API

Privacy Policy

Last Updated: 27 January 2026

1. Introduction

This Privacy Policy explains how API – Artificial Portugal Intelligence ("API", "we", "us", or "our") collects, uses, discloses, and otherwise processes personal data when you interact with our website (api.com.pt), our services, events, training and educational initiatives, community channels, and AI-enabled tools.

For the purposes of the EU General Data Protection Regulation (GDPR), API is the data controller with respect to the processing activities described in this Privacy Policy, unless we explicitly state otherwise.

We value transparency and aim to make our data practices easy to understand. This Privacy Policy explains how personal data is processed when you:

  • visit or interact with our website;
  • contact us or submit inquiries;
  • register for or participate in our events or community initiatives;
  • receive communications from us; or
  • interact with our AI-powered tools, including the Alice chatbot.

This Privacy Policy should be read together with any notices provided at the point of collection (for example, during event registration, contact forms, or within the Alice chat interface). If you do not agree with this Privacy Policy, please do not use our website or submit personal data through our channels.

2. Our Role in Processing Personal Data

For the processing activities described in this Privacy Policy, API acts as the Data Controller, within the meaning of the GDPR, as it determines the purposes and means of processing personal data.

This includes, in particular, personal data processed in connection with:

  • the operation of our website;
  • communications and inquiries;
  • event registrations and community participation;
  • marketing and informational communications; and
  • interactions with our AI-powered chatbot, Alice.

Where we engage third-party service providers to support our activities, such providers act as data processors on our behalf and process personal data solely in accordance with our documented instructions and applicable data protection agreements.

3. Data Controller Contact Details

API – Artificial Portugal Intelligence

Controller: Filipe Macedo

Location: Porto, Portugal

Email for privacy-related inquiries: api@api.com.pt

Website: api.com.pt

4. Personal Data we Process

4.1. Nature and Categories of Personal Data

When you visit or otherwise interact with our website, API processes certain personal data that you voluntarily provide or that is generated automatically as part of the operation, security, and maintenance of the website. The categories of personal data processed via the website may include:

Contact and Communication Data

Personal data you choose to provide when submitting inquiries or contacting us through the website, such as your name, email address, phone number, company name, and the content of your message.

Event and Community Registration Data

Personal data provided when registering for events, workshops, training sessions, or community initiatives promoted through the website, including identification and contact details and, where relevant, professional or business-related information.

Technical and Usage Data

Technical data automatically generated when accessing the website, such as IP address (anonymized where possible), device type, browser information, access timestamps, and basic usage data required to ensure website functionality, security, and performance.

4.2. Purposes and Legal Bases of Processing

Personal data collected via the website is processed for the following purposes and on the corresponding legal bases under the GDPR:

PurposeLegal Basis
responding to inquiries and requests submitted through the website, and carrying out pre-contractual steps at your requestPerformance of pre-contractual steps - Article 6(1)(b) GDPR
providing information about our services, events, training initiatives, and community activitiesLegitimate Interests - Article 6(1)(f) GDPR
managing registrations for events and community initiativesConsent - Article 6(1)(a) GDPR; OR Performance of pre-contractual steps - Article 6(1)(b) GDPR (when applicable)
ensuring the security, integrity, and technical stability of the website, preventing abuse, and detecting or mitigating fraudulent or malicious activityLegitimate Interests - Article 6(1)(f) GDPR

Where processing is based on legitimate interests, API has assessed that such interests do not override the fundamental rights and freedoms of data subjects, taking into account the nature of the data processed and the reasonable expectations of users.

4.3. Cookies and Similar Technologies

The website uses cookies and similar technologies in accordance with applicable data protection and ePrivacy legislation.

Strictly necessary cookies are used to ensure the proper functioning, security, and stability of the website. These cookies are essential and do not require user consent.

Analytics and marketing cookies, including technologies such as Google Analytics and the Meta Pixel, are used only where you have provided your explicit consent via the cookie banner or preference management tool displayed when you first visit the website.

You may accept or reject non-essential cookies at any time and may withdraw or modify your consent through the cookie preference manager or through your browser settings.

Detailed information about the cookies and similar technologies used on the website, including their purposes, duration, and how to manage your preferences, is provided in our Cookies Policy, which is made available separately on the website and should be read together with this Privacy Policy.

4.4. Data Subjects

Depending on the nature of the interaction and the services or initiatives involved, API may process personal data relating to different categories of data subjects. In the context of the activities described in this Privacy Policy, data subjects may include, in particular:

Website Visitors

Individuals who visit or otherwise interact with the API website, including users who browse content, submit inquiries, or engage with interactive features.

Business Contacts and Clients

Representatives, employees, or collaborators of organisations that contact API or engage with API in connection with advisory services, workshops, training sessions, or AI-related projects.

Event and Community Participants

Individuals who register for, attend, or otherwise participate in events, training sessions, community initiatives, or educational activities organised or promoted by API.

Users of AI-Powered Tools

Individuals who interact with API's AI-powered tools and interfaces, including the chatbot Alice, for the purpose of obtaining information, scheduling meetings, or engaging with community initiatives.

Communication Recipients

Individuals who receive communications from API, such as newsletters, event-related messages, or service-related communications, where such communications are sent in accordance with applicable data protection law.

API processes personal data relating to the above categories of data subjects only to the extent necessary and in accordance with the purposes, legal bases, and safeguards described in this Privacy Policy.

5. API Services Overview

API provides a set of services and initiatives that may involve the processing of personal data in different operational contexts. These services are designed to support organisations and individuals in understanding, adopting, and scaling artificial intelligence in a practical, responsible, and sustainable manner. API's activities involving the processing of personal data include, in particular:

AI Strategy, Advisory, and Product Services

Consulting, advisory, and product-related services aimed at supporting organisations in the design, development, implementation, and governance of AI systems, including workshops, assessments, and strategic guidance. In this context, personal data may be processed in connection with business communications, meeting scheduling, and service delivery.

AI Automation and Enablement

The design and implementation of intelligent automation solutions and internal enablement initiatives, including training sessions and executive workshops, which may involve the processing of contact and professional data of participants.

Events and Community Initiatives

The organisation of educational events, community meetups, training sessions, and AI-related initiatives, including the management of registrations, communications, and participation logistics.

AI-Powered Tools and Interfaces (Alice)

The operation of AI-powered tools, including the chatbot Alice, which supports information provision, meeting scheduling, and community onboarding through user-initiated interactions on the website.

Personal data processed in this context is used exclusively for legitimate, clearly defined purposes related to the provision of API's services and initiatives and is processed in accordance with this Privacy Policy and applicable data protection law.

Where API engages third-party service providers to support the delivery of its services (for example, infrastructure providers, communication tools, or AI service providers), such providers act as data processors and process personal data solely on the basis of API's documented instructions and applicable data protection agreements.

6. Use of Artificial Intelligence

API uses artificial intelligence ("AI") technologies as part of its services and internal tools to support information provision, operational efficiency, and user engagement. AI systems operated by API are designed to assist and augment human decision-making, not to replace it, and are implemented in accordance with principles of transparency, proportionality, and human oversight.

6.1. Purposes of AI Use

AI technologies are used by API, in particular, to:

  • provide information about API's services, events, and initiatives;
  • support meeting scheduling and availability checks;
  • facilitate community onboarding and engagement;
  • assist with the handling of inquiries and requests; and
  • improve service quality and operational efficiency.

AI systems are deployed strictly within predefined functional boundaries and are not used for profiling, scoring, or behavioural prediction of individuals.

6.2. AI-Powered Chatbot (Alice)

API operates an AI-powered chatbot named Alice, which interacts with users through the website.

Alice is designed to operate as a support and facilitation tool and relies on a controlled information environment. Responses are generated based on internal documentation and predefined instructions, and Alice is configured to avoid generating speculative or unverifiable information.

Users are clearly informed when they are interacting with an AI system, and Alice's functionality is limited to the purposes described in this Privacy Policy.

6.3. Human Oversight and Automated Decision-Making

AI systems operated by API, including Alice, do not make automated decisions that produce legal effects or similarly significant effects on individuals within the meaning of Article 22 of the GDPR.

Human oversight is maintained at all times. Where a request cannot be appropriately handled by the AI system, or where human intervention is required, the interaction is escalated to API staff.

AI-generated outputs may be reviewed, validated, or supplemented by human personnel, particularly in contexts involving scheduling confirmation, service-related inquiries, or complex requests.

6.4. AI Transparency and Regulatory Classification

API's use of AI is designed to comply with applicable transparency and information obligations under data protection law and relevant AI-specific regulation.

The AI systems operated by API qualify as limited-risk AI systems within the meaning of the EU Artificial Intelligence Act. Accordingly, API implements appropriate transparency measures, including informing users when they are interacting with an AI system and ensuring that AI outputs are subject to human oversight.

6.5. Use of Personal Data in AI Systems

Personal data processed through AI systems is used exclusively for the purposes described in this Privacy Policy.

API does not use personal data or user interactions to train or fine-tune general-purpose AI models. AI service providers engaged by API process data solely to generate responses or support functionality, in accordance with API's documented instructions and applicable data protection agreements.

7. Sub-Processors

To support its activities and the operation of its services, API engages a limited number of trusted third-party service providers that process personal data on API's behalf ("Sub-Processors").

Sub-Processors are selected based on their technical and organisational security measures and are engaged only to the extent necessary to support API's operations. All Sub-Processors are subject to contractual obligations imposing data protection, confidentiality, and security requirements consistent with Article 28 of the GDPR.

7.1. Identified Sub-Processors

The following Sub-Processors are engaged:

AI Services

OpenAI - Used to support AI-powered interactions through the chatbot Alice. OpenAI processes data solely for the purpose of generating responses in accordance with API's documented instructions.

Workflow and Automation

n8n (self-hosted) - Used as a workflow orchestration engine to route chatbot interactions, manage logic flows, and integrate with other services. n8n is self-hosted under API's control within the European Union.

Communication and Scheduling

Google Workspace (including Gmail and Google Calendar) - Used for meeting scheduling, calendar availability checks, and email notifications related to user interactions and service communications.

Email and Communications

Mailchimp - Used for managing newsletters and event-related or informational communications, where users have provided their consent.

Analytics and Advertising Technologies

Google Analytics - Used to collect aggregated website usage statistics, where users have provided their consent.

Meta Platforms (Meta Pixel) - Used for marketing and advertising purposes, where users have provided their explicit consent.

7.2. Role and Instructions

All Sub-Processors process personal data solely on API's documented instructions and only for the purposes described in this Privacy Policy. API does not permit Sub-Processors to use personal data for their own independent purposes.

Where applicable, Sub-Processors may act as independent controllers in relation to certain processing activities (for example, analytics or advertising technologies). In such cases, processing is subject to the Sub-Processor's own privacy policies, and users are informed accordingly.

7.3. Updates to Sub-Processors

API may update the list of Sub-Processors from time to time to reflect changes in its operational requirements or service providers. Material changes will be reflected in an updated version of this Privacy Policy or otherwise communicated where required by applicable law.

8. International Data Transfers

API is established in the European Union and primarily processes personal data within the EU. However, in the context of the services described in this Privacy Policy, personal data may be transferred to, or accessed from, countries outside the European Economic Area ("EEA").

Such transfers may occur in particular where API engages third-party service providers whose infrastructure or corporate entities are located outside the EEA, including providers of AI services, analytics, advertising technologies, and communication tools.

8.1. Safeguards for International Transfers

Where personal data is transferred outside the EEA, API ensures that such transfers are carried out in accordance with applicable data protection law and are subject to appropriate safeguards, as required by Chapter V of the GDPR. In particular, where applicable, international data transfers are based on:

  • Adequacy decisions adopted by the European Commission, where the recipient country is recognised as providing an adequate level of data protection; and/or
  • Standard Contractual Clauses ("SCCs") approved by the European Commission, concluded with the relevant service providers, together with any supplementary technical or organisational measures required under applicable law.

8.2. Assessment of Transfers

API takes into account the nature of the data transferred, the purposes of the processing, and the role of the recipient when relying on international transfer mechanisms. Where required, API assesses whether the safeguards implemented ensure a level of protection for personal data that is essentially equivalent to that guaranteed within the European Union.

9. Data Retention

API retains personal data only for as long as necessary to fulfil the purposes for which it is processed, in accordance with the principles of data minimisation and storage limitation set out in the GDPR. Retention periods are determined taking into account the nature of the data, the purposes of the processing, applicable legal or contractual obligations, and the need to ensure security and accountability.

9.1. Website and Communication Data

Personal data collected through the website, including contact and inquiry data, is retained for the period necessary to respond to requests, manage follow-up communications, and support business development activities. Where no further interaction occurs, such data is periodically reviewed and deleted or anonymised.

9.2. Event and Community Data

Personal data processed in connection with event registrations, training sessions, or community initiatives is retained for the duration of the relevant activity and for a limited period thereafter, to manage communications, attendance records, and follow-up interactions. Where data is processed for ongoing community participation or communications, it is retained until the individual withdraws consent or requests deletion, unless longer retention is required by law.

9.3. AI-Powered Tools and Chatbot Interactions

Interactions with the AI-powered chatbot Alice are session-based. Frontend chat history is cleared when the session ends. Backend logs and technical records generated in connection with chatbot interactions are retained only for limited periods, as necessary for operational integrity, security monitoring, and troubleshooting, and are periodically deleted or anonymised.

9.4. Scheduling and Business Records

Personal data processed in connection with meeting scheduling and related communications (including calendar entries and confirmation emails) is retained for as long as necessary to manage business relationships and comply with applicable legal or accounting obligations.

9.5. Deletion and Anonymisation

Personal data is securely deleted or anonymised when it is no longer required for the purposes for which it was collected or otherwise processed, unless retention is required to comply with legal obligations or to establish, exercise, or defend legal claims.

10. Security Measures

API implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 of the GDPR. These measures are designed taking into account the state of the art, the nature, scope, context, and purposes of the processing, and the risks to the rights and freedoms of individuals.

10.1. Technical Measures

API applies a range of technical safeguards to protect personal data, including, where appropriate:

  • encryption of data in transit using secure communication protocols;
  • secure hosting and infrastructure configurations under API's control;
  • access controls designed to limit access to systems and data to authorised personnel only;
  • rate limiting and monitoring mechanisms to prevent abuse and unauthorised access to AI-powered tools;
  • proxy architectures and origin validation to protect backend systems and credentials.

10.2. Organisational Measures

In addition to technical safeguards, API implements organisational measures, including:

  • access to personal data restricted on a strict need-to-know basis;
  • confidentiality obligations applicable to individuals with access to personal data;
  • internal procedures for handling data protection and security incidents;
  • human oversight over AI-powered systems and escalation procedures where required.

10.3. Ongoing Review

Security measures are reviewed and updated as necessary to ensure an appropriate level of protection, taking into account technological developments, changes to processing activities, and identified risks.

11. Data Subject Rights

Under the GDPR, data subjects have the following rights in relation to their personal data:

Right of Access

to obtain confirmation as to whether personal data concerning them is being processed and, where that is the case, access to such data.

Right to Rectification

to request the correction of inaccurate personal data or the completion of incomplete data.

Right to Erasure ("right to be forgotten")

to request the deletion of personal data in certain circumstances.

Right to restriction of processing

to request that the processing of personal data be limited in specific situations.

Right to Object

to object to the processing of personal data based on legitimate interests, where applicable.

Right to Withdraw Consent

where processing is based on consent, to withdraw such consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. In Portugal, the competent authority is the Comissão Nacional de Proteção de Dados (CNPD).

Requests to exercise data subject rights may be submitted by contacting . api@api.com.pt

For security and verification purposes, API may require additional information to confirm the identity of the requesting individual before responding to a request. Requests will be handled in accordance with the timelines and requirements set out in the GDPR.

12. Changes to this Privacy Policy

API may update this Privacy Policy from time to time to reflect changes in its processing activities, services, legal or regulatory requirements, or operational practices.

Any updated version of this Privacy Policy will be made available on the website, together with an updated "last updated" date. Where changes materially affect the way personal data is processed, API will take appropriate steps to inform data subjects, in accordance with applicable data protection law.

This Privacy Policy is effective as of the date indicated at the top of the document.

By using our website or services, you acknowledge that you have read and understood this Privacy Policy and the manner in which personal data is processed as described herein. Where processing is based on consent, such consent is obtained separately and in accordance with applicable law.