Privacy Policy

Effective: 2026-06-16

This Privacy Policy explains how PME AI ("we", "us", "our") collects, uses, stores, and discloses information when you use our services at pme-ai.pt and any associated subdomains.

If you have questions, contact us at admin@pme-ai.pt.


1. Who We Are (Data Controller)

The data controller for the purposes of this policy is:

PME AI Contact: admin@pme-ai.pt

We are a productized AI agency that builds and runs bespoke AI agents for SME clients (tenants). We act as data controller for platform-level data and as data processor on behalf of tenants for data generated by their agent workflows.


2. What Data We Collect

We collect the following categories of data:

2.1 Authentication and account data (via Clerk)

  • Email address and full name provided at sign-up
  • Profile image (if provided through your identity provider)
  • Session tokens and authentication timestamps

2.2 Tenant configuration

  • Tenant slug (subdomain identifier), display name, approval workflow settings
  • Per-tenant spending caps and usage quotas

2.3 Per-tenant secrets (stored envelope-encrypted)

  • Instagram and Meta platform OAuth access tokens granted by you for content publishing
  • Third-party API keys you provide for integrations

2.4 Agent workflow audit logs

  • Records of each agent run: trigger source, steps executed, content generated, publish status
  • Approval and rejection events for human-in-the-loop workflows

2.5 Cost and telemetry data

  • Token counts, image generation counts, and inferred cost per run attributed to your tenant
  • API latency and error rates used for reliability monitoring

2.6 Generated content records

  • Images and captions produced by AI agents on your behalf
  • Published content metadata (Instagram post IDs, publish timestamps)

3. How We Use Your Data

We use the data above to:

  • Provide the AI agent platform service and execute agent workflows on your behalf
  • Enforce per-tenant usage caps and billing attribution
  • Investigate errors and support requests via audit logs
  • Comply with applicable legal obligations under Portuguese and EU law
  • Improve platform reliability (aggregate, anonymised telemetry only)

We do not use your data for advertising, do not sell your data to third parties, and do not use your tenant content data to train AI models.


4. Meta Platform Integration

We integrate with Meta's Instagram Graph API to publish content on your behalf as a tenant. Specifically:

  • We request the following permissions on your behalf during the OAuth authorization flow:
    • instagram_business_basic — read basic business profile information
    • instagram_business_content_publish — publish photos and videos to your Instagram Business account
    • pages_show_list — list the Facebook Pages associated with your account
    • business_management — manage your Meta Business assets as required for content publishing
  • We use exclusively the minimum permission set required to deliver the Instagram content publishing capability. We do not request permissions to read your audience insights, access Direct Messages, or perform automated engagement actions (likes, follows, comments).
  • Your Instagram and Meta OAuth access tokens are stored envelope-encrypted in our database (one encryption key per tenant row, wrapped by a platform-level key stored in our secrets manager). Tokens are never stored in plaintext.
  • Token refresh operations are performed automatically within the 60-day Meta token lifetime. You can revoke access at any time from your Meta Business settings.
  • We process your Meta-platform data solely to execute agent workflows you have configured or approved. We do not share Meta-platform data with any party other than Meta itself (in the course of API calls).

5. Data Retention

| Data category | Retention period | |---|---| | Agent workflow audit logs | 90 days from run date | | Cost and usage records | 1 year from billing period | | Published content records | Indefinitely (audit trail for your business) | | Authentication session data | Per Clerk's retention policy (session expiry + 30 days) | | Envelope-encrypted secrets | Until you revoke access or terminate your account |

You can request deletion of your data at any time by contacting admin@pme-ai.pt. Deletion is completed within 30 days of the request.


6. Your Rights (GDPR / Portuguese Data Protection Law)

As a user located in the EU or Portugal, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to portability — request your data in a machine-readable format
  • Right to restrict processing — request that we limit how we use your data
  • Right to object — object to processing based on our legitimate interests
  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time

To exercise any of these rights, contact admin@pme-ai.pt. We will respond within 30 days.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Portuguese data protection authority (CNPD — Comissão Nacional de Proteção de Dados, www.cnpd.pt).


7. Security

We implement the following security measures:

  • Encryption at rest: per-tenant secrets (OAuth tokens, API keys) are envelope-encrypted using AES-256-GCM with a data encryption key (DEK) per tenant row and a platform key encryption key (KEK) held in a dedicated secrets manager
  • Encryption in transit: all data transmitted to and from our platform uses TLS 1.2 or higher
  • Row-level security: our database enforces row-level security policies ensuring tenant data is logically isolated
  • Access controls: platform staff access is gated by Clerk authentication and an email allow-list

We are a year-1 platform. We are not yet certified for SOC 2 or ISO 27001. We will update this policy when certifications are obtained.


8. Third Parties We Share Data With

We share data with the following sub-processors to operate the platform:

| Provider | Purpose | Data shared | |---|---|---| | Clerk (clerk.com) | User authentication and session management | Email, name, session tokens | | Neon (neon.tech) | Database hosting | All structured platform data | | Vercel (vercel.com) | Application hosting and edge delivery | Request logs, edge telemetry | | Sentry (sentry.io) | Error and performance monitoring | Stack traces, request metadata | | Langfuse (langfuse.com) | LLM call observability and tracing | LLM prompt/response traces, token counts | | Anthropic (anthropic.com) | AI inference (Claude models) | Prompts and context sent for AI generation | | OpenAI (openai.com) | AI image generation (gpt-image-1) | Image generation prompts | | Cloudflare R2 (cloudflare.com) | Object storage for generated images | Generated image files | | Upstash (upstash.com) | Rate limiting and ephemeral cache | Per-tenant request counts | | Resend (resend.com) | Transactional email delivery | Approval notification emails | | Meta (facebook.com) | Instagram content publishing | Content, captions, and OAuth tokens for API calls |

All sub-processors are contractually bound to handle your data in compliance with applicable data protection law.


9. Children's Privacy

Our platform is a B2B service directed at businesses and their authorized staff. We do not knowingly collect data from individuals under the age of 16. If you believe we have inadvertently collected such data, contact admin@pme-ai.pt.


10. Changes to This Policy

We will notify you by email to the address on your account at least 30 days before any material changes to this policy. Continued use of the platform after the effective date of changes constitutes acceptance.


11. Contact

For any privacy-related queries, data subject requests, or complaints:

Email: admin@pme-ai.pt

We aim to respond within 5 business days.