Jo's AIC LogoJo's AIC

Privacy Policy

Last updated: May 2, 2026

1. Data Controller

The data controller is Jo's AIC, legally based in Italy.

Controller: Benito Finetto

Email: contatto@josaic.com

2. Types of Data Collected

We collect the following types of personal data:

  • Identification data (name, email, company) voluntarily provided via the form
  • Usage data (monthly AI spend, subscriptions, data types processed)
  • Technical data (hashed IP address, consent version)
  • Navigation data (technical cookies necessary for operation)

3. Purposes of Processing

Data is processed for the following purposes:

  • Service provision: Calculation of AI Local ROI and generation of personalized report
  • Legitimate interest: Anonymized statistical analysis of calculator results
  • Consent: Sending commercial communications about AI consulting services (revocable at any time)

4. Legal Basis for Processing

Processing is based on: (a) performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) for service delivery; (b) legitimate interest (Art. 6(1)(f) GDPR) for statistical analysis; (c) explicit consent (Art. 6(1)(a) GDPR) for commercial communications.

5. Data Subject Rights

At any time, you have the right to:

  • Access your personal data (Art. 15 GDPR)
  • Rectify inaccurate data (Art. 16 GDPR)
  • Erase your data ('right to be forgotten', Art. 17 GDPR)
  • Restrict processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)

To exercise your rights, visit our consent withdrawal page.

6. Data Retention

Contact data is stored for 36 months from collection. Aggregated usage data is stored for 12 months. Consent records are stored for 36 months. Technical data (rate limiting) is deleted after 24 hours.

7. International Data Transfers

Your data is processed on servers located within the European Union. We do not transfer data to third countries.

8. Data Security

We implement appropriate technical and organizational measures: encryption in transit (TLS), one-way hashing of IP addresses, restricted data access, automated retention policies.

9. Changes to this Policy

This policy may be updated. The latest version will always be available on this page with the last updated date.

Jo's AIC | How much are you giving away to cloud providers every year?