Data Privacy Agreement

Last updated: 23 July 2026 · Version 1.0

1. Controller

This Data Privacy Agreement ("DPA") describes how personal data is processed by:

OneSAM s.r.o.
Lidická 81, 602 00 Brno, Czech Republic
Contact for privacy matters: privacy@onesam.ai

OneSAM s.r.o. acts as the controller for personal data of website visitors, prospects and its own account holders, and as a processor for personal data that a business customer submits through the Service.

2. Scope

This DPA applies to the OneSAM website, forms, dashboards, APIs and related services (the "Service"). It complements our Terms and Conditions. For business customers, this DPA also serves as a data processing agreement under Article 28 GDPR; a signed counterpart is available on request.

3. Categories of personal data we process

  • Account and contact data: name, business e-mail, company, role, phone (when provided).
  • Form submissions: data submitted through "Start free" and "Book a demo" forms, including message content.
  • Usage and telemetry: request metadata routed through the Gateway (timestamps, model used, token counts, latency, cost, user identifier). Prompt and response content is logged only if the customer explicitly enables it.
  • Technical data: IP address, browser and device information, log data, security events.
  • Billing data: billing address, VAT ID, invoice history. Card data is handled by our payment processor and is not stored by OneSAM.

4. Purposes and legal bases

  • Provide and operate the Service — performance of a contract (Art. 6(1)(b) GDPR).
  • Handle demo requests and pre-contractual communication — performance of a contract / steps prior to entering a contract.
  • Security, abuse prevention and troubleshooting — legitimate interest (Art. 6(1)(f) GDPR).
  • Billing, tax and accounting — legal obligation (Art. 6(1)(c) GDPR).
  • Product analytics and improvement — legitimate interest, using aggregated or pseudonymized data where feasible.
  • Marketing communications — consent (Art. 6(1)(a) GDPR); you may withdraw consent at any time.

5. Sub-processors

To operate the Service we engage carefully selected sub-processors, including cloud hosting, e-mail delivery, analytics and third-party AI model providers. Each sub-processor is bound by written obligations that are no less protective than this DPA. An up-to-date list is available on request at privacy@onesam.ai.

When a customer routes a request to a third-party AI provider through the Gateway, that provider processes the request under its own terms. Customers can configure which providers are allowed.

6. International transfers

We primarily process data within the European Union. Where data is transferred outside the EEA, we rely on adequacy decisions or on the European Commission's Standard Contractual Clauses (2021/914) combined with supplementary measures where required.

7. Retention

  • Account data: for the duration of the account, then deleted or anonymized within 90 days.
  • Form submissions: up to 24 months, unless a contract is concluded.
  • Gateway request metadata: up to 13 months by default, configurable per plan.
  • Invoices and accounting records: retained for the period required by Czech law (typically 10 years).
  • Security logs: up to 12 months.

8. Security

OneSAM maintains an information security program aligned with ISO 27001 practices. Measures include encryption in transit (TLS 1.2+) and at rest, role-based access controls, least-privilege principles, audit logging, regular vulnerability scanning, secure software development, and vendor risk management. Personnel with access to personal data are bound by confidentiality obligations.

9. Your rights

Subject to GDPR, you have the right to:

  • access your personal data and receive a copy;
  • request rectification of inaccurate data;
  • request erasure or restriction of processing;
  • object to processing based on legitimate interests;
  • data portability where applicable;
  • withdraw consent at any time, without affecting prior processing;
  • lodge a complaint with a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (ÚOOÚ, uoou.cz).

To exercise your rights, contact privacy@onesam.ai. We respond within one month.

10. Cookies and similar technologies

The public website uses only strictly necessary cookies by default. Any optional analytics or marketing cookies are loaded only after consent through the cookie banner, where available.

11. AI content and outputs

Prompts and outputs are treated as customer confidential information. OneSAM does not use customer prompts or responses to train its own or any third-party AI models unless the customer has explicitly opted in.

12. Changes to this DPA

We may update this DPA to reflect changes in law or in the Service. Material changes are notified in the dashboard or by e-mail before they take effect.

13. Contact

OneSAM s.r.o., Lidická 81, 602 00 Brno, Czech Republic · privacy@onesam.ai