Skip to content
AffinityAI
ProductFor board meetingsPricingAboutSign in

AffinityAI legal

Privacy Notice

Version 4 · Effective 15 August 2026

Forito Oy, Business ID 2046733-7, Rantapolku 7 A, 00330 Helsinki, Finland is the controller for account, service-operation, website and business-contact data described here. Customers are ordinarily controllers for Customer Content and Forito processes it on their instructions.

1. Personal data we process

We process account identity and authentication data; workspace roles and membership; billing and transaction metadata; support and security records; website choices; and business-contact data. Customer Content may contain participant input, project context and generated outputs.

We do not require prohibited special-category, criminal, children’s, payment-card, password or authentication-secret data in Customer Content.

2. Sources

Data comes from users, workspace administrators, authentication and payment providers, service operation, support interactions and lawful business-contact sources.

3. Purposes and legal bases

We process data to perform contracts, secure and improve the Service, meet legal obligations and pursue legitimate B2B service, fraud-prevention and business-development interests. Consent is used where required for non-essential analytics or direct marketing.

4. Email notifications, preferences and consent evidence

We send necessary account, email-verification, security, service-administration and billing messages to provide and protect AffinityAI and meet our contractual or legal obligations. These necessary messages cannot always be disabled while the relevant account, workspace or subscription remains active.

Participant activity emails, Deadline reminders and Scenario progress reminders are optional operational categories. Account users can change or withdraw these preferences in Email preferences. An invited participant can use an invitation-scoped opt-out link to stop eligible Deadline reminders for that invitation without changing another invitation or another person’s preferences.

Marketing email consent is separate from acceptance of the Terms and acknowledgement of this Privacy Notice. The choice is unchecked by default, account creation is not conditional on it, invited participants are not enrolled in marketing, and consent can be granted or withdrawn in Email preferences as easily as it was given. AffinityAI does not currently send marketing campaigns.

We keep the current email preferences and append-only consent and preference evidence, including the category, wording and wording version, source, action and time. This lets us apply choices consistently and demonstrate consent or withdrawal where needed.

For operational delivery we process notification event and delivery-job metadata such as the notification category and event, workspace and Scenario identifiers, template and template-version identifiers, intended due time, attempt count, status, send and delivery timestamps, and provider message identifiers or hashes. Resend delivers these emails and reports delivery, bounce, complaint, failure and suppression events so we can prevent repeated or unwanted sending and resolve delivery problems.

Operational notification templates do not include participant answers, AI synthesis or other confidential response content. They contain only limited service context, such as the Scenario title, participant display name where relevant, deadline context and a link to the authorized AffinityAI view or preference page.

5. AI processing

Customer Content may be sent to contracted AI providers only to provide requested functionality. It is not used by Forito to train shared or general-purpose models without separate explicit opt-in, and one customer’s content is not used to improve another customer’s outputs.

6. Recipients and transfers

We use the providers listed on the Subprocessors page for hosting, authentication, AI, email and payments. Resend acts as our operational email delivery provider. International transfers use applicable contractual and legal safeguards.

7. Retention

Active service data is retained while needed to provide the Service. A commercial downgrade or the end of paid entitlement does not itself delete workspace data; applicable feature restrictions are distinct from personal-data retention. Data remains subject to account status, security controls, customer instructions and the deletion process described here.

When an account or service relationship is terminated or a valid deletion instruction is received, data is deleted or returned according to the applicable agreement and instructions. Permanent deletion ordinarily completes within 30 days after it begins, unless law requires limited retention.

Content-free deletion evidence may be retained for three years. Financial records are retained for periods required by Finnish accounting and tax law. Business prospect data is ordinarily deleted or re-evaluated after 24 months without meaningful interaction; a minimal suppression record may remain to honor objections.

Consent evidence, limited notification-event and delivery metadata, provider-event evidence and suppression records are retained only while necessary to provide the Service, demonstrate consent and compliance, prevent unwanted future sending, resolve delivery issues and meet applicable legal obligations. Project, workspace and account deletion processes remove notification records linked to the deleted scope where applicable, while limited consent, compliance or suppression evidence may need to remain for those purposes.

A personal account with no active workspace may be deleted after 24 months without meaningful activity, following reasonable advance notice and an opportunity to preserve it. Shared company content is not deleted merely because one account is deleted.

8. Rights and choices

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection, withdraw consent, and complain to a supervisory authority. Workspace content requests may need to be directed through the Customer. Requests may be sent to privacy@affinityai.app; a commercial downgrade does not remove these rights or instructions.

9. Cookies and analytics

Strictly necessary technologies operate without analytics consent. Google Analytics 4 (GA4) is used only on approved public marketing pages and starts only after a visitor accepts analytics through the consent controls. Visitors can reject analytics or change their choice through Cookie settings without losing access to the public website or AffinityAI product.

GA4 measures public website traffic, campaign attribution and a limited set of manually allowlisted public interactions. AffinityAI does not use GA4 User-ID, Google Signals, Google Ads integration, advertising personalization, Enhanced Measurement or cross-domain tracking. GA4 does not receive AffinityAI account identifiers, email addresses, names, company or workspace identifiers, Scenario or participant identifiers or content, prompts, answers, invitation links or security codes.

The GA4 event-data retention setting is 14 months. This setting applies to event-level data used in explorations and does not set a fixed deletion period for every form of aggregated reporting data maintained by Google.

AffinityAI also records server-owned product milestones in Google BigQuery using allowlisted structured event and campaign-attribution fields. These records exclude Scenario, chat, answer, prompt and participant content, use privacy-preserving digests where limited correlation is needed, and distinguish Preview from Production. The configured BigQuery datasets are located in the EU.

10. Children and B2B scope

The Service is for business users aged 18 or older and is not directed to children or consumers.

11. Contact

Email privacy@affinityai.app or write to Forito Oy at the address above.

ProductWhy scenariosPricingSecurityAboutPrivacyTerms

Bold decisions, made together.