AIViral is responsible for lawful, transparent outreach with working opt-outs. The customer is responsible for lawful follow-up after delivery. Every participant is accountable for its own obligations.
AIViral is operated by Ai Viral Sweden AB, a Swedish limited company (org. no. 559433-0952). Contact: support@aiviral.com.
Roles, mapped to the real data flow
GDPR assigns responsibilities by who decides the purpose and means of each processing step. In our service the flow has two distinct decision-makers:
- AIViral decides how outreach campaigns are run, how responses are qualified and how leads are matched and delivered. For these operations we act as a controller.
- The customer decides how to contact and use a delivered lead and becomes an independent controller at delivery.
This allocation is reflected in our contracts. It means each party is accountable for its own decisions — we are responsible for lawful outreach and delivery, and the customer is responsible for lawful follow-up.
Lawful basis for outreach
Our outreach is business-to-business: we contact people in their professional capacity, about services plausibly relevant to their role and company. Where GDPR requires a lawful basis for this processing, we rely on legitimate interest, documented through a balancing test, or on another basis where local law requires it.
Local marketing and ePrivacy rules can impose additional requirements for electronic outreach in specific countries. We configure campaigns to respect those rules, including sender identification and opt-out mechanisms in every message.
Opt-outs travel with the record
Every outreach message includes a working way to opt out. When a recipient opts out, the suppression applies immediately — to the campaign they responded to and to all future campaigns across our service. Suppression records are kept so the person is never contacted again.
If a prospect asks where their details came from, we tell them plainly. Transparency is not a threat to this business model — it is a requirement for it.
Transparency duties on all sides
Under Articles 13 and 14, individuals must receive an understandable notice covering the controller's identity and contact details, purposes and legal bases, recipient categories, retention, international transfers and their rights. We provide this in our outreach and on this site for the processing we control; customers receiving a lead may have their own notice obligation toward the individual when they make contact.
Accountability also means data minimization — collecting only the fields the agreed purpose needs — plus records of processing activities and, where the risk profile requires it, a data protection impact assessment.
Rights requests and complaints
Individuals have rights to access, rectification, erasure, restriction, portability and objection. Requests are answered by the responsible controller within the legal timeframe, normally one month.
Because a lead passes from us to the customer, the parties coordinate: we identify the record, trace delivery, and the receiving customer applies deletion or suppression in its systems. Individuals may also complain to their supervisory authority at any time.
Contracts, transfers and incidents
Before processing begins, the required written agreements are in place, covering instructions, security measures, subprocessor approval, assistance with rights requests, deletion on termination and audit rights.
For transfers outside the EEA/UK we rely on recognized transfer mechanisms — adequacy decisions or standard contractual clauses — with supplementary measures where the assessment requires them. If a personal-data breach occurs, the responsible controller assesses notification duties and deadlines; we support customers with the information needed for that assessment.
Customer checklist
- Have a lawful basis ready for how you will contact delivered leads.
- Identify yourself clearly and reference the prospect's expressed interest when you reach out.
- Honor opt-outs and deletion requests in your own systems, and tell us so we can suppress the record.
- Store received leads in access-controlled systems and delete them when the purpose ends.
- Get jurisdiction-specific legal review of your outreach rules where you operate.
This page is an operational overview, not legal advice. Related reading: our privacy policy, terms of service and security practices.
