aace
PrivacyData deletionAAce sign in
Perti Laboratories · AAce

Privacy Policy

This policy explains how Perti Laboratories handles information when agencies, their clients, and their customers use AAce.

Effective and last updated: August 15, 2026

1. Who we are and when this policy applies

AAce is a customer-journey, customer relationship management, content operations, and communications platform provided by Perti Laboratories (“Perti,” “AAce,” “we,” “us,” or “our”). This policy applies to the AAce application, its website widget and hosted forms, tenant portal, and connected services.

Marketing agencies and the businesses they manage decide what customer information to collect and how to use it. For that customer information, Perti generally acts as their service provider or processor. Perti acts as a controller for AAce account administration, service security, billing and business operations, and direct communications with our users.

2. Information we collect

AAce account and business information

We process names, business email addresses, account roles, agency and tenant affiliations, authentication records, settings, support requests, and audit history.

Customer and lead information

At the direction of an agency or tenant, AAce may process names, email addresses, telephone numbers, social handles, form responses, conversation messages, consent records, customer status, opportunities, notes, tasks, bookings, campaign activity, and other information the business chooses to collect.

Tenant content and knowledge

We process business descriptions, FAQs, approved knowledge, journey and workflow definitions, prompts, email and social content, uploaded images or videos, calendars, and provider configuration supplied by authorized users.

Connected Facebook and Instagram information

When an authorized user connects Meta accounts, AAce may receive and store Facebook Page and Instagram professional-account identifiers, account names and usernames, access tokens, published content identifiers, comments, mentions, messages, reactions, postbacks, timestamps, and performance metrics. AAce does not request or store a person’s Facebook or Instagram password.

Technical information

We process browser and session identifiers, IP-derived request information, timestamps, device and request metadata, error details, security events, and application logs needed to operate and protect the service.

3. How we use information

  • Provide, secure, troubleshoot, and improve AAce.
  • Run customer journeys, maintain CRM records, and preserve an inspectable interaction history.
  • Publish approved email and social content and receive engagement from connected channels.
  • Match engagement to an existing customer when authorized identifiers support the match, while sending ambiguous matches for human review.
  • Generate grounded conversational responses and structured interpretations using the tenant’s approved information.
  • Measure content, campaign, journey, and conversion performance.
  • Respond to support, privacy, security, and legal requests.

We do not sell personal information or Meta Platform Data. We do not use Meta Platform Data for unrelated advertising, data brokerage, or surveillance.

4. Artificial intelligence

AAce may send limited conversation context and approved tenant knowledge to the language-model provider configured for the tenant or agency, currently including OpenRouter-supported providers. The model may interpret language or generate wording, but AAce’s deterministic runtime controls business state and workflow transitions. Agencies should not place unnecessary sensitive personal information in prompts, knowledge sources, or customer conversations.

5. How information is shared

We share information only as needed with:

  • the agency, tenant, and authorized users responsible for the relevant customer relationship;
  • hosting, database, monitoring, email, calendar, language-model, and support providers that help operate AAce;
  • connected providers such as Meta and Google when an authorized user directs AAce to publish, retrieve, schedule, or communicate through that provider;
  • professional advisers, authorities, or other parties when required by law or reasonably necessary to protect rights, safety, and service integrity; and
  • a successor in a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and legal requirements.

6. Retention and deletion

We retain information for as long as needed to provide AAce to the relevant agency or tenant, maintain security and audit records, resolve disputes, and meet legal obligations. Retention can also be controlled by the agency or tenant responsible for the data. Connected-provider credentials are removed from AAce when the connection is deleted, but previously created CRM, engagement, content, and audit records may remain until the tenant or an authorized requester asks for deletion.

Deletion from active systems and backups may occur on different schedules. We may retain limited information where law, fraud prevention, security, dispute resolution, or enforcement of agreements requires it. See our Data Deletion Instructions.

7. Security

AAce uses tenant-scoped authorization, encrypted provider credentials, signed webhook verification, access controls, audit records, and other administrative and technical safeguards. No system is perfectly secure, and we cannot guarantee that unauthorized access or loss will never occur.

8. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or to object to certain processing. An end customer should normally contact the business with which they interacted because that business controls the customer relationship. You may also contact Perti directly, and we will coordinate with the appropriate agency or tenant when necessary.

You can remove AAce from your Meta Apps and Websites settings and ask the relevant agency or tenant to disconnect the account in AAce. Removing the Meta authorization may stop future access but does not by itself delete information previously stored in AAce.

9. Children

AAce is a business service and is not directed to children under 13. A tenant may use AAce in a business context involving a parent or guardian and a child participant, but the tenant is responsible for appropriate notice, consent, and collection practices.

10. International processing

AAce and its service providers may process information in the United States and other countries. Where required, the responsible parties should use appropriate contractual and legal safeguards for cross-border transfers.

11. Changes to this policy

We may update this policy as AAce, its providers, or applicable requirements change. We will post the revised version here with a new effective date and provide additional notice when legally required.

12. Contact us

Contact Perti Laboratories at aace@perti.io. Include “Privacy Request” in the subject line and identify the relevant agency, business, or AAce tenant when known.

Questions about this document?

Email aace@perti.io.

AAce is a Perti Laboratories product.v0.10.6PrivacyData deletion