mAI EngageSign in

Ελληνική έκδοση

Privacy Policy

Last updated: 19 July 2026

1. Who we are

mAI Engage is operated by RETAIL MANAGEMENT SOLUTIONS, Single-Member Private Company (Μονοπρόσωπη ΙΚΕ), 73 Grammou St., 15124 Marousi, Attica, Greece, VAT 801291892, GEMI 153674701000 («we»).

For data protection matters: Ιωάννης Κοτρώτσιος, i.kotrotsios@rm.gr, tel. +30 210 300 4011.

2. Two roles — and why it matters to you

We provide software that businesses («customers») use to manage comments, reviews and messages on their own social media accounts.

  • For our customers' account data (name, email, billing) we act as data controller.
  • For their audience's data — that is, for you, if you commented on or messaged a business page — we act as data processor. The business managing that page is the controller.

3. What we process

  • Account data: name, email, password (stored only as an Argon2id hash), language, timezone.
  • Platform data, on the customer's instruction and exclusively through official APIs: public comments and reviews, private messages sent to the customer's page, and the author's public profile details (display name, username, avatar).
  • AI processing: texts are sent to the AI provider we engage, to produce an analysis and a draft reply. We do not use your data to train models of our own.
  • Billing data: subscription and payment status via Stripe. We never see or store card numbers.

Platform credentials (OAuth tokens) are encrypted at rest with AES-256-GCM and are never written to logs.

4. Legal bases

  • Performance of a contract (Art. 6(1)(b)) — to provide and bill the service.
  • Legitimate interests (Art. 6(1)(f)) — security, abuse prevention and operational logging. For comment processing, the business's legitimate interest in responding to its audience is determined by that business as controller.
  • Legal obligation (Art. 6(1)(c)) — tax and accounting records.

5. If you commented on or messaged a customer's page

This section concerns you directly, under Article 14 GDPR — because we did not obtain your data from you, but from the platform. There is also a separate plain-language notice written for you rather than for businesses.

  • Source: the business's public page or account on Facebook, Instagram, Google, YouTube or another connected platform.
  • Categories: the text you wrote, its timestamp, your public profile, and AI-derived attributes (sentiment, intent, priority).
  • Purpose: to let the business see, triage and reply.
  • Your rights are normally exercised against the business. If you contact us, we will forward the request to them and assist technically.

6. Retention

Interaction data is retained for as long as each customer configures (default 365 days, range 30–3650) and is then anonymised: the text and the author's identifying details are stripped, keeping only what prevents the same record from being re-ingested.

When a customer requests deletion of their workspace, a 30-day grace period applies before irreversible erasure.

Automatic anonymisation covers public comments and their authors' details, the reply drafts generated from them, review content, and private messages together with their attachments and the conversation's contact details.

CRM records do not expire on the clock: they are your own business records, entered by your staff. They are erased when the data subject asks, or when the workspace is deleted.

7. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and to withdraw consent where consent is the basis.

Submit a request to i.kotrotsios@rm.gr or to the business managing the page. We respond within 30 days (Art. 12(3)). See also the data deletion instructions, which cover the automated Facebook and Instagram process.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifisias Ave., 11523 Athens, www.dpa.gr).

8. Recipients and sub-processors

RecipientPurposeLocation
Render Services, Inc.Application and database hostingEU (Frankfurt)
84codes AB (CloudAMQP)Message queue between servicesEU
Stripe Payments Europe, Ltd.Subscriptions and payments (we never see card numbers)EU / USA
Slack Technologies, LLCNotifications and approvals in Slack, if the customer connects itUSA
Twilio Inc.SMS delivery (e.g. verification codes), where enabledUSA
Functional Software, Inc. (Sentry)Application error tracking, for fault diagnosisEU (Frankfurt)
Meta Platforms Ireland Ltd.Facebook & Instagram — source of the comments and messages the customer managesEU
Google Ireland Ltd.Google Business Profile & YouTube — source of reviews and commentsEU

Our business customers receive the full list, including the AI provider and the email delivery provider, in the data processing agreement (Art. 28).

9. Transfers outside the EEA

The application and database are hosted within the EU. Some recipients in the table above process data outside the EEA; those transfers rely on the European Commission's Standard Contractual Clauses (Art. 46) or on an adequacy decision.

10. Security

Credential encryption with AES-256-GCM and key rotation; encryption in transit; per-customer data isolation; an audit trail that never copies personal data content; role-based access.

11. Cookies

We use no tracking, advertising or third-party analytics cookies. The application sets one strictly necessary cookie (httpOnly, SameSite=strict) to keep you signed in, and holds the short-lived access token in browser memory. Strictly necessary cookies do not require consent.

12. Changes

Material changes are notified to customers before they take effect. The date at the top always reflects the last update.

mAI Engage — a product of Retail Management Solutions
PrivacyTermsNotice for commentersData deletionContact+30 210 300 4011