Privacy Policy
Draft. Requires legal review before publication.
| Version | 1.0 |
| Effective Date | 2026-08-29 |
| Applicable to | aiput.site, REST API and MCP interface of the service |
The primary version of the document is in English. Texts in other languages are provided for convenience; in case of discrepancies, the primary version shall prevail, except where mandatory provisions require interpretation in the language of the consumer.
1. Who processes your data
Data Controller in the context of Regulation (EU) 2016/679 (GDPR):
| Name | Pavel Kanakhistov — self-employed individual (autónomo) |
| NIF | Z1825610J |
| Country | Spain (postal address – upon request) |
| pavel.knx@gmail.com | |
| Website | https://aiput.site |
Further – "we", "service". We do not appoint a Data Protection Officer (DPO): the scale of data processing does not require it.
2. Two different roles
This is the key distinction, from which everything else depends.
Regarding the data associated with your account – we are in control. Email address, name, session data, payment information: we determine how and for what purpose this data is processed, and we are responsible for this before you.
Regarding the content of your websites: you are the controller, and we are the processor. We store and provide files according to your instructions, without determining the purposes of their processing. If the published website contains personal data of third parties – texts about employees, customer reviews, photographs, a contact form – you are responsible for providing the legal basis for their processing. For business users, we conclude a separate agreement on data processing upon request (DPA).
The published website is accessible to anyone on the internet. We cannot restrict the number of people who view it.
3. We collect very little, and here is what we do not collect
The service is structured in such a way that it requires very few personal data. Websites that are published are, by their nature, publicly accessible, and all that is required for operation is to know the account holder and whether a subscription has been paid.
Therefore, we do not collect:
- information about your website visitors. We do not track visits, do not use tracking cookies, and do not maintain logs of user activity. Website infrastructure-level monitoring is disabled: visitor requests are not stored anywhere. If you require statistics, you are responsible for providing them yourself, and you are responsible for obtaining consent for their use.
- passwords. Access is via Google or a one-time code; we do not require passwords.
- Payment details. Stripe is the only party that can view the card.
- the content of your websites for analytical purposes. We do not read files, index them, or use them to train models;
- regarding your behavior. No analytics, no advertising pixels, no profiling, no cross-site tracking.
The IP address and browser string are recorded once, upon creating a login session, and are only needed so that you can distinguish your sessions from one another. They are not collected during normal use of the service.
The rate limiting of code requests to email is implemented such that the IP address is not stored. A counter is maintained based on an irreversible value calculated from the address using our secret. The original IP address cannot be recovered from this value, and the counters are deleted after their expiration period.
4. What data do we collect
4.1. Account and Login
Via Google. Google provides us with the following information: email address, name, link to profile picture, email verification status, and your Google account's permanent identifier. We do not see or obtain your Google password.
Using a one-time code. We only receive the email address. The code is stored as an irreversible hash and is deleted after use or expiration.
4.2. Automatically upon use
- IP address and browser string (User-Agent) – are recorded once, at the time of session creation; subsequent requests do not collect this information.
- Login time, last activity time, and session end time
- Publication History: Time, Result, Website Identifier, and Error Text if Publication Failed
4.3. Terms of Service
Files that you or an AI agent acting on your behalf upload for publication: HTML, CSS, JavaScript, images, fonts, and other static files. We do not analyze their content, index it, or use it for any purpose other than hosting it on the internet at your request. We do not use the content of your websites to train models.
4.4. Payment information
Payment card details are processed by Stripe. We do not receive, view, or store them. We store the customer's identifier and subscriptions, as well as payment amounts, currency, status, and dates, within Stripe – this is required for accounting purposes.
5. Why and on what grounds
| Purpose | Data | Ground (Article 6 GDPR) |
|---|---|---|
| Provision of the service, access to the account | Account, sessions | Performance of the Contract, Clause 1(b) |
| Hosting of your websites | Website content | Performance of the Contract, Clause 1(b) |
| Payment acceptance and invoice generation | Payment records | Performance of the Contract, Clause 1(b) |
| Accounting and tax accounting | Payment records | Legal obligation, paragraph 1(c) |
| Rate limiting, abuse protection | IP address, call logs | Legitimate interest, paragraph 1(f) |
| Responses to your inquiries | Correspondence | Legitimate interest, paragraph 1(f) |
Legitimate interest in the two final lines – ensuring the service's functionality and security. You have the right to object to such processing (Section 9).
We do not use your data for advertising, do not profile you, and do not make automated decisions regarding you with legal consequences.
6. How long do we retain your data
| Data | Term |
|---|---|
| Account and login methods | As long as the account remains active |
| Sessions | 30 days after the expiration or termination date |
| One-time login codes | 30 minutes, or until the first use |
| Website content | As long as the website remains active. |
| Publication History | 12 months after the website is removed |
| Payment records and invoices | 6 years – Commercial Code, Article 30 |
The daily automated cleaning process is executed, rather than a manual operation: upon its occurrence, records are deleted without your request or our involvement.
Upon deletion of your account, a string containing only your internal identifier and a deletion marker will remain, without your address, name, or any other personal information. This is necessary to free your email address – otherwise, it would not be possible to create a new account using the same email address.
We are legally obligated to retain payment records and cannot delete them earlier than required by law, even at your request. This constitutes a direct limitation on the right to deletion (Article 17 of the GDPR).
7. To whom do we transfer data
We do not sell your data or transfer it to third parties for their own purposes. We use the services of third-party processors:
| Handler | What does it do | Where |
|---|---|---|
| Cloud infrastructure provider | Hosting of the service, database, and publication of your websites. | EU and other regions |
| Google Ireland Ltd. | Authentication via Google Account | European Union |
| Stripe Payments Europe, Ltd. | Payment acceptance and tax calculation | European Union |
| Transaction mail provider | Delivery of emails with login codes | European Union |
A data processing agreement has been concluded with each party.
The parties with whom you interact directly, we will identify by name. The list of infrastructure providers – this category may change, and we do not consider it necessary to disclose the full details of the service. An up-to-date list of processors with names is available upon request at pavel.knx@gmail.com – this is your right under Article 15 of the GDPR, and we cannot refuse it.
We may also disclose information if required by law or in response to a valid request from a duly authorized governmental agency or regulatory body.
8. Transfer outside the EEA
Certain processors may process data in the United States or other countries outside the EEA. In such cases, we ensure compliance with Chapter V of the GDPR: standard contractual terms (SCC), approved by the European Commission, and/or certification of the recipient under the EU-U.S. Data Privacy Framework. Copies of the guarantees and an up-to-date list of recipients can be obtained at pavel.knx@gmail.com.
9. Your Rights
- Access (Article 15) – to obtain a copy of your data
- Correction (Article 16) – to correct inaccuracies
- Deletion (Article 17) – the right to delete is not absolute: payment records are retained due to legal obligations (Section 6)
- Limitation of Processing (Article 18)
- Portability (Article 20) – obtain data in a machine-readable format
- Objection (Article 21) to processing based on legitimate interests
- Consent Declaration (Article 7(3)) – at any time, without affecting the legality of prior processing.
Contact us at pavel.knx@gmail.com. We will respond within 30 days. We may request proof of identity if the request is not made from an address associated with the account.
Right to Complain (Article 77). The supervisory authority of the controller is the Agencia Española de Protección de Datos, Spain, www.aepd.es. If you are located in the EU/EEA, you may also contact the data protection authority in your country of residence.
10. Account Deletion
The account can be deleted in the personal account. Upon deletion:
- Websites are immediately removed from publication;
- website files and publication history will be deleted within the timeframe specified in Section 6;
- active sessions and access keys are recognized;
- Payment records are retained for the period specified by law.
Cancellation of subscription and account deletion are separate actions. The procedure for refunding for unused periods is described in the Purchase Policy.
11. Cookies
The service uses only technically necessary cookies:
| Cookie | Purpose | Term |
|---|---|---|
siteai_session | Maintaining login to the account | 30 days |
siteai_oauth_state | Protection against fraudulent login requests via Google | 10 minutes |
We do not use analytical, advertising, or any third-party tracking cookies. Therefore, we do not display the consent banner: cookies necessary for technical functionality do not require consent. If analytics are ever implemented, the banner will become mandatory, and this section will become invalid.
The websites you publish may contain their own cookies – you are responsible for these and for obtaining consent for their use.
12. Safety
Measures under Article 32 of the GDPR:
- encryption during transmission – HTTPS/TLS on all connections;
- encryption at the infrastructure level provided by the vendor;
- Login via OAuth 2.0 / OpenID Connect and one-time codes – we do not obtain or store your password;
- User account information is protected by additional security measures at the application level;
- resource verification upon each request – if the resource is not accessible using your key, the website is unavailable to you;
- user data isolation;
- Rate limiting and protection against automated abuse.
No system is absolutely secure. In the event of a breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours (Article 33) and, in cases of high risk, you (Article 34).
13. A single standard for all countries
We apply a single standard of personal data protection to all users, regardless of their location. This standard is based on GDPR: the legal grounds, the rights of subjects, the retention periods, and the requirements for processors, as well as the guarantees of transfer, as outlined in sections 2–12, all apply to everyone. If the laws of your country of residence grant you more rights or shorter retention periods, those laws will apply.
14. Age
This service is not intended for persons under the age of 18. We deliberately do not collect data from children.
15. Changes
We may update this Policy. We will notify you of any material changes by email at least 30 days before the changes take effect. The version and date are indicated at the beginning of this document.
16. Contacts
pavel.knx@gmail.com