1. Who is responsible
My Companies AI is an unincorporated business trading as My Companies AI. Contact privacy@mycompaniesai.com about personal information and privacy rights, help@mycompaniesai.com for customer support, or legal@mycompaniesai.com for formal contractual matters. Primary application hosting is in Scotland, UK.
We are a controller for information used to administer our business, accounts, enquiries, billing and service security. Your employer or other organisation is normally the controller of personal data in its uploaded knowledge and workplace use of the assistant; we process that data on its instructions under our DPA. If the organisation acts for another controller, it must have authority to give us instructions. Ask your organisation for its own privacy notice.
2. Information we collect
- Account and organisation details: names, work email addresses, company names, website, country, timezone, roles, permissions, invitations and subscription details.
- Authentication and security records: password hashes, encrypted MFA information, hashed recovery and session tokens, sign-in events, device/browser information and network addresses when supplied by our trusted network services.
- Customer content: document originals and versions, extracted text, search representations, questions, replies, conversation history, feedback, knowledge gaps and approval/access records.
- Usage and billing records: question counters, AI-processing usage estimates, plan and promotion records, payment-provider identifiers, invoices and payment status. Full card details are handled by Stripe when payment services are used.
- Communications: support and legal requests, information you include in them, and verification, invitation, account-recovery and service emails.
We receive information directly from you, from your organisation and its administrators, from other authorised users where they upload or share it, and from service providers involved in security, email and payments. Do not send more personal data than is needed. Account and security details necessary to provide access are required; optional enquiry details are your choice.
3. Purposes and lawful bases
| Purpose | UK / EU GDPR basis |
|---|---|
| Create accounts, provide the subscription and answer pre-contract enquiries | Contract where you personally contract with us; otherwise legitimate interests in administering the Customer's service and communicating with its representatives. |
| Authentication, fraud prevention, misuse investigation, fair-use enforcement and service recovery | Legitimate interests in a secure, reliable service and protecting customers; legal obligation where a specific requirement applies. |
| Billing, accounting and legal claims | Contract, applicable accounting/tax obligations, and legitimate interests in establishing or defending claims, as relevant. |
| Support, necessary service notices and handling rights requests | Contract or legitimate interests in resolving enquiries; legal obligation for applicable privacy requests. |
| Optional marketing or non-essential tracking, if introduced | Consent where required, obtained separately before use; otherwise only a specifically identified lawful basis allowed by applicable law. |
We weigh legitimate interests against individuals' rights and reasonable expectations. You may object to processing on that basis. We do not treat a company's subscription agreement as the lawful basis for every employee's personal information. The Customer must determine its own lawful bases, provide notices and obtain any necessary permissions for workplace content and use.
4. AI processing and human access
Approved knowledge relevant to an authorised question is retrieved to help generate a reply. Document text may also be sent for search indexing during analysis before publication. An unpublished document is excluded from answers, but upload and analysis still involve processing. Questions, relevant passages and generated replies can contain personal data.
We use OpenAI's API for AI processing. OpenAI states that API data is not used for model training by default unless the account holder opts in. We do not use Customer content to train a shared model for our own purposes. OpenAI may retain content in abuse-monitoring logs, normally for up to 30 days, with exceptions for legal or safety needs. We do not promise zero provider retention. See OpenAI's data controls.
Authorised Customer administrators and managers have the access associated with their roles and settings. Authorised service operators may access data where necessary for support, security, recovery or legal compliance. Support access is not an unrestricted right to browse your content. The assistant does not itself make legally binding decisions about people. The Customer must not use generated answers as a substitute for meaningful human review.
6. Retention and deletion
We retain information according to its purpose, the Customer's instructions, the need to run and secure the account, applicable record-keeping duties and the time needed to resolve a specific dispute. Expiry of a session, trial or subscription does not automatically erase all stored records.
- Documents, versions and conversations remain while needed for the workspace, until authorised deletion or closure instructions are carried out. Conversation-retention settings are handled through an operator-managed retention process; changing a setting does not itself trigger an automatic purge. Contact support to arrange and confirm a retention action.
- Routine local backups use a 14-day rolling schedule. Separate migration or deployment recovery copies can remain longer while needed to verify a safe recovery or resolve an incident. They are not an indefinite archive entitlement. A deletion request must also address those copies; backup data is restricted to recovery purposes and deletion instructions must be reapplied after restoration.
- Account, security, audit, question-count and spending records can remain after content deletion where still necessary for billing, abuse prevention, accountability or legal claims. Removing a conversation does not reset an allowance. We assess whether identifiers can be removed and do not retain records merely because storage is available.
- Queued account-email content is removed from the application after successful sending or cancellation; failed payloads are cleared under the queue's expiry rules. Delivery metadata and the email provider's own logs and backups have separate retention periods. Information sent to support or legal mailboxes remains only as needed to handle the matter and any justified follow-up.
Request a record-specific retention explanation or deletion at privacy@mycompaniesai.com. Where law requires retention, we will explain the relevant reason and restrict further use. The DPA provides additional return and deletion commitments for Customer personal data.
7. Security and suitability
Controls include public HTTPS, server-side company and document permissions, protected password storage, MFA controls, malware scanning of uploads, approval before publication, rate limits, restricted service-account permissions, monitoring and recovery backups. No security measure eliminates every risk.
The Service is not end-to-end encrypted. Original files and application data currently do not have application-level document encryption, and operational backups are local rather than a geographically independent disaster-recovery service. We make no claim of certification for classified or highly regulated material. Discuss any special-category, criminal-offence, health or other high-risk data before uploading it.
8. Your rights and complaints
Depending on applicable law and the processing involved, you may ask for access, correction, deletion, restriction, a portable copy, or object to processing, including direct marketing. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. Additional rights can apply to significant automated decisions. We will not discriminate against you for exercising applicable rights.
Email privacy@mycompaniesai.com. We may ask for proportionate identity or authority evidence and will respond within applicable legal time limits; UK and EU requests are normally handled within one month, subject to lawful extensions or pauses. We will explain a refusal or an applicable charge. For company-controlled content, contact your organisation first; we will forward relevant requests and assist it rather than change its data without authority.
You may complain to the UK Information Commissioner's Office, an appropriate EEA supervisory authority, or your local privacy regulator where applicable. You do not have to complain to us first. California and other US state rights apply where the relevant law covers the business and the processing; we do not claim those laws apply to every customer. We do not sell or share data for targeted advertising, so there is no such activity to opt out of.
You can use your browser's Print or Save as PDF option to keep a copy. For an earlier accepted version, contact legal@mycompaniesai.com.
