Skip to main content
← Back to Policies

Privacy Policy

How Deputise handles personal data and protects user privacy.

Privacy Policy

Deputise Ltd

Your privacy is important to us. This Privacy Policy explains how Deputise Ltd collects, uses, discloses, and protects your personal information when you use our website and the Deputise platform (collectively, the "Service").

This policy applies to all visitors, registered users, and customers of the Service.

Effective date: March 1, 2026 Last updated: August 30, 2026


1. Who We Are

We are Deputise Ltd, a company registered in England and Wales with company number 17082681, with our registered address at:

71-75 Shelton Street Covent Garden London WC2H 9JQ

For the purposes of applicable data protection legislation, Deputise Ltd is the data controller of personal information collected through the Service when you interact with us directly (e.g. creating an account, visiting our website). Where you use the Service through an organisation, we may act as a data processor on behalf of that organisation.

For questions about this Privacy Policy, contact us at: Email: privacy@deputise.ai


2. Information We Collect

2.1 Information You Provide

  • Account information: name and email address when you register. Signing in is by emailed link, so there is no password
  • Profile information: any additional details you choose to add to your account
  • Payment information: billing details processed through our third-party payment provider (we do not store full payment card details)
  • Communications: messages you send to us via email, support channels, or feedback forms
  • User-generated content: data, prompts, configurations, instructions, and any other content you provide to or through AI assistants on the platform, including content you make available to the people you invite to use an assistant
  • Safety reports: where you report an assistant's answer as harmful, we record what you wrote, a copy of the answer you reported, the name of the assistant, and the email addresses of the person who raised the report and the assistant's owner

2.2 Information Collected Automatically

  • Log data: IP address, browser type and version, pages visited, time and date of visit, time spent on pages, referring URL, and other diagnostic data
  • Device data: device type, operating system, and unique device identifiers
  • Usage data: features used, interactions with the platform, and transaction records
  • Crash reports: where the Service fails in your browser, the error, where in our code it happened, and the page you were on. Crash reports are sent whichever cookie choice you make. Where you have allowed cookies and are signed in, the report is recorded under your account; where you have chosen essential cookies only, or have not answered the banner, it carries no name or identifier for you
  • Cookies and similar technologies: see Section 10 below

2.3 Information from Third Parties

Signing in is by emailed link, so ordinarily we receive nothing about you from anyone else. Where signing in with Google is enabled and you choose it, Google sends us the basic profile information on that account, such as your name and email address. We may also receive information about you from publicly available sources.


3. How We Use Your Information

We use your personal information for the following purposes:

  • Service delivery: to provide, operate, maintain, and improve the Deputise platform
  • Generating answers: to send the messages in a conversation, together with the configuration its owner gave the assistant, to the third-party AI providers named on our sub-processors page, so that an answer can be produced
  • Account management: to create and manage your account, authenticate your identity, and process transactions
  • Communication: to respond to your enquiries, provide customer support, and send service-related notices
  • Sharing and escalation: to send an invitation to a person named by an assistant's owner, to give that person access to the assistant, and to pass a question to that owner when the person chatting asks for human help
  • Safety and trust: to detect, prevent, and address fraud, abuse, security incidents, and violations of our terms
  • Analytics and improvement: to understand how users interact with the Service, identify trends, and improve our platform
  • Fault diagnosis: to record the errors that occur while you are using the Service, so that we can find and repair them
  • Connected AI agents: to let an AI agent you have authorised to reach your account read and act on whatever the permissions you approved cover, which reach further than your own conversations and are set out in Section 5
  • Legal compliance: to comply with applicable laws, regulations, legal processes, or governmental requests, and to establish, exercise, or defend legal claims

3.1 AI Model Training

We do not use your personal data to train AI models. We may use strictly anonymised data to:

  • Improve how assistants work, through analysis of failures and functional gaps
  • Work with AI providers to improve their models, where we can help identify improvements

Personal data is never shared as part of this process.


We process your personal information only where we have a lawful basis to do so:

  • Performance of a contract: where processing is necessary to provide the Service to you under our Terms of Service
  • Legitimate interests: where processing is necessary for our legitimate interests (such as improving our Service, ensuring security, and preventing fraud), provided those interests are not overridden by your rights
  • Consent: where you have given explicit consent for a specific processing activity (e.g. analytics). You may withdraw consent at any time
  • Legal obligation: where processing is necessary to comply with a legal obligation to which we are subject

Analytics cookies, and recording your activity under your account, rest on your consent, which you give through the cookie banner and can withdraw at any time. The cookieless measurement that continues where you have not given it, and the crash reports described in Section 2.2, rest on our legitimate interest in understanding whether the Service works and in keeping it working. Section 9 sets out how to object to processing based on our legitimate interests.


5. How We Share Your Information

We do not sell your personal information. We may share your information with:

  • Service providers and sub-processors: third-party vendors who assist us in operating the Service, including hosting, payment processing, analytics, email delivery, and AI inference providers. These providers are contractually obligated to process your data only as instructed by us and in accordance with this policy. For a full list, see our Sub-Processors page
  • Invited recipients: where you, as an assistant's owner, invite a named individual to use that assistant, that individual will be given access to the assistant and to information necessary for them to use it
  • Assistant owners: where you use an assistant someone else owns and you ask to be put through to a person, your question goes to its owner, who can then read the conversation it came from and see the name and email address on your account
  • Our own staff: a member of our staff may read a conversation where that is necessary to investigate a safety report, a support request, or a suspected breach of our Acceptable Use Policy. Whenever a member of our staff opens a conversation, we record who opened it, which conversation it was and why, and we keep that record as set out in Section 7. Access is limited to staff who need it for the work in front of them
  • Connected AI agents: where you authorise an AI agent to reach your Deputise account, it can read and act on whatever the permissions you approved cover, for as long as that authorisation stands. Each permission is listed for your approval before access is granted, and you can see the AI agents you have authorised, and withdraw any of them, in your account settings. Those permissions reach further than your own conversations. They can cover:
    • The transcript of a conversation someone else has had with an assistant you own, once that conversation has escalated a question to you
    • The name and email address of everyone you have shared an assistant with, and of anyone whose question is waiting for you
    • The facts recorded for your assistants, which can include private details such as a password or an address, and which an AI agent holding that permission can replace
    • Your credit balance, together with the credits themselves, since answers your assistants give are charged to you
    • The name, profile picture and email address on your own account
  • Professional advisors: lawyers, auditors, and insurers where necessary for the provision of professional services
  • Law enforcement and regulators: where required by law, regulation, legal process, or governmental request, or where necessary to protect our rights, property, or safety, or the rights, property, or safety of others
  • Business transfers: in connection with any merger, acquisition, restructuring, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any such change

6. International Transfers of Personal Information

Your personal information may be stored and processed in the United Kingdom, the European Economic Area (EEA), the United States, or any other country in which we or our sub-processors maintain facilities.

Where we transfer personal information outside of the UK or EEA, we ensure appropriate safeguards are in place, including:

  • Transfers to countries with an adequacy decision from the UK Secretary of State or the European Commission
  • Standard Contractual Clauses (SCCs) approved by the European Commission and/or the UK International Data Transfer Agreement (IDTA)
  • Other legally recognised transfer mechanisms

The UK benefits from an EU adequacy decision. Where we transfer data from the EU/EEA to the UK, this is covered by that adequacy finding.


7. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • Account data: retained for the duration your account is active, and deleted or anonymised within 31 days of account deletion
  • Transaction data: retained for up to 7 years after the transaction to comply with financial and tax reporting obligations
  • Conversations, messages and the pictures sent with them: retained for as long as the conversation exists, and deleted within 31 days of the conversation being deleted, whether you delete it or it goes with your account
  • Analytics data and crash reports: retained for up to 24 months
  • Application logs: retained for 7 days
  • Sign-in link requests that never resulted in an account: retained for 90 days
  • Safety reports: retained until the report has been reviewed and decided, and for 24 months after that
  • Records of staff access to your information: retained for 24 months

When personal information is no longer required, we will securely delete or anonymise it.

Safety reports are an exception to the account data window above. A report names the person who raised it and the owner of the assistant it is about, and it holds a copy of the answer that was reported. Those details are kept for the period set out above even where one or both of those accounts have since been deleted, so that a record of reported content cannot be destroyed by the person it is about. We rely on our legitimate interest in the safety of the Service, and on our legal obligations, to keep them.


8. Data Security

We implement commercially reasonable technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (TLS) and at rest, access controls, regular security assessments, and incident response procedures.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account.


9. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

9.1 Rights Under UK GDPR and EU GDPR

  • Access: request a copy of the personal information we hold about you (Data Subject Access Request)
  • Rectification: request correction of inaccurate or incomplete personal information
  • Erasure: request deletion of your personal information in certain circumstances. Safety reports are retained as described in Section 7
  • Restriction: request that we restrict processing of your personal information
  • Portability: request a copy of your personal information in a structured, commonly used, machine-readable format
  • Objection: object to processing based on legitimate interests or for direct marketing purposes
  • Automated decision-making: not be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you
  • Withdraw consent: where processing is based on consent, withdraw that consent at any time

To exercise any of these rights, contact us at privacy@deputise.ai. We will respond within one month.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

UK: Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Tel: 0303 123 1113 Website: the Information Commissioner's Office

EU: your local Data Protection Authority A list of EU DPAs is available from the European Data Protection Board

9.2 Rights Under U.S. State Privacy Laws

Residents of states with comprehensive privacy laws (including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware, Iowa, Minnesota, Nebraska, New Hampshire, New Jersey, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, Utah, and others as enacted) may have additional rights, including:

  • Right to know what personal information we collect, use, and disclose
  • Right to delete personal information we hold about you
  • Right to correct inaccurate personal information
  • Right to opt out of the sale of personal information, targeted advertising, or profiling that produces legal or similarly significant effects
  • Right to non-discrimination for exercising your privacy rights

We do not sell personal information as defined under applicable U.S. state privacy laws.

Global Privacy Control: If your browser or a browser extension sends a Global Privacy Control (GPC) signal, we treat it as a choice of essential cookies only. Analytics then sets no cookie, keeps nothing in your browser's storage and records nothing under your account, and we do not show you the cookie banner, because the signal has already answered it. We honour the signal for everyone who sends it, not only where a state law requires it.

Your own answer takes priority over the signal, in both directions. Select Cookie preferences, in the site footer or in your account menu if you are signed in, to open the banner and answer for yourself, and to change that answer later. See our cookie policy for what each answer does.

Do Not Track: We do not respond to the older browser "Do Not Track" (DNT) signal, which was never standardised and which browsers send in ways we cannot read as a deliberate choice. Send GPC, or answer the cookie banner, and we will honour that.

California-Specific Disclosures (CCPA/CPRA)

In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, IP address, account ID), commercial information (transaction records, purchase history), internet/electronic network activity (usage data, log data), and inferences drawn from the above.

We collect and use these categories for the business purposes described in Section 3. We do not sell or share (as defined by the CCPA) personal information for cross-context behavioural advertising.

To exercise your rights, contact us at privacy@deputise.ai with the subject line "Privacy Rights Request".

9.3 Rights Under Canadian Privacy Law (PIPEDA)

If you are a Canadian resident, you have the right to:

  • Access personal information we hold about you
  • Request correction of inaccurate personal information
  • Withdraw consent for collection, use, or disclosure of your personal information (subject to legal and contractual restrictions)

Requests will be fulfilled within 30 days. If we cannot resolve your concern, you may contact the Office of the Privacy Commissioner of Canada.

9.4 Rights Under Australian Privacy Act

If you are an Australian resident, you have rights under the Privacy Act 1988 (Cth) to access and correct your personal information. Some third-party providers may not be bound by the Australian Privacy Principles; by using the Service, you acknowledge that where information is shared with such providers, they may not be accountable under the Privacy Act.


10. Cookies and Similar Technologies

We use cookies and similar tracking technologies to operate and improve the Service. These include:

  • Strictly necessary cookies: required for the Service to function (e.g. authentication, session management)
  • Analytics cookies: help us understand how the Service is used (e.g. page views, feature usage)
  • Preference cookies: remember your settings and preferences

Our analytics provider is PostHog, listed on our sub-processors page. Analytics records the pages you open, the clicks, changes and form submissions you make on them, and the events the product raises for its own features. An interaction is recorded as the kind of interaction it was and the address of the page it happened on, with the text on and around the control removed before the event is sent, so the content of your conversations and the instructions written for an assistant are not part of it. We do not use session replay, so no recording is made of your screen or of what you type into it.

Choosing essential cookies only stops the cookies rather than the measurement. Analytics then runs without a cookie, without anything kept in your browser's storage, without a session identifier and without a name, and we record your activity under your account only where you have allowed cookies. Where visits made without cookies are counted, our analytics provider does the counting from the request itself, such as the address it came from and the browser that made it, as a value that cannot be turned back into either and that it replaces daily. Crash reports are sent either way, carrying what Section 2.2 describes.

You can manage cookie preferences through your browser settings or through any cookie consent mechanism we provide on the Service. Disabling certain cookies may affect the functionality of the Service.

For the categories of cookie we use and how to change the choice you made, see our cookie policy.


11. Children's Privacy

The Service is not directed at individuals under the age of 18 (or the age of majority in your jurisdiction, whichever is higher). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@deputise.ai and we will take steps to delete it.


12. AI Transparency and the EU AI Act

Deputise is a platform where a person can create an AI-powered assistant and share it privately with people they invite. In accordance with transparency obligations under the EU AI Act (Regulation (EU) 2024/1689):

  • Disclosure of AI interaction: when you interact with an AI assistant on the platform, you will be informed that you are interacting with an AI system
  • Content labelling: where AI-generated content is produced through the platform, it will be identified as such where required by applicable law
  • Risk classification: we do not deploy AI systems classified as high-risk or prohibited under the EU AI Act. The platform facilitates the use of general-purpose AI models provided by third-party AI providers. Our terms of service make each owner responsible for their assistant's compliance with applicable law, including the EU AI Act, and prohibit any use the EU AI Act classifies as a prohibited practice
  • Human oversight: an assistant's owner controls how it is configured and can change or remove it at any time. Everyone using an assistant is responsible for reviewing what it says before relying on it for consequential decisions

The Service may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.


14. Business Transfers

If Deputise Ltd is acquired, merges with another entity, or enters bankruptcy, your personal information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.


15. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page. If changes are material, we will notify you by email or through the Service before they take effect.

We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.


16. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of your rights, contact us at:

Deputise Ltd 71-75 Shelton Street Covent Garden London WC2H 9JQ

Email: privacy@deputise.ai