Privacy Policy
How A³ collects, uses, shares and protects the information you share when you claim a live session, apply to get listed, or take part in an A³ session.
Last updated: 12 September 2026 · Draft for legal review — bracketed details to be completed by the operating entity before launch.
Who we are
A³ ("A³", "we", "us") is the enterprise AI adoption ecosystem: we qualify an enterprise's stated problem, select a vetted partner, and create the environment for proof — a live session, then a workshop and deployment where the fit holds up. A³ is a venture of Block-9 Group.
The controller of the personal data described in this policy is [legal entity name], [legal form], registered office at [registered address], Greece, registration number [number]. You can reach us about privacy at [privacy@ email]. [If a Data Protection Officer is appointed: DPO contact — name/email.]
This policy applies to this website, the two forms it hosts (claiming a live session and applying to be listed), the scheduling step that follows them, our email and call communications with you, and A³ live sessions, workshops and their recordings. Where the GDPR applies, we act as controller for all of the above unless stated otherwise below.
What we collect, and where it comes from
We collect what you give us and a minimum of technical data. We do not buy personal data and we do not track you across other websites.
When you claim a free live session, you give us: your full name, work email, company, role, department, team size, the AI-adoption blocker you describe, the outcome you want from the session, your preferred timeframe, whether the problem may be discussed publicly (yes / only if anonymised / private only), and your recording preference. If you request a time, we also record the slot you chose and your browser's time zone.
When you apply to be listed as a partner, you give us: company, website, primary contact name, contact email, category, current stage, a one-line description, delivery model, whether you can support a live demonstration, deployment capability, typical customer and engagement size, delivery markets, industries served, security or compliance credentials, and up to two enterprise references. References may contain the names and contact details of people at other organisations: by submitting them you confirm you are entitled to share them with us for review, and we use them only to verify your application. References are never published.
When you take part in a live session, workshop or deployment: the names, roles and organisation of participants, the questions and context shared in the room, and — where recording has been agreed — the audio, video and screen content of the session, which may include your voice and image.
When you contact us or we contact you: the content of emails, call notes and scheduling details.
Technical data: our servers keep minimal request logs for security and abuse prevention (IP address, timestamp, the page requested, and — for form submissions — the domain of your email address, not the address itself). Analytics data is collected only if you accept analytics cookies (see “Cookies & analytics”).
- We do not ask for, and ask you not to submit, special categories of data (health, political opinions, religious beliefs and the like) or bank, card or government-ID details in any free-text field.
- Please describe your problem at the level needed for matching. Do not include trade secrets, customer personal data or regulated information in the form — that context belongs in a private session, once the format and confidentiality have been agreed.
Why we use your data, and on what legal basis
We use personal data only for the purposes below. Each purpose rests on one of the legal bases in Article 6 of the GDPR.
- To review the problem you submit, confirm technical or commercial context where needed, select the best-fit partner and arrange your session — steps taken at your request before entering into a relationship (Art. 6(1)(b)) and our legitimate interest in running the A³ matching process (Art. 6(1)(f)).
- To review a partner application, check references, and decide on listing and A³ Vetted status — steps taken at your request (Art. 6(1)(b)) and our legitimate interest in keeping the directory trustworthy (Art. 6(1)(f)).
- To run live sessions, workshops and deployments, including sharing the participants and context with the matched partner — performance of the arrangement you asked for (Art. 6(1)(b)).
- To record a session — your consent (Art. 6(1)(a)), given when the format is agreed and confirmed at the start of the session. You can decline recording without losing the session.
- To publish a public session recording in the library — the consent of the participants who appear in it (Art. 6(1)(a)). Private sessions are never published unless the customer expressly agrees.
- To send you the emails needed to deliver what you asked for (confirmations, scheduling, follow-up on your session or application) — Art. 6(1)(b). We do not send marketing newsletters unless you separately opt in; you can opt out of any such message at any time.
- To measure how the site is used with analytics — your consent (Art. 6(1)(a)), given through the cookie banner and changeable at any time.
- To keep the site and our forms secure and to prevent abuse (rate limiting, spam filtering, logs) — our legitimate interest (Art. 6(1)(f)).
- To comply with legal obligations, respond to lawful requests, and establish or defend legal claims — Art. 6(1)(c) and (f).
We do not use your data to make automated decisions that produce legal or similarly significant effects on you. Matching is done by people at A³.
Public and private sessions, and recordings
A³ runs two session formats, and which one applies is agreed with you before anything is scheduled.
- Private enterprise session: only your invited team, A³ and the matched partner are in the room. Nothing from it is published. A recording, if you agree to one, is shared with you and the partner for internal review and is not used for any other purpose.
- Public A³ session: the enterprise problem is anonymised and discussed with a broader audience. Public sessions may be recorded and, with the permission of the people who appear in them, added to the public library on this site.
If you take part in a recorded session, you will be told before it starts. You may ask for your contribution to be edited out of a public recording, or for a recording to be taken down, by contacting [privacy@ email]; we will act on the request without undue delay. Partner speakers give their permission for publication when they agree to co-host a public session.
Who we share your data with
We share personal data only where it is needed to deliver what you asked for, with the categories of recipients below. We never sell personal data.
- The matched partner: when you claim a session, we share the problem you described, the outcome you want, and the names and roles of the participants with the single partner (or, for multi-layer problems, the small partner team) selected for it — so they can prepare the scenario. Partners may not use this information for any other purpose or contact you outside the A³ process without your agreement.
- Service providers acting on our behalf, under contract: hosting (Hetzner Online GmbH, Germany, EU data centre), email delivery, a CRM to keep track of requests and applications, a scheduling tool, video-conferencing and recording tools for online sessions, and Google Analytics 4 (Google Ireland Limited) if you accept analytics. [Final provider list to be confirmed by the operating entity before launch.]
- Professional advisers (lawyers, accountants, auditors) where necessary, bound by confidentiality.
- Public authorities where the law requires it, and parties to a legal claim where necessary to establish or defend it.
- A successor entity if A³ is reorganised, merged or acquired — you would be informed and this policy would continue to apply.
International transfers
We run the site and store form data in the European Economic Area. Some service providers (for example Google, for analytics) may process data in the United States or elsewhere. Where that happens we rely on an adequacy decision (such as the EU–US Data Privacy Framework for certified providers) or the European Commission's Standard Contractual Clauses, together with additional safeguards where needed. Partners located outside the EEA receive session context only under contractual safeguards. You can ask us for details of the safeguards used at [privacy@ email].
How long we keep it
We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymise it. Our standard periods are:
- Session requests and partner applications: 24 months after our last contact with you, unless a session, workshop or listing follows — in which case for the duration of that relationship plus 24 months.
- Partner references: until the application is decided, then deleted within 3 months.
- Private session recordings: for the period agreed with you — by default 12 months — after which they are deleted; you may ask for earlier deletion at any time.
- Public session recordings: for as long as they are published in the library; removed on request of a participant as described above.
- Email correspondence and call notes: 24 months after last contact.
- Security and request logs: 12 months.
- Analytics data: Google Analytics retention is set to 14 months; the analytics cookies themselves expire after 13 months at most.
- Your cookie decision: stored in your browser until you clear it or change it.
- Records we must keep to meet accounting, tax or legal obligations: for the statutory period, then deleted.
Your rights
Under the GDPR you have the right to access the personal data we hold about you and receive a copy; to have inaccurate data corrected; to have data erased where there is no longer a lawful reason to keep it; to restrict processing in certain cases; to receive the data you gave us in a portable format; to object to processing based on our legitimate interests; and to withdraw consent at any time (for recording, publication or analytics) without affecting what was done before you withdrew it.
To exercise any of these rights, email [privacy@ email]. We may ask you to confirm your identity. We respond within one month, extendable by two further months for complex requests, in which case we will tell you.
If you believe we have handled your data unlawfully you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, Kifissias 1-3, 115 23 Athens, www.dpa.gr) or to the supervisory authority of the EU country where you live or work. We would appreciate the chance to address your concern first.
Cookies & analytics
This site uses no advertising cookies and no third-party tracking. It stores the following in your browser:
- Theme (local storage, key “theme”): your light/dark preference. Functional, no consent required, kept until you clear it.
- Cookie decision (local storage, key “a3-consent”): whether you accepted or declined analytics. Functional, no consent required, kept until you clear or change it.
- Google Analytics 4 (cookies “_ga” and “_ga_*”): set only if you accept analytics in the banner. Used to count visits and understand which pages and buttons are used. “_ga” expires after 13 months. IP addresses are not stored by Google Analytics 4.
We implement Google Consent Mode v2: before you make a choice, every consent signal is set to “denied” and no analytics cookie is placed. If you decline, Google Analytics receives at most cookieless, aggregated pings that cannot identify you. You can change your decision at any time via the “Cookies” link in the footer of every page, or by clearing your browser's site data.
Videos on this site are hosted on our own servers; playing them does not load any third-party player or cookie. The full list of what the site stores, with durations, is in our Cookies Policy at /cookies.
Security
We protect personal data with technical and organisational measures appropriate to the risk: transport encryption, strict security headers and a content security policy on the site, input validation, rate limiting and anti-abuse controls on our forms, access to submissions restricted to the A³ founders and the people who need it to arrange your session, and contractual data-protection terms with every provider. No method of transmission or storage is perfectly secure, but we work to keep your data safe and will inform you and the competent authority of any breach as the law requires.
Children
This site and the A³ process are intended for professionals acting on behalf of organisations. We do not knowingly collect personal data from anyone under 18.
Links to other sites
The site links to partner websites and other third-party sites. Their privacy practices are their own; this policy does not cover them.
Changes to this policy
We may update this policy as the A³ service, our providers or the law change. The current version and its date are shown at the top of this page. Where a change materially affects how we use data you have already given us, we will tell you before it takes effect.
Contact
[Legal entity name] · [registered address], Greece · [privacy@ email]. [DPO contact, if appointed.]