ROGA AI.

Legal

Privacy Policy

Effective date: 26 August 2026 · Replaces the version of July 2026

This notice explains what personal data ROGA AI LIMITED collects, why, on what legal basis, who we share it with, how long we keep it, and what your rights are. It is written to be read, not skimmed past — if anything in it is unclear, write to us and we will answer in plain language.

1. Who we are and what this notice covers

rogaai.com is operated by ROGA AI LIMITED, a company registered in Gibraltar under Company No. 125994, Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA (“ROGA”, “we”, “us”). ROGA is a group of three divisions: ROGA Marketing (a full-service marketing agency), ROGA Technology (AI-native software engineering), and ROGA Labs (our products, including The AI CMO).

This notice covers rogaai.com and the services our Marketing and Technology divisions deliver to clients. ROGA Labs products, including The AI CMO, have their own privacy notices, published on each product's site.

We process personal data under the General Data Protection Regulation as it applies in Gibraltar (the Gibraltar GDPR and the Data Protection Act 2004) and, where our clients or the people concerned are in the European Economic Area or the United Kingdom, under the EU GDPR and the UK GDPR. Every purpose in this notice rests on a specific legal basis (Section 4). Where that basis is consent, it is asked for separately and can be withdrawn as easily as it was given.

2. Your data, or your organisation's data: our role

Which of these applies to you decides who is responsible for what.

2.1 You visit rogaai.com or contact us

We are the controller. This covers website visitors, people who e-mail us, and anyone who asks about our services.

2.2 You work for a client, prospect, supplier or partner

We are the controller of the business-contact data we hold about you — your name, role, work e-mail and phone, and our correspondence — which we use to deliver and manage the relationship.

2.3 Your data is entrusted to us by one of our clients

When a client engages ROGA Marketing or ROGA Technology and gives us personal data to work with — customer lists, CRM records, analytics, support transcripts, datasets for a software build — the client is the controller and we are its processor. We process that data only on the client's documented instructions, under our Data Processing Agreement, which sets out the subject matter, purposes, categories of data, security measures, sub-processors, assistance, audits and deletion. For that processing the DPA prevails over this notice, and the client's own privacy notice is the one that applies to you.

2.4 You apply to work with us

We are the controller of application data, which we keep for the recruitment process and, with your agreement, for future roles.

3. Information we collect

3.1 Information you give us

Name, organisation, role, e-mail address, phone number, and whatever you include in a message, brief, proposal request or application. We do not ask for special categories of personal data and ask you not to send them.

3.2 Information collected automatically on rogaai.com

With your consent only, anonymous page-view analytics (page, referrer, country, device class) through Vercel Web Analytics, which sets no cookie and keeps no IP address. Without consent, we collect nothing beyond the server logs our hosting provider keeps for security (Section 8). The full inventory is in our Cookie Policy.

3.3 Information from clients during an engagement

Whatever the client's Statement of Work makes available for the agreed purpose — described for each engagement in Annex I of the DPA. We ask clients to share only the fields the work needs and to pseudonymise where they can.

3.4 Information from other sources

Publicly available business information (company websites, professional networks, company registers) used to prepare for a conversation you or your organisation has started with us, or to research markets for a client.

4. How we use it, and on what legal basis

Where we are the controller (Sections 2.1, 2.2 and 2.4):

PurposeLegal basis
Answering enquiries, preparing proposals, delivering and managing engagementsPerformance of a contract, or steps taken at your request before entering one
Invoicing, tax and accounting recordsContract; legal obligation
Keeping our systems secure: access control, logging, abuse prevention, incident responseLegitimate interests (security and integrity of our systems); legal obligation
Understanding how rogaai.com is used and improving itConsent, given through the cookie banner
Occasional communications about ROGA's work, to existing clients and people who asked to hear from usConsent, or legitimate interests for existing clients about similar services — with an easy way to opt out in every message
RecruitmentSteps taken at your request before entering a contract; legitimate interests
Establishing, exercising or defending legal claims; complying with law and lawful requestsLegitimate interests; legal obligation

Where we are a processor (Section 2.3), we use the data for one purpose only: performing the services the client has instructed, as documented in the Statement of Work and the DPA. The legal basis is the client's to establish. We never process a client's data for our own purposes, and we do not sell personal data.

5. AI tools and your information

AI is part of how we work. Our teams use AI models to research, draft, analyse and build. When personal data is involved, these rules apply:

  • Client personal data is sent to a model provider only when the Statement of Work calls for it, only the fields the task needs, and only to providers engaged under terms that exclude retention beyond the request and any use for training.
  • We do not use client data, or content generated from it, to train, fine-tune or improve any model — ours or a third party's — unless a client has agreed to a specific training arrangement in writing. Custom models built for a client are the client's, trained on the client's data alone.
  • AI output that affects people is reviewed by a person before it is acted on. We do not use AI to make decisions with legal or similarly significant effects on individuals, and we do not instruct models to infer special categories of data.
  • Enterprise clients may fix the provider, the model, the processing region and zero-retention routing for their engagement (DPA, Annex IV).

6. How we share information; sub-processors

We do not sell, rent or trade personal data. We share it with the service providers below, which act on our instructions; with advisers under confidentiality; where the law requires it; and in a merger, acquisition or sale of assets, in which case we notify you before your data is transferred.

6.1 Sub-processor register

ProviderPurposeLocationAssurance
Vercel Inc.Hosting of rogaai.com; web analytics with your consentUnited States (edge network worldwide)SOC 2 Type II, ISO 27001
Google Cloud / Google WorkspaceCloud infrastructure, e-mail, documents and collaborationEU and United StatesSOC 2 Type II, ISO 27001
AI model providers (Anthropic, OpenAI, Google)Model requests during engagements, per Section 5 — only where the Statement of Work providesUnited States / EU, per engagementSOC 2 Type II

Engagement-specific tools — a client's CRM, advertising platforms, e-mail service or cloud account — are named in the Statement of Work and listed in Annex III of the DPA for that engagement. Each sub-processor is bound by a written agreement imposing data-protection obligations equivalent to ours, and we check its security assurance before and during use. When we add or replace a sub-processor of client data, clients under a DPA are notified at least 30 days in advance and may object as that agreement provides.

7. International data transfers

We are established in Gibraltar. Some of our providers process data in the United States. Where personal data originating in the EEA, the United Kingdom or Gibraltar is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant) or, for recipients certified under the EU–US Data Privacy Framework, on that certification, together with the safeguards in Section 9. Our Information Sharing & Transfer policy requires a recorded transfer basis for every cross-border flow. Copies of the mechanisms in use are available to clients on request.

8. How long we keep information

InformationRetention
Enquiries and proposals that do not become an engagement12 months from our last exchange, then deleted
Client and business-contact dataFor the relationship and 3 years after it ends, unless a legal claim requires longer
Client personal data processed as processorFor the term of the Statement of Work; returned or deleted at the client's choice within 30 days of the end of the engagement, and from backups within 90 days as they expire
Deliverables and working files containing personal dataAs the Statement of Work provides; otherwise deleted with the engagement data above
Consent and opt-out recordsKept as evidence for as long as the underlying obligation exists — an opt-out stays in force so you stay excluded
Data-subject request logs3 years
Server, access and security logs90 days online, up to 1 year in encrypted archive
BackupsEncrypted; deleted data ages out within 90 days
Recruitment applications6 months after the process ends; longer only with your agreement
Billing and tax recordsAs long as tax and accounting law requires (typically 7 years)

Our Retention & Secure Disposal policy runs a quarterly review; anything past its period is queued for disposal within 30 days, and disposal is logged.

9. How we protect information

We operate a security programme under SOC 2 Type II and GDPR-aligned policies covering information security governance, access control, encryption, secure development, vendor management, incident response, business continuity, and data classification, retention and disposal. The measures that matter most to you:

  • Encryption: TLS 1.2 or higher for all data in transit, with weak ciphers disabled; provider-managed encryption at rest for storage, databases and backups; keys held in a managed key service, rotated at least annually, with access logged.
  • Access control: least-privilege access protected by multi-factor authentication; access to client data granted on need, reviewed quarterly and logged; revoked within 48 hours at offboarding.
  • Data classification: four levels (Public, Internal, Confidential, Restricted); client personal data is handled as Confidential or Restricted, encrypted, shared only over approved channels, and only under contract.
  • Secure development: code review, dependency and vulnerability scanning in the pipeline, severity-based patch timelines (critical within 7 days), and penetration testing at least annually.
  • Resilience: daily encrypted backups retained 30 days online, restore tests quarterly, and a maintained business continuity plan.
  • Incident response: a documented process with named roles; where a personal data breach affects a client's data we notify that client without undue delay and within 48 hours of confirming it, so it can meet its own 72-hour duty; where the breach concerns data we control, we notify the Gibraltar Regulatory Authority within 72 hours where the law requires.
  • People: confidentiality undertakings, background screening proportionate to role, and security and privacy training on joining and annually.
  • Vendors: providers that touch client or Restricted data must hold a current SOC 2 Type II report or equivalent, reviewed annually.

Our Trust Center, with the live status of the SOC 2 Type II examination and the policies in force, is at trust.inc/roga-ai-limited. A fuller description of the technical and organisational measures is Annex II of the Data Processing Agreement. No method of transmission or storage is perfectly secure; if you believe data you gave us has been compromised, contact us at once.

10. Your rights

10.1 What you can ask

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy
  • Rectify inaccurate or incomplete data
  • Erase your data where there is no longer a reason for us to keep it
  • Restrict processing while a question about it is resolved
  • Port the data you gave us to another provider in a machine-readable form
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent at any time where consent is the basis, without affecting processing before the withdrawal
  • Complain to a supervisory authority: the Gibraltar Regulatory Authority (gra.gi), or the authority of the EEA country or the UK where you live or work

10.2 How to ask

Write to contact@rogaai.com with “Privacy request” in the subject. We may need to verify your identity. We answer within one month; for complex requests we may extend by up to two further months and will tell you why. Requests are free unless clearly unfounded or excessive. Every request, decision and completion date is logged.

10.3 If your data was entrusted to us by a client

The client is the controller and the one to answer your request. If you write to us, we forward your request to the client within three business days, do not act on it without the client's instruction unless the law requires us to, and give the client the technical help it needs so it can answer you within the legal time limit.

11. Cookies and consent

rogaai.com sets one strictly necessary cookie to remember your consent choices. Optional analytics run only if you opt in and are off by default. The full inventory — name, purpose, duration and recipient — is in our Cookie Policy, where you can also change or withdraw your consent at any time. Your choice is recorded with a timestamp, its scope and the method used.

12. Children

Our services are for businesses and professionals and are not directed at anyone under 18. We do not knowingly collect personal data from children; if we learn that we have, we delete it. Clients are responsible for the age rules that apply to their own audiences.

13. Changes to this notice

We update this notice when our practices, the law or our sub-processors change, and within 30 days of any significant change in processing. Each version is dated at the top and archived, so you can see what applied at any time. For material changes — a new purpose, a new category of data, a new sub-processor of client data — we notify affected clients before the change takes effect and, for clients under a DPA, as that agreement provides.

14. Contact

ROGA AI LIMITED

Registered in Gibraltar, Company No. 125994

Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA

Privacy requests and Data Protection Officer: contact@rogaai.com

Security: contact@rogaai.com

Trust Center: trust.inc/roga-ai-limited