Version 1.0, 2026-10-05.
Privacy policy
This policy explains what personal data HumanAI processes, why, for how long, who we share it with and your rights. It covers the website, the portal, the cockpit and the meeting app.
Who we are. The controller is MANEIRA ASTUTA - DESENVOLVIMENTO, OTIMIZAÇÃO, GOVERNANÇA E EDUCAÇÃO, UNIPESSOAL LDA (NIPC 515710202), Av. Padre Luís Pinto Carneiro, n.º 234, 4585-172 Gandra PRD (Paredes), Portugal, which operates the HumanAI platform. Privacy contact: rpad@rpad.pt (Rui Dias). We have not appointed a data protection officer because, given the nature and scale of our processing, the law does not require one (GDPR art. 37).
Our two roles. We act as controller for website visitors, people who contact us, and user accounts (access management, security, service communications). We act as processor for the content our customers put on the platform (code, tickets, documents, meeting recordings and transcripts, information about people involved in projects), following the customer's instructions and data processing agreement. If you work for a customer, or took part in a meeting recorded by a user, the controller for that data is the organisation using HumanAI; contact them first, and we will help them respond.
What we process and why.
| Situation | Data | Purpose | Legal basis (GDPR art. 6) |
|---|---|---|---|
| Website visit | IP address and request data in server logs | Run and protect the site | Legitimate interest in security |
| Contact form | Name, email, company, message | Reply to you | Pre-contractual steps at your request, or legitimate interest |
| Platform account | Name, email, username, project, role, password (hash only), Google account link if you make one, second factor (TOTP) | Create and manage your access | Legitimate interest, ours and that of the organisation you work for, in creating and managing the accounts it asks for; contract where you are the customer yourself |
| Platform use | Requests, approvals, agent sessions, usage, activity and audit logs | Provide the service, history, usage billing, incident investigation | Legitimate interest in providing the service your organisation contracted, security and evidence; contract where you are the customer |
| Personal access tokens | Tokens you register in your own vault | Act in customer systems on your behalf, under your identity | Legitimate interest in providing the service you ask for; contract where you are the customer |
| Platform emails | Email, name, message content, delivery status | Invitations, access recovery, request and approval notices | Legitimate interest in providing the service; contract where you are the customer |
| Billing | Customer name, tax number, address and contact, billed usage | Invoicing and tax and accounting duties | Contract with the customer; legal obligation |
| Voice dictation (optional) | Audio while you speak, resulting text; your voice is not used to identify you | Dictate in the cockpit | Legitimate interest in providing the feature you ask for |
| Meeting recording (optional) | Audio, transcript, named participants, summary | Support the team's meeting work | Processed on behalf of the recording organisation |
| Voice profile (optional) | A mathematical representation of a named person's voice | Recognise that person in later meetings | That person's explicit consent (GDPR art. 9(2)(a)) |
| Professional profile on the platform (optional) | What you yourself confirm: role, skills, certifications, languages, goals and work preferences | Tailor agents and suggestions to your work; show it to whom you choose | Legitimate interest in tailoring the service; you can view, export and delete it at any time |
| CV reading for the profile (optional) | The CV file, only while it is read | Propose professional facts (skills, certifications, languages, role) that you confirm or discard | Consent, asked at each reading. Read on our server, in an isolated reader with no network; not sent to any AI provider or third party; the file is not kept. Address, phone, email, date of birth and photo never enter the profile |
Account data is needed to use the platform; optional features only process data if you use them. Where data does not come from you (for example, a user mentions you in a project or names you in a meeting), it comes from the customer organisation or that user.
We do not sell personal data, use it for advertising, or make automated decisions with legal effects on you. HumanAI does not use customer content to train its own models.
AI agents. When you use an AI agent, the content needed for the task goes to that agent's provider. With a customer's data, only providers that customer authorised are used, and never a provider without a valid transfer safeguard with EU customers' personal data. Providers, countries and safeguards are listed on the Subprocessors & Integrations page.
Meeting recordings and voice profiles. Recording is off until someone starts it. Whoever records must tell every participant before starting and obtain their consent; if anyone objects, do not record. Recording people without their consent is forbidden by our Terms and is a criminal offence in Portugal. Recordings and transcripts support the team's work and may not be used to monitor workers' performance or behaviour. Voice recognition is created only when someone explicitly asks for it for a named person and that person consents, personally, through a link they receive; refusing has no consequence; it is stored on the recording device and can be deleted at any time. People who do not want to be recognised take part normally and appear as "Other".
Sharing. With the subprocessors on our public list, each bound by an agreement; with AI providers you or your organisation enable; with authorities where the law requires. Customers' billing data (name, tax number, address, contact and billed usage) also goes to Rauva (Portugal, EU), which handles our invoicing and accounting, and to the Portuguese Tax Authority, as required by tax law; it is kept for 10 years. Rauva has no access to platform content. HumanAI platform administration can access all projects to operate and support the service, and that access is logged.
International transfers. Servers are in the EU (Germany), encrypted backups in Portugal and the portal database in Ireland. Some subprocessors are US companies and may access data from there; we rely on the EU-US Data Privacy Framework where the company is certified, or on the European Commission's standard contractual clauses.
Retention. Account: while active plus 12 months. Audit and approval logs: 12 months. Server logs: 90 days. Customer content: for the contract term; export available for 30 days after the end, and everything deleted from active systems within 60 days of the end unless the law requires retention; in backups it disappears when the backup expires, at the latest 6 months later. Backups: daily; encrypted off-site copies kept up to 6 months, in Portugal; if a backup is ever restored, data already deleted is deleted again. Invoices and billing records: 10 years, as tax law requires. Meeting recordings and transcripts: as the customer sets, 180 days by default. Voice profiles: until consent is withdrawn or deletion is requested, and at most 12 months without use. Terms acceptance and consent records: for the life of the account plus 5 years, as evidence. Contact, onboarding and support emails: 24 months.
Security. Each person works in an isolated environment, connections are encrypted, sensitive platform operations require a second factor, personal tokens stay in their owner's vault and are never shared, and relevant actions are logged. For breaches of data we control, we notify the CNPD within 72 hours and tell you when there is a high risk to you; for customer data, we tell the customer within 48 hours at most.
Your rights. Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest; where we rely on consent, you can withdraw it at any time. Write to rpad@rpad.pt; we answer within one month (extendable where the law allows). You may lodge a complaint with the CNPD (www.cnpd.pt).
Minors. HumanAI is a professional service and not intended for people under 18.
Changes. Material changes are announced 30 days in advance by email and in the cockpit, and the new version is shown at your next sign-in; changes can take effect immediately where the law or security requires it.