Skip to content

Aqtos

Privacy

Last updated and effective: 7 October 2026

This policy explains how Aqtos handles personal information when you use our website, services and connections to AI assistants. It describes the purposes of processing, who receives information and your privacy choices. Where processing requires consent, that consent is requested separately; simply visiting our website is not consent to every use described here.

1. Introduction

Welcome to Aqtos.com. We are committed to protecting your privacy and ensuring your personal information is collected and used responsibly. This Privacy Policy outlines how we handle the information you provide us.

2. Data Collection

  • Email Subscriptions: When you subscribe to our launch notification, we collect your email address. This information is used exclusively to send you updates about Aqtos. We use Mailerlite as our email marketing platform.
  • Contact Us Form: If you contact us using our form, we collect your name, email, subject, and message. This information is used solely to respond to your inquiries and provide support.
  • Website Analytics and Tracking: We use Google Analytics, LinkedIn Pixel, and Facebook Pixel on our website. These tools help us understand how visitors interact with our site and enable us to track user behavior, such as pages visited and time spent on our site. This information is used for analytics and remarketing purposes.

3. Data Use and Sharing

Your information is not shared with or sold to third parties, except as necessary to provide the services requested (e.g., Mailerlite for email subscriptions, and analytics and remarketing services like Google Analytics, LinkedIn Pixel, and Facebook Pixel). We take reasonable steps to ensure that third-party services used also adhere to privacy and data protection standards.

4. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and hold certain information. These technologies are used to enhance and personalize your website experience, as well as for analytics and advertising purposes.

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting https://app.retention.com/optout

5. Connecting Aqtos to ChatGPT and other AI assistants

This section covers the Aqtos connection to ChatGPT, including our plugin and Model Context Protocol (MCP) tools, and equivalent connections to other AI assistants. It explains how information moves between your connected assistant and BOSS*, the purposes for which it may be used, and your choices. These integration-specific protections take precedence over the general website analytics and marketing provisions elsewhere in this policy.

Information processed through the connection

The information processed depends on the tools you use, the request you make and your account permissions. Relevant categories include:

  • Account and connection information: account and workspace identifiers, user identity information such as your name or email where needed, and the permissions associated with the connection.
  • Request information: the task-specific inputs and content passed to an Aqtos tool so it can perform a search, analysis or supported action.
  • Workspace records: information relevant to that request, such as project and task details, assignees, comments, client contact details, time entries, team availability, budgets, invoices or expenses, where supported by the tool and permitted by your access.
  • Technical and security information: limited request identifiers, timestamps, tool names, status or error codes, and connection or network information needed to operate and protect the service. Logs are subject to the limits below.

Our integration policy requires collection and disclosure to be limited to the information needed for the requested operation. It does not permit requesting or collecting your full conversation history merely because you connect an assistant. Please share only information you are entitled to use through the connection.

Purposes and recipients

Integration information may be used to authenticate and authorize access, respond to your requests, carry out supported operations in your workspace, investigate errors, provide support you request and protect the service against misuse. For example, a request to summarize a project’s risks can involve retrieving relevant tasks and returning those records to the connected assistant; a request to create a task can store that task in BOSS*.

When you use ChatGPT, relevant tool results are transmitted to OpenAI so ChatGPT can respond to you. When you choose another assistant, the equivalent results are transmitted to that assistant’s provider. The provider’s own terms, privacy policy, account settings and data controls govern its handling of information it receives. Aqtos’s retention limits do not set OpenAI’s or another provider’s retention periods or training practices.

Other categories of recipients can include service providers supporting hosting, infrastructure, security and customer support, to the extent necessary for those functions; authorized people in your workspace when an operation creates or changes shared records; and authorities or professional advisers where disclosure is legally required or necessary to establish, exercise or defend legal claims. Service-provider access must be limited to the relevant purpose and subject to appropriate confidentiality and data-protection obligations. You can request information about providers involved in your connection at [email protected].

Advertising, profiling and AI training

Our policy prohibits selling integration request content or workspace records, sharing them with advertising networks, using them for targeted advertising or unrelated behavioral profiling, or using them to train Aqtos or third-party general-purpose AI models. Connecting an assistant does not subscribe you to marketing messages. Website analytics, cookies and remarketing described elsewhere in this policy are separate from the processing of integration content.

Retention and deletion

The following retention limits apply to Aqtos’s handling of integration data from the effective date of this policy:

  • Request and response content: process it to complete the requested operation. Our policy does not permit routine storage of raw request or response content in diagnostic logs. Content deliberately saved by an operation becomes a workspace record. If you supply content for a support investigation, it follows the support limit below.
  • Routine technical logs: retain for no more than 30 days from collection, with unnecessary personal information and authentication secrets excluded or redacted.
  • Connection information: retain while the connection is active; remove connection-specific information within 30 days after revocation or disconnection is recorded by Aqtos, except for limited records needed under the exceptions below. Revoking access must prevent further authorized use of that connection; retaining an audit record does not authorize continued access.
  • Workspace records: retain while needed to provide your workspace under the applicable customer agreement and administrator instructions. Aqtos’s policy is to remove records from active systems within 30 days of a verified, authorized deletion request, unless an exception below applies. Disconnecting an assistant is not itself a request to delete your workspace or records created through it.
  • Integration support content: retain for no more than 90 days after the support case closes, unless you request earlier deletion or a specific exception below applies.
  • Deleted data in backups: remove through backup rotation within 90 days of deletion from active systems. Backup copies must be restricted to recovery purposes and any applicable deletion must be reapplied if a backup is restored.

Longer retention is limited to information required by an applicable legal obligation, a legal hold or a specific documented security incident or legal claim. Such information must be limited to what is necessary, restricted from unrelated use and deleted when the relevant obligation or need ends. Where permitted, we explain any applicable exception when responding to your deletion request.

Your controls and privacy requests

You can stop using the integration and remove the connection through your AI assistant’s connection controls. To request revocation on Aqtos’s side, contact your workspace administrator or [email protected]. Your workspace administrator manages your access to company records. Removing a connection does not automatically erase information already returned to an assistant; use that provider’s privacy and deletion controls for its copies.

You can request access, correction, deletion or an export of personal information by emailing [email protected]. Identify your account or workspace and the request, but do not send passwords or access tokens. We may need to verify your identity and authority. Where Aqtos processes company workspace information on behalf of your employer or another customer, we coordinate the request with that organization. We respond within the time required by applicable law and explain any permitted extension or limitation.

Access limits and sensitive information

Our policy requires authenticated, permission-based access and limits each tool to the information necessary for its function. Authentication must take place through the designated sign-in or authorization flow; passwords, API keys, one-time codes and access tokens must not be included in conversations or tool results. The ChatGPT integration must not be used to collect, solicit or process payment-card data subject to PCI DSS, protected health information, government identifiers or authentication secrets. Other regulated sensitive information may only be processed where strictly necessary for a supported function, legally permitted and accompanied by the required disclosure and consent.

For company workspace data, the customer generally determines the purposes of processing and Aqtos acts on its instructions. Aqtos is responsible for its own processing of account administration, security and support information, as explained in the rights section below.

6. Data Security

We implement appropriate security measures to protect against unauthorized access to or unauthorized alteration, disclosure, or destruction of data.

7. User Rights

You have the right to access, update, or delete your personal information at any time. If you wish to unsubscribe from our emails, you can do so using the link provided in our emails. You can also adjust your browser settings to refuse cookies if you prefer.

European Union Data Subject Rights EU Residents

If you are a resident of the European Union (“EU”), United Kingdom, Lichtenstein, Norway, or Iceland, you have additional rights under the EU General Data Protection Regulation (the “GDPR”) regarding your Personal Data, as detailed below.

In this section, “Personal Data” and “processing” are used as defined in the GDPR. Generally, “Personal Data” refers to information that can be used to identify a person individually, and “processing” broadly encompasses actions performed with data such as collection, use, storage, and disclosure. Aqtos will be the controller of your Personal Data processed in connection with the Services.

Should there be any discrepancies between this section and other parts of this Privacy Policy, the section or part that provides greater protection of Personal Data will prevail. If you have questions about this section or its applicability to you, please contact us at [email protected]. Note that we may process Personal Data of our customers’ end users or employees when providing certain services to customers, in which case we act as the processor of Personal Data. If we are processing your Personal Data as a processor (not the controller), please contact the controller party first to address your rights regarding such data.

We process your Personal Data only on a lawful basis. Lawful bases for processing include consent, contractual necessity, and our “legitimate interests” or those of third parties, as further explained below.

Contractual Necessity: We process certain categories of Personal Data as a matter of “contractual necessity,” meaning we need to process the data to fulfill our Terms of Use with you, enabling us to provide you with the Services. Without this data, you may not be able to use all or parts of the Services.

Examples include:

  • Profile or Contact Data
  • Web Analytics or other network activity information
  • Payment Data
  • Social Network Data
  • Device Data
  • Other Identifying Information you voluntarily provide

Legitimate Interest: We process certain categories of Personal Data when it aligns with the legitimate interest of us or third parties. We may de-identify or anonymize Personal Data to further these legitimate interests. Examples of these interests include:

  • Providing, customizing, and improving the Services
  • Marketing the Services
  • Communicating with you
  • Fulfilling legal requirements and enforcing legal terms
  • Completing corporate transactions

Consent: In some cases, we process Personal Data based on your explicit consent at the time of data collection. When processing is based on consent, it will be clearly indicated at the point and time of collection.

Other Processing Grounds: Occasionally, we may need to process Personal Data to comply with a legal obligation, protect your or others’ vital interests, or perform a task in the public interest.

Sharing Personal Data

Recipients and purposes are described in section 3 and, for ChatGPT and other AI connections, section 5. The integration-specific limits on advertising, profiling and model training apply regardless of the general service or marketing purposes described elsewhere in this policy.

EU Data Subject Rights

You have rights regarding your Personal Data, including the ones listed below. For more information or to make a request, please email us at [email protected].

Please note that in some cases, we may not be able to fully comply with your request, for example, if it is frivolous or extremely impractical, infringes on the rights of others, or is not legally required. In such cases, we will still respond to inform you of our decision. We may also require additional information, which may include Personal Data, to verify your identity and the nature of your request.

Access: You can request information about the Personal Data we hold about you and receive a copy of such data. You can also access some of your Personal Data by logging into your account.

Rectification: If you believe any Personal Data we hold about you is incorrect or incomplete, you can request that we correct or supplement it. Some of this information can also be corrected directly by logging into your account.

Erasure: You can request that we erase some or all of your Personal Data from our systems.

Withdrawal of Consent: If we process your Personal Data based on consent, you have the right to withdraw this consent at any time. However, withdrawing consent may require you to provide express consent on a case-by-case basis for certain uses or disclosures of Personal Data necessary for the utilization of our Services.

Portability: You can request a copy of your Personal Data in a machine-readable format and ask us to transmit it to another controller where technically feasible.

Objection: You can inform us of your objection to further use or disclosure of your Personal Data for certain purposes, such as direct marketing.

Restriction of Processing: You can request us to limit further processing of your Personal Data.

Right to File Complaint: You have the right to complain about Aqtos’s practices regarding your Personal Data to the supervisory authority in your country or EU Member State. A list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en.

8. Changes to this Policy

We may update this Privacy Policy from time to time. The effective date above identifies the current version. Where required by law, we will notify you of material changes or obtain consent before applying them. We encourage you to review this policy periodically.

9. Contact Us

If you have any questions about this Privacy Policy, please contact us through our website or at [email protected].