necessary licence, device and version data. It is used to validate the licence, enforce the agreed machine count, deliver the correct version and determine update entitlement.

Your local workspace and its contents are never included in activation, validation or updates.

7. Course platform and video

We process the necessary login and session data to give access to the course portal. Session data expires after 30 days or is deleted when you log out.

When you mark a lesson as completed, we store the licence reference, the lesson and the time. The course does not measure how much of a video you have watched.

Course videos are delivered by Vimeo. The player is configured to limit tracking, and it does not load until you have given your consent. Vimeo may then receive technical data needed to deliver and protect the video player, including IP address, browser and device information. Section 11 describes the choice and the specific technologies.

8. Support and other communication

When you write to us, we process your email address, your message, any attachments and the order or product details needed to understand and resolve the matter.

As a rule we only ask for a masked licence reference or another safe confirmation. Do not send your full licence key or information about your own customers, employees and partners by ordinary email unless we have expressly agreed a secure method.

9. AI and automated checks

We may use AI as an internal working tool to summarise or analyse general product, customer-segment and support themes. We do not send names, email addresses, payment details, addresses, company or VAT numbers, licence data, device identifiers or unedited support enquiries to an AI service for this purpose.

Before material is used for internal AI analysis, we remove direct identifiers and aggregate the data where possible. If data can still be linked to a person, we continue to treat it as personal data and apply a relevant data processing agreement and a valid transfer basis.

AI analysis is never used to assess an individual or to determine price, licence access, course access, support or any other entitlement.

Licence and access checks run automatically under the agreed product terms. If you believe a check is wrong, contact support and a person will review the matter.

10. Purposes and legal bases

  • Purchase, delivery, licence, course and support: GDPR Article 6(1)(b) where you are the contracting party yourself. Where you buy or use the product on behalf of a company, the basis is our legitimate interest in entering into and performing the B2B agreement under Article 6(1)(f).
  • Invoicing, bookkeeping, tax and responding to lawful requests from authorities: a legal obligation under Article 6(1)(c).
  • IT security, prevention of misuse, troubleshooting and documenting the agreement: our legitimate interest in protecting the service, our customers and our legal position under Article 6(1)(f).
  • Loading the course video from Vimeo: your consent under Article 6(1)(a), together with the national rules implementing the ePrivacy Directive.
  • Limited product, business and customer-segment analysis, including the internal AI analysis described above: our legitimate interest in understanding and improving AGM AI OS under Article 6(1)(f).

When we rely on legitimate interests, we weigh data minimisation, the professional customer relationship, your reasonable expectations and the relevant safeguards.

You can object. You can object at any time to processing based on our legitimate interests by writing to support@agm-ai-os.com. We then assess whether the processing must stop.

11. Cookies and similar technologies

The website sets two cookies of its own, and both are necessary for functions you asked for yourself. Beyond those, two things are optional, and neither of them loads until you have said yes: the course video and our own measurement of how the site is used. There is no advertising on the site — no tracking pixels, no tag managers and no social plugins.

The course video is delivered by Vimeo, and the player stores four files on your device when it loads. That is why it does not load until you have said yes. If you say no, the rest of the course portal works exactly as before.

The measurement is entirely our own. The events go from your browser to our own server and into our own database — Google, Meta, Hotjar and every other third party receive nothing at all. We record which page was seen, roughly what was clicked and how far down the page you got. We do not store your IP address, anything about your browser or your device, or anything at all that ties the measurement to you, your email or your licence. The identifier that holds a single visit together is kept in the browser tab and is gone the moment you close it, so what we count is visits, not people. The events are deleted after 90 days.

NameSet byPurposeDuration
agm_course_sessionAGM AI OSKeeps you logged in to the course portal30 days
agm_cookie_consentAGM AI OSRemembers your choices about cookies12 months
agm_visitAGM AI OSHolds one visit together in the statistics — kept in the browser tab, not a cookieUntil you close the tab
player_clearanceVimeoProtects the video player against misuse7 days
cf_clearanceCloudflare (for Vimeo)Protects the video player against misuse1 year
__cf_bmCloudflare (for Vimeo)Tells humans and bots apart30 minutes
_cfuvidCloudflare (for Vimeo)Limits the number of requests to the playerSession

When you allow the player, Vimeo and Cloudflare receive your IP address along with information about your browser and your device. That is required to deliver and protect the video. The player runs with tracking switched off and therefore sets no cookies for statistics or advertising.

You can always change your mind. Your choices are stored for 12 months and can be changed at any time on the cookie page, which is linked at the bottom of every page. Withdrawing consent is as easy as giving it, and it costs nothing.

The legal basis for the necessary cookies is the exemption for strictly necessary technologies. The legal basis for the video player and for the measurement is your consent, which you can withdraw at any time; the aggregate numbers are then used on the basis of our legitimate interest in improving the site. If we later introduce advertising, that is a new purpose, and you will be asked again.

12. Who receives data?

  • Stripe: payment, tax calculation, invoicing, fraud checks and refunds.
  • Cloud, hosting and database providers: operation of the website, licence system, course portal, database, backup and security logs.
  • Transactional email providers: sending and delivering licence and purchase information.
  • Course administration and customer communication providers: creating and maintaining course access where that function is used.
  • Vimeo and Vimeo’s security provider: delivering and protecting course videos once you have allowed the player.
  • Selected AI providers: only the minimised material described in section 9.
  • Auditors, lawyers, insurers and public authorities where necessary or required by law.

Our providers may only process data according to their role and the agreements that apply to the specific processing. We do not sell personal data.

13. Processing outside the EU/EEA

Some of our payment, cloud, email, video and AI providers are international companies or use sub-processors in, among other places, the United States. This may mean that personal data is processed in or accessed from countries outside the EU/EEA.

For every actual transfer we apply a valid transfer basis. That may be the European Commission’s adequacy decision under the EU-U.S. Data Privacy Framework for a certified US recipient, or the European Commission’s standard contractual clauses with relevant supplementary measures.

You can contact us to learn the specific basis for a transfer and to receive a copy of the relevant safeguards or information about where they are made available.

14. How long do we keep data?

  • Order, invoice and accounting material is kept as a rule for 5 years from the end of the financial year it relates to.
  • Licence, activation and course data is kept for as long as the licence and the associated course access exist. Data that does not have to be retained for other reasons is deleted or anonymised as a rule no later than 3 years after final termination.
  • Support enquiries are kept as a rule for up to 3 years after the matter is closed. Data is deleted earlier when there is no longer a legitimate need, and may be kept longer during an active dispute or legal claim.
  • Operational and security logs are deleted on an ongoing basis and as a rule no later than after 30 days. Short-lived records used to limit misuse are deleted sooner.
  • Delivery logs for transactional emails are kept as a rule for up to 30 days.
  • Your cookie choice is stored for 12 months on your own device. We keep no central register of individual choices.
  • Material containing pseudonymised personal data used for internal analysis is deleted or anonymised once the specific analysis and any necessary quality check are complete.

When data is deleted from active systems, a protected copy may remain in a rolling backup for up to 30 days before it is overwritten. Data may be kept longer where legislation, an official requirement or a specific legal claim makes it necessary.

15. How we protect the data

We apply risk-based technical and organisational measures, including access restrictions, encrypted transmission, protection against misuse, backup and ongoing assessment of security.

Only people and providers with a legitimate need are given access. No technical solution is risk-free, so we adapt the measures to the nature of the data, the scope of the processing and the current risks.

16. Your rights

Depending on the circumstances you can request access to your personal data, have inaccurate data corrected, have data erased, have the processing restricted, receive data in a structured format, or object to processing based on our legitimate interests.

Where processing is based on your consent, you can withdraw that consent at any time. This does not affect the lawfulness of the processing carried out before the withdrawal.

These rights are not absolute. We may, for example, be required to keep invoicing records under accounting law, or data needed to establish or defend a legal claim. We explain the reason if we cannot meet a request in full.

Write to support@agm-ai-os.com to exercise your rights. We may ask for the information needed to confirm your identity. We reply without undue delay and normally within one month of receiving the request.

17. Complaints to a supervisory authority

Please contact us first so that we can look into a problem and put it right. You also have the right to complain to a data protection supervisory authority if you believe our processing of your personal data breaches the rules. Tabtimize ApS is established in Denmark, where the authority is Datatilsynet; complaints about the use of cookies are handled by the Danish Agency for Digital Government. You may also complain to the supervisory authority in your own country.

Datatilsynet — contact details and how to complain

18. Changes to this policy

We update this policy when our processing, our categories of providers or legal requirements change. The current version and update date are shown at the top of the page. For material changes that genuinely affect existing customers or users, we give notice in an appropriate way, for example by email or through the course portal.

Tabtimize ApS
Company reg. no. 38975579
Grundtvigs Alle 137
6700 Esbjerg, Denmark
support@agm-ai-os.com