Loading…
Loading…
DRAFT FOR PRODUCT PREVIEW — not legal advice and not a binding agreement. Pending counsel, operating-entity designation, and partner review. Mandatory consumer and data-protection rights are not waived.
This Privacy Notice explains how the MyInstantAI Agent Marketplace (“MyInstantAI”, “we”, “us”, “the platform”) processes personal data when you visit our sites, create or join a workspace, rent or configure AI agents, use Studio / embed / App / WhatsApp / Ask AI channels, or connect third-party Actions (OAuth integrations).
It applies to visitors, workspace members, and end users who interact with agents you deploy. It does not cover third-party sites you link to (Shopify, Slack, Zendesk, Stripe, LLM providers, etc.) — those have their own policies.
Controller / processor roles depend on your commercial arrangement (self-serve marketplace vs partner-hosted). Until counsel confirms the operating entity per region, treat role allocations as provisional.
Operating entity, registered address, and designated Information Officer / DPO: TBD — to be published when the contracting entity is confirmed for each market (including South Africa POPIA registration where required).
Product contact for privacy requests during the draft period: your partner / MyInstantAI support channel, quoting your workspace id and a clear description of the request.
Related internal drafts (not customer contracts): Record of Processing Activities, DPIA skeleton, breach runbook, and DPA/BAA templates maintained for assurance evidence.
Account & workspace: user identifiers, display names or emails you supply, workspace id, role/membership (readonly, agent, admin, owner), authentication mode metadata (mock staging headers vs OIDC claims when enabled).
Commercial & metering: rental / subscription state, token or wallet balances and top-up events (no payment card PAN stored in chat or our primary app DB — card data is handled by Stripe or your wallet provider).
Agent configuration: agent package ids, model settings, knowledge documents and pasted text you upload, crawled page text you request, tool/Action bindings.
Conversations & ops: chat messages, session ids, correlation ids, channel (web, embed, app, WhatsApp, Ask AI), guardrail/safety events, rate-limit signals, and append-oriented audit events.
Integrations: OAuth access and refresh tokens (encrypted at rest), provider metadata (e.g. Slack team, Shopify shop host, Zendesk subdomain), webhook delivery logs necessary for debugging.
Leads & requests: optional name, email, and message content when you submit Ask AI leads or custom agent requests.
Technical: IP address and user-agent as processed by our hosting providers and edge logs; theme, locale, and consent preference in browser storage.
We do not intentionally collect special-category data (health, biometrics, etc.) as a product feature. If you upload such data into knowledge or chat, you are responsible for having a lawful basis and appropriate safeguards.
Directly from you when you register, configure agents, chat, upload knowledge, connect Actions, or contact support.
Automatically from your browser or app (session, consent, device/browser metadata, security logs).
From third-party providers when you authorise OAuth connectors or when LLM providers return model outputs based on prompts you send.
From your organisation’s administrators if they invite you into a workspace or configure agents on your behalf.
Provide and operate the marketplace, agent runtime, embedding, and metering — typically contract / steps prior to contract (TBD counsel).
Secure the service (authentication, RBAC, SSRF controls, webhook HMAC, rate limits, abuse prevention, audit) — typically legitimate interests or legal obligation (TBD).
Improve reliability and safety (guardrails, evaluation, incident response) — legitimate interests (TBD); we will not use your private workspace content to train public foundation models unless a separate agreement says otherwise.
Respond to data-subject and enterprise requests (access, export, erasure) — legal obligation / contract (TBD).
Optional analytics and product measurement only after consent where required — consent (see Cookies notice).
Sales follow-up on Ask AI / custom requests — consent or legitimate interests (TBD).
You interact with an AI system. Prompts and retrieved knowledge may be sent to a configured model provider (OpenAI, Anthropic, or a partner gateway) to generate replies and tool calls.
Live paths may apply input/output guardrails and PII redaction hooks before storage or display; these reduce risk but are not a guarantee that sensitive data never appears in logs or model contexts.
Confirm-before-write and human handoff are available for side-effecting Actions. You remain responsible for what your agents are authorised to do in third-party systems.
EU AI Act transparency: we disclose AI-system interaction in product UI (chat/embed/Trust). High-risk classifications, if any, will be assessed per use case with counsel — we do not claim conformity assessment completion in this draft.
Hosting & data stores: e.g. Railway (staging), Microsoft Azure (production path when cut over), managed Postgres, optional Redis/Upstash for rate limits and sessions.
Model inference: LLM providers or partner gateway under your configured model mode.
Payments: Stripe or partner wallet — we do not store PAN in chat.
OAuth vendors you connect (Slack, Google, Microsoft, Shopify, HubSpot, Zendesk, etc.) receive authentication and API traffic you authorise.
Professional advisors, auditors, or authorities where required by law.
We do not sell personal data. A current subprocessor narrative is maintained in Trust / compliance documentation and will be attached to customer DPAs when executed.
Staging may run outside the EU/EEA (e.g. Railway US). LLM inference may occur in the provider’s regions. Production Azure region pinning and SCCs / adequacy / supplementary measures: TBD per customer DPA.
Until residency commitments are signed, do not assume EU-only processing. Honest status labels appear in the Trust Center.
Workspace operational data: retained while the workspace is active and for a wind-down period after closure (exact days TBD counsel).
Chat transcripts and knowledge: until deleted by an authorised admin, superseded, or erased under a DSAR / managed erasure job.
Audit events: append-oriented; practical caps may apply in storage — policy TBD (see audit retention docs).
OAuth tokens: until you disconnect the connector or the workspace is erased.
Consent preference in the browser: until cleared or overwritten.
Backups and logs held by subprocessors follow their schedules and our deletion instructions once production backup policy is finalised (TBD).
Technical measures include TLS in transit, encrypted OAuth tokens at rest, production boot hardening (strong secrets, mock-rail dual acknowledgments, Postgres required unless dual file-fallback ACK), outbound URL safety for connectors, webhook HMAC signatures, zod validation and body-size limits on key APIs, CSP (with documented residuals), and optional distributed rate limiting.
Organisational measures (access control, breach process, vendor review) are being formalised; see the draft breach-72h runbook and Trust Center. No SOC 2 / ISO certificate is claimed in this draft.
Depending on GDPR, UK GDPR, POPIA, CCPA/CPRA, and other applicable laws, you may have rights to access, rectify, erase, restrict, object, portability, and to withdraw consent.
Workspace owners/admins can initiate a structured DSAR export (JSON pack excluding OAuth secrets) and request managed workspace erasure (audit tombstones may remain).
End users of a customer’s agent should contact that customer (controller) in the first instance; we will assist the customer as processor where applicable.
You may lodge a complaint with a supervisory authority in your jurisdiction (e.g. Information Regulator of South Africa, EU DPA, ICO). Contact details TBD once the operating entity is designated.
The marketplace is directed at business users. We do not knowingly offer the service to children. If you believe we have collected a child’s data inappropriately, contact support for deletion.
We will update the “Last updated” date when this draft changes. Material changes before customer cutover will be communicated through the product or your partner channel. Binding privacy terms will appear in the executed DPA / MSA.
Privacy / DSAR: partner or MyInstantAI support — include workspace id, requester role, and the right you wish to exercise.
Security vulnerabilities: see SECURITY.md (private reporting). Do not open public issues for exploitable findings.