Privacy Policy
AITA World, S.L. (hereinafter "AITA", "we", "us" or "our"), with registered office at Sabino Arana 8, 2º, 48013 Bilbao, Bizkaia, Spain, tax identification number (CIF) B75859744, is the controller of the personal data processed through the website aita.world and through its commercial, partner, and investor-relations communications.
This Policy is issued under Regulation (EU) 2016/679 ("GDPR"), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD"), and Law 34/2002 on Information Society Services and E-Commerce ("LSSI-CE").
1. Controller and Contact
| Controller | AITA World, S.L. |
|---|---|
| Tax ID (NIF/CIF) | B75859744 |
| Registered Office | Sabino Arana 8, 2º, 48013 Bilbao, Bizkaia, Spain |
| General Contact | info@aita.world / +34 695 526 230 |
| Data Protection Contact | privacy@aita.world |
| Data Protection Officer | Not appointed. AITA has determined that appointment of a DPO is not currently required under Article 37 GDPR. Data protection enquiries are handled directly by our compliance team at privacy@aita.world. |
2. Whose Data We Process
This Policy applies when you:
- Visit
aita.world; - Submit a contact, partnership, or information-request form;
- Subscribe to our newsletter or company updates;
- Communicate with us by email, telephone, or messaging platforms;
- Are contacted by us as part of our B2B outreach as a representative of an organisation relevant to our pipeline (EPC contractor, equipment supplier, landowner, public authority, financial institution, prospective investor, or partner);
- Engage with us as a counterparty, advisor, or service provider in connection with a project, corporate transaction, or fundraising.
3. Categories of Data We Process
We collect only what is strictly necessary for the purpose:
- 3.1. Identification and contact data: Full name, position, organisation, professional email, professional telephone, country, language preference.
- 3.2. Communications data: Content of your messages to us, attachments, meeting notes, and follow-up records.
- 3.3. Commercial-relationship data: Role you or your organisation plays regarding a project or transaction, associated documentation (NDAs, term sheets, technical exchanges), and status in our internal CRM.
- 3.4. Investor-relations data: Identity, organisation, area of interest, and documents shared during bilateral conversations. AITA does not make any public offering of securities through this website.
- 3.5. Technical data: IP address, browser and device information, language, time zone, referral page, log files, and security events.
- 3.6. Cookies and similar technologies: See clause 11 and our separate Cookie Policy.
We do not collect special categories of personal data (Art. 9 GDPR). Please do not include sensitive data in your communications.
4. Sources of Data
We obtain personal data directly from you, from your employer or counterparty, and — for our B2B outreach — from publicly available sources (company registries, professional networks, conference participant lists, public procurement records) and third-party B2B data providers operating under their own legal bases.
5. Purposes and Legal Basis
We process your data under the following legal grounds pursuant to Art. 6 GDPR and Spanish national law:
- Responding to enquiries: Art. 6(1)(b) GDPR (pre-contractual steps) or Art. 6(1)(f) GDPR (legitimate interest).
- B2B Direct Outreach: Art. 6(1)(f) GDPR (legitimate interest) read in light of Article 19 LOPDGDD (presumption of lawfulness for B2B contact data). We do not conduct bulk unsolicited commercial email prospecting. Commercial emails comply with Art. 21 LSSI-CE.
- Project & Counterparty Management: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligation).
- Investor Relations: Art. 6(1)(b) GDPR (pre-contractual) and Art. 6(1)(f) GDPR (legitimate interest in capital raising).
- Newsletters: Art. 6(1)(a) GDPR (explicit consent) or Art. 21(2) LSSI-CE (soft opt-in for existing clients).
- Accounting and Tax Compliance: Art. 6(1)(c) GDPR (Spanish Commercial Code, General Tax Law).
- Website Security & Analytics: Art. 6(1)(f) GDPR (security logs) and Art. 6(1)(a) GDPR (non-essential analytics cookies).
B2B Safeguards: Messages identify AITA as the sender, explain the source of data, and offer an immediate opt-out. Phone outreach in Spain is screened against the Lista Robinson (www.listarobinson.es).
6. Recipients and Subprocessors
Personal data is accessed strictly on a need-to-know basis by AITA personnel and authorised processors under Art. 28 GDPR agreements (cloud infrastructure, analytics, marketing measurement, and external resources).
We do not sell personal data. We do not use it for behavioural advertising. We do not transfer personal data to AI providers to train general-purpose models.
The itemised list of third-party subprocessors is published at aita.world/legal/subprocessors.
7. International Data Transfers
Our primary backend infrastructure operates within the European Economic Area (AWS region eu-north-1, Stockholm). Third-party transfers outside the EEA (e.g., to the USA) are governed by European Commission adequacy decisions (including the EU–U.S. Data Privacy Framework) or Standard Contractual Clauses (SCCs) under Commission Decision (EU) 2021/914.
8. Data Retention
- Website and Security Logs: 12 months.
- Contact Form Inquiries (non-converted): 12 months from last interaction.
- Newsletter Subscriptions: Retained until unsubscription + 3 years for evidentiary purposes.
- B2B Prospect Records (CRM): Up to 3 years from last meaningful interaction.
- Active Contracts and Project Data: Duration of relationship + 6 years (Spanish Commercial Code, Art. 30).
- Tax and Accounting Records: 6 to 10 years as required by Spanish Tax / AML legislation.
9. Your Data Rights
Under GDPR and LOPDGDD, you have the right to Access (Art. 15), Rectify (Art. 16), Erase (Art. 17), Restrict (Art. 18), Portability (Art. 20), and Object (Art. 21) to processing.
To exercise your rights, write to privacy@aita.world. You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es.
10. Security
We implement technical and organisational measures appropriate to the risk, including TLS 1.2+ encryption in transit, encryption at rest, role-based access control, logging, and an Art. 33 GDPR breach response protocol (AEPD notification within 72 hours).
11. Cookies
Details regarding technical and non-essential cookies are set out in our dedicated Cookie Policy. You can manage preferences anytime via the "Cookie preferences" link in the footer.
12. Minors
The website is intended strictly for professional B2B audiences and is not directed at persons under 18 years of age.
13. Changes to this Policy
Updates are published at aita.world/legal/privacy with the "Last Updated" date updated accordingly.
14. Use of Google API Services and User Data
This section applies to users who connect a Google account to the AITA Platform.
14.1. Limited Use Compliance: AITA’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used strictly to provide in-app features (sign-in, email-to-CRM linking, calendar sync), is never used for advertising, and is never used to train general-purpose AI models.
14.2. Scopes Requested:
| Scope | Data Accessed | Feature Enabled |
|---|---|---|
openid, email, profile |
Basic profile info | "Sign in with Google" authentication |
gmail.readonly, gmail.send, gmail.compose, gmail.labels |
Email threads, headers, bodies, labels | Embedded email agent in CRM (viewing, sending replies, task extraction) |
calendar.readonly |
Calendar events, times, attendees | In-platform calendar sync and scheduling conflict prevention |
14.3. Data Revocation: You can revoke access anytime in Platform settings or via Google Security at myaccount.google.com/permissions. Synced data is deleted within 30 days of disconnect.
15. Contact
AITA World, S.L.Sabino Arana 8, 2º, 48013 Bilbao, Bizkaia, Spain
Legal & Compliance: privacy@aita.world