- Your local AGM AI OS workspace and your business files stay on your own computer and are never sent to us.
- We process the data needed for purchase, invoicing, licensing, course access, security and support.
- Stripe handles the payment. We never receive your full card number, your CVC code or your bank login details.
- No advertising, and no third party measures you. The course video and our own statistics only load once you say yes.
- We do not send directly identifying customer or payment data to an AI service as part of internal analysis.
- We do not make fully automated decisions that have legal effect or similarly significant consequences for you.
1. Who is the data controller?
Tabtimize ApS is the data controller for the processing described in this policy. AGM AI OS and AI Growth Minds are operated by the same legal entity.
Write to support@agm-ai-os.com about both the product and your personal data.
2. What does our responsibility cover?
Tabtimize ApS is the controller for processing connected with the website, purchase and payment, licence and course access, and support.
When you connect AGM AI OS to an AI service or another external service yourself, that processing follows your own or your company’s agreement with the provider you chose. Tabtimize ApS does not receive what you send to that service and does not choose the provider for you.
3. What data do we process?
- Contact and company details: name, email address, company name, billing address, country and company registration or VAT number.
- Order and payment details: purchase date, product, amount, currency, discount, payment status, invoice and tax details, and transaction references.
- Licence and activation details: licence data, a pseudonymous device identifier, product and software version, activation time and update entitlement.
- Operational and security data: IP address, timestamps and the data needed about requests, errors and possible misuse of the service.
- Course data: login and session data, plus the lessons you mark as completed yourself.
- Communication: what you send to support, and the data we need in order to answer and resolve the matter.
The device identifier is generated automatically from a limited set of technical details about the device and is linked to the licence. We therefore treat it as personal data, not as anonymous information.
We do not ask for sensitive personal data. Please do not send health data, national identification numbers or other sensitive or confidential information to support unless it is strictly necessary and agreed with us in advance.
4. Where does the data come from, and is it required?
We receive data directly from you, automatically from your use of the website, the licence client and the course portal, and from Stripe in connection with the payment. If someone else in your company buys the licence for you, we may receive your work contact details from that company.
Contact, company, billing and payment details are required to complete the purchase and issue an invoice. Licence, device and version data are required to activate the licence, enforce the agreed machine count and deliver the right updates. Without this data we cannot deliver those functions.
Contacting support and marking lessons as completed are voluntary. You can unmark a lesson again and log out of the course portal.
If we receive your data from your company, we give you access to this policy no later than our first direct communication with you.
5. Purchase, payment and invoicing
When you choose to buy, you are sent to a checkout hosted by Stripe. Stripe collects the contact, company, billing and payment details required for payment, tax calculation and invoicing.
Tabtimize ApS never receives your full card number, your CVC code or your bank login details. We receive limited information about the transaction and the payment method for delivery, bookkeeping, refunds, prevention of misuse and handling of disputes.
The checkout page sits on Stripe’s own domain. Any cookies you meet there are set by Stripe under Stripe’s own privacy policy and cannot be read by us.
6. Licence, activation and updates
During activation and ongoing licence checks we process the necessary licence, device and version data. It is used to validate the licence, enforce the agreed machine count, deliver the correct version and determine update entitlement.
Your local workspace and its contents are never included in activation, validation or updates.
7. Course platform and video
We process the necessary login and session data to give access to the course portal. Session data expires after 30 days or is deleted when you log out.
When you mark a lesson as completed, we store the licence reference, the lesson and the time. The course does not measure how much of a video you have watched.
Course videos are delivered by Vimeo. The player is configured to limit tracking, and it does not load until you have given your consent. Vimeo may then receive technical data needed to deliver and protect the video player, including IP address, browser and device information. Section 11 describes the choice and the specific technologies.
8. Support and other communication
When you write to us, we process your email address, your message, any attachments and the order or product details needed to understand and resolve the matter.
As a rule we only ask for a masked licence reference or another safe confirmation. Do not send your full licence key or information about your own customers, employees and partners by ordinary email unless we have expressly agreed a secure method.
9. AI and automated checks
We may use AI as an internal working tool to summarise or analyse general product, customer-segment and support themes. We do not send names, email addresses, payment details, addresses, company or VAT numbers, licence data, device identifiers or unedited support enquiries to an AI service for this purpose.
Before material is used for internal AI analysis, we remove direct identifiers and aggregate the data where possible. If data can still be linked to a person, we continue to treat it as personal data and apply a relevant data processing agreement and a valid transfer basis.
AI analysis is never used to assess an individual or to determine price, licence access, course access, support or any other entitlement.
Licence and access checks run automatically under the agreed product terms. If you believe a check is wrong, contact support and a person will review the matter.
10. Purposes and legal bases
- Purchase, delivery, licence, course and support: GDPR Article 6(1)(b) where you are the contracting party yourself. Where you buy or use the product on behalf of a company, the basis is our legitimate interest in entering into and performing the B2B agreement under Article 6(1)(f).
- Invoicing, bookkeeping, tax and responding to lawful requests from authorities: a legal obligation under Article 6(1)(c).
- IT security, prevention of misuse, troubleshooting and documenting the agreement: our legitimate interest in protecting the service, our customers and our legal position under Article 6(1)(f).
- Loading the course video from Vimeo: your consent under Article 6(1)(a), together with the national rules implementing the ePrivacy Directive.
- Limited product, business and customer-segment analysis, including the internal AI analysis described above: our legitimate interest in understanding and improving AGM AI OS under Article 6(1)(f).
When we rely on legitimate interests, we weigh data minimisation, the professional customer relationship, your reasonable expectations and the relevant safeguards.
12. Who receives data?
- Stripe: payment, tax calculation, invoicing, fraud checks and refunds.
- Cloud, hosting and database providers: operation of the website, licence system, course portal, database, backup and security logs.
- Transactional email providers: sending and delivering licence and purchase information.
- Course administration and customer communication providers: creating and maintaining course access where that function is used.
- Vimeo and Vimeo’s security provider: delivering and protecting course videos once you have allowed the player.
- Selected AI providers: only the minimised material described in section 9.
- Auditors, lawyers, insurers and public authorities where necessary or required by law.
Our providers may only process data according to their role and the agreements that apply to the specific processing. We do not sell personal data.
13. Processing outside the EU/EEA
Some of our payment, cloud, email, video and AI providers are international companies or use sub-processors in, among other places, the United States. This may mean that personal data is processed in or accessed from countries outside the EU/EEA.
For every actual transfer we apply a valid transfer basis. That may be the European Commission’s adequacy decision under the EU-U.S. Data Privacy Framework for a certified US recipient, or the European Commission’s standard contractual clauses with relevant supplementary measures.
You can contact us to learn the specific basis for a transfer and to receive a copy of the relevant safeguards or information about where they are made available.
14. How long do we keep data?
- Order, invoice and accounting material is kept as a rule for 5 years from the end of the financial year it relates to.
- Licence, activation and course data is kept for as long as the licence and the associated course access exist. Data that does not have to be retained for other reasons is deleted or anonymised as a rule no later than 3 years after final termination.
- Support enquiries are kept as a rule for up to 3 years after the matter is closed. Data is deleted earlier when there is no longer a legitimate need, and may be kept longer during an active dispute or legal claim.
- Operational and security logs are deleted on an ongoing basis and as a rule no later than after 30 days. Short-lived records used to limit misuse are deleted sooner.
- Delivery logs for transactional emails are kept as a rule for up to 30 days.
- Your cookie choice is stored for 12 months on your own device. We keep no central register of individual choices.
- Material containing pseudonymised personal data used for internal analysis is deleted or anonymised once the specific analysis and any necessary quality check are complete.
When data is deleted from active systems, a protected copy may remain in a rolling backup for up to 30 days before it is overwritten. Data may be kept longer where legislation, an official requirement or a specific legal claim makes it necessary.
15. How we protect the data
We apply risk-based technical and organisational measures, including access restrictions, encrypted transmission, protection against misuse, backup and ongoing assessment of security.
Only people and providers with a legitimate need are given access. No technical solution is risk-free, so we adapt the measures to the nature of the data, the scope of the processing and the current risks.
16. Your rights
Depending on the circumstances you can request access to your personal data, have inaccurate data corrected, have data erased, have the processing restricted, receive data in a structured format, or object to processing based on our legitimate interests.
Where processing is based on your consent, you can withdraw that consent at any time. This does not affect the lawfulness of the processing carried out before the withdrawal.
These rights are not absolute. We may, for example, be required to keep invoicing records under accounting law, or data needed to establish or defend a legal claim. We explain the reason if we cannot meet a request in full.
Write to support@agm-ai-os.com to exercise your rights. We may ask for the information needed to confirm your identity. We reply without undue delay and normally within one month of receiving the request.
17. Complaints to a supervisory authority
Please contact us first so that we can look into a problem and put it right. You also have the right to complain to a data protection supervisory authority if you believe our processing of your personal data breaches the rules. Tabtimize ApS is established in Denmark, where the authority is Datatilsynet; complaints about the use of cookies are handled by the Danish Agency for Digital Government. You may also complain to the supervisory authority in your own country.
18. Changes to this policy
We update this policy when our processing, our categories of providers or legal requirements change. The current version and update date are shown at the top of the page. For material changes that genuinely affect existing customers or users, we give notice in an appropriate way, for example by email or through the course portal.
Company reg. no. 38975579
Grundtvigs Alle 137
6700 Esbjerg, Denmark
support@agm-ai-os.com