Privacy Policy
Last updated: September 29, 2026
Who we are and what this covers
4GPTs ("we") is the data controller for the personal data described in this policy. We are a United States company that also operates in Greece. This policy covers our website at 4gpts.com: browsing it, booking a meeting, requesting the free e-shop audit, applying for the AI-Shop closed beta, asking us to write when SIL runs on another agent host, and writing to us. A separate policy covers the 4GPTs products and partner programme. It explains what we collect, why, how we protect it, and the rights you have under the EU General Data Protection Regulation (GDPR), Greek Law 4624/2019, the California Consumer Privacy Act as amended (CCPA/CPRA), and other US state privacy laws.
What we collect
What you give us: your name and email when you book a meeting or write to us; and your e-shop's address, your name and your email when you request the free audit, together with the language you used, any campaign parameters in the link that brought you, and the box you tick to agree to the audit terms of service and this policy. When you apply for the AI-Shop closed beta: your e-shop's address, your name, your email, your platform, anything you write about what you want done first, the language you used, any campaign parameters, and the box you tick to agree to the terms of service and this policy. When you ask us to write when SIL runs on another agent host: your email, the host you pick, the language you used, any campaign parameters, and the box you tick to agree to this policy. There are no accounts and no newsletter. What is collected automatically: your IP address, browser, operating system, device type, the page that sent you here, the pages you visit and how you interact with them. We collect this through cookies and similar technologies only after you consent, and we keep a record of your consent. We do not collect sensitive personal data, and we do not collect payment data.
Why we use it
To answer your meeting requests and questions (legal basis: performing a contract with you, or our legitimate interest in answering a general question). To run the free audit you requested and email you the report (performing a contract with you), and to email you a short survey and information on the full report and next steps, as set out in the audit terms of service you agree to on the form (your consent). To read your beta application and answer it (steps you ask us to take before a contract). To write to you once, when SIL runs on the host you picked, and for nothing else (your consent). To measure how the website is used, only after you consent (your consent). To keep the website secure and to prevent abuse (our legitimate interest). To meet our legal obligations under Greek and US law (legal obligation). To improve the website from aggregated usage patterns that identify nobody (our legitimate interest). We do not use your data for behavioural advertising, profiling, or ad targeting.
Cookies
Essential cookies keep the website working and secure. They cannot be switched off. Analytics cookies show us how visitors use the site. They are set only after you accept them in the consent banner. We use no advertising or social media cookies, and the advertising features of our analytics are switched off. You can change your choice at any time in the banner. If you accept, we remember your choice for one year. If you decline, we remember it for the current browser session only. You can also control cookies in your browser; blocking essential cookies may stop parts of the website from working.
Analytics
Analytics is off until you consent. After you consent, our analytics vendor records how the website is used: pages visited, time on page, and clicks. Nothing is recorded before consent, and we use none of the vendor's features that estimate behaviour without it. Analytics data is kept for 14 months. We do not sell it or share it for advertising.
Who receives your data
We share personal data only with vendors that act on our instructions, and only as far as their service needs. Hosting, content delivery and security vendors process IP addresses and request data to serve and protect the website, and to check that a form is sent by a person. An analytics vendor processes usage data, only after you consent. A scheduling vendor processes the name and email you give when you book a meeting. An email delivery vendor sends the emails that confirm and deliver the audit, and processes your name, email and e-shop address for that. It also sends the confirmations of a beta application and of a SIL request, and processes what that confirmation names. The audit request itself reaches our own mailbox and our own reports service. A beta application and a SIL request reach our own mailbox only. We have a data processing agreement with every vendor. We may also disclose data to regulators, courts or public authorities when the law requires it. We do not sell personal data, and we do not share it with anyone for their own marketing.
Transfers outside the EU
We operate in both the European Union and the United States, so data may move between the European Economic Area and the US. Every such transfer is covered by a safeguard the GDPR recognises: the EU-US Data Privacy Framework where a vendor is certified under it, or the European Commission's Standard Contractual Clauses otherwise. Ask us and we will send you a copy of the safeguards we rely on.
How long we keep it
Analytics data: 14 months. Meeting bookings and questions: 3 years from your last contact with us. Audit requests and reports: 3 years from your last contact with us. Beta applications: 3 years from your last contact with us. SIL requests: until we write the one email, or until you ask us to delete the request, whichever comes first. Consent records: 5 years, so we can show that we complied. Security logs: 12 months. After that we delete the data or make it anonymous.
Security
We protect your data with encryption in transit, access limited to the people who need it, and regular security reviews. Our hosting and security vendors shield the website from attacks and malicious traffic. If a data breach is likely to put your rights at risk, we notify the Hellenic Data Protection Authority within 72 hours, and we notify you without undue delay if the risk to you is high. For US residents we follow the applicable state breach notification laws. No system is completely secure, and we cannot promise that ours is.
Your rights in the EU and Greece
Under the GDPR and Greek Law 4624/2019 you can ask for a copy of your data, have it corrected, have it deleted subject to legal exceptions, restrict how we use it, receive it in a machine-readable format, object to processing based on our legitimate interests, and withdraw your consent at any time without affecting what was done before. We make no automated decisions about you. We answer within one month, or within three months for complex requests, and we charge nothing. Write to audit@reports.4gpts.com. You can also complain to the Hellenic Data Protection Authority at www.dpa.gr or contact@dpa.gr.
Your rights in the US
If you live in California or another US state with a privacy law, you can ask what personal information we collected about you in the last 12 months, ask us to delete it, and ask us to correct it. We do not sell personal information and do not share it for cross-context behavioural advertising. We will not treat you differently for exercising your rights. We honour Global Privacy Control signals as an opt-out. We answer verified requests within 45 days, or within 90 days with notice. Write to audit@reports.4gpts.com.
Children
This website is not for children. We do not knowingly collect data from anyone under 13, the age set by US law, or under 15, the age set by Greek law. If we learn that we have, we delete it. Parents and guardians can write to audit@reports.4gpts.com.
Opting out
We honour Global Privacy Control signals. You can switch analytics cookies off in the consent banner at any time. We do not respond to Do Not Track signals, which have no agreed standard. Global Privacy Control serves the same purpose, and we honour it.
Changes to this policy
We may update this policy when our practices, our technology or the law change. For material changes we post a notice on the website at least 15 days before they take effect. The date at the top shows when this policy was last revised.
Contact
For questions, requests or complaints about privacy, write to audit@reports.4gpts.com or to 4GPTs, Athens, Greece. We answer within the time the law sets, and we never hold a request against you. If you are in the EU and unhappy with our answer, you can complain to the Hellenic Data Protection Authority at www.dpa.gr or contact@dpa.gr.