Privacy Policy
Last updated:October 28, 2025.
At 2aT.ai (“Company,” “we,” “our,” or “us”), we respect your privacy and are committed to protecting your personal data.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website,
create an account, or use our AI-powered B2B sourcing and procurement platform (collectively, the “Service”).
By using the Service, you agree to this Privacy Policy. If you do not agree, please discontinue use.
1. Who We Are
2aT.ai is an AI-powered B2B marketplace operated by 2aT™, a company registered in Delaware, USA.
We enable clients and providers to discover and offer business services using AI-driven analysis and semantic search.
2. Information We Collect
2.1. Information You Provide
We collect personal and business information that you voluntarily provide when using the Service, such as:
- Name, job title, and contact details (email, phone number, etc.)
- Company name, website, industry, and role
- Case studies, descriptions, or other content you submit
- Account credentials (username, password)
- Feedback or support messages
2.2. Information We Collect Automatically
When you access or use the Service, we automatically collect certain technical and usage information, including:
- Log data:IP address, browser type and version, operating system, device identifiers, and access timestamps.
- Usage data:pages viewed, search queries, clicks, referring/exit pages, and interaction timestamps.
- Cookies and analytics:we use cookies, web beacons, and similar technologies to analyze and improve our Service performance.
Analytics and Behavior Tracking Tools
We use third-party analytics and session-recording services to understand how users interact with the platform and to improve user experience. These include:
- Google Analytics– aggregated statistics on site usage, traffic sources, and device data. IPs anonymized in the EU.
- Hotjar– anonymous behavioral data such as clicks, scrolls, heatmaps, and session replays.
- Similar tools– e.g., Microsoft Clarity or Mixpanel for product improvement.
Analytics providers act as our data processors under GDPR and are bound by strict confidentiality and data-processing agreements.
2.3. Information from Public and Third-Party Sources
2aT.ai may collect and process publicly available business data, including:
- Company websites, directories, and verified professional databases
- Case studies or references available online
- Industry databases and other lawful data providers
Such data may be used to create or enrich provider profiles labeled as “Public Source” or “AI-Based.”
3. How We Use Your Information
We process personal and company data to:
- Operate, maintain, and improve the Service
- Enable clients to discover and evaluate providers
- Generate AI-based insights, similarity matches, and provider analyses
- Display provider profiles and case studies on the platform
- Communicate with users regarding updates, security, and account matters
- Ensure compliance with legal and regulatory requirements
- Detect, prevent, and mitigate fraudulent or abusive activity
4. Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA), our processing of personal data is based on:
- Contractual necessity:To provide the Service to registered users
- Legitimate interest:To process publicly available business data and improve sourcing accuracy
- Consent:For optional marketing communications or cookies
- Legal obligation:To comply with applicable laws or regulatory requests
5. Data Sharing and Disclosure
We may share your data with:
- Service providers assisting with hosting, analytics, or communication tools
- Business partners involved in platform improvement and security operations
- Legal authorities, if required to comply with applicable laws
- Buyers or investors, in connection with corporate transactions (merger, acquisition, or sale)
We do notsell or rent personal information to third parties.
6. AI-Generated and Analytical Content
2aT.ai uses artificial intelligence modelsto:
- Summarize, categorize, and evaluate provider information
- Generate analytical scores (Trustability, Formal Requirements Fit, Cultural Fit, etc.)
- Produce text summaries or recommendations for clients
AI-generated content is derived from existing data and algorithms. Outputs may include inferred or reformulated dataand are provided for informational purposes only.
7. Data Retention
We retain data for as long as necessary to:
- Provide the Service
- Comply with legal obligations
- Resolve disputes and enforce agreements
When data is no longer needed, it is securely deleted, anonymized, or archived.
8. International Data Transfers
Your information may be transferred to and processed in countries outside your own, including the United States and the European Union. When data is transferred internationally, we apply safeguards such as:
- Standard Contractual Clauses (SCCs) for EU users
- Adequacy decisions recognized by the European Commission
- Contractual and technical measures to ensure equivalent protection
9. Your Rights
Depending on your jurisdiction, you have the following rights:
- Under GDPR (EU/EEA users):
- Access your personal data
- Correct inaccurate or incomplete data
- Request deletion (“right to be forgotten”)
- Restrict or object to certain processing
- Port your data to another service
- Withdraw consent at any time (where applicable)
- Under CCPA/CPRA (California users):
- Request disclosure of collected personal information
- Request deletion of personal information
- Opt out of data sale or sharing (we do not sell personal data)
- Non-discrimination for exercising privacy rights
You can exercise these rights by contacting us at support@2aT.ai
10. Cookies and Tracking Technologies
2aT.ai uses cookies and similar technologies to operate, secure, and improve the Service.
When you first visit our website, you will see a cookie consent bannerthat allows you to:
- Accept all cookies
- Reject non-essential cookies
- Customize preferencesby category
You may change or withdraw your consent at any time via the “Cookie Preferences” link available on our site footer.
10.1 Types of Cookies We Use
Essential Cookies
- Required for the basic operation and security of the platform.
- Enable functions such as authentication, load balancing, and session management.
- These cookies cannot be disabled in our systems.
Analytics and Performance Cookies
- Help us understand how users interact with 2aT.ai and improve the platform experience.
- Use tools like Google Analytics, Hotjar, and similar platforms.
- May collect anonymized IP, device type, and behavior patterns.
- Used exclusively for internal analysis and product optimization.
Functional Cookies
- Remember your choices and preferences (language, region, display settings).
- Enhance usability and personalization without cross-site tracking.
Marketing and Personalization Cookies
- Used only if you consent to receive marketing or promotional materials.
- Help us measure campaign effectiveness and personalize content.
- 2aT.ai does not allow third-party advertising networks to track users across unrelated sites.
10.2 Third-Party Cookies
- Some cookies are placed by third-party service providers acting on our behalf (e.g., analytics providers or security tools).
- These third parties are contractually bound to process data solely according to our instructions and in compliance with GDPR and CCPA/CPRA.
10.3 Managing and Withdrawing Consent
You can:
- Adjust cookie settings anytime via the "Cookie Preferences" panel on our website.
- Configure your browser to block or delete cookies (note: essential cookies may be required for the platform to work correctly).
- Use global opt-out tools like YourOnlineChoices.eu (EU users) or Network Advertising Initiative (US users).
10.4 Retention of Cookie Data
- Cookie lifespans vary by type and purpose:
- Session cookies expire when you close your browser.
- Persistent cookies remain stored for up to 12 months, unless deleted earlier.
- All cookie data is periodically reviewed and deleted when no longer required.
11. Data Security
We implement technical and organizational measures to protect your information from unauthorized access, disclosure, or loss, including:
- Data encryption in transit and at rest
- Role-based access controls
- Regular security audits and vulnerability testing
However, no online system is fully secure, and we cannot guarantee absolute security.
12. Children's Privacy
- 2aT.ai is intended for business professionals aged 18 and older.
- We do not knowingly collect or process data from children.
- If you believe a minor has provided us information, please contact support@2at.ai, and we will delete it promptly.
13. Changes to this Policy
- We may update this Privacy Policy periodically.
- The "Last Updated" date reflects the most recent version.
- Significant changes will be communicated via email or a notice on the platform.
14. Contact Information
If you have questions or requests regarding this Privacy Policy or your data, contact us at:
Email: support@2at.ai
15. Compliance and Effective Jurisdiction
- This Policy is governed by the laws of the State of Delaware, USA, and complies with the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA/CPRA).
- For EU residents, disputes may be referred to the competent data protection authority in your country.