Legal - Privacy notice
Privacy Policy
Effective from Last reviewed Version 1.5
1. At-a-glance summary
PartnerMe AI ("we", "us", "PartnerMe AI") is a professional collaborating platform powered by AI agents. We process your personal data to run the service for you: matching you with relevant connections, drafting and publishing content on the platforms you connect, drafting replies to the comments and messages you receive there, boosting engagement within the communities you join, powering the AI assistant and your agents (including the media they generate for you), providing messaging, meetings, calendar and team workspaces, and keeping the service safe and secure. This Privacy Policy explains, in plain English, what we collect, why, who we share it with, how long we keep it, and the controls you have over it.
- You must be 18 or over to sign up.
- We never sell or share your personal data (including under the CCPA's broad definitions).
- You can download a copy of everything we hold or delete your account at any time at /account/privacy.
- You can pause all AI agent activity on your account at any time (Article 18 right to restriction).
2. Who we are
PartnerMe AI is the data controller for the personal data processed under this Privacy Policy. Our registered contact for data-protection matters is:
- Email: privacy@partnerme.net
- Designated Data Protection contact (UK / EU): see above email; we will route your message to our internal data-protection lead. Where we are required to appoint a formal DPO we will publish their contact details here.
3. What personal data we collect
3.1 Account & profile
- Email address, password (stored only as a bcrypt-12 hash), display name, date of birth (for the 18+ gate), region (UK / EU / US-CA / US / OTHER, derived from a country signal on your request where one is available; without one we default to OTHER, which receives the strictest consent treatment).
- Profile fields you choose to fill in: headline, bio, location text, avatar image, work experience, education, languages, skills, external links.
3.2 Service usage
- Posts you create, drafts the Auto-Posting, Auto-Replying and Network-Boosting AIs produce for your review, post feedback, recommendation responses, calendar events you create, meetings you join, messages you send.
- Connection activity (who you sent / accepted connection requests with) and feedback you give on agent recommendations.
- AI media generation:when you ask the AI to generate an image or short video for a post or story, we process the generation brief and store the generated media and its generation record. If you explicitly opt in, photos you attach can be used as subject references for that generation (for example "make the person in my photos the hero of the image"). For recurring series (scheduled stories or feed media plans) you consent once, when you set the series up, choosing the media kind and quality tier with the prices shown - and that choice is locked for the series. Each scheduled run then generates exactly the number of media items you chose for that step of the series (one, unless you set more) on exactly those terms; how many runs happen - and so how many items over time - is set by the schedule you chose, and changing or removing the series changes or withdraws that consent. Using a photo as a generation reference never publishes it by itself - the generated output is new media. The same photo can, if you choose, also sit in your as-is posting queue (the default when a series mixes attached and generated steps), and it is then published as-is when its queue turn comes; you can equally keep photos as generation subjects only, so they are never posted. Disconnecting the platform immediately removes the series' queue and source entries, so nothing further is posted or generated from them; the files themselves are your chat attachments and remain in your encrypted storage until your account is deleted, when they are purged. Generation is performed by our cloud AI providers (see section 5) under contracts that prohibit using your content to train their models.
- Voice: voice notes you record are transcribed by our AI provider and the transcript is stored encrypted; realtime voice conversations with the AI are processed live and billed by duration. Video meetings run on our own UK-hosted infrastructure and are not recorded by us.
3.3 Integrations
- When you connect LinkedIn, Google, Instagram, Threads, WordPress (including WordPress.com), Wix, Webflow, or Circle - or any further connector we make available - we store the OAuth access & refresh tokens (AES-256-GCM encrypted at rest) and the granular scopes you granted. We never store the password to your social account.
- For LinkedIn specifically, the four scope choices you can independently grant or revoke are: auto-posting; recommendations from your network; populate-profile; verification badge.
- Google API Services Limited Use disclosure: PartnerMe AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data (including Google Calendar events and availability) is used only to provide the user-facing features described in this policy, is transferred to others only as necessary to provide those features or for security and legal compliance, is never used for advertising, and is never used to develop, improve, or train generalised artificial-intelligence or machine-learning models. Our AI features process your data solely at your direction to deliver the feature you requested, under provider contracts that prohibit the use of your content for model training.
3.4 Imported leads (people who are not PartnerMe AI users)
- Our matchmaking can suggest people from curated lists of publicly available professional profiles ("leads") imported by a PartnerMe AI administrator from public sources. For each lead we store: name, public profile URLs (for example LinkedIn, Instagram or Twitter/X, where publicly available), photo URL, location, current company + title, languages, skills and other fields - all encrypted at rest (AES-256-GCM) - plus a small set of non-sensitive professional data points generated by AI.
- How the AI uses those data points: the Matchmaking AI compares a lead's non-sensitive professional data points with what a PartnerMe AI user has told us they are looking for, and may suggest that lead to the user as a result. Nobody is contacted automatically, and a human user always decides whether to reach out, which they can only do through the lead's own public profile.
- Data minimisation by design: long-form profile text (the "about" section, job descriptions, education descriptions, headline-like text) is redacted, used ONLY to generate those data points, and is never stored.
- We never import or store email addresses, phone numbers, postal addresses, or private direct-contact channels for leads. The only way a user can reach a lead is via the lead's own public profiles.
- Leads are processed under legitimate interest (Article 6(1)(f)), retained only while they remain relevant to the matchmaking purpose and subject to periodic review (see section 6), and have the same data-subject rights as everyone else - including immediate erasure on request (see section 7.1).
3.5 Your LinkedIn connections (optional)
- If you grant the "recommendations from my network" LinkedIn purpose, your connections are imported directly from LinkedIn through its member-authorised data portability interface - there is no manual file upload. We store for each connection: name, public profile URL, company and position - encrypted at rest - plus non-sensitive professional data points generated by AI from the connection's position and company only (never their name or profile URL), under the same processing terms as the rest of the Matchmaking AI. Until those data points exist a connection is not considered for suggestions.Email addresses present in LinkedIn's data are dropped at parse time and never stored.
- These are used for exactly one purpose: letting the Matchmaking AI suggest people from your own network who fit what you're looking for. We never read your LinkedIn messages.
- Revoking the purpose (or disconnecting LinkedIn, or deleting your account) erases every imported connection immediately.
3.6 Payment & billing
- If you subscribe to a paid plan, Stripe handles your card details directly. We never touch raw card numbers or CVCs. Stripe gives us back a customer id, a subscription id, invoice metadata, and payment status.
3.7 Technical telemetry
- IP address (hashed with a per-deployment lookup salt before storage - we never persist raw IP), browser User-Agent string, log timestamps, last-login timestamp.
- AI usage counters (tokens consumed, cost, feature used) for billing & capacity planning.
3.8 Consent records
- Every cookie-consent decision is stored as a row with your hashed IP, region, the version of the consent banner you saw, and your choices per category. PECR + UK GDPR Article 7(1) require this audit trail.
3.9 Inbound comments and messages on your connected accounts
- If you enable auto-replies for a connected social account, we receive the comments and direct messages sent TO that account (via the platform's webhooks, or by periodically reading recent comments and unanswered messages through the platform's official API) so the Auto-Replying AI can draft responses for you. For each item we store: the message or comment text, the sender's public display name or handle, the platform's item id, and a link to the item where the platform provides one. Text and sender names are encrypted at rest.
- These items usually contain personal data of the people who wrote to you. They are kept - encrypted at rest - for as long as the platform stays connected: the comment or message is shown together with its drafted reply on your Auto-Replies page, so you can always review what was answered and how, and the stored record prevents the same item from ever being answered twice (see section 6).
- Conversation context. So that replies read like a natural conversation, we also keep the recent history of each conversation or comment thread the AI works on: the last few messages in a direct-message conversation (both the other person's and your own) and the replies under a comment, with the sender's handle and the time sent. Direct-message bodies are sealed with hybrid post-quantum encryption (X25519 + ML-KEM-768, the NIST FIPS 203 standard - see section 8) so that only you and the AI drafting for you can read them; comment text and sender handles are encrypted at rest. This history is used only to draft and show you the reply in context - it is never used for any other purpose.
- Messages you ask the AI to write. When you ask the AI in chat to write a new personalised message to the people you already have a direct-message conversation with (or to some of them), it reads the recent history of those conversations, as above, to personalise each message. Instagram only lets us reach people you already have a conversation with, and only within 24 hours of their last message to you. Whether each message is sent only after you approve it, or immediately as it is drafted, follows the reply autonomy mode you have chosen.
- Disconnecting the account erases the stored items for that platform immediately - including the drafts, the comment copies inside them, and the conversation history kept for context.
3.10 Learning your writing style
- To draft posts and replies that sound like you, the AI agents learn from content YOU authored: the briefs and examples you give them, your feedback on their drafts, files and links you share in chat, and - when you connect a social account - your own recently published posts and your own replies on that platform.
- We never use other people's messages to learn your style. Only content you authored yourself is stored for style learning; messages and comments other people sent you are never added to your style-learning data.
- What is stored: excerpts of your own published content (encrypted at rest) and short, non-sensitive descriptive data points derived from them, scoped to the specific connected account. Style signals may inform drafting across your other connected platforms and the three content agents (Auto-Posting, Auto-Replying, Network-Boosting) so you do not have to teach each one separately.
- Disconnecting an account erases the learning data stored for it, immediately.
- De-identified improvement data (generalised lessons): occasionally the AI may judge a piece of feedback you gave to be a general writing lesson that could improve drafting for everyone (for example "shorter opening sentences work better"). In that case it first rewrites the lesson with every identifying detail removed - no names, companies, places, links or handles - and only that generalised, de-identified version goes any further. It is then used for model improvements of our own AI systems, for all users, and only after a human platform administrator has reviewed and applied it. How a lesson is submitted depends on your plan: on paid plans the exact de-identified text is shown to you in chat and nothing is submitted unless you explicitly approve that visible text; on the Free plan these generalised, de-identified lessons are submitted automatically as part of how we provide the free service. In both cases your original feedback wording stays private to your account and continues to personalise only your own agents. Because the retained lessons are fully de-identified, they are no longer personal data: they become part of the common improvement pool for all users, are not connected to your account, and remain in that pool even if you later delete your account. Your own preferences, briefs, style examples and per-account feedback are never shared with other users, and none of this trains the underlying third-party AI models.
3.11 Teams and communities
- Team workspaces share by design.If you join a team, the other members can see what you do in the team workspace: content you create there (posts, replies, engagement drafts, generated media, agent chat threads, meetings and calendar entries) and the shared connectors and the data flowing through them. Your AI credit spending in the team is recorded in the team ledger: you always see your own spending, and members holding the team's credits-visibility permission can additionally view the shared pool, allocations and member spending. Team administrators also see a team audit log of administrative actions. Preferences and training data contributed to the team's agents belong to the team. Your personal workspace is never visible to a team.
- Invitations: team members are invited by picking people you are already connected with on the platform - there is no invitation by email address. The invited person is notified in-app (and by email, per their notification settings), accepts or declines in the app, and pending invitations expire automatically after 14 days.
- Communities:your membership and display name are visible to the other members of a community you join, and a request to join an approval-based community is visible to that community's owner. Network boosting in a community is opt-in: opting in makes your published posts on connected platforms visible to other opted-in members' agents so they can draft engagement. You can leave a community, or withdraw from boosting, at any time.
- Leaving and deletion:leaving a team or community ends your access immediately; records that belong to the team (team-workspace content, shared connector data, team training data, ledger and audit entries) remain with the team. When you delete your account you choose what happens to teams you own: transfer to the most senior remaining member (the default), or deletion of the team together with everything it owns - team-workspace content (posts, drafts, replies, conversations, calendar entries), team agent data, generation records, team communities and connectors. A team with no remaining members is always deleted the same way, and remaining members are notified when an owner's deletion removes their team.
3.12 The feedback agent
The feedback button on every page is a voluntary channel for telling us about bugs, ideas and requests for PartnerMe AI. Using it is never required.
- What we collect (signed in): the messages you write there, files you choose to attach, the page you opened it from, the app version, your browser family, the date and time, and your acceptance of this section (section 3.8). The conversation is stored encrypted and linked to your account so the team can follow up and you can see the status of what you sent.
- What we collect (not signed in): the text of the form, optional contact details, and a one-way hash of your IP address kept for 24 hours to limit abuse of the form (we never store the IP address itself).
- How it is processed: an AI assistant turns what you write into a short summary for the PartnerMe AI team, with names, contact details, links and handles removed. The team sees these summaries and how often different people report the same thing, never who reported it.
- Your name:the team sees your name or e-mail address with a report only if you tick the "share my name" option (off by default, changeable at any time). Every such view is recorded in our audit log.
- What it is not used for:training AI models, the learning data or model-improvement pools in section 3.10, or any content drafted for you or anyone else. Please do not include other people's personal data or health information.
- Your control:the "Your reports" tab shows everything you sent and its status; deleting your account removes your identity from every feedback record. Retention is in section 6.
4. Lawful bases (UK GDPR / EU GDPR Article 6)
We rely on different lawful bases for different purposes. See Article 6 GDPR for the full list of available bases. The mapping is:
| Purpose | Lawful basis |
|---|---|
| Creating + operating your account | Contract (Art. 6(1)(b)) |
| Auth, security, fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| AI agent recommendations + auto-posting | Contract (Art. 6(1)(b)) - core service |
| Learning your writing style from content you authored (section 3.10) | Contract (Art. 6(1)(b)) - core service, erased on disconnect |
| Improving our own AI systems with generalised, de-identified lessons derived from your feedback (section 3.10) | Paid plans: consent (Art. 6(1)(a)) - only the exact de-identified text you approve in chat. Free plan: legitimate interest (Art. 6(1)(f)) - the lesson is fully de-identified before any further use and reviewed by our team, and your original feedback stays private to your account. Human review by our team applies in both cases |
| AI media generation, including using your attached photos as generation references (section 3.2) | Contract (Art. 6(1)(b)) for generation you request; Consent (Art. 6(1)(a)) for the standing photo-reference and recurring-series options, revocable any time |
| Receiving + storing comments/messages sent to your connected accounts, and the recent conversation history around them, so replies and messages you ask for can be drafted in context (section 3.9) | Legitimate interest (Art. 6(1)(f)) - answering messages addressed to you and acting on your explicit instructions; kept only while the account stays connected (section 6) |
| Processing imported leads (non-users) for matchmaking suggestions | Legitimate interest (Art. 6(1)(f)) - minimised fields, periodic retention review, full objection/erasure rights honoured immediately |
| Matching from your own LinkedIn connections | Consent (Art. 6(1)(a)) - the "recommendations from my network" purpose, revocable any time |
| Marketing emails (newsletter, promotions) | Consent (Art. 6(1)(a)) - opt-in only |
| Cookies in the analytics / marketing categories | Consent (Art. 6(1)(a)) - PECR Reg. 6 |
| Operating team workspaces and communities you join or create (section 3.11) | Contract (Art. 6(1)(b)) - sharing within the team or community is the feature itself; roles, permissions and opt-ins limit who sees what |
| Receiving and structuring product feedback you send through the feedback agent (section 3.12) | Consent (Art. 6(1)(a)) - recorded before your first message and withdrawable at any time; sharing your name with a report is a separate opt-in. Keeping the de-identified notes and cross-reporter patterns afterwards: legitimate interest (Art. 6(1)(f)) - they no longer identify you |
| Abuse prevention on the public feedback form (section 3.12) | Legitimate interest (Art. 6(1)(f)) - a one-way hash of the IP address kept for 24 hours, plus submission caps |
| Operating the referral and affiliate programme (section 17) | Affiliates: contract (Art. 6(1)(b)) - the Affiliate Programme Terms you accept when you join. Attribution and purchase facts of referred users: legitimate interest (Art. 6(1)(f)) - operating and auditing the programme, disclosed at sign-up and checkout. Fraud checks on referrals: legitimate interest (Art. 6(1)(f)). Commission and payout records: legal obligation (Art. 6(1)(c)) - six-year financial-record rule |
| Retaining financial records 6 years | Legal obligation (Art. 6(1)(c)) - UK HMRC rule |
| Notifying the ICO of a personal data breach | Legal obligation (Art. 6(1)(c)) - Art. 33 |
6. How long we keep it
- Account profile, messages, posts: until you delete your account, OR 3 years of inactivity (no login), whichever comes first. Inactive accounts are anonymised automatically by the retention scanner.
- Financial records (invoices, payment history): 6 years from the end of the relevant tax year (UK HMRC requirement). Personal data on those records is wiped at the 6-year boundary by the retention scanner.
- Consent logs: until you delete your account; anonymous (non-logged-in) consent records are pruned after 24 months.
- Breach register entries: 6 years from detection (ICO retention practice), deleted automatically by the retention scanner; contents are encrypted at rest and affected accounts are recorded only as irreversible hashes.
- Internal audit logs (records of administrative actions on accounts): 7 years, deleted automatically by the retention scanner; contents are encrypted at rest.
- PHI access log (HIPAA-enabled workspaces only): at least 6 years from each entry (HIPAA §164.316(b)(2) - a legal obligation, so it is not erased when an account is deleted or anonymised). It records only who accessed what and when - never the health information itself - and once your account is anonymised its entries no longer identify you. It is available to the responsible Covered Entity or Business Associate and to regulators on request.
- Imported leads (non-users): retained for as long as they remain relevant to the matchmaking purpose described in section 3.4, subject to periodic review of continued relevance - and erased immediately, in full, whenever a lead asks us to (see section 7.1) or objects under Article 21.
- Your imported LinkedIn connections: until you revoke the "recommendations from my network" purpose, disconnect LinkedIn, or delete your account - whichever comes first. Erasure is immediate, not scheduled.
- Inbound comments/messages on your connected accounts (section 3.9): kept for the lifetime of that platform connection - they power your Auto-Replies page (each comment or message is shown together with its drafted reply, encrypted at rest) and prevent the same item from ever being answered twice. Disconnecting the platform, a platform-side deauthorisation, a platform data-deletion request, or deleting your account erases them all immediately - the items and the drafts alike.
- Writing-style learning data (section 3.10): until you disconnect the connected account it was learned for (erasure is immediate), or delete your account - whichever comes first.
- Voice-note transcripts, media-generation records and queued story/plan media: voice-note transcripts are part of your chat history, and media-generation records are kept as billing evidence - both are erased when you delete your account. The queue of a recurring plan (a recurring posting schedule that attaches or generates media for each run) is shorter-lived: removing the plan immediately clears its standing generation consent, its rotation, its topic brief and its queue of not-yet-used media - a queue is never carried over to a later plan - and disconnecting the platform removes it too. Files you shared in chat remain in your encrypted storage until your account is deleted, when they are purged.
- De-identified improvement data (section 3.10): the generalised lesson text - approved by you on paid plans, or submitted automatically on the Free plan - is fully de-identified before it is stored, so it is no longer personal data; it belongs to the common improvement pool for all users and is not deleted when an account is deleted (the internal record of which account submitted it is removed at deletion).
- Team and community records (section 3.11): records that belong to a team (team-workspace content, shared connector data, team training data, ledger and audit entries) live for the life of the team - leaving removes your access, not the team's records. Teams you own are transferred or deleted when your account is deleted.
- Feedback agent (section 3.12): your feedback conversations, attachments, the original wording of a form submission, any shared name or e-mail address, and the link between a report and your account are kept for 24 months from the report, then wiped (or earlier, when you delete your account). The de-identified structured notes and the cross-reporter patterns are kept as product records after that, as they no longer identify anyone. Feedback consent records follow the consent-record rule above. The one-way hash of the IP address used to limit abuse of the public form is kept for 24 hours.
- Referral and affiliate programme (section 17): referral codes, the payout country, waitlist entries and the affiliate account itself are deleted with your account. Commission and payout records are financial records: 6 years from the end of the relevant tax year, in pseudonymised form once the account is deleted, then removed by the retention scanner. Attribution records lose their link to an account when that account is deleted. Daily click totals per code contain no personal data.
7. Your rights
Under UK GDPR / EU GDPR Articles 15-22 you have the following rights. Most of them are self-serve at /account/privacy.
- Article 15 - Access: click "Download my data" to receive a JSON file of everything we hold about you, with property keys obfuscated and internal references hashed.
- Article 16 - Rectification: edit your profile fields directly on the platform.
- Article 17 - Erasure ("right to be forgotten"): click "Delete my account". Requires your password + typing DELETE for confirmation. Your personal data is erased or irreversibly anonymised across our systems, including matchmaking profiles, imported connections, calendar links, voice transcripts, media-generation records and agent learning data. What remains: financial records (retained-but-anonymised per the 6-year rule), de-identified connection counts, and the tamper-evident PHI access log where HIPAA applied (6-year legal retention). Generalised improvement lessons (section 3.10) are separate from your account data: once submitted they are fully de-identified and belong to the common improvement pool for all users, so they are not connected to your account and are not deleted with it - deleting your account removes our internal record of which account submitted them.
- Article 18 - Restriction of processing: click "Pause agent activity" - all four AI agents pause immediately: the Matchmaking AI stops recommending you and to you, the Auto-Posting AI stops drafting, the Auto-Replying AI stops reading and answering your inboxes, the Network-Boosting AI stops engaging (and other members' agents stop engaging with your posts), and emails driven by agent activity stop with the agents. Account and security emails always go through, and notifications about other people's activity (messages, meetings, connection requests) continue according to your notification settings. You can resume at any time; paused windows are not replayed.
- Article 20 - Portability: the same JSON file from Article 15 is machine-readable and portable.
- Article 21 - Object: turn off marketing categories in your email preferences; this also acts as Article 21 opt-out for direct marketing. You may also object, on grounds relating to your particular situation, to any processing we base on legitimate interests (section 4) by emailing privacy@partnerme.net; we will stop that processing unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims (Article 21(1)).
- Article 22 - Automated decision-making: our AI recommendations and content drafting are not "solely automated" decisions with legal or similarly significant effects within the meaning of Article 22. By default every draft (post, reply, boost) is created in "draft" status and requires your approval before publishing. If, after training it through assisted drafts, your edits and your feedback, you explicitly switch an individual agent - or, for network boosting, an individual engagement method - to autonomous mode on the Autonomy page, its drafts publish without per-item review; that is your standing instruction, you can switch back to assisted or manual mode at any time, and every published item remains visible and attributable on the relevant agent's page (Auto-Posting, Auto-Replies, or the Network Boost page for engagement drafts). If you want to opt out of profiling-based recommendations entirely, use the Article 18 pause toggle.
- Right to complain (Article 77): you can complain to the UK Information Commissioner's Office or your local EU supervisory authority at any time, without contacting us first.
7.1 If you are a lead (not a PartnerMe AI user)
If your public professional profile (for example LinkedIn or Instagram) was imported into PartnerMe AI as a lead (section 3.4) you hold the same rights, even though you have no account. Within one month of your request (Articles 12(3), 14, 15, 17, 21) we will: confirm whether we hold a lead record for you, send you a copy of it, erase it entirely on request, and/or stop suggesting you to our users. Erasure removes your profile record and every interaction record referencing it. You can reach us through any of these channels:
- Fastest - message us from the profile itself: send a direct message to our official LinkedIn company page or our official Instagram page from the profile you want removed on that network. Because the message arrives from the exact profile our lead record points at, your identity is verified instantly and we can erase the record without asking you for anything else.
- Email: write to privacy@partnerme.net citing your public profile URL. Because an email address is not linked to any lead record we hold (we never store lead email addresses), we may need to ask for reasonable additional information to verify that you are the person behind that profile (Article 12(6)) before we erase it.
We do not hold any private contact channel for leads, so we act on these requests when you contact us; this section serves as our Article 14 transparency notice.
8. How we secure your data (Article 32)
- PII columns are encrypted at rest with AES-256-GCM (envelope encryption) - emails, names, profile fields, OAuth tokens, support tickets, inbound comment/message text and sender names (section 3.9), draft replies, your style-learning content (section 3.10), and every text field of a feedback report including any contact details you choose to share (section 3.12).
- Passwords are bcrypt-12 one-way hashes, never stored in cleartext.
- Lookup hashes (SHA-256-HMAC) are used to query encrypted columns without decrypting.
- HTTPS everywhere; a two-year HSTS policy (includeSubDomains, preload-ready) is served in production.
- Multi-factor authentication is required for administrators and offered to all users.
- Sessions are bound to httpOnly + Secure + SameSite=Lax cookies; tokens stored as SHA-256 hashes server-side.
- User-to-user direct messages are end-to-end encrypted (MLS, RFC 9420) - our servers relay only ciphertext they cannot read. Ingested social DMs are sealed with hybrid post-quantum encryption (X25519 + ML-KEM-768) before storage.
- PII is scrubbed from log records before they leave the process; logs for the auto-reply and style-learning pipelines carry only event counts, providers and internal ids - never message text, sender names or content.
- Secrets live only in a locked cloud key vault; deployments authenticate with short-lived workload identities (no long-lived cloud credentials), and each AI agent reaches the database through its own least-privilege role.
- Databases and internal services run on a private virtual network, not the public internet.
- Security-relevant access is recorded on tamper-evident, hash-chained audit logs with automated integrity verification, and automated alerts watch our logs for accidental credential leaks.
- Service-to-service calls between our AI agents are cryptographically signed and replay-protected.
- Ongoing dependency-vulnerability monitoring across all our repositories, with continuous internal security review.
9. Personal data breaches (Articles 33 + 34)
If we detect a personal data breach we will notify the UK Information Commissioner's Office within 72 hours of becoming aware, where the breach is likely to result in a risk to your rights and freedoms (Article 33). Where the risk is "high", we will also notify the affected data subjects directly without undue delay (Article 34).
10. Children's data
PartnerMe AI is not directed at children. We require all users to be 18 or over and enforce this at signup via a date-of-birth check and a checkbox affirmation. See the standalone Children's Policyfor details and the contact path if you believe an under-18 has signed up.
11. International transfers
Some of our processors are based outside the UK / EEA. Where we transfer your personal data internationally we rely on UK adequacy decisions, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses (SCCs), or the EU SCCs alone. See the full International Transfers notice.
12. California (CCPA / CPRA) notice
For California residents, in addition to the GDPR rights above:
- You have the right to know what categories of personal information we collect, the purposes, and who we share with - covered above.
- You have the right to delete - same flow at /account/privacy.
- You have the right to correct.
- You have the right to opt out of "sale" or "sharing" - PartnerMe AI does not sell or share your personal information, as those terms are defined by the CCPA / CPRA: we run no advertising, and our only analytics (Google Analytics) is consent-gated and configured with all advertising features disabled, IP anonymisation on, and service-provider terms. The "Do Not Sell or Share My Personal Information" toggle in our cookies banner exists as a guarantee anyway - switching it on keeps analytics off entirely, regardless of any other choice.
- You have the right to limit the use of sensitive personal information.
- You have the right to non-discrimination for exercising any of the above.
13. Canada (PIPEDA) notice
For Canadian residents, we follow the Personal Information Protection and Electronic Documents Act (PIPEDA). You can contact us at privacy@partnerme.net to access, correct, or challenge our compliance. The federal regulator is the Office of the Privacy Commissioner of Canada.
15. Changes to this notice
We update this notice as the Service and the law evolve, and - as with clause 18 of the Terms of Service - notice is proportionate to impact: (i) changes that materially reduce your rights or protections under this notice are announced by email and an in-app banner at least thirty (30) calendar days before they take effect; (ii) other material changes - including any new processing purpose or a change of lawful basis - are announced the same way at least fourteen (14) calendar days in advance, and where the new processing relies on your consent we ask for that consent before the processing begins rather than merely notifying you; (iii) where a change affects your cookie choices, the cookies-consent banner version is also bumped so you re-confirm them; and (iv) non-material changes (clarifications, typo fixes) take effect when posted, with the dates and document version at the top of this page updated. Where a change is required by law or by a regulator, a shorter notice period may be unavoidable. Earlier versions of this notice are preserved in our document version history and are available on request.
16. HIPAA & Protected Health Information
Protected Health Information ("PHI", as defined under the U.S. Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, "HIPAA") is prohibited by default and is processed only inside a HIPAA-enabled workspace operating under a signed, active Business Associate Agreement (the "BAA"). HIPAA is enabled per workspace - each Team and your personal account is governed independently - at /account/hipaa. Where a workspace is HIPAA-enabled, we process PHI only as needed to provide the features you use (for example in-app messages, AI auto-replies, AI matchmaking, the AI assistant, and voice-note transcripts) and only as permitted by the BAA, on a minimum-necessary basis; what PHI you handle and where, including through platforms you connect, is your decision under your own HIPAA obligations. You can review the in-product BAA at /baa.
We protect PHI in HIPAA-enabled workspaces with safeguards including:
- encryption in transit and at rest, plus field-level encryption of designated PHI fields and end-to-end encryption for user-to-user direct messages;
- routing of all AI operations in a HIPAA-enabled workspace only to a BAA-covered AI model - our default model is not BAA-eligible and never serves a HIPAA-enabled workspace, and AI fails closed (refuses) if a covered model is unavailable (outside a HIPAA-enabled workspace the default model serves all requests, which is why PHI must not be submitted there); this includes the feedback agent (section 3.12), whose reports from a HIPAA-enabled workspace are additionally kept out of cross-reporter patterns and whose identity reveals are audited separately;
- multi-factor authentication required for access to HIPAA-enabled workspaces, with PHI processing denied by default outside them;
- a tamper-evident PHI-access audit log whose integrity we verify on a recurring basis.
PHI is never used for marketing, advertising, AI model training or fine-tuning, analytics, profiling, or product improvement. It is used solely to provide the Service to you and as permitted by the BAA. Individual PHI rights (access, amendment, restriction, and accounting of disclosures) are the responsibility of our customer as the Covered Entity (or applicable Business Associate); if an individual contacts us directly about PHI, we route the request to the relevant customer and assist as the BAA provides, rather than responding to the individual ourselves. Subprocessors that may process PHI on our behalf are limited to those with appropriate BAA coverage - only BAA-covered providers and models supplied through Azure - and are disclosed in our processor register (section 5); our default non-BAA AI model never receives PHI from a HIPAA-enabled workspace. Platforms you connect (for example LinkedIn or Instagram) are not our subprocessors: whether PHI is sent or published through them is your decision and your own HIPAA responsibility, including any individual authorisations those disclosures require. With respect to PHI, the BAA controls over this Privacy Policy to the extent of any conflict.
17. Referral and affiliate programme
Our Refer & earn programme lets a user (an "affiliate") share a referral code. A person who signs up with it (a "referred user") receives a discount on the first invoice of an annual Plus or Team plan, and the affiliate earns a commission on that invoice. The Affiliate Programme Terms govern the programme; this section explains the personal data involved.
17.1 What we process
- About affiliates: the referral code (and any retired codes), the country you chose for payouts, your Stripe account identifier and the setup status Stripe reports to us, your acceptance of the Affiliate Programme Terms (version and time), your commission and payout records (amounts, dates, statuses and Stripe references), and programme statistics: clicks on your link counted as daily totals (no IP address or device details are recorded), sign-ups and conversions.
- About referred users: the attribution - which code was used, when it was captured, and whether it came from the referral link, the registration field or checkout - and the purchase facts needed to calculate the commission: the plan bought, the date and the amount paid. A referral link stores the code in your browser for 30 days so that it can be applied when you register.
- Never stored by us: bank details. Stripe collects the identity, business and bank details that payouts require on its own forms; we receive only an account identifier and status signals.
17.2 Why, and on what lawful basis
- Running the programme for affiliates - issuing codes, calculating and paying commission, showing balances and statements: contract (Article 6(1)(b)), the Affiliate Programme Terms you accept when you join.
- Attributing referred users and calculating commission: legitimate interest (Article 6(1)(f)) in operating and auditing the referral programme. Referred users are told at sign-up and at checkout that the code is recorded, and the processing is limited to the facts above.
- Preventing fraud- checks for self-referral and for payment cards matching the affiliate's, and review of chargebacks: legitimate interest (Article 6(1)(f)) in keeping the programme honest.
- Keeping commission and payout records: legal obligation (Article 6(1)(c)) - they are financial records under the six-year HMRC and Companies Act 2006 rules.
17.3 Who sees what
- Affiliates never see referred users' personal data.An affiliate's dashboard shows counts, the plan, the date and the amount of each conversion - never a name, an email address or any other identifying detail.
- Referred users see which code was applied to their account and the discount it gives.
- Stripe(Stripe Payments Europe, Limited and Stripe Payments UK, Ltd) processes affiliate payouts for us as a processor and is an independent controller of the identity, business and bank details it collects for its own know-your-customer, anti-money-laundering and tax obligations, under Stripe's own privacy policy. Stripe's transfer safeguards are described in section 5 and in the International Transfers notice.
- Our administrators can see the full programme records, including which affiliate referred which user, behind administrator authentication, with every action recorded in our audit log.
17.4 How long we keep it
- Referral codes, the payout country, waitlist entries and the affiliate account itself: until you delete your account; they are deleted with it.
- Attribution records: the link to an account is removed when that account is deleted - the referred user's or the affiliate's - and what remains identifies nobody.
- Commission and payout records: six years from the end of the relevant tax year, as financial records, in pseudonymised form once the account is deleted, then removed by the retention scanner.
- Programme statistics: daily click totals per code, which contain no personal data.
Your rights in section 7 apply to all of this. You can object to the attribution processing on grounds relating to your particular situation by emailing privacy@partnerme.net; if we stop it, the referral discount can no longer be applied and no commission arises from your purchases.
