Legal
Privacy Policy.
Effective Date: 18.07.2026
This Privacy Policy describes how Theron AI collects, uses, discloses, and protects personal data in connection with its website and its AI-powered lead conversion service. It is issued in accordance with Regulation (EU) 2016/679 (“GDPR”) and Romanian Law No. 190/2018.
1.Introduction
This Privacy Policy describes how Theron AI collects, uses, discloses, and protects personal data in connection with its website and its AI-powered lead conversion service. It is issued in accordance with Regulation (EU) 2016/679 (“GDPR”) and Romanian Law No. 190/2018.
This Policy applies to (i) visitors to theronai.app, (ii) businesses that subscribe to the Services (“Clients”), and (iii) individuals who contact a Client through the Services (“Leads”). Where you are a Lead, the Client you contacted is the controller of your data; see Section 4.
2.Definitions
- Client
- means a business that has subscribed to the Services.
- Controller / Processor
- have the meanings given in Article 4 GDPR.
- Data Processing Agreement (DPA)
- means the agreement executed between Theron AI and each Client governing processor obligations.
- GDPR
- means Regulation (EU) 2016/679.
- Lead
- means an individual who contacts, or is contacted by, a Client through the Services.
- Personal Data
- has the meaning given in Article 4(1) GDPR.
- Services
- means Theron AI's AI-powered lead response, qualification, booking, and escalation service, delivered via WhatsApp, SMS, email, and web forms, together with the associated client portal.
- Special Category Data
- means personal data described in Article 9(1) GDPR.
- Sub-Processor
- means a third party engaged by Theron AI to process Personal Data on its behalf.
3.Identity and Contact Details
Full identifying details of Theron AI, including its legal name, registration number, fiscal code, and registered office, are set out in Schedule A. This information is displayed in accordance with Romanian Law No. 365/2002 on electronic commerce.
Contact for all data protection matters: contact@teron.ai
Supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (“ANSPDCP”), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania — anspdcp.ro
4.Our Roles: Controller and Processor
4.1 As Controller. Theron AI acts as Controller for data relating to its own Clients: business and billing details, portal credentials and activity, configuration inputs, and support correspondence.
4.2 As Processor. Theron AI acts as Processor for the personal data of a Client’s Leads — names, contact details, message content, conversation history, and booking data. This data is processed solely on the documented instructions of the relevant Client, who remains its Controller. A DPA executed with each Client governs this relationship in accordance with Article 28(3) GDPR and takes precedence over this Policy on matters of data processing.
4.3 Leads. If you are a Lead, the business you contacted is the Controller of your data. Requests to access, correct, or delete your data should be directed to that business. Theron AI will assist the Client in responding to such requests but cannot act on Lead data without the Client’s instruction, except where required by law.
5.Categories of Personal Data
5.1 Client Data: name, business name, email address, phone number, billing and VAT details, portal credentials and session activity, configuration inputs (business hours, pricing, calendar availability, service descriptions), support correspondence, and performance baseline figures disclosed at onboarding.
5.2 Lead Data: name, phone number, email address, message content transmitted via WhatsApp, SMS, email, or web forms, conversation history, timestamps, channel metadata, qualification signals, appointment and booking details, and escalation status.
5.3 Website Data: contact and enquiry form submissions; server logs, including IP address and user agent, retained for security purposes.
6.Special Category Data
6.1 Nature of the Data. Theron AI’s Services are used by businesses in sectors where inbound messages may routinely contain Special Category Data — for example, references to health, medical conditions, or treatment in messages to clinics and dental practices, or references to legal proceedings in messages to law firms.
6.2 Allocation of Responsibility. The Client, as Controller, is responsible for establishing a valid condition under Article 9(2) GDPR — typically explicit consent, or, where applicable, processing necessary for the provision of health care under Article 9(2)(h) subject to professional secrecy obligations. Theron AI processes such data only as Processor, under the Client’s documented instructions.
6.3 Additional Safeguards. Special Category Data is subject to encryption in transit and at rest, role-based access control, database-level row security isolating each Client’s data, and access logging. This data is deleted in accordance with Section 11 and is never used for model training, product analytics, or any purpose beyond delivery of the Client’s Services.
6.4 Healthcare and Medical-Sector Clients. Where a Client is a healthcare provider, dental practice, or aesthetic clinic:
- a.the Client warrants it has established a valid Article 9(2) condition and obtained any consent required before a Lead's message reaches the Services;
- b.the Client warrants its intake channels display an appropriate privacy notice and AI-interaction disclosure;
- c.Theron AI does not construct patient records, treatment histories, or longitudinal clinical profiles from this data;
- d.where the Client is subject to professional secrecy obligations under Law No. 95/2006 or applicable professional college rules, the Client remains responsible for ensuring Theron AI's processing is compatible with those obligations, and Theron AI's personnel are bound by confidentiality commitments under Article 28(3)(b) GDPR;
- e.a Client subject to a record-retention obligation inconsistent with Section 11 must notify Theron AI in writing before onboarding so an alternative period can be agreed in the DPA.
7.Automated Processing and Artificial Intelligence
7.1 Use of AI. The Services use artificial intelligence models to generate replies, assess qualification signals, determine escalation, and propose appointment times.
7.2 Transparency. In accordance with Article 50 of Regulation (EU) 2024/1689 (the “EU AI Act”), individuals interacting with the Services must be informed they may be communicating with an AI system, unless this is obvious from context. This disclosure is the Client’s responsibility; Theron AI provides the technical mechanism for it.
7.3 Automated Decision-Making. Where the Services’ qualification and routing logic produces a legal or similarly significant effect on an individual without human involvement, the rights in Article 22 GDPR apply, including the right to obtain human intervention and to contest the outcome. The escalation function within the Services exists in part to provide this human involvement. Individuals may request human review through the Client they contacted.
7.4 No Warranty of Accuracy. AI-generated output may be inaccurate, incomplete, or contextually incorrect, and does not constitute medical, legal, financial, or other professional advice.
8.Purposes and Legal Bases
Personal Data is processed for the following purposes and on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Delivery of subscribed Services | Article 6(1)(b), performance of a contract |
| Billing, accounting, and tax compliance | Article 6(1)(c), legal obligation |
| Account and portal administration | Article 6(1)(b), performance of a contract |
| Security, fraud prevention, and service reliability | Article 6(1)(f), legitimate interest |
| Marketing communications to prospective Clients | Article 6(1)(a) consent, or the soft opt-in under Law No. 506/2004 |
| Lead Data processed on a Client's behalf | The Client's own legal basis; Theron AI processes under Article 28 as Processor |
| Special Category Lead Data | The Client's Article 9(2) condition, as described in Section 6 |
Theron AI does not sell Personal Data and does not use Client or Lead Data to train or fine-tune AI models. Message content is transmitted to model providers solely to generate a response within an active conversation.
9.Sub-Processors and Recipients
9.1 Theron AI engages the Sub-Processors listed in Schedule B, each bound by a data processing agreement offering protection no less stringent than this Policy.
9.2 Theron AI will provide Clients with at least thirty (30) days’ written notice before appointing a new Sub-Processor or replacing an existing one, during which the Client may object on reasonable data protection grounds in accordance with Article 28(2) GDPR.
10.International Transfers
Certain Sub-Processors process data outside the European Economic Area. Database, authentication, and portal infrastructure is hosted with Supabase in Switzerland, which benefits from a European Commission adequacy decision under Article 45 GDPR; no additional transfer safeguard is required for this Sub-Processor. Other Sub-Processors process data in the United States. Such transfers are made pursuant to (i) the recipient’s certification under the EU-U.S. Data Privacy Framework, and/or (ii) Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, supplemented by a transfer impact assessment. Copies of the relevant safeguards are available on request.
11.Data Retention
11.1 Lead Data. Lead personal data — including name, contact details, and message content — is automatically deleted thirty (30) days after the relevant conversation closes. This is Theron AI’s default retention period and does not constitute indefinite retention of Lead Data.
11.2 Aggregated Metrics. Aggregated performance metrics (counts, averages, and conversion rates) that do not identify any individual are retained for the duration of the Client’s contract.
11.3 Other Data. Client account and configuration data is retained for the duration of the contract plus twelve (12) months. Billing and accounting records are retained for ten (10) years in accordance with Romanian Accounting Law No. 82/1991. Security logs are retained for ninety (90) days.
11.4 Client Instructions. A Client with a legal or professional obligation to retain communications for longer than thirty (30) days must instruct Theron AI accordingly in the DPA. Clients are responsible for exporting, via the client portal, any Lead Data they wish to retain before automated deletion occurs.
11.5 Termination. On termination of a Client’s contract, remaining data is deleted or returned in accordance with Article 28(3)(g) GDPR, subject to the retention obligations above.
12.Security and Breach Notification
12.1 Measures. Theron AI applies encryption in transit (TLS) and at rest, database-level row security isolating each Client’s data, role-based access control, authenticated portal access, access logging, and dedicated per-Client messaging infrastructure.
12.2 Breach Notification. Theron AI will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of a personal data breach where required under Article 33 GDPR, and will notify affected Clients without undue delay to enable them to meet their own notification obligations. Where a breach presents a high risk to individuals, notification to those individuals is the Controller’s responsibility, with Theron AI’s assistance.
12.3 No system is entirely secure, and Theron AI does not warrant absolute security.
13.Your Rights
Subject to applicable law, you have the right to:
- access your personal data
- rectify inaccurate data
- request erasure
- restrict processing
- object to processing based on legitimate interest
- receive your data in a portable format
- withdraw consent at any time
- not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect
Requests may be sent to contact@teron.ai. Theron AI will respond within one (1) month, extendable by a further two (2) months for complex requests, with notice.
You may lodge a complaint with ANSPDCP or the supervisory authority of your habitual residence.
15.Children's Data
The Services are directed at businesses and their adult customers. Theron AI does not knowingly process the data of children under sixteen (16) years of age, the digital consent age under Romanian law. A Client whose own customers may include minors remains responsible for addressing this in its own controller-side notices.
16.Amendments to This Policy
Theron AI may amend this Policy from time to time. Material changes will be communicated to Clients by email at least fourteen (14) days before taking effect. The version number and effective date above reflect the current text.
17.Contact
[Registered address — see Schedule A]
A.Schedule A — Company and Operational Details
The following details are to be completed before publication:
Data Protection Officer: No Data Protection Officer has been appointed. An internal assessment under Article 37(1) GDPR concluded that appointment of a DPO is not mandatory, as Theron AI’s core activities do not involve large-scale, regular and systematic monitoring of individuals, nor large-scale processing of Special Category Data as a core activity.
Website analytics tooling in use: None.
B.Schedule B — Sub-Processor Register
| Sub-Processor | Purpose | Region |
|---|---|---|
| 360dialog GmbH | WhatsApp Business Platform messaging, as Meta Business Solution Provider | Germany (EU) |
| Meta Platforms Ireland Ltd. | Underlying WhatsApp Business Platform infrastructure | EU/US |
| OpenAI, L.L.C. | Reply generation, qualification, and escalation logic (GPT-4o-mini) | United States |
| Supabase Inc. | Database, authentication, and portal infrastructure | Switzerland |
| n8n GmbH (n8n Cloud) | Workflow orchestration | [confirm hosting region] |
| Twilio Inc. | SMS delivery | United States [confirm applicable regional entity] |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Subscription billing and payment processing | United States / Ireland (EU) |
| [Hosting provider, e.g. Vercel] | Website and portal hosting | [to be confirmed] |
This register is maintained on an ongoing basis and provided to Clients on request.