Privacy Policy
Last updated: [DATE — set on publication]
1. Who we are
This Privacy Policy explains how [LEGAL ENTITY NAME] (“MyRemotePA”, “we”, “us”), of [REGISTERED ADDRESS], collects and uses personal data when you use the MyRemotePA platform and services. We are the data controller for that personal data. [If applicable: we are registered with the UK Information Commissioner’s Office under registration number [ICO NO].]
For any privacy question, or to exercise your rights, contact us at [PRIVACY CONTACT EMAIL]. [If a Data Protection Officer is appointed, add their contact here.]
2. The information we collect
- Account data: your name, business/account name, email address, and authentication credentials (passwords are stored only as secure hashes).
- Member context: information you choose to record for your assistant to use (for example, about your business, preferences and people), and the content of your conversations and requests.
- Usage data: records of how you use the Services, including AI usage counts, requests, and audit logs kept for security and account integrity.
- Payment data: billing details processed by our payment providers; we receive confirmation and limited transaction information, but do not store full card numbers ourselves.
- Technical data: IP address, device/browser information and cookies necessary to operate the site and keep your session secure.
3. How we use your information, and our legal bases
We process your personal data to provide the Services you have subscribed to (performance of a contract); to take payment and prevent fraud (contract and legitimate interests); to secure and improve the platform (legitimate interests); and to comply with legal obligations. Where we rely on legitimate interests, we have balanced those against your rights.
Your AI assistant is designed to work only with your own account’s information. We do not use the content of one member’s conversations to answer another member, and we do not sell your personal data.
4. Service providers and sub-processors
We share personal data with carefully selected providers who process it on our behalf, under contract and only on our instructions. These currently include:
- Anthropic — provides the AI model that powers the AI Personal Assistant; conversation content is sent to it to generate responses.
- SumUp — processes card payments. Bank transfers go directly to our bank; no card processor is involved.
- Email and infrastructure providers — deliver transactional email and host the platform securely.
- [Add any others as they are introduced, e.g. analytics, telephony/reception, concierge partners.]
5. International transfers
Some of our providers may process data outside the UK/EEA. Where that happens, we ensure an appropriate safeguard is in place (such as UK/EU adequacy, the International Data Transfer Agreement, or Standard Contractual Clauses). [Confirm the specific mechanism for each provider with your adviser.]
6. How long we keep it
We keep personal data for as long as needed to provide the Services and for a reasonable period afterwards to meet legal, accounting and security obligations, after which it is deleted or anonymised. [Set specific retention periods per data category with your adviser.]
7. Your rights
Under UK GDPR / GDPR you have rights to access your personal data; to have it corrected or erased; to restrict or object to certain processing; to data portability; and to withdraw consent where we rely on it. To exercise any right, contact [PRIVACY CONTACT EMAIL]; we will respond within the time the law allows.
You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk) — though we would welcome the chance to resolve any concern first.
8. Security
We protect your data with encryption in transit, hardened infrastructure, modern authentication, least-privilege access and strict separation between accounts. No system is perfectly secure, but security is engineered into the platform from the ground up, not added afterwards.
9. Cookies
We use cookies that are necessary to run the site and keep your session secure. [If any non-essential/analytics cookies are added, describe them here and provide a consent mechanism as required by law.]
10. Children
The Services are intended for businesses and adults, and are not directed at children. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here and, for material changes, take reasonable steps to let you know.