Skip to content
My Companies AI
HomeHelp HubSign in

MY COMPANIES AI · HELP HUB

Privacy notice

What information we use, why we use it, who receives it and how to exercise your privacy rights.

Published 11 September 2026 · Version 2026-09-11

Terms & conditionsPrivacy noticeData Processing AgreementCookie noticeService providers

On this page

  1. 1. Who is responsible
  2. 2. Information we collect
  3. 3. Purposes and lawful bases
  4. 4. AI processing and human access
  5. 5. Recipients and international processing
  6. 6. Retention and deletion
  7. 7. Security and suitability
  8. 8. Your rights and complaints
  9. 9. Cookies, children and updates

1. Who is responsible

My Companies AI is an unincorporated business trading as My Companies AI. Contact privacy@mycompaniesai.com about personal information and privacy rights, help@mycompaniesai.com for customer support, or legal@mycompaniesai.com for formal contractual matters. Primary application hosting is in Scotland, UK.

We are a controller for information used to administer our business, accounts, enquiries, billing and service security. Your employer or other organisation is normally the controller of personal data in its uploaded knowledge and workplace use of the assistant; we process that data on its instructions under our DPA. If the organisation acts for another controller, it must have authority to give us instructions. Ask your organisation for its own privacy notice.

2. Information we collect

  • Account and organisation details: names, work email addresses, company names, website, country, timezone, roles, permissions, invitations and subscription details.
  • Authentication and security records: password hashes, encrypted MFA information, hashed recovery and session tokens, sign-in events, device/browser information and network addresses when supplied by our trusted network services.
  • Customer content: document originals and versions, extracted text, search representations, questions, replies, conversation history, feedback, knowledge gaps and approval/access records.
  • Usage and billing records: question counters, AI-processing usage estimates, plan and promotion records, payment-provider identifiers, invoices and payment status. Full card details are handled by Stripe when payment services are used.
  • Communications: support and legal requests, information you include in them, and verification, invitation, account-recovery and service emails.

We receive information directly from you, from your organisation and its administrators, from other authorised users where they upload or share it, and from service providers involved in security, email and payments. Do not send more personal data than is needed. Account and security details necessary to provide access are required; optional enquiry details are your choice.

3. Purposes and lawful bases

Processing for which we act as controller
PurposeUK / EU GDPR basis
Create accounts, provide the subscription and answer pre-contract enquiriesContract where you personally contract with us; otherwise legitimate interests in administering the Customer's service and communicating with its representatives.
Authentication, fraud prevention, misuse investigation, fair-use enforcement and service recoveryLegitimate interests in a secure, reliable service and protecting customers; legal obligation where a specific requirement applies.
Billing, accounting and legal claimsContract, applicable accounting/tax obligations, and legitimate interests in establishing or defending claims, as relevant.
Support, necessary service notices and handling rights requestsContract or legitimate interests in resolving enquiries; legal obligation for applicable privacy requests.
Optional marketing or non-essential tracking, if introducedConsent where required, obtained separately before use; otherwise only a specifically identified lawful basis allowed by applicable law.

We weigh legitimate interests against individuals' rights and reasonable expectations. You may object to processing on that basis. We do not treat a company's subscription agreement as the lawful basis for every employee's personal information. The Customer must determine its own lawful bases, provide notices and obtain any necessary permissions for workplace content and use.

4. AI processing and human access

Approved knowledge relevant to an authorised question is retrieved to help generate a reply. Document text may also be sent for search indexing during analysis before publication. An unpublished document is excluded from answers, but upload and analysis still involve processing. Questions, relevant passages and generated replies can contain personal data.

We use OpenAI's API for AI processing. OpenAI states that API data is not used for model training by default unless the account holder opts in. We do not use Customer content to train a shared model for our own purposes. OpenAI may retain content in abuse-monitoring logs, normally for up to 30 days, with exceptions for legal or safety needs. We do not promise zero provider retention. See OpenAI's data controls.

Authorised Customer administrators and managers have the access associated with their roles and settings. Authorised service operators may access data where necessary for support, security, recovery or legal compliance. Support access is not an unrestricted right to browse your content. The assistant does not itself make legally binding decisions about people. The Customer must not use generated answers as a substitute for meaningful human review.

5. Recipients and international processing

We use OpenAI for AI requests, Cloudflare for traffic delivery and security, and Purelymail (Add Rabbit LLC) for email. Stripe is used for card billing when payment services are enabled. Their roles, data categories and locations are described in our provider register. Advisers, authorities or a successor business may receive necessary information for a lawful purpose, subject to appropriate confidentiality and safeguards.

The application database, original files and local operational backups are hosted in Scotland. That does not make processing UK-only: OpenAI and Cloudflare have international operations, and Purelymail identifies its email hosting as northern Virginia, USA. Remote access and recipients' own email providers may also involve other countries.

Where transfer restrictions apply, we must use a valid mechanism: an applicable adequacy decision or regulation, or appropriate contractual safeguards such as the EU Standard Contractual Clauses with the UK Addendum, the UK IDTA, and any required Swiss adaptations and assessments. A provider name, TLS connection or link to its policy is not itself a transfer safeguard. Contact privacy@mycompaniesai.com for the arrangements applicable to your processing and a copy of relevant safeguards, with confidential details redacted where necessary. Any additional arrangement required for your use must be completed before that processing begins.

We do not sell personal information, use Customer content for targeted advertising, or share it for cross-context behavioural advertising.

6. Retention and deletion

We retain information according to its purpose, the Customer's instructions, the need to run and secure the account, applicable record-keeping duties and the time needed to resolve a specific dispute. Expiry of a session, trial or subscription does not automatically erase all stored records.

  • Documents, versions and conversations remain while needed for the workspace, until authorised deletion or closure instructions are carried out. Conversation-retention settings are handled through an operator-managed retention process; changing a setting does not itself trigger an automatic purge. Contact support to arrange and confirm a retention action.
  • Routine local backups use a 14-day rolling schedule. Separate migration or deployment recovery copies can remain longer while needed to verify a safe recovery or resolve an incident. They are not an indefinite archive entitlement. A deletion request must also address those copies; backup data is restricted to recovery purposes and deletion instructions must be reapplied after restoration.
  • Account, security, audit, question-count and spending records can remain after content deletion where still necessary for billing, abuse prevention, accountability or legal claims. Removing a conversation does not reset an allowance. We assess whether identifiers can be removed and do not retain records merely because storage is available.
  • Queued account-email content is removed from the application after successful sending or cancellation; failed payloads are cleared under the queue's expiry rules. Delivery metadata and the email provider's own logs and backups have separate retention periods. Information sent to support or legal mailboxes remains only as needed to handle the matter and any justified follow-up.

Request a record-specific retention explanation or deletion at privacy@mycompaniesai.com. Where law requires retention, we will explain the relevant reason and restrict further use. The DPA provides additional return and deletion commitments for Customer personal data.

7. Security and suitability

Controls include public HTTPS, server-side company and document permissions, protected password storage, MFA controls, malware scanning of uploads, approval before publication, rate limits, restricted service-account permissions, monitoring and recovery backups. No security measure eliminates every risk.

The Service is not end-to-end encrypted. Original files and application data currently do not have application-level document encryption, and operational backups are local rather than a geographically independent disaster-recovery service. We make no claim of certification for classified or highly regulated material. Discuss any special-category, criminal-offence, health or other high-risk data before uploading it.

8. Your rights and complaints

Depending on applicable law and the processing involved, you may ask for access, correction, deletion, restriction, a portable copy, or object to processing, including direct marketing. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. Additional rights can apply to significant automated decisions. We will not discriminate against you for exercising applicable rights.

Email privacy@mycompaniesai.com. We may ask for proportionate identity or authority evidence and will respond within applicable legal time limits; UK and EU requests are normally handled within one month, subject to lawful extensions or pauses. We will explain a refusal or an applicable charge. For company-controlled content, contact your organisation first; we will forward relevant requests and assist it rather than change its data without authority.

You may complain to the UK Information Commissioner's Office, an appropriate EEA supervisory authority, or your local privacy regulator where applicable. You do not have to complain to us first. California and other US state rights apply where the relevant law covers the business and the processing; we do not claim those laws apply to every customer. We do not sell or share data for targeted advertising, so there is no such activity to opt out of.

9. Cookies, children and updates

See our Cookie notice for authentication and network-security technologies. The application does not include advertising trackers or behavioural analytics. Essential service messages are separate from marketing consent.

The Service is for adult business users and is not directed to children. Do not knowingly create an account for someone under 18 or upload children's personal information without a prior agreed lawful arrangement. Tell us if you believe such information was provided inappropriately.

We will update this notice when practices change and identify the publication date. Material changes will be brought to users' attention where required. An updated notice does not create consent for a new purpose or remove existing rights.

You can use your browser's Print or Save as PDF option to keep a copy. For an earlier accepted version, contact legal@mycompaniesai.com.

My Companies AICustomer supportPrivacy requestsLegal enquiriesHelp Hub