Privacy Policy

This Privacy Policy explains how we collect, use, store, and protect your information when you use our Services.

Last updated: August 1, 2026

此頁面僅提供英文版本。

1. Introduction

M.M. KIMA DEVELOPMENT LTD, a company registered in Cyprus, operating under the trade name PandAi7 ("Company," "we," "us," or "our"), is committed to protecting your privacy and handling your data responsibly.

This Privacy Policy explains how we collect, use, disclose, store, and protect information when you visit our website, use our platform, or interact with any of our services, including website generation, hosting, AI-powered editing, and related communications (collectively, the "Services").

This Privacy Policy should be read alongside our Terms of Service, which govern your use of the Services. Terms defined in the Terms of Service have the same meaning when used in this Privacy Policy.

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the Services.

1.1 Data Controller

For purposes of applicable data protection laws, the data controller is:

M.M. KIMA DEVELOPMENT LTD
Operating as PandAi7
68 Spyrou Kyprianou, 4042 Germasogeia, Limassol, Cyprus

You can contact us through our Contact page.

We have not appointed a Data Protection Officer unless stated otherwise on this page. If applicable law requires appointment of a Data Protection Officer in the future, we will update this Policy with the relevant contact details.

2. Information We Collect

2.1 Business Information

We collect publicly available business information including business name, address, phone number, and business category. This information is used to generate and populate your website. During the preview window, photographs may be temporarily displayed from third-party sources but are not stored by the Company. Upon subscription, the Customer provides their own photographs and confirms their business details, which replace any third-party sourced content.

2.2 Account Information

When you access your account, we collect the email address used for authentication. We do not collect or store passwords. You may authenticate either through a magic link sent to your email address, through a one-time verification code (OTP) during the subscription flow, or by signing in with a supported third-party identity provider (see Section 2.8). We also record the timestamp of your most recent sign-in for security auditing.

2.3 Usage Data

We automatically collect information about how you interact with the Platform, including pages visited, features used, edit requests made, session duration, browser type, device information, IP address, and referring URLs.

2.4 Payment Information

When you purchase a subscription, Add-ons, or Edit Packs, payment information is collected and processed by our third-party payment provider. We do not directly collect, store, or have access to your full payment card details. We may receive limited transaction information such as the last four digits of your card, transaction amount, and billing status.

Before payment we also collect a billing profile containing your full name, phone number, billing address, country, entity type (individual or business), and country-specific tax identifier where applicable. This information is used to issue invoices and to satisfy tax and regulatory requirements. We retain billing profiles associated with paid subscriptions for the duration required by applicable tax and accounting laws.

2.5 AI Interaction Data

When you use our AI editing features, we collect the prompts and instructions you submit, as well as the content generated or modified by the AI in response. AI prompts, instructions, uploaded content, and generated outputs are processed to provide the requested AI editing feature, maintain service security, troubleshoot errors, enforce usage limits, and improve the Platform. We do not use Customer Content or AI Interaction Data to train our own general-purpose AI models. Our use of third-party AI providers is subject to the sub-processor commitments described in Section 6.1. The same applies to the canonical-language site content we submit to our AI translation provider when you enable additional language versions of your site.

2.6 Communication Data

If you contact us or respond to our communications, we collect the content of those messages, your email address, and any other information you choose to provide.

Support requests. Support requests you submit through the Platform are stored with your account so that the conversation history remains available to both of us. The content of a support request may be sent to a third-party AI provider in order to draft a reply; that draft may be reviewed by a person before it is sent or sent automatically, and any request can be escalated to a person on request. Support content is not used to train our own general-purpose AI models, and our use of third-party AI providers is subject to the sub-processor commitments described in Section 6.1.

2.7 Domain Registration Data

When you purchase a domain through the Platform, we share registrant contact information with the third-party domain registrar as required for domain registration. This includes the Company's contact details (not your personal information) as the registrant of record. The domain name you select and its association with your website are stored in our systems.

2.8 Authentication via Third-Party Identity Providers

If you choose to sign in using a third-party identity provider (Google or LinkedIn), we receive limited public profile information from that provider after you authorize the connection: your verified email address, your display name, a profile picture URL, and a locale preference. We only proceed with accounts whose email address the provider has marked as verified.

We do not store the provider's access tokens or refresh tokens — we use our own session once authentication succeeds. We store the provider's user identifier so that subsequent sign-ins from the same account can be recognized, and we record when each provider was linked and last used. You may unlink a connected provider at any time from your account settings; for your security, after you disconnect a provider we will block sign-ins through that provider for approximately 30 days (the exact duration is configurable on our side) until you explicitly re-enable it from your account settings. During this period you can still sign in via magic-link email.

Your interactions with Google or LinkedIn during the authentication step are governed by those providers' own privacy policies and terms.

2.9 Self-Serve Site Generation Data

When a visitor uses the public self-serve website-generation tool on our marketing site, we accept one of two inputs: a Google Place identifier selected through our autocomplete search, or manually entered business details. Where a Place identifier is selected, the business information used to populate the resulting website (name, address, category, phone, opening hours, and photographs) is retrieved from Google's Places API and the visitor does not need to provide it themselves. Where details are entered manually, that information is supplied by the visitor.

Autocomplete works by forwarding the visitor's typed query to Google's Places Autocomplete service in real time so Google can return matching business suggestions. The visitor's typed text is sent to Google but is not retained on our servers; queries that fail are logged with only an error code and HTTP status (no query content). After a place is selected, our result preview embeds a Google Map through Google's keyed Maps Embed iframe — Google may set short-lived cookies on its own origin and see the standard request signals (referrer, IP, browser characteristics) that any third-party iframe receives.

Google services are provided by Google and are subject to Google's own terms and privacy policy. We do not control Google's independent collection or use of information when a visitor interacts with Google services embedded in or used by the Platform.

To prevent abuse of these public endpoints we apply per-visitor, per-session, and per-IP quotas enforced in short-lived server-side counters; require a bot-mitigation challenge on the Generate-Site submission step (see Section 11); and log submissions (including source IP and the identifier that was submitted) for audit and anti-abuse purposes. When visitors upload photographs through the manual-entry form, those images are stored in association with the generated website.

In-browser image editing. Where supported by the browser-based editing flow, uploaded photographs are processed in the visitor’s browser before transmission, including cropping, rotation, resizing, and removal of common camera metadata such as EXIF GPS fields. This is designed to prevent common embedded metadata from being uploaded to the Platform. We cannot guarantee that every possible form of embedded or hidden metadata will be removed from every file type. Photographs are additionally re-encoded on our servers when saved, which removes metadata from the stored image.

2.10 Pre-Subscription Edit Demonstration Data

Before a website is subscribed-to, anonymous visitors and the prospective owner can interact with an in-page editor to demonstrate the platform's editing capabilities. Visitors may type inline text changes, upload replacement photographs, and submit short natural-language prompts to our AI editor to preview how a section could be rewritten. These submissions are stored on our servers temporarily — they are not committed to the live website at submission time. The eventual paying owner reviews the queued submissions during the subscription confirmation step and chooses whether to apply or discard them.

Data we collect for this purpose includes: (a) the verbatim text the visitor typed and the photographs they uploaded; (b) a salted hash of the visitor's IP address (we do not retain the raw IP for this feature); (c) an opaque session identifier stored in a tamper-evident HMAC-signed cookie on the visitor's browser; (d) a hash of any AI prompt the visitor submitted (the verbatim prompt is not retained beyond the live request); and (e) audit-log entries describing the action timestamps and outcome, with no personal identifiers beyond the IP hash. To prevent abuse we apply per-IP, per-site, and global rate limits, require a Cloudflare Turnstile challenge for AI-based edits, and cap the number of demonstration AI edits per site.

Pre-subscription edit submissions are retained for up to seven (7) days from submission and are permanently deleted thereafter, regardless of whether they were ever reviewed or applied. If the prospective owner subscribes and applies the submissions, the resulting content becomes part of the active website and is then governed by the retention rules in Section 8.

3. How We Collect Information

We collect information through the following methods:

  • Directly from you: When you create an account, use the AI editor, upload content, subscribe to a plan, or contact us.
  • From publicly available sources: We collect business information from public directories, mapping services, and business listing platforms to generate websites. This information is already publicly accessible.
  • Automatically: Through cookies, server logs, and similar technologies when you interact with the Platform. This includes usage data, device information, and IP addresses.
  • From third-party services: We may receive information from our service providers, including payment confirmation from payment processors, business data from mapping and directory APIs, and verified profile information from third-party identity providers (Google or LinkedIn) when you choose to sign in through those services.

3.1 Information Not Collected Directly From You

In some cases, we generate preliminary or preview website materials using business information obtained from publicly available sources, business directories, mapping services, or business listing APIs. This may include business name, address, phone number, category, opening hours, and publicly available images where permitted for preview display.

Where we process personal data that was not obtained directly from the relevant individual, we rely on the lawful bases described in Section 5 and provide removal or correction options through our Contact page.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • To generate, deploy, and host your business website
  • To provide AI-powered content editing and modification features
  • To authenticate your identity and provide secure access to your account
  • To process subscriptions, Add-on activations, Edit Pack purchases, domain registrations, and other transactions
  • To send transactional communications, including authentication emails, subscription reminders, and service notifications
  • To monitor and enforce compliance with our Terms of Service and Acceptable Use policy, including automated and manual screening of website content for prohibited or unlawful material
  • To detect, prevent, and address abuse, fraud, and security issues
  • To improve, maintain, and optimize our Services and Platform
  • To comply with legal obligations and respond to lawful requests

6. Data Sharing and Third Parties

We do not sell your personal information. We may share your information with the following categories of third parties, solely for the purposes described in this Privacy Policy:

  • AI service providers: Content you submit through AI features may be sent to third-party AI model providers for processing.
  • Payment processors: Transaction and billing information is shared with our payment provider to process subscriptions and purchases.
  • Cloud infrastructure providers: Your data is stored and processed on servers operated by third-party cloud hosting providers.
  • Business data and mapping providers: We query third-party APIs to discover publicly available business information. Business data from these providers is used transiently during website generation and is not permanently stored on our servers. During the preview window, business photographs may be served directly from third-party content delivery networks. Upon subscription, these are replaced with Customer-provided imagery.
  • Email and messaging providers: We use third-party services to deliver authentication emails and service notifications.
  • Third-party identity providers: When you choose to sign in with Google or LinkedIn, your browser is redirected to that provider to complete authentication. We share the minimum information required to initiate the sign-in exchange; the provider returns a verified email address, name, profile picture URL, and locale. We do not share your usage data or any other account content with these identity providers.
  • Analytics: We operate a self-hosted, cookie-free analytics service (Umami) on our own infrastructure. Aggregated visit data (page, referrer, coarse geography, browser and device type) is not shared with any external analytics vendor.
  • Domain registrars and DNS providers: When you purchase a domain, registration details are shared with our third-party domain registrar to complete the registration. Domain routing and SSL data is shared with our DNS and CDN provider.
  • Legal and regulatory authorities: We may disclose information where required by law, legal process, or government request, or where necessary to protect our rights, safety, or property.

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections described in this policy.

6.1 Sub-processors and Service Providers

We use third-party service providers to operate the Platform. These providers may process personal data only as necessary to provide services to us, such as hosting, payment processing, authentication, email delivery, AI processing, bot prevention, domain registration, DNS, and CDN.

We may update our service providers from time to time. Where required by law or contract, we will maintain appropriate data-processing agreements and transfer safeguards.

7. International Data Transfers

The Company is registered in Cyprus (European Union) and operates internationally. Your information may be transferred to, stored, and processed in countries outside of your country of residence, including countries outside the European Economic Area (EEA).

Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place in accordance with GDPR requirements, such as standard contractual clauses approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms.

Our third-party service providers, including AI model providers, cloud infrastructure, and payment processors, may process data in various jurisdictions. We require that these providers maintain appropriate levels of data protection consistent with this Privacy Policy and applicable law.

8. Data Retention

We retain your information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. Specifically:

  • Preview website data (non-subscribers): Generated preview websites are retained for a short window (currently 48 hours; the exact duration is published via the Platform) and are then permanently deleted. No archive is retained for non-subscribers. If you later wish to subscribe, we will regenerate a fresh website from your business information; your prior preview cannot be recovered. Preview websites are configured not to be indexed by search engines — they are served with directives that exclude them from search results, sitemaps, and search-engine archives, and links shared on social platforms display a generic “Pending subscription” preview card rather than the underlying business details. Real business name, photographs, and other identifying details appear in search results and social previews only after the Customer completes the post-payment confirmation step.
  • Paid but not yet confirmed (awaiting completion): Upon subscription payment, temporary third-party preview data (including business-listing data and imagery) is removed, and the website displays a generic “awaiting completion” page — containing no business details — until the Customer completes the post-payment confirmation step. During this period we send transactional setup-reminder emails. Content the Customer subsequently provides is retained for the duration of the subscription.
  • Active subscription website data: Retained for the duration of your active subscription.
  • Cancelled subscription website data: Upon cancellation, your website is placed in an archived state at the end of your paid billing period and retained for up to 365 days, during which you may reactivate your subscription to restore the site with your edits intact. After 365 days, the archived website and its content are permanently deleted.
  • Post-deletion summary record: When a preview website is deleted we retain a minimal technical record of it — the web address it used, its business category, the design selections made, language settings, and counts of any edits or support messages. This record contains no business name, address, phone number, opening hours, or photographs. Where the preview was created from a business listing, that listing's identifier is retained so a fresh website can be generated on request. Personal data captured alongside the record (such as the IP address that created the preview) is removed after a short retention period.
  • AI interaction data: Prompts and generated content follow the same retention as the underlying website (preview window or archive window).
  • Pre-subscription edit submissions: Visitor-submitted text edits, photo uploads, and queued AI drafts described in Section 2.10 are retained for up to 7 days from submission and are permanently deleted thereafter, whether or not they were ever applied.
  • Payment, invoice, and tax records: Retained as required by applicable financial and tax regulations (typically 6–7 years), independently of subscription status.
  • Communication records: Records of transactional communications and opt-out preferences are retained to honor your communication preferences.
  • Outbound email records: We keep a log of the transactional emails we send, recording the recipient, subject, message type, delivery status, and timestamps. Where diagnostic logging is enabled, the log also stores the rendered message body, which can include the contents of the email itself — such as a sign-in link, a verification code, or a message submitted through a website contact form. These records are purged on a rolling schedule.
  • Audit logs: Account activity and security events are retained in accordance with configured log-retention policies, which may be shorter than the periods above.

When data is no longer required, it is securely deleted or anonymized. You may request deletion of your personal data at any time, subject to our legal obligations and legitimate business needs.

8.1 Backups

Deleted data may remain in backups or disaster-recovery snapshots for a limited period until those backups are overwritten or expire according to our backup lifecycle. We do not use backup copies for ordinary business purposes and restore them only for security, continuity, or disaster-recovery needs.

9. Data Security

We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using TLS/SSL protocols
  • Secure database storage with access controls
  • Passwordless authentication (see Section 2.2) — no passwords are collected or stored; sign-in uses single-use, time-limited magic-link tokens or a verified third-party identity provider
  • Regular monitoring for security threats and vulnerabilities
  • Access to personal data restricted to authorized personnel on a need-to-know basis

While we strive to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data. If you become aware of a security breach affecting your account, please contact us immediately.

10. Your Rights

Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights regarding your personal data:

  • Right of access: You have the right to request a copy of the personal data we hold about you.
  • Right to rectification: You have the right to request correction of inaccurate or incomplete personal data.
  • Right to erasure: You have the right to request deletion of your personal data, subject to our legal obligations and legitimate interests.
  • Right to restrict processing: You have the right to request that we limit the processing of your personal data in certain circumstances.
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object: You have the right to object to the processing of your personal data based on legitimate interests, including for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on consent, you have the right to withdraw your consent at any time.
  • Rights regarding automated decision-making: We use automated tools, including AI, to screen website content for material that violates our Terms of Service or Acceptable Use policy. If suspected prohibited content is detected, your website may be placed under a temporary hold and taken offline pending review by our team; a permanent removal is never made by automated means alone. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human review of, express your view on, or contest any such hold by contacting us.

To exercise any of these rights, please contact us. We will respond to your request within thirty (30) days. If we are unable to fulfill your request, we will explain why.

You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus, or with the supervisory authority in your country of residence.

11. Cookies

We use a small number of cookies on our Platform. Cookies are small text files stored on your device that help us provide and secure our Services.

Types of cookies we use:

  • Essential cookies: Required for the Platform to function properly, including session management and authentication (for example, the secure, HTTP-only session cookie issued after a successful magic-link or OAuth sign-in, and short-lived cookies used to bind OAuth state and pending-link flows). These cannot be disabled.
  • Pre-subscription editor session cookies: When a visitor interacts with the in-page editor on a pre-subscription website, we set a tamper-evident HMAC-signed cookie containing only an opaque session identifier (no personal information) and scoped to that specific site. The cookie binds the visitor's queued edits to their session and is required to add to or modify those edits. If a visitor opens or compares multiple pre-subscription sites we issue one such cookie per site visited; each cookie is independent and expires automatically after 48 hours, matching the lifetime of the pre-subscription site itself. Pending edit submissions are governed by the separate retention window described in Section 2.10.
  • Pre-subscription visitor session cookie: When a visitor submits the Generate-Site form on the marketing site, we set a tamper-resistant cookie containing only a random session identifier and the URL path of the single generated site. The cookie is HTTP-only, scoped to that one site's path (no cross-site tracking), and required so we can render that one site without re-fetching its data from Google on every visit. We use this cookie to support session-bound rendering of preview data and to help operate the Generate-Site feature in line with our interpretation of applicable Google service requirements. The cookie expires automatically after 48 hours, matching the lifetime of the pre-subscription site itself. For abuse-detection purposes our server-side audit logs additionally record the IP address that initiated the session in a one-way hashed form.
  • Functional cookies: Used to remember your preferences, such as your selected language, to improve your experience on the Platform.
  • Bot-mitigation challenges: Certain interactive endpoints (the Generate-Site submission step on our marketing site, the public review form, and the pre-subscription AI editor) display a Cloudflare Turnstile challenge to confirm the request originates from a human. Cloudflare may set short-lived cookies and read browser characteristics in connection with the challenge. The challenge does not perform behavioural tracking and we do not receive a persistent identifier from Cloudflare.
  • Embedded Google Map: The Google Maps Embed shown on the Generate page (described in Section 2.9) may cause Google to set short-lived cookies on its own origin. Those cookies are governed by Google's privacy policy and are not accessible to our Platform.
  • Referral and partner attribution cookie: When you visit our marketing site through a partner's or an existing customer's referral link, we set an HTTP-only cookie containing only the referring code (no personal information) for up to 14 days, so that if you later subscribe we can credit the referrer. The cookie is scoped to our marketing site, performs no cross-site tracking, and referrers are never shown who subscribed through their link.

Analytics: Our self-hosted analytics system does not set cookies or use cross-site tracking identifiers. Section 6 describes what it records and confirms that no third-party analytics provider is used; Section 12.1 describes what Customers receive about visits to their own websites.

We do not use advertising cookies or cross-site tracking. Essential cookies cannot be disabled as they are required for the Platform to function; disabling them will prevent you from signing in. You can clear cookies at any time through your browser settings.

If we introduce non-essential analytics, advertising, or retargeting cookies in the future, we will update this Policy and, where required, request consent before those technologies are used.

12. Customer Websites Hosted Through PandAi7

PandAi7 hosts websites for Customers under Company-controlled domains, subdomains, or URL paths, including pandai7.com. When a visitor accesses a Customer Website hosted through PandAi7, we process technical information necessary to deliver, secure, maintain, and measure the website. This may include IP address, browser and device information, referrer, pages visited, timestamps, security logs, and similar technical data.

For website content, business communications, contact forms, booking requests, customer inquiries, reviews, menus, pricing, offers, and other business-specific interactions, the Customer is responsible for determining what information is collected from visitors and how it is used. In those cases, the Customer may act as the data controller, and PandAi7 may act as a service provider or processor providing hosting and platform services.

Visitors should review the legal pages and privacy notices published on the relevant Customer Website. Questions about the Customer’s products, services, business practices, refund policies, appointments, bookings, or visitor-submitted information should be directed to the Customer unless the issue concerns PandAi7’s platform, security, abuse, or hosting operations.

12.1 Customer Website Analytics

We may provide Customers with aggregated or limited analytics about visits to their Customer Websites, such as page views, referrers, approximate geography, browser type, device type, and visit timestamps. We do not provide Customers with full raw server logs unless required for security, legal, or support purposes.

13. Children's Privacy

Our Services are designed for businesses and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete such data promptly. If you believe that we have collected information from a child, please contact us.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or applicable law. Updated versions will be posted on this page with a revised "Last updated" date.

For material changes that significantly affect how we handle your personal data, we will notify you via email or through the Platform no less than thirty (30) days before the changes take effect. The updated Privacy Policy will apply from its effective date. Where required by law, we will request consent or provide additional notice before applying material changes to processing activities.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

M.M. KIMA DEVELOPMENT LTD

Operating as PandAi7

68 Spyrou Kyprianou, 4042 Germasogeia, Limassol, Cyprus

Contact: Contact form

For GDPR-related inquiries, you may also contact the Office of the Commissioner for Personal Data Protection in Cyprus at www.dataprotection.gov.cy.