Legal

Privacy Policy

Last updated 17 September 2026. This policy explains how Ai Viral Sweden AB handles personal data in connection with the Ai Viral website, dashboard and service.

1. Controller and contact details

The controller of the personal data described in this policy is Ai Viral Sweden AB, a Swedish limited liability company with company registration number 559433-0952, Sweden.

For all privacy matters, including requests to exercise your rights, contact us at support@aiviral.com. Please include enough information for us to identify your account.

This policy forms part of, and should be read together with, our Terms of Service.

2. Scope

This policy covers our public website, the sign-up and onboarding flow, the customer dashboard, our billing operations and our support communications. It does not cover third-party websites, social platforms, communities, directories or ad networks, which process data under their own policies and for their own purposes.

Ai Viral is a business-to-business service. Where you use it on behalf of a company, the personal data we process about you is primarily business contact and account data in a professional capacity.

3. Personal data we collect

Account data. Name or display name, email address, password credentials handled by our authentication provider, company name where provided, and the identity data returned by Google when you choose to sign in with Google.

Campaign data. The website address you submit, the information derived from analysing that site (product name, description, category, audience, value propositions, keywords), your channel selection, your daily budget, campaign status, and the record of actions planned, queued and delivered.

Billing data. A customer reference at our payment provider, whether a card is on file, the card brand and last four digits, payment status, charge history, amounts and dates. Full card numbers and security codes are entered directly into our payment provider's hosted fields and are never received or stored by us.

Usage and technical data. IP address, browser and device information, approximate location derived from IP, pages and screens viewed, feature interactions, timestamps, referrer, session identifiers, error and diagnostic logs.

Communications data. Support emails and their content, and any information you voluntarily send us, including outreach lists, briefs and feedback.

Outreach recipient data. Where our work includes email or direct outreach, we may process business contact details of recipients. Where you supply such data, you act as controller for it and confirm you have a lawful basis to share it with us; we then process it as your processor under our Terms of Service.

We do not intentionally collect special categories of personal data (such as health, biometric, religious or political data) and ask you not to send them to us.

4. How we collect it

Directly from you when you sign up, submit a website, choose a budget, save a card or contact support; automatically through cookies and similar technologies when you use the site and dashboard; and from service providers such as our authentication, payment and analytics providers acting on our behalf.

5. Why we use it and our legal bases

To provide the service (performance of a contract). Creating and securing your account, analysing your website, planning and performing promotional actions, displaying your activity feed and results, and providing support.

To take payment (performance of a contract and legal obligation). Storing a card on file, charging your daily budget in arrears, handling failed payments, refunds where applicable, disputes and accounting.

To secure and improve the service (legitimate interests). Preventing fraud, abuse and unauthorised access, monitoring reliability, debugging, analysing aggregated usage, developing new features, and training our internal playbooks using aggregated or de-identified data.

To communicate with you (legitimate interests and, where required, consent). Service, billing and security notices, product updates, and marketing to business contacts. You can opt out of marketing at any time.

To comply with law and protect our rights (legal obligation and legitimate interests). Bookkeeping and tax records, responding to lawful requests, enforcing our terms, and establishing, exercising or defending legal claims.

6. AI processing

To analyse your website and draft promotional copy, we send the public content of the URL you submit, together with the campaign context and prompts needed for the task, to AI model providers that act as our processors under contract. We do not send them your billing details or your password.

AI-generated output is reviewed and executed by our team. Output may be inaccurate or incomplete, and you are responsible for reviewing the claims made about your own product as described in our Terms of Service.

7. Who we share data with

We share personal data only as necessary, with categories of recipients including: cloud hosting, database and storage providers; authentication providers; our payment provider and its fraud-prevention services; email delivery providers; analytics and error-monitoring providers; AI model providers; and the social platforms, communities, directories, newsletters and advertising networks where work is performed.

We may also disclose data to professional advisers, auditors and insurers; to authorities, courts or law enforcement where legally required or where we believe disclosure is necessary to protect rights, safety or property; and to an acquirer or successor in connection with a merger, reorganisation, financing or sale of assets.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising by third parties.

8. International transfers

Some of our providers are located outside the EU/EEA, including in the United States. Where we transfer personal data outside the EU/EEA, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary technical and organisational measures where appropriate. You may request further information about these safeguards by emailing us.

9. Cookies and similar technologies

Strictly necessary. Used to keep you signed in, maintain your session, remember your onboarding progress and protect against abuse. These cannot be switched off without breaking the service.

Analytics and performance. Used to understand how the product is used, measure reliability and improve the experience, in aggregated form.

We also use browser local storage to retain onboarding drafts and preferences on your own device. You can clear cookies and local storage, or block non-essential cookies, in your browser settings; doing so may degrade parts of the service.

10. Retention

We keep account, campaign and action data for as long as your account is active, and afterwards for as long as needed to provide continuity, resolve disputes and enforce our agreements — normally up to twenty-four (24) months after closure.

Billing, invoice and accounting records are retained for the period required by Swedish bookkeeping law, currently seven (7) years. Security and access logs are typically retained for up to twelve (12) months. After the applicable period we delete the data or irreversibly anonymise it, and we may keep aggregated statistics that no longer identify anyone indefinitely.

11. Security

We use encryption in transit, encrypted storage at our infrastructure providers, row-level access controls scoped to your own account, least privilege for staff access, authentication through a dedicated provider, and monitoring and logging. Card data is handled by a PCI-DSS compliant payment provider.

No system is perfectly secure. You are responsible for keeping your credentials confidential and for the security of the devices you use. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected users without undue delay.

12. Your rights

Subject to applicable law, you may request access to the personal data we hold about you, correction of inaccurate data, deletion, restriction of processing, portability of data you provided to us, and you may object to processing based on our legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing.

Email support@aiviral.com to make a request. We will respond within one (1) month and may extend that period by two (2) further months for complex requests, as permitted by the GDPR. We may need to verify your identity, and we may decline or limit a request where an exemption or legal retention obligation applies, or where the request is manifestly unfounded or excessive.

If you are in the EU/EEA and believe we have handled your data unlawfully, you may lodge a complaint with your local data protection authority. In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). We ask that you contact us first so we can try to resolve the matter.

13. Automated decision-making

We use automation and AI to plan and prioritise marketing work. We do not make decisions about you that are solely automated and produce legal effects or similarly significant effects on you within the meaning of Article 22 of the GDPR. Payment authorisation decisions are made by our payment provider and your card issuer.

14. Children

The service is intended for business users aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to this policy

We may update this policy to reflect changes in our service, providers, or legal requirements. The current version is always published on this page with the date of the latest update. Where changes are material, we will notify you by email or in the dashboard before they take effect where required by law. Continued use of the service after an update constitutes acceptance of the updated policy.

16. Contact

Ai Viral Sweden AB, company registration number 559433-0952, Sweden. Privacy questions and rights requests: support@aiviral.com.