Last updated: January 2025

1. Information We Collect

B2B Customer Information You Provide

We collect information you provide directly when you:

API Usage Data Automatically Collected

End-User Data Processing (Via Your API Integration)

2. Legal Basis for Data Processing (GDPR)

We process your business data under the following legal bases:

Contract Performance (Article 6(1)(b))

Legitimate Interests (Article 6(1)(f))

Consent (Article 6(1)(a))

Legal Obligation (Article 6(1)(c))

3. How We Use Your Information

Core API Service Delivery

Business Operations

4. AI Data Processing and OpenAI Integration

How End-User Conversations Are Processed

  • API request flow: Your application sends user messages to our /chat/message endpoint
  • OpenAI processing: Messages are forwarded to OpenAI's API for AI companion response generation
  • Conversation context: Recent message history included to maintain conversation continuity
  • Response delivery: AI responses returned to your application via our API
  • No model training: End-user conversations are not used to train OpenAI's models (per their API terms)

Data Security in AI Processing

Important: While messages are processed by OpenAI for response generation, all stored conversation data in our database is encrypted and accessible only to authorized systems.

5. Data Storage and Encryption

Advanced Encryption Implementation

Data Storage Locations

6. Data Sharing and Third-Party Providers

We share data with trusted third parties only as necessary for API service delivery:

Essential Service Providers

OpenAI (US) - AI conversation processing for end-user messages

Stripe (US/EU) - Payment processing for B2B subscriptions

Resend (EU) - Email delivery for account verification and notifications

MongoDB Atlas (Global) - Secure cloud database hosting

International Data Transfers

Some service providers are located outside the UK/EU:

7. Enterprise Customer Data Processing

Customer End-User Data Handling

Data Processing Agreements (DPAs)

8. Data Retention and Deletion

Retention Periods

Data Deletion Process

9. Your Privacy Rights Under GDPR and UK Law

Your Business Data Rights

Under GDPR and UK data protection law, your organization has the following rights:

How to Exercise Your Rights

10. Cookies and Tracking Technologies

Essential Cookies (Always Active)

Analytics Cookies (Optional - Requires Consent)

Managing Cookie Preferences

11. API Security and Access Controls

Authentication and Access Management

Security Monitoring

12. Important Disclaimers and Limitations

AI Service Limitations

  • AI Response Accuracy: Our AI companions may occasionally generate inaccurate, inappropriate, or biased responses that require human oversight
  • Crisis Detection: While our system includes crisis detection capabilities, it cannot guarantee detection of all crisis situations or replace professional intervention
  • End-User Responsibility: API customers are responsible for implementing appropriate safeguards and user agreements for their end-users
  • Professional Care: AI companions are not licensed therapists and cannot replace professional mental health services

Business Service Limitations

13. Data Security and Breach Response

Security Measures

Data Breach Response Protocol

14. Changes to This Privacy Policy

15. Supervisory Authority and Complaints

If you have concerns about our data processing practices:

Contact Information

For privacy-related questions, data rights requests, or concerns about our data processing:

Data Protection Contact

Company Information

CompanionFrame Limited
Registered in England and Wales
United Kingdom

Response Commitments

  • General inquiries: Response within 2 business days
  • Data rights requests: Response within 30 days (may extend to 60 days for complex requests)
  • Security incidents: Acknowledgment within 24 hours, full response within 72 hours
  • Privacy complaints: Response within 5 business days