Privacy Policy
Effective date: 1 January 2026
Last reviewed: 27 June 2026
Applies to: visitors of phaneosai.com, registered agency partners, and end-client contacts whose personal data we process in connection with our AI integration services.
1. Who we are
phaneosAI is an AI integration partner for agencies worldwide. For the purposes of EU and UK data protection law, we act as a controller for data collected through this website and our partner registration process. For personal data that an agency asks us to process on its behalf in the course of delivering AI services to the agency's client, we generally act as a processor, governed by our Data Processing Addendum.
Controller contact:
Email: hello@phaneos.cloud
Address: Ho Chi Minh City, Vietnam
EU representative: contact via the email above and we will route to our designated EU representative.
We do not currently have a statutory obligation to appoint a Data Protection Officer. If you have privacy questions, please use the contact above.
2. What data we collect and why
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Name, agency name, email, phone | Partner registration form | Onboard agency partners, send partner docs, schedule intro calls, deliver services | Contract / legitimate interest |
| Partnership model preference | Registration form | Tailor onboarding and commission setup | Contract |
| Optional message / meeting time | Registration form | Understand partner needs and schedule calls | Consent, withdrawable any time |
| Email open/click data | Resend / transactional email provider | Confirm delivery and improve partner communications | Legitimate interest |
| IP address, browser type, pages visited | Web server logs / analytics | Security, fraud prevention, website improvement | Legitimate interest |
| LinkedIn profile data | Public sources, when you link to us | Professional networking and partner verification | Legitimate interest |
We do not collect special-category data (health, biometrics, religion, etc.) through the website. If an agency later shares such data for a client project, that processing is covered by our Data Processing Addendum, not this Privacy Policy.
3. How we use AI and your data
- We do not use your personal data, prompts, or client content to train, fine-tune, or improve any AI model.
- We use enterprise LLM APIs (OpenAI, Anthropic, and others) under Zero Data Retention (ZDR) or equivalent business-tier agreements whenever technically available.
- We apply human review before any AI-generated output is delivered to an agency's client.
- For details, see our AI Usage Policy.
4. Cookies and similar technologies
We use only strictly necessary first-party cookies and server-side analytics. We do not use marketing pixels, third-party ad trackers, or behavioral profiling cookies.
Because we do not store non-essential identifiers on your device, we do not show a cookie-consent banner for analytics under current EU guidance. If we ever add non-essential cookies, we will obtain your prior consent in a clear, easily withdrawable way.
You can disable cookies in your browser at any time. Core site functionality will remain available.
5. Who we share data with
We share personal data only with trusted processors who help us run our business:
| Processor | Service | Location / safeguards |
|---|---|---|
| Resend | Transactional email | United States / Standard Contractual Clauses |
| Vercel | Website hosting | United States / Standard Contractual Clauses |
| OpenAI / Anthropic | AI model inference | United States / Business API terms, ZDR where enabled |
We do not sell personal data. We do not share data for behavioral advertising.
6. International transfers
phaneosAI is based in Vietnam. If you are in the EU, UK, or another jurisdiction, your data may be transferred to Vietnam or the United States. We rely on:
- Vietnam: our direct operations, protected by Vietnam's Law on Personal Data Protection 91/2025/QH15 and Decree 356/2025/ND-CP.
- United States: Standard Contractual Clauses approved by the European Commission (2021/914), with additional technical and organizational safeguards for sensitive transfers.
7. Data retention
- Partner registration data: retained as long as the partner relationship is active, then deleted or anonymized within 12 months, unless legal obligations require longer retention.
- Email and communication logs: 24 months, for customer support and dispute resolution.
- Web server logs: 90 days, for security monitoring.
- Client project data processed as a processor: deleted or returned per the agency's instructions at project end, per our Data Processing Addendum.
8. Your rights
Depending on your location, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data in certain circumstances.
- Restrict processing or object to it.
- Port your data to another service.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with your local supervisory authority.
To exercise your rights, email hello@phaneos.cloud. We respond within 30 days.
9. Security and breach notification
We implement encryption in transit (TLS 1.3), access controls, least-privilege permissions, and regular security reviews. In case of a personal data breach, we will notify affected individuals and relevant regulators within 72 hours where required by law.
Full details are in our Security Policy.
10. Children's privacy
Our services are not directed to individuals under 18. We do not knowingly collect data from children.
11. Changes to this policy
We review this Privacy Policy at least annually and whenever material changes occur. The effective date at the top of the page shows the latest revision.
This Privacy Policy is provided for transparency and compliance purposes. It does not constitute legal advice. phaneosAI recommends that agencies and end-clients consult their own legal counsel for jurisdiction-specific obligations.