Privacy
Privacy policy
What we collect, why, how long we keep it and how you have it deleted. No generalities — one line for each thing that is actually stored.
Last revised: 14 August 2026
1. Who processes your data
The data controller is 3D Code EOOD. The statutory details and the correspondence address are on the Company page. For data protection matters, write to the official email published there.
2. Data from the site forms
When you submit the contact, demo, quote or readiness form, we store one row containing:
- Name and email — required, because without them we cannot reply.
- Phone, company and VAT number — when you fill them in; the fields are not required everywhere.
- The message and the questionnaire answers.
- The page you submitted from, where you arrived from, and any campaign parameters in the address (utm_source and similar).
- IP address and browser details — to defend against automated spam and to limit the number of submissions.
- The exact wording of the consent you accepted, and the moment of acceptance.
3. Why we keep the consent wording
We record verbatim the wording that stood next to the tick box on the day you submitted. Site text changes; proving consent means proving what was accepted then, not what the page says today.
4. The credit calculator
The calculator on the pricing page and on the home page asks for an email before it works out a figure. Besides the number on screen we send a detailed proposal to that address — what we understood from your description and how you can reach the finished system. We record:
- Your email and the exact wording of the consent you accepted.
- The description you wrote and the figures calculated from it.
- The page, the source and any campaign parameters in the address.
- IP address and browser details — to defend against automated spam.
5. How many emails the calculator sends
One. It goes out about an hour after the calculation and is the only automatic letter from the calculator. If you come back and price something else, the next one is a week away at the earliest — and we send nothing if we have already got into a conversation with you in the meantime. You stop them for good by replying to the letter with the word “stop” or writing to contact@ai-cloud.gr; your address goes onto a list we check before every send. Your estimates stay with us as an enquiry, but no more mail reaches you. We neither sell nor pass these addresses to anybody.
6. The chat assistant on this site
Every page carries a chat assistant in the bottom right corner. If you write to it, we store the conversation — including:
- The full text of your questions and of the answers — so do not type passwords, other people’s personal data, or anything you would not send by email.
- IP address and details of the browser, the device and the operating system.
- The approximate location (city and country), derived from the IP address.
- The language of the conversation and a technical identifier tying the turns into one conversation.
7. How the chat assistant works
The answers come from an Anthropic language model, to which we send only your question, the earlier turns of the same conversation and publicly available information about our services. The assistant has no access to your account, your payments or your enquiries. The basis is our legitimate interest in answering questions quickly and in checking that the assistant answers correctly. Using it is optional — the same questions can be asked by email or by phone.
8. The “AI help” assistant inside your account
Inside your account there is a second assistant, “AI help”, which answers only about the customer area — what each screen is for and where a given button is. That conversation is NOT recorded: not by us, and not in your browser. It is gone as soon as you reload the page. To the language model we send your question, the earlier turns of the same conversation, a description of the screens in the account and three facts about you — your role in the account, whether the account is a company or an individual, and whether your email is confirmed. We do not send your balance, your invoices, your projects or your requests; it has no access to them and cannot find them out. All we record is a counter — that a question was asked, by whom and when, without the question itself — because every answer is paid for by us and this is the only way to stop abuse. The basis is our legitimate interest.
9. The visit log
We count our readers ourselves rather than running someone else's analytics tool. Each time a page is opened, our server writes one row:
- IP address, together with details of the browser, the device and the operating system.
- The approximate location (city, region and country), derived from the IP address.
- The page you opened and its language.
- The address you came from and any campaign parameters in it (utm_source and similar) — this is how we tell whether an advert or a post did any work.
10. Why the visit log needs no banner
Because the log lives entirely on our server: it sets no cookie and writes nothing into your browser. We do not follow which other sites you visit and we do not join your visits into a lasting profile — the technical fingerprint that counts visitors for the day is replaced every 24 hours, after which the same person is indistinguishable from a new one. The basis is our legitimate interest in knowing whether the site is read and where people come from. Object with one message to the address below and we stop recording your visits.
11. Account data
On registration we store email, name, password (only as an irreversible hash, never in readable form) and the organisations you belong to. We also keep a technical record of sign-ins and of administrator actions — who changed what, and when.
12. Log of account activity
We record what happens in your account: signing in and out, creating, opening, pausing and deleting a project, invitations and role changes, payments and changes to the organisation — with date, time, internet address and browser type. Separately we note which portal screens you opened (for example “Credits” or “Invoices”), without their content and without any cursor tracking; one screen is recorded at most once every five minutes. Work INSIDE a project is not recorded here. The basis is our legitimate interest in running the service, in being able to answer a question like “who deleted this project”, and in spotting a sign-in that was not yours. The record of opened screens is kept for 90 days; the trace of actions with consequences stays while the account exists, because it is also your protection in a dispute.
13. Restricting access after abuse
If someone abuses the site, we may refuse access from a particular internet address or from a particular device. The list is manual: every entry is made by a person, for a specific reason, and is never created automatically by a profiling system. We record the address or the device's technical number, the reason, who entered it and when, and for how long. For a device we keep only a random number your browser was given by us — it holds nothing about you and is not used for tracking or advertising; it is also described in Cookies. The restriction does not stop you reading the site, only acting on it, and it has an end date. The basis is our legitimate interest in protecting the service and our other customers. If you believe you are affected by mistake — one internet address is often shared by many people — write to us at the address below and we will remove it.
14. Several accounts from one browser
We make a note when two or more accounts are used from one and the same browser. We record the browser's random number (the same aicloud.did as in the section above), which accounts have signed in with it, when for the first and last time, and whether the account was created from there. The reason is simple and we say it plainly: we give bonus credits on registration, and some people spend them and open a new account for new ones. The basis is our legitimate interest in not paying twice for the same thing, and the period is 180 days from last use. One thing follows automatically: the welcome credits on registration are one per customer and one per browser — if an account from the same browser has already received them, the next one does not. We record that too: that an account was not given welcome credits, how many, and because of which other account. Nothing else follows by itself — no account is restricted, frozen or closed because of such a match without a person deciding. A match is not proof: a work computer, a family laptop or two colleagues at one desk look exactly the same. So not receiving welcome credits does not affect your use of the service, the credits you bought or your rights under the law — and if you believe it was a mistake, write to us and we will give them. Their terms are in the Terms of use.
15. Payment data
Card payments are processed by Stripe. Your card number never passes through our systems and is not stored with us. From Stripe we receive a payment confirmation and a transaction identifier, in order to credit your balance.
16. Legal bases
Each of the above rests on one of the following bases:
- Consent — for enquiries from the forms and for the email left in the credit calculator. You may withdraw it at any time, with one message.
- Performance of a contract — for the account, the credits and the delivery of the service.
- Legal obligation — for accounting and tax records.
- Legitimate interest — for spam and abuse defence (IP address, submission counts, the counter of questions to “AI help”, the restricted-access list, the note that several accounts are used from one and the same browser), for platform security, for the chat assistant conversations and for the visit log.
17. How long we keep it
We do not keep data "just in case". The periods are:
- Form enquiries — up to 24 months from the last communication, then deleted.
- Rows identified as spam — up to 6 months, only so that they are not accepted again.
- Chat assistant conversations — 90 days, then deleted automatically.
- Conversations with the “AI help” assistant inside your account — not kept at all. The counter of questions asked (without their text) is deleted after 30 days.
- Descriptions submitted to the credit calculator (on the pricing page or inside your account) — the text and the IP address are deleted after 90 days. Only the calculated figures remain, and nobody can be identified from them.
- The email left in the calculator, together with the description and the estimate — up to 24 months from the last communication, as an enquiry from the site. If you opt out, the address itself stays on the opt-out list so that we never write to you again by mistake.
- The visit log — 90 days, after which the detailed rows are deleted automatically. What remains is a daily summary (visit counts per page, country and source) that holds no IP addresses and in which nobody can be identified.
- Signals raised on suspicion of abuse — 90 days. Where a signal led to action against an account, the text, the IP address, the approximate location and our own reply are kept for 2 years, so that we can show you what the decision rested on if you dispute it. After that only the type of the signal and the country remain.
- Restricted-access records (internet address or device number) — while the restriction is in force, and 180 days after it expires or is removed, so that we know what has already been done about the same case. They are then deleted permanently.
- The note that several accounts are used from one and the same browser — 180 days from the last time the account was used from that browser. It is then deleted permanently, together with the browser number itself.
- The record that an account was not given welcome credits, and because of which other account — while the account exists. This is a record about money, not about a browser: it is kept so that we can answer you if you ask why, and it holds no browser number.
- Copies of the messages we have sent you (confirmations, invoices, notifications) — 12 months, then deleted automatically. The one-time sign-in and password-reset links are not kept in those copies.
- Support requests raised from your account and the conversations on them — while the request is open, and 24 months after it is closed, then deleted automatically together with the messages in them.
- Account data — while the account exists, and up to 6 months after it is closed.
- Accounting and tax records — 10 years, as required by Bulgarian law, to which the company issuing the invoices is subject.
- Technical security logs — up to 12 months.
18. Who we share it with
We do not sell personal data and do not give it to third parties for advertising. We use the following providers, each under contract and only for what is stated:
- A provider of AI infrastructure and hosting — storage and processing of the data in the platform. Data at rest is held in the European Union (Frankfurt).
- Language model providers — OpenAI, Anthropic and Google. Only the text you submit for processing goes to them, and only so that the answer can be produced.
- Stripe — processing of card payments.
- An email service provider — sending confirmations, notifications and replies.
- Where processing takes place outside the European Economic Area — as it may during language model inference — it relies on the European Commission standard contractual clauses.
- If a subprocessor handling personal data changes, we tell you at least 14 days in advance.
19. Your data does not train models
Nothing you submit or create in the platform is used to train or fine-tune artificial intelligence models — neither by us nor by the infrastructure provider, which has given us that undertaking in writing. It is processed only to produce the answer you asked for.
20. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- obtain access to the data we hold about you;
- have inaccurate data corrected;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interest;
- receive your data in a machine-readable form in order to move it elsewhere;
- withdraw consent at any time, without affecting the lawfulness of processing before that.
21. How to exercise them
Send a request to the official email or the correspondence address on the Company page. We answer within one month. If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority of our own country — the Commission for Personal Data Protection (CPDP), Sofia, cpdp.bg. As a data subject in Greece you also have the right, under Art. 77 GDPR, to turn to the Hellenic Data Protection Authority (HDPA), Athens, dpa.gr.
22. Cookies
The site sets no tracking cookies and shows no consent banner, because there is nothing to ask consent for — the visit log above writes nothing into your browser either. The full inventory of what your browser stores is on the Cookies page.
23. Automated decisions
The readiness questionnaire score is indicative and does not lead to an automated decision with legal effect for you. No account is approved, refused or restricted automatically on the basis of profiling.
24. Security
We apply technical and organisational measures proportionate to the risk: encrypted connections, access separated by role, a log of administrative actions, and passwords stored only as an irreversible hash. On a personal data breach we notify the supervisory authority and the people affected as the GDPR requires; the infrastructure provider has undertaken to inform us within 72 hours. We hold no certification of our own — the ISO/IEC 27001 and SOC 2 certificates belong to the cloud provider, not to us. The full description of the measures, including what we do not yet have, is on the Data security page. If you use the platform to process personal data of your own customers or staff, the Data processing agreement applies as well.
25. Children
The service is not intended for people under 18 and we do not knowingly collect their data. If we learn that we have received a minor's data, we delete it.
26. Changes to this policy
When processing changes — for example if we ever add a third-party analytics tool — this document is updated before the change, not after it. The date of the last revision is at the top of the page.