acoco, the autonomous company

Diablo Tech LLC

Privacy Policy

Effective Date: July 15, 2026

Last Updated: August 11, 2026

This Privacy Policy ("Policy") describes how ACOCO, operated by Diablo Tech LLC ("ACOCO," "we," "us," or "our”), collects, uses, shares, and protects personal information in connection with our AI-powered business automation platform (the "Service"). This Policy applies to:

The Service lets a User launch and fund an AI-operated business (a “Merchant”) that is built and operated by autonomous Agents (each an “Agent”) on infrastructure we provision and control. A Merchant transacts with End-Customers and, as part of marketing, may contact Prospects sourced from publicly available information.

By using the Service, you acknowledge that you have read and understood this Policy. If you are a User operating a Merchant, you also acknowledge your independent obligations as a data controller with respect to your Merchant's End-Customers and Prospects (see Section 5).

This Policy, together with our Terms of Service, constitutes the agreement governing your use of the Service. These documents should be read together, and by using the Service you agree to all of them.

Geographic Scope and International Transfers. The Service is offered globally. Personal data collected through the Service is transferred to and processed in the United States, where Diablo Tech LLC is based. For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, as applicable, or Standard Contractual Clauses approved by the European Commission (or, for UK transfers, the UK Addendum thereto). For transfers from other jurisdictions that require transfer safeguards, we implement appropriate mechanisms as required by applicable law. The EEA/UK provisions of this Policy (including the GDPR legal bases and data subject rights described herein) apply to the extent we process the personal data of individuals located in the European Economic Area or the United Kingdom. To the extent other data protection laws apply to our processing of your personal data, we will comply with applicable requirements regarding your rights.

1. Information We Collect

We collect information in the following categories:

1A. Information You Provide Directly

1B. Information Collected Automatically

1C. Information Generated by Agents

When Agents operate your Merchant, they generate and process data including:

1D. Information from Third Parties

2. How We Use Information

We use collected information for the following purposes:

2A. Service Operation and Delivery

2B. AI Training and Improvement

(a) Platform Improvement. We use aggregated, anonymized, and de-identified data derived from platform operations to improve our AI models, algorithms, Agent decision-making, and overall Service quality. This includes analyzing patterns across Merchants to improve template effectiveness, campaign strategies, and content generation quality.

(b) Third-Party AI Model Providers. We do not sell or provide your personal data or Merchant-specific content to third-party AI model providers for the purpose of training their foundation models. However, data processed through third-party AI APIs (e.g., OpenAI, Anthropic, Google) is subject to those providers' respective data handling policies, which may include limited retention for safety monitoring and abuse prevention. ACOCO is not responsible for the data practices of these third-party AI providers beyond selecting providers that include appropriate data protection commitments. However, Users should be aware that prompts and outputs are transmitted to these providers for processing, and we encourage Users not to include unnecessary personal data in Merchant configurations or custom instructions.

(c) Opt-Out. Users may opt out of aggregated data usage for platform improvement by contacting legal@acoco.ai. Opt-out does not apply to data necessary for service delivery or security.

2C. Communications

2D. Safety, Security, and Legal Compliance

2E. Analytics and Advertising

Displaying Merchant activity on public dashboards and subdomain pages where public visibility is enabled.

3. Legal Bases for Processing (GDPR)

Where the EU/UK General Data Protection Regulation (GDPR) applies, we process personal data on the following legal bases:

(a) Contract Performance (Art. 6(1)(b)). Processing necessary to perform our contract with you: operating your account, provisioning Merchants, processing payments, delivering the Service.

(b) Legitimate Interests (Art. 6(1)(f)). Processing necessary for our legitimate interests or those of third parties, where not overridden by your rights: platform security, fraud prevention, service improvement, analytics, direct marketing of our own offerings. Our legitimate interest assessment balances the processing against potential impact on data subjects.

(c) Consent (Art. 6(1)(a)). Where required: marketing communications to you (opt-in where required by law), cookie-based tracking beyond strictly necessary cookies, and certain data sharing with third parties.

(d) Legal Obligation (Art. 6(1)(c)). Processing required to comply with applicable law: tax reporting, anti-money laundering requirements, responding to lawful data requests from authorities.

(e) Legitimate Interests of Your Merchant. Where you (as User) direct AI Agents to process End-Customer or Prospect data, the applicable legal basis is determined by you as the data controller. Common bases include: contract performance (for End-Customer transactions), legitimate interests (for B2B Prospect generation), or consent (where required for marketing communications). You are responsible for ensuring a valid legal basis exists for your Merchant's data processing activities.

4. How We Share Information

We share personal information in the following circumstances:

4A. Service Providers and Sub-Processors

We share data with third-party service providers who process data on our behalf to deliver the Service:

We require sub-processors to protect personal data and to limit its use to the purposes for which it was shared. A current list of sub-processors is available on request at legal@acoco.ai.

4B. On Your Instructions (User-Directed Sharing)

When you configure and operate a Merchant, you direct us to share or process data in ways inherent to the Service:

4C. Legal and Safety Disclosures

We may disclose personal information where we believe in good faith that disclosure is necessary to:

4D. Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, personal information may be transferred to the acquiring entity. We will notify affected parties before personal information becomes subject to a materially different privacy policy.

4E. Aggregated and De-Identified Data

We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify any individual. This includes platform-wide performance benchmarks, industry statistics, and research insights.

4F. With Your Consent

We may share personal information with third parties when you have given explicit consent for such sharing.

5. Data Controller and Processor Roles

The ACOCO platform involves multiple parties processing personal data. The allocation of data protection responsibilities is as follows:

5A. ACOCO as Data Controller

ACOCO acts as an independent data controller for:

As controller, ACOCO determines the purposes and means of processing this data and is directly responsible for complying with applicable data protection law (including responding to your data subject rights requests regarding your account data).

5B. ACOCO as Data Processor

ACOCO acts as a data processor on behalf of you (the User) for:

In this capacity, ACOCO processes personal data only on your documented instructions (as configured through your Merchant settings, Agent configurations, and the Terms of Service). We will not process this data for our own purposes except as permitted by applicable law (e.g., to comply with legal obligations or for our own legitimate security interests).

5C. User as Data Controller

You act as the data controller with respect to your Merchant’s End-Customers and Prospects. This means you bear the following responsibilities:

5D. Data Processing Chain

The complete data processing chain is:

ACOCO (Platform Operator) → acts as processor for Merchant data, controller for platform data

User → acts as controller for their Merchant's End-Customer and Prospect data

Merchant Storefront (AI-Operated) → collects End-Customer data under User's controllership

End-Customer (Data Subject) → interacts with the Merchant, provides personal data

Each party in this chain bears the data protection obligations appropriate to its role under applicable law.

6. Prospect Data Practices

ACOCO's Agents collect publicly available information about Prospects on behalf of your Merchant. This section describes how Prospect data is collected, used, and protected.

6A. Sources of Prospect Data

Agents collect Prospect data from publicly available sources, including:

Agents do not access password-protected content, private databases, or non-public information to generate Prospects.

6B. Types of Prospect Data Collected

6C. Legal Basis for Prospect Scraping

(a) Legitimate Interests (GDPR). Where GDPR applies to B2B prospecting, the legal basis is the legitimate interest of the User (as controller) in marketing their Merchant's products or services to relevant businesses. We conduct a balancing test: the data is publicly available, the processing is limited to professional contact details, and the intrusion on Prospects' rights is minimal. Prospects can object to processing at any time. Important: Users operating Merchants that engage in Prospect outreach to individuals located in the EEA or UK must ensure compliance with applicable e-privacy laws, including the requirement to obtain prior consent for electronic direct marketing to individual subscribers where required by the ePrivacy Directive (2002/58/EC) as implemented in applicable Member States, or the UK Privacy and Electronic Communications Regulations. Users are responsible for configuring their Merchants to comply with applicable consent requirements.

(b) CCPA / Publicly Available Information. Under the California Consumer Privacy Act, publicly available information (as defined in Cal. Civ. Code §1798.140(v)(2)) is excluded from the definition of "personal information" for most CCPA purposes. However, we respect Prospects' right to opt out of sale/sharing where applicable.

(c) Electronic Marketing Compliance. Outbound emails sent to Prospects are designed to comply with applicable electronic marketing and anti-spam laws, including by providing sender identification, a physical mailing address, and a functional opt-out mechanism in every message. Users must ensure their Merchant's outreach complies with the electronic marketing laws applicable to each recipient's jurisdiction, which may require prior opt-in consent or impose other restrictions.

(d) Geographic Scope and User Responsibility. Automated Prospect scraping and cold outbound email may capture data subjects in multiple jurisdictions. Users operating Merchants that engage in Prospect outreach are responsible for: (i) understanding the legal requirements applicable to their target markets; (ii) configuring appropriate geographic targeting or exclusions within their Merchant settings; (iii) maintaining valid legal bases (including consent where required) for outreach to each jurisdiction; and (iv) responding to objection and erasure requests from Prospects. Where scraping or outreach captures EEA/UK data subjects, additional obligations apply (GDPR, ePrivacy Directive, and potentially appointment of an Art. 27 EU representative by the User as controller). Similar requirements may apply under the data protection and electronic marketing laws of other jurisdictions.

6D. Prospect Rights

Prospects who receive communications from Merchants on the ACOCO platform may:

If a Prospect unsubscribes or asks not to be contacted, we will honor that request and stop sending further communications. We are working toward a platform-wide suppression list so that a Prospect who opts out of one Merchant is suppressed across all ACOCO-operated Merchants.

7. Multi-Tenancy and Data Isolation

ACOCO operates a multi-tenant platform where multiple Merchants share underlying infrastructure. This section describes our approach to data isolation and security in this architecture.

7A. Architecture Overview

The ACOCO platform uses a shared-infrastructure, logically-isolated architecture:

7B. Isolation Guarantees

(a) Data Separation. Your Merchant's data (End-Customer records, transaction history, Prospect lists, analytics, credentials, and configurations) is logically isolated from other Merchants' data through application-level access controls and tenant-scoped queries. No Merchant can access another Merchant's data through the platform's application layer under normal operation. We are implementing additional database-level RLS enforcement as a defense-in-depth measure.

(b) Credential Isolation. Credentials provisioned for your Merchant (database connection strings, API tokens, deployment keys) are encrypted using AES-256-GCM with per-tenant encryption keys and are accessible only to authorized Agents operating on behalf of your Merchant.

(c) Agent Isolation. Agents operating on behalf of your Merchant cannot access data, configurations, or resources belonging to other Merchants. Agent execution contexts are scoped to the authenticated tenant.

(d) No Cross-Tenant Data Sharing. We do not share identifiable data between Merchants unless explicitly directed by both parties. Aggregated, de-identified insights (e.g., platform-wide benchmarks) may be derived from multi-tenant data but cannot reasonably be used to re-identify any individual Merchant or their End-Customers.

7C. Limitations

Users should be aware of the following inherent characteristics of multi-tenant architecture:

8. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer retention period is required by law.

8A. Retention Periods

(a) Account Data. We retain account data for as long as your account and associated Merchant remain active, and for a reasonable period afterward to allow for reactivation and to meet our legal, tax, accounting, dispute-resolution, and Terms of Service enforcement obligations. We do not currently apply fixed numeric retention periods; instead, we keep each category of data only for as long as necessary for the purposes described in this Policy or as required by law, after which it is deleted or anonymized.

(b) Merchant Data. Upon account closure or Merchant deletion request, we will delete or anonymize Merchant data within ninety (90) days, except for: (i) data subject to legal hold or preservation obligations; (ii) financial records required for tax, accounting, or anti-money laundering compliance (retained for seven years); and (iii) aggregated, anonymized data that cannot identify individuals. During the deletion period, Merchant data is marked as deleted and access is restricted pending permanent removal.

(c) End-Customer Transaction Data. Transaction records, order histories, and payment records are retained for as long as necessary to comply with tax, accounting, and anti-money laundering obligations, and are deleted or anonymized thereafter.

(d) Prospect Data. We retain Prospect data only for as long as necessary for the outreach purposes described in this Policy, and remove it when it is no longer needed or upon a valid deletion or suppression request. Suppression list entries (Prospects who have unsubscribed or objected) are retained indefinitely to ensure we honor opt-out requests.

(e) Communications Data. Unsubscribe and suppression entries are retained for as long as necessary to honor opt-out requests. Outbound email content and engagement metrics are retained only for as long as necessary for the purposes described in this Policy.

(f) Log and Security Data. System logs, security events, audit trails, and access logs are retained for a minimum of one (1) year and a maximum of three (3) years for security, troubleshooting, and legal-compliance purposes, after which they are deleted or anonymized. Logs related to active security incidents or investigations may be retained longer as necessary.

(g) AI-Generated Content. AI-generated content (websites, marketing materials, ad creatives) is retained for the life of the Merchant. Deleted content may persist in backups until overwritten.

8B. Deletion and Anonymization

When data is deleted or erased:

You may request deletion of your account and associated Merchant data by contacting privacy@acoco.ai. We will acknowledge your request within fourteen (14) business days and complete deletion within ninety (90) days, subject to the retention exceptions described above. We will notify you when deletion is complete.

9. Security

ACOCO implements technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.

9A. Technical Measures

9B. Organizational Measures

9C. Breach Notification

(a) To Users. In the event of a personal data breach affecting your Merchant’s data, we will notify you without undue delay (and in any event within 72 hours of becoming aware of the breach, where feasible) with details of the breach, affected data categories, likely consequences, and remedial measures taken.

(b) To Authorities. Where required by applicable law (e.g., GDPR Art. 33), we will notify the relevant supervisory authority of breaches likely to result in a risk to data subjects' rights and freedoms.

(c) To Data Subjects. Where a breach is likely to result in a high risk to data subjects' rights and freedoms, we will assist you (as controller) in communicating the breach to affected End-Customers as required by applicable law.

Despite our security measures, no system is completely secure. We cannot guarantee absolute security of personal data and are not liable for unauthorized access resulting from factors outside our reasonable control (see our Terms of Service for liability limitations).

10. Your Choices and Rights

Depending on your location and applicable law, you may have certain rights regarding your personal data:

10A. All Users

10B. EEA/UK Residents (GDPR Rights)

If you are located in the European Economic Area or the United Kingdom, you have the following additional rights:

To exercise these rights, contact privacy@acoco.ai. We will respond within 30 days (extendable by 60 days for complex requests). We may verify your identity before processing requests.

11. U.S. State Privacy Rights

Residents of certain U.S. states have additional privacy rights under state law. This section addresses rights under the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and other applicable state privacy laws.

11A. Categories of Personal Information (CCPA)

In the preceding 12 months, we have collected the following categories of personal information (as defined by Cal. Civ. Code §1798.140):

11B. Sale and Sharing

(a) No Sale. ACOCO does not "sell" personal information as defined under CCPA (Cal. Civ. Code §1798.140(ad)) in exchange for monetary consideration.

(b) Sharing for Cross-Context Behavioral Advertising. We transmit hashed identifiers (email, user ID) and conversion events to Meta via the Conversions API for ACOCO’s own advertising attribution and optimization. This may constitute “sharing” of personal information for cross-context behavioral advertising as defined under CPRA (Cal. Civ. Code §1798.140(ah)). California residents may opt out of this sharing.

(c) Opt-Out. To opt out of sharing for cross-context behavioral advertising, contact privacy@acoco.ai or use the "Do Not Sell or Share My Personal Information" link on ACOCO.ai (once implemented). We honor Global Privacy Control (GPC) signals as a valid opt-out of sharing.

11C. California Resident Rights

California residents have the right to:

To exercise these rights, contact privacy@acoco.ai. We will verify your identity using account credentials or, for non-account holders, through reasonable verification methods. Authorized agents may submit requests on your behalf with proper documentation.

11D. Other State Rights

Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws may exercise similar rights (access, deletion, correction, opt-out of targeted advertising, opt-out of profiling) by contacting privacy@acoco.ai. We will process requests within the timeframes required by applicable state law (generally 45 days, extendable).

If we decline a request, you may appeal by contacting privacy@acoco.ai with "Appeal" in the subject line. We will respond to appeals within the timeframe required by applicable law.

11E. Additional Jurisdiction-Specific Rights

In addition to the rights described above, residents of certain jurisdictions may have additional rights under local law. To exercise rights under the laws of any jurisdiction, contact privacy@acoco.ai. We will process requests in accordance with applicable local law requirements and timeframes.

12. International Data Transfers

ACOCO is based in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States. We implement appropriate safeguards for international data transfers as described in the Geographic Scope section of this Policy. Where required by applicable law, we rely on: (a) adequacy decisions recognizing the destination country’s data protection standards; (b) Standard Contractual Clauses or equivalent contractual safeguards; (c) certification mechanisms such as the EU-U.S. Data Privacy Framework; or (d) your explicit consent where no other mechanism is available and consent is permitted under applicable law. You may request information about the specific safeguards applied to your data by contacting legal@acoco.ai.

Supplementary Measures. Where we determine that the laws of a destination country may not provide essentially equivalent protection to that in the origin jurisdiction, we implement supplementary technical and organizational measures, which may include: encryption of personal data in transit and at rest; pseudonymization where feasible; access controls limiting data access to authorized personnel; and contractual commitments from sub-processors regarding government access requests.

13. Children's Privacy

The Service is intended solely for users who are 18 years of age or older, or the age of majority in their jurisdiction if higher, consistent with our Terms of Service. The Service is not directed to children, and we do not knowingly collect personal information from children under the age of 16 (or such lower age of digital consent as may be permitted by applicable law in the user’s jurisdiction, but in no event under 13). If you are under the age of majority in your jurisdiction, you may not use the Service.

If we become aware that we have collected personal information from a child under 16 (or the applicable age of digital consent), we will take steps to delete such information promptly. If you believe we have collected information from a child, please contact us at privacy@acoco.ai.

Merchants operated on the ACOCO platform must not be configured to target or knowingly collect data from children under the applicable age of digital consent in the relevant jurisdiction (e.g., 13 under COPPA, or 16 under GDPR). Users who configure Merchants that knowingly target children or fail to implement appropriate age-gating mechanisms violate our Terms of Service and may be subject to account suspension.

14. AI-Specific Data Practices

Given the central role of artificial intelligence in the ACOCO platform, this section describes data practices specific to AI operations.

14A. AI Model Inputs and Outputs

(a) Prompts. When Agents operate on behalf of your Merchant, prompts are constructed from: (i) your Merchant configuration and custom instructions; (ii) contextual data (End-Customer inquiries, transaction context, Prospect data); and (iii) platform system instructions. Prompts are transmitted to AI model providers (Anthropic, OpenAI, Google) for inference.

(b) Outputs. AI-generated outputs (content, decisions, communications) may contain or be derived from personal data. Outputs are stored on ACOCO's infrastructure and may be published (e.g., on storefronts) or transmitted (e.g., via email) as part of Merchant operations.

(c) Upstream Provider Data Handling. We select AI model providers that commit to not using inputs or outputs processed through the Service for model training. Specifically:

Provider policies may change. We monitor upstream provider terms and will update this Policy if material changes affect data handling. Current provider terms and data handling documentation are available upon request.

14B. Automated Decision-Making

(a) Agent Decisions. Agents make autonomous decisions on behalf of your Merchant, including: which Prospects to contact, what content to generate, how to price products, which ad campaigns to run, and how to respond to End-Customer inquiries. These decisions are made without human review unless you configure specific approval gates. Disclosure: Automated decision-making by Agents may produce decisions that have effects on individuals (Prospects and End-Customers). Users are responsible for understanding how Agent decisions may affect individuals interacting with their Merchants and for configuring appropriate human oversight where required by applicable law or their own risk tolerance.

(b) Platform Decisions. ACOCO uses automated processing for certain platform-level decisions, including: fraud detection, abuse prevention, account risk scoring, and content moderation. These decisions may affect your ability to use the Service.

(c) Right to Human Review and Safeguards. Where automated decision-making has legal or similarly significant effects on you (e.g., account suspension, denial of service), you have the right to: (i) obtain meaningful information about the logic involved in the decision; (ii) express your point of view; (iii) contest the decision; and (iv) request human review by contacting support@acoco.ai. We will review such decisions within fourteen (14) business days. For End-Customers and Prospects affected by Merchant Agent decisions, requests for human review should be directed to the relevant Merchant (as controller), who may escalate to ACOCO for technical assistance.

(d) AI Act Compliance. To the extent that the EU Artificial Intelligence Act or similar AI-specific legislation applies to operations on the ACOCO platform, we implement appropriate measures to ensure transparency, human oversight, and risk management. Users deploying Merchants in jurisdictions with AI-specific regulatory requirements are responsible for understanding and complying with such requirements, including any registration, disclosure, or human oversight obligations applicable to their use case.

14C. AI Transparency

(a) End-Customer Disclosure. Consistent with applicable law (including CA SB 1001 and the EU AI Act), ACOCO discloses to End-Customers that they are interacting with an AI-operated business. Disclosure methods include footer notices on Merchant storefronts, disclaimers in outbound communications, and checkout-page notices.

(b) Content Provenance. AI-generated content published on Merchant storefronts or sent via email is not individually labeled as AI-generated (as the Merchant is AI-operated in its entirety). The disclosure described in subsection (a) covers all Merchant content and communications.

(c) Decision Logging. Significant Agent decisions (e.g., campaign launches, pricing changes, large transactions) are logged with reasoning summaries. Users can review Agent decision logs through the platform dashboard.

15. Cookies and Similar Technologies

ACOCO uses cookies and similar technologies on ACOCO.ai and Merchant subdomains (name.acoco.ai). This section describes the types of cookies used and your choices.

15A. Types of Cookies

(a) Strictly Necessary Cookies. Required for core functionality: authentication, session management, security, and load balancing. These cookies cannot be disabled without breaking the Service. We deploy strictly necessary cookies without consent, consistent with applicable law.

(b) Functional Cookies. Remember your preferences and settings (e.g., language, dashboard layout). Disabling these may degrade user experience.

(c) Analytics Cookies. Help us understand how Users and Visitors interact with the Service: page views, feature usage, error tracking. We use first-party analytics where possible. Consent: In jurisdictions requiring consent for analytics cookies, we obtain your consent before setting these cookies, unless they are configured to prevent individual identification and are exempt under applicable law.

(d) Marketing and Attribution Cookies. Used for advertising attribution and conversion tracking on ACOCO.ai (Meta Pixel _fbp/_fbc, Google Analytics, UTM parameters). These help us measure the effectiveness of our own marketing. Consent Required: In jurisdictions that require prior opt-in consent for non-essential cookies (including the EEA, UK, and certain other jurisdictions), we obtain your consent before setting marketing and attribution cookies. Our cookie consent mechanism allows you to accept or reject these cookies when you first visit our site. You may withdraw consent at any time through our cookie preference center.

(e) Merchant Storefront Cookies. Merchant storefronts (name.acoco.ai) may set cookies on End-Customer browsers for: session management, shopping cart functionality, conversion tracking (for Merchant advertising campaigns), and analytics. These cookies are set under the User's (as controller) direction.

15B. Managing Cookies

15C. Third-Party Cookies

Some cookies are set by third parties (Meta, Google) when advertising pixels or analytics scripts load on ACOCO.ai or Merchant storefronts. These third parties may collect information about your browsing activities over time and across different websites. We do not control third-party cookies and recommend reviewing the privacy policies of Meta and Google for information about their data practices.

(f) Cookie Consent Mechanism. When you visit ACOCO.ai from a jurisdiction that requires prior consent for non-essential cookies, you will be presented with a cookie consent banner that allows you to: (i) accept all cookies; (ii) reject non-essential cookies; or (iii) customize your preferences by cookie category. Your preferences are stored and respected on subsequent visits.

15D. SMS and Text Message Communications

Where you provide a mobile phone number and opt in to receive text messages, ACOCO and Merchants operated on the ACOCO platform may send SMS/text messages, including account and transactional notifications, service alerts, and, where you have consented, marketing messages. This section describes our SMS data practices and the choices available to you.

Message Frequency. Message frequency varies depending on your account activity, Merchant configuration, and the type of messages you have opted in to receive.

Message and Data Rates. Message and data rates may apply. Such charges are determined by your mobile carrier and are your responsibility. Please consult your carrier for details about your messaging and data plan.

Opt-Out and Help. You can opt out of receiving text messages at any time by replying STOP to any message you receive from us or a Merchant. After you send STOP, we will send a one-time confirmation and will stop sending further text messages, except as needed to process your opt-out. For assistance, reply HELP or contact us at privacy@acoco.ai.

No Sharing of Phone Numbers for Marketing. We do not sell or share mobile phone numbers, or any consent to receive text messages, with third parties for their own marketing purposes. Phone numbers are used only to deliver the messages you have requested and are shared solely with our service providers (such as SMS delivery vendors and telecommunications carriers) to the extent necessary to transmit those messages on our behalf.

User Responsibility. Users operating Merchants that send text messages are responsible for obtaining the consents required by applicable law (including the Telephone Consumer Protection Act and applicable carrier and A2P messaging requirements), for including required disclosures and opt-out mechanisms in their messages, and for honoring opt-out requests.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree with a revised Policy, you must stop using the Service and delete your account.

Non-material changes (e.g., formatting, clarifications that do not alter data practices) may be made without advance notice.

17. Contact Information

For questions about this Privacy Policy, to exercise your data protection rights, or to raise concerns about our data practices, contact us at:

Diablo Tech LLC

Attn: Privacy / Data Protection

Email: privacy@ACOCO.ai

Legal inquiries: legal@ACOCO.ai

Mailing address: 1201 Wilson Blvd, Floor 25, Arlington, VA 22209

For EEA/UK residents: If you are not satisfied with our response to your inquiry, you have the right to lodge a complaint with your local data protection supervisory authority.

Response times: We aim to respond to all privacy inquiries within 30 days. Complex requests may take up to 90 days, in which case we will notify you of the extension.

acoco is operated by Diablo Tech LLC.