GDPR Compliance

The General Data Protection Regulation (GDPR) defines how personal data must be handled for individuals and organisations in the European Union (EU) and European Economic Area (EEA). GetMyAI processes personal data in accordance with GDPR requirements, with a practical focus on lawful processing, accountability, and responsible data handling based on current platform capabilities.

This page provides a high-level overview. Detailed information is available in the supporting documentation.

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Access your personal data
  • Correct inaccurate information
  • Request data deletion
  • Restrict specific processing
  • Receive portable data
  • Object to certain processing

Requests can be submitted to support@getmyai.ai and are handled within applicable regulatory timelines.

Our GDPR Measures

  • Data Minimisation
  • Only data required to operate and support the platform is collected.

  • Purpose Limitation
  • Data is processed only for defined, service-related purposes.

  • Storage Limitation
  • Data is retained based on plan and operational requirements.

  • Transparency
  • Clear information is provided about how data is processed and protected.

How We Process Data

Depending on the context, GetMyAI may act as a controller or processor when operating as a business AI chatbot for organisations.

  • Data Controller
  • Account management, authentication, billing, and platform administration.

  • Data Processor
  • Processing customer-submitted data on behalf of organisations under contractual terms.

Where applicable, processing responsibilities are governed by contractual terms.

Types of Data We Handle

Based on platform usage, GetMyAI may process:

  • Account and user information
  • Platform usage and interaction data
  • Support and communication data

This data is used only to operate the service, provide support, maintain security, and meet legal or contractual obligations. Personal data is not sold or shared for unrelated purposes.

Enterprise & AI Data Handling

  • Organisational data isolation
  • Enterprise data is logically separated within a multi-tenant architecture, supporting organisations that require a secure AI chatbot for regulated business environments.

  • Controlled access
  • Access to data is restricted to authorised personnel only, helping maintain a trusted AI chatbot for customer-facing use.

  • AI usage boundaries
  • Data provided to AI models is used solely to generate requested outputs, supporting strong AI agent privacy, and is not used to train shared or global models.

Data Retention Overview

Data retention depends on the service plan:

  • Free plans: Data deleted after 14 days of inactivity
  • Paid plans: Data retained during subscription and up to 60 days after expiry
  • Support communications: Retained for service and compliance purposes

Deleted data is removed from backups within 7 days, subject to legal obligations.

Security Safeguards

GetMyAI applies technical and organisational measures to protect personal data, including:

  • Encryption in transit and at rest
  • Role-based access controls
  • Secure authentication mechanisms
  • Monitoring and logging
  • Periodic security reviews

International Data Transfers

Customer data is hosted on AWS infrastructure located in the United States (us-east-1). Where data is processed outside the EU or EEA, transfers occur through established cloud providers with appropriate safeguards.

Transparency & Ongoing Updates

Our compliance information is reviewed and updated as regulatory requirements, product capabilities, or operational practices change. This approach helps organisations adopt a trusted AI chatbot while maintaining transparency and regulatory alignment.

Learn More About Our Compliance Practices

For detailed information about how GetMyAI manages data protection, security, and regulatory responsibilities, access our full compliance documentation or contact our team.

Contact Our Team

Questions about data protection, security, or compliance?