This Privacy Policy explains how the GramForge operating company (“GramForge”, “we”) handles personal data when you visit our websites (gramforge.io and gramforge.dev), join early access, create an account or use our service (the “Service”). It is written to meet the EU and UK General Data Protection Regulation (“GDPR”) and other applicable privacy laws.
1. Who is responsible
For data about our website visitors, early-access members and customers, GramForge is thecontroller. Contact: privacy@gramforge.io.
For data about the clients and subscribers of our customers (“End Users”) — people who talk to an assistant or read a channel run through GramForge — our customer is the controller and GramForge acts as a processorunder our Data Processing Terms. If you are an End User, please contact the business whose assistant you used; we will help them answer your request.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Contact and account data | Email address, name, password hash, language, time zone | You |
| Business information | Description of your work, services, prices, schedule, texts, files and knowledge base you provide | You |
| Telegram data | Your Telegram user ID and username; your assistants' access tokens (stored encrypted); channels you connect | You, Telegram |
| Billing data | Plan, invoices, billing country, payment status. Card numbers are handled by our payment provider and never reach us | You, payment provider |
| Usage and technical data | IP address, browser and device type, pages visited, actions in the dashboard, error logs, usage counters | Automatically |
| Communications | Support requests, feedback, survey answers, interview notes (with your agreement) | You |
We do not ask for special categories of personal data about you. Please do not include such data in your business description unless it is needed.
3. Why we use it and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Managing the early-access list and inviting you | Consent, which you can withdraw at any time; and our legitimate interest in prioritising invitations |
| Creating your account and providing the Service, including AI generation, hosting and support | Performance of a contract |
| Billing, accounting and tax records | Performance of a contract; legal obligation |
| Security, fraud and abuse prevention, enforcing our Terms | Legitimate interests; legal obligation |
| Improving the Service using aggregated usage statistics | Legitimate interests |
| Product news and offers by email | Consent, or legitimate interest for existing customers where permitted; you can unsubscribe in every email |
We do not sell your personal data, and we do not use it for targeted advertising by third parties.
4. AI processing
To generate assistants, replies and posts, we send the relevant business information and conversation context to AI model providers acting as our sub-processors. Their terms do not allow them to use this data to train their models. We do not use your data or End User data to train AI models, and we do not make decisions that produce legal or similarly significant effects about you solely by automated means.
5. Who we share it with
We share personal data only with service providers that process it on our behalf under written contracts, and only as needed:
| Sub-processor | Purpose | Location |
|---|---|---|
| Fornex Hosting S.L. | Server hosting and backups | Germany (EU) |
| Anthropic, PBC | AI model processing | United States |
| Payment provider (to be named before paid plans open) | Payments, invoicing, tax | — |
| Email delivery provider (to be named before launch emails are sent) | Sending service and account emails | — |
Messages between assistants and End Users travel through Telegram, which processes them as an independent controller under its own privacy policy. We may also disclose data where required by law or to protect rights and safety, and to a successor in a merger or acquisition, subject to this policy. We will update the list above before adding or replacing a sub-processor.
6. International transfers
Some providers are located outside the European Economic Area and the United Kingdom. When we transfer personal data to a country without an adequacy decision, we use the European Commission's Standard Contractual Clauses (and the UK Addendum) and additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
7. How long we keep it
- Early-access list: until you join the Service or withdraw, and no longer than 24 months after you signed up.
- Account and business data: for as long as your account is active, then 30 days to let you export it, after which it is deleted.
- End User data: as instructed by our customer, and deleted within 30 days after the customer's account ends.
- Backups: overwritten within 30 days.
- Security logs: up to 90 days.
- Billing and tax records: as long as required by law, typically up to 10 years.
8. Security
We encrypt data in transit (TLS) and encrypt assistant access tokens and personal data at rest. Access is limited to staff who need it, protected by strong authentication and logged. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as required by law.
9. Your rights
Depending on where you live, you have the right to:
- access your personal data and receive a copy;
- correct inaccurate data;
- delete your data;
- restrict or object to processing, including processing based on legitimate interests and direct marketing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting earlier processing;
- lodge a complaint with a data protection authority, in particular in the country where you live or work.
To use these rights, write to privacy@gramforge.io. We respond within one month and may need to verify your identity. California residents: we do not sell or share personal information as defined by the CCPA/CPRA and do not use sensitive personal information for purposes that require an opt-out; you may exercise the rights above, and we will not discriminate against you for doing so.
10. Cookies
Our marketing website does not use advertising or analytics cookies, and fonts are served from our own servers. The dashboard uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. If we add optional analytics, we will update this policy and ask for your consent where required.
11. Children
The Service is for businesses and professionals and is not directed to children. Customers must be at least 18. We do not knowingly collect personal data from children under 16 as customers.
12. Changes
We may update this policy. We will post the new version here with a new effective date and, for material changes, notify customers by email or in the dashboard in advance.
13. Contact
Privacy questions and requests: privacy@gramforge.io.