Privacy Policy — Ama Work

Last updated: 2026-10-02

Ama Work ("the App") is published on Google Play by the developer Sono POS - Restaurant Solutions and operated by ATC GROUP COMPANY LIMITED ("we", "us"). The same app is listed on the Apple App Store as Tax Paper Tool (its name until September 2026) and runs on the web at tax.atcgroup.cc. This policy explains what data the App collects, how it is collected, what it is used for, and who it is shared with. It covers the iOS app, the Android app and the web version.

Data We Collect, and How

How We Use It

We do not use your data to train any AI model of ours, we do not sell it, we do not share it with data brokers, and the App contains no advertising or third-party analytics SDKs.

Third-Party AI Processing — and Your Consent

To perform OCR, classification, translation and chat, the following is sent through our backend to third-party AI providers — Google (Gemini) and OpenAI — for processing:

The App asks for your permission inside the App before any of this is sent, and states what is sent and to whom. If you decline, the App keeps working — scanning to your archive, document management, time tracking, shift planning, tasks and the team channel need no AI. You can grant or withdraw the permission at any time under Mehr → Einstellungen → KI; withdrawing stops any further transfer.

The following is never sent to an AI provider: your password, your bank transactions, tax ID, social-security number, IBAN, address, health data, internal team messages (apart from the single announcement or group-room message a reader taps to translate, described above), time-tracking records, location data, and your points or bonus. This holds for both assistants: each receives your own question and only the context described above, never what a colleague wrote — consent to use AI is given by each person for themselves, and nobody can give it on somebody else's behalf.

For account suggestions (Kontierungs-KI), the model receives selected invoice fields (supplier name, amounts, tax rates and line descriptions), the account catalogue, applicable accounting rules, confirmed examples and saved accounting instructions. It receives no chat or team-channel messages. Suggestions carry a reason and are held back from DATEV until a person confirms the account.

These providers process the data to generate a response, act as processors on our behalf under contractual terms that require a level of protection equivalent to this policy, and do not use it to serve you ads.

Ami Voice Guide

The web version has a guide, Ami, that walks you through setting the App up, step by step. You can type questions to it; questions you type go through our server to the AI providers named above, together with the texts of the setup steps. You can also talk to it. The voice is optional: it is off unless your employer switches it on, and it starts only after you have agreed to it yourself, in the App, where you can also withdraw that agreement at any time.

When you ask Ami in text about company data, it reads only company data you are allowed to see and sends it to the text AI model as KI-Chat does; the voice AI never receives that looked-up data.

For a command in the web Omnibox that needs an AI answer, the text model receives your command, the current page, up to eight recent command messages and, only for a business document you may read, a limited summary of that document; recognised simple commands stay on our server.

Ami keeps your typed sessions for up to the number of days your business chooses (0, 7, 30 or 90; 30 by default) so you can read them again; spoken turns are not stored; memories are saved only when you click “Remember” (or “Add” for a note you write yourself); only you can read or delete your sessions and memories.

Ami speichert Ihre getippten Sitzungen bis zu der vom Betrieb gewählten Zahl von Tagen (0, 7, 30 oder 90; standardmäßig 30), damit Sie sie wieder lesen können; gesprochene Beiträge werden nicht gespeichert; Erinnerungen werden nur gespeichert, wenn Sie auf „Merken“ klicken (oder für eigene Notizen auf „Hinzufügen“); nur Sie können Ihre Sitzungen und Erinnerungen lesen oder löschen.

Ami lưu các phiên bạn gõ tối đa số ngày do cơ sở chọn (0, 7, 30 hoặc 90; mặc định 30) để bạn xem lại; lượt nói không được lưu; ghi nhớ chỉ được lưu khi bạn bấm “Ghi nhớ” (hoặc “Thêm” với ghi chú tự viết); chỉ bạn được đọc hoặc xóa phiên và ghi nhớ của mình.

Ami looks up company data, reads the document you have open, or prepares an action for you only after you have agreed to that yourself, once, in the App — it asks the first time it needs it. You can withdraw that agreement at any time at the bottom of the Ami panel; without it, Ami answers only general questions. The Ami panel on the right side of the web version follows the same rules as the command field; if you talk to it, the voice rules below apply, and the voice AI never receives looked-up data.

Exercise Mode (Übungsmodus)

The web version also offers short exercises in which Ami leads you step by step. They run in a practice copy of your company (Übungsbetrieb) that belongs to you alone. It is filled with made-up example data — a demo branch, three invented employees and two shift templates — and never with the data of your real company. Nothing you do there leaves it: no push notifications, no e-mails, no logins, no bank or DATEV connections.

Questions About Your Own Payslip

If you ask the assistant about a payslip, it may receive de-identified text from your own current and previous payslip. Before transfer, the server removes tax ID, social-security number, IBAN, address, health data and internal personnel identifiers. It does not read team-chat messages or another employee's payslip. The assistant explains the figures supplied by the payroll program; it does not calculate tax, social-security contributions or net pay, and it does not give tax or legal advice.

This transfer happens only after you consent to the current AI disclosure. If you decline or withdraw consent, you can still open and download your payslips normally.

Automatic Checking of Task Photos (Automatische Prüfung von Aufgabenfotos)

Your employer can give a task an example photo of the expected result and, separately, switch on automatic checking for it. It is off unless your employer switches it on. When you hand in such a task, our server sends your proof photo, the example photo and the task's description to Google (Gemini) and asks whether the result matches. If you use the App in a language other than German, the name of that language is sent too, so that the reason can be written in it.

Points and Bonus (Punkte und Bonus)

Your employer can switch on points for tasks. It is off unless your employer switches it on.

In Germany, points, a leaderboard, deadline reminders and the automatic photo check may require the agreement of the works council under §87(1) no. 6 and nos. 10–11 BetrVG before they are switched on; that is your employer's decision to take, not something the App decides for them.

Bank Connections (Kontoauszüge)

A business can let the App read one of its bank accounts, so that its statements arrive without anybody uploading them. The account holder signs in to their own bank and confirms it; our servers never receive the bank password, PIN or TAN, and the App never initiates a payment. What our server receives is the list of booked transactions and the balance of the chosen account. Two providers carry this out, and the business chooses which one:

The business can disconnect the account in the App at any time, and the holder can withdraw the access at their bank. Transactions already imported stay in the business’s books.

Data Storage and Retention

Your documents, extracted text, account data and team messages are stored on our own servers in Europe (not in a third-party consumer cloud product). Tax documents are kept for as long as the statutory retention period your business is subject to requires. Internal team messages are deleted automatically after a period your employer chooses — one year by default, and configurable up to "keep indefinitely" — see Einstellungen → Chat-Aufbewahrung.

Read Marks in the Team Chat

The App can record, per person and per conversation, how far that person has read — a single timestamp per room, overwritten each time, not a log of visits and not a count of anything. It exists so the app can show you which conversations have something new in them.

Your employer controls two separate settings for this, under Einstellungen → Chat:

There is no record of when you opened the App, no "last online", no "is typing", and no count of how many messages anybody writes. Read marks are deleted together with the messages they refer to, under the retention period above. In Germany, switching on read receipts may require the agreement of the works council under §87 BetrVG; that is your employer's decision to take, not something the App decides for them.

Your Rights

You can delete any document from within the App at any time. You may request access to, correction of, or deletion of your personal data, and you may object to processing. Write to the address below: we act within 30 days and confirm when it is done. Deleting your account deletes the data associated with it.

Children

The App is a business tool for company employees and is not directed at children.

Contact

ATC GROUP COMPANY LIMITED, trading on Google Play as Sono POS - Restaurant Solutions (developer of Ama Work)
Email: anhoev@googlemail.com
Support: tax.atcgroup.cc/support · Terms of Service