Privacy Policy
Effective 21 July 2026 · Last updated 21 July 2026
This Privacy Policy explains how Boon IT SRL (“Cooper”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you visit cooperaiq.com and its subdomains or use the Cooper services described below. It also explains the rights you have over your personal data under the EU General Data Protection Regulation (GDPR) and Romanian data protection law.
We designed Cooper to run on very little personal data. We do not track visitors, we do not run advertising or analytics cookies, and we do not sell personal data. Where we do process personal data, this policy tells you what, why, and on what legal basis.
1. Who we are
The controller responsible for your personal data is Boon IT SRL, a company incorporated in Romania and based in Cluj-Napoca, Romania.
For any question about this policy or about how we handle your personal data, contact us at privacy@cooperaiq.com.
Cooper is the AI recommendation index for business software. It measures how AI assistants recommend B2B software across categories and publishes the results. The service is operated within the Sweetspot group of products.
2. Scope of this policy
This policy applies to personal data we process through:
- the public Cooper website and index at cooperaiq.com, including product profiles, category pages, news, and the newsletter signup;
- the Cooper Dashboard for verified product owners at app.cooperaiq.com;
- the Cooper Ads advertiser application at advertiser.cooperaiq.com; and
- the platform services at api.cooperaiq.com that support the above.
This policy does not cover the practices of third parties we link to or that you engage separately, including AI assistants and software vendors we write about. Their handling of your data is governed by their own policies.
3. Summary of key points
- No visitor tracking. The public website uses no analytics, no advertising technology, and sets no cookies. We do not build profiles of visitors.
- Only essential cookies. The only cookies we set are strictly necessary, first-party session cookies used to keep you signed in to the Cooper Dashboard or the advertiser application.
- Passwordless sign-in. We authenticate accounts with one-time email links, not passwords.
- Minimal identifiers. We never store your IP address in raw form. Where we need it to prevent abuse of our sign-in links, we store only an irreversible hashed value.
- Payments handled by our merchant of record. Advertiser payments are processed by Polar Software. We never receive or store your full card details.
- We do not sell personal data and we do not use it for third-party advertising.
4. Personal data we collect
Information you provide when claiming a product. When you claim a product on Cooper to manage its profile, we collect your work email address, your full name, your role, and the product you are claiming. We use this to verify that you are entitled to manage the profile and to create your account in the Cooper Dashboard.
Product profile content. If you manage a claimed product, the descriptive content and business contact details you publish on that profile (for example a contact email, website, or phone number) are stored and shown publicly on Cooper because you chose to publish them.
Advertiser account information. When you sign up for Cooper Ads, we collect your work email and company name, and, for your account settings, details such as a company domain, a reporting email address, a reporting time zone, and your notification preferences. When you run a campaign we store the creative you upload (advertiser name, short description, destination URL, and logo) and campaign and billing records.
Newsletter subscription. When you subscribe to a Cooper newsletter, we collect your email address, an optional first name, and the newsletters you selected. This information is stored with our email provider (see Section 8). You can unsubscribe or change your selection at any time using the link in every newsletter.
Sign-in and security data. Because sign-in is by one-time email link, we generate and store single-use tokens and short-lived session identifiers so we can log you in and keep you signed in. To rate-limit sign-in requests and prevent abuse, we store an irreversible hash derived from your IP address and browser user agent. We do not store the raw IP address or user agent.
Communications. If you email us or submit a support or upgrade request, we receive the content of your message and any details you include, and we keep our correspondence so we can respond and keep records.
Payment information. Advertiser payments are processed by our merchant of record, Polar Software. Your card details are provided to and handled by Polar, not by us. We receive and store the resulting order and billing records (such as an order reference, amount, receipt link, and the billing information contained in the confirmation Polar sends us) to fulfil your campaign and meet our accounting and tax obligations.
Server logs. Our hosting provider automatically records technical information such as requests to our servers as part of operating and securing the service. We use these for security, debugging, and reliability, not to profile you.
5. Data in the public index
Cooper’s core function is to measure and publish how AI assistants recommend software products. The index is about software products and companies, not about individuals. Our measurement queries sent to AI assistants are non-personal questions about software categories (for example, “what is the best software in a given category”) and do not contain personal data about our users or visitors.
Occasionally, public information about a product or company that we index may incidentally include the name of an individual (for example a founder named in public sources). Where such information relates to an identifiable person, we process it in reliance on our legitimate interest in operating an accurate, independent software index, and you may exercise the rights described in Section 11.
6. How we use personal data and legal bases
Under the GDPR we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)) — to create and operate your Cooper Dashboard or advertiser account, verify product claims, run and report on advertising campaigns, and provide the services you request.
- Legitimate interests (Article 6(1)(f)) — to secure our services and prevent abuse of sign-in links, to operate and improve Cooper, to maintain the independence and accuracy of the index, and to respond to your enquiries. Where we rely on legitimate interests, we balance them against your rights and you may object as described in Section 11.
- Consent (Article 6(1)(a)) — to send you the newsletters you selected. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.
- Legal obligation (Article 6(1)(c)) — to keep accounting, tax, and transaction records we are required by law to retain.
9. International data transfers
Some of our service providers are located outside the European Economic Area (EEA), including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under the GDPR, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, so that your data continues to receive an equivalent level of protection. You can contact us for more information about the safeguards that apply to a particular transfer.
10. How long we keep data
We keep personal data only for as long as we need it for the purposes described in this policy, and then delete or anonymise it. In particular:
- Account data (Cooper Dashboard and advertiser accounts) is kept for as long as your account is active, and for a reasonable period afterwards to handle wind-down, disputes, and record-keeping.
- Sign-in tokens and session identifiers are short-lived: one-time links expire in minutes and are single-use, and sessions expire after at most 30 days or when you sign out.
- Newsletter data is kept until you unsubscribe or ask us to remove it.
- Transaction and accounting records are kept for the period required by Romanian tax and accounting law.
- Published profile content that you chose to make public remains published until you change or remove it or close the account.
11. Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to: request access to your personal data; have inaccurate data corrected; have your data erased; restrict or object to our processing; receive certain data in a portable format; and, where we rely on consent, withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@cooperaiq.com. We will respond within the time limits set by the GDPR (normally within one month). We may need to verify your identity before acting on a request. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro). We would appreciate the chance to address your concerns first.
12. Security
We take appropriate technical and organisational measures to protect personal data. Sign-in links and the tokens behind our sessions are handled using one-time, expiring credentials; sensitive tokens are stored in hashed form; access to production systems is restricted; and traffic is served over encrypted connections. No method of transmission or storage is ever completely secure, but we work to protect your data and to address any incident promptly.
13. Children
Cooper is a business service intended for professionals and organisations. It is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Third-party links and embeds
Cooper links to third-party websites, including the sites of software products we index. We are not responsible for the privacy practices of those sites.
Some claimed product profiles may include a video that a vendor chose to embed from YouTube. The video does not load until you click to play it. When you play it, your browser connects directly to YouTube (a Google service), which may receive your IP address and set its own cookies under Google’s privacy policy. If you do not play the video, no data is sent to YouTube.
15. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date above, and for material changes we will take reasonable steps to notify you. Your continued use of Cooper after an update means you accept the revised policy.
16. Contact and complaints
Questions, requests, or complaints about this policy or your personal data can be sent to privacy@cooperaiq.com, or by post to Boon IT SRL, Cluj-Napoca, Romania.