Privacy Policy
Overview
At Subgen AI, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy is designed to help you understand how we collect and process your personal data when you use our Services.
Scope
This Privacy Policy does not apply where Subgen AI processes personal data on behalf of a Commercial Customer, as a Data Processor. In such cases, the Data Processing Agreement governs the processing of personal data by Subgen AI in its role as a Data Processor.
1. Definitions
The capitalized terms in this document will have the meanings below:
- Agreement: The service agreement between You and Subgen AI, which includes (i) the Terms of Use, (ii) applicable Additional Terms, and, where relevant, (iii) the Data Processing Agreement.
- Data Controller: The entity responsible for decisions regarding Your Personal Data, such as what data to collect, how it is processed, and how long it is retained.
- Data Processor: The entity processing Personal Data on behalf of the Data Controller under their instructions.
- Serenity* Platform: The online platform accessible at https://serenitystar.ai in SaaS mode, including all features and services provided therein.
- Personal Data: Any data that directly or indirectly relates to You.
- Processing: Any operation performed on Your Personal Data (e.g., collection, use, transfer, deletion).
- Services: All services provided by Subgen AI through Serenity* Star, including APIs, Agent Builder, and other platform functionalities.
- You or the Customer: Any individual or entity accessing or subscribing to the Services, referred to in this Policy as "You," "Your," or "Yours."
2. Who is the Data Controller?
2.1. Subgen AI as Data Controller
Subgen AI, registered in the United Kingdom under Company Number 15374966, serves as the Data Controller when processing Your Personal Data in connection with Serenity* Star.
You can contact us:
- By email: [email protected]
- By mail: Subgen AI, Attn: Privacy Team, 100 Avebury Boulevard, Milton Keynes, MK9 1FH, United Kingdom
2.2. Subgen AI as Data Processor
If You are a Commercial Customer, Subgen AI may also process Personal Data on Your behalf as a Data Processor. In such cases, these activities are described in the applicable Data Processing Agreement. This Privacy Policy only covers Subgen AI's Processing activities as a Data Controller.
3. What Kind of Personal Data Do We Collect?
3.1. Personal Data We Collect Directly from You
- Identity, Account, and Contact Data: When You create an account or subscribe to Services.
- Payment and Billing Information: Collected when You subscribe to Paid Services.
- Inputs and Feedback: Any data you provide while using our Services.
3.2. Personal Data Generated by Your Use of Our Services
- Technical Data: Including cookies and security logs, subject to Your consent where required.
- Outputs: Generated content that may include Personal Data depending on the nature of Your Inputs.
3.3. Personal Data Indirectly Provided to Us
Our AI models are trained on publicly available data, which may incidentally include Personal Data despite efforts to filter it out.
4. Why Do We Use Your Personal Data?
We use your Personal Data for the following purposes:
- Provide Our Services: To create and manage your account, respond to your Inputs, generate Outputs, and handle support requests.
- Administration and Security: To manage and secure the platform and communicate with You regarding non-marketing purposes.
- Develop and Train Models: To improve AI models while ensuring data is anonymized and de-identified.
- Marketing: To send newsletters and promote Services.
- Compliance and Dispute Resolution: To comply with legal obligations and manage disputes.
5. How Long Do We Store Your Personal Data?
We retain Personal Data for as long as necessary to achieve the purposes outlined in this Privacy Policy. For example:
- Account Data: Retained during Your active subscription and up to 1 year post-termination for evidence purposes.
- User Data: Retained as needed for service functionality or up to 30 days for monitoring abuse, unless You opt out.
6. Who Do We Share Your Personal Data With?
We share Personal Data only with:
- Authorized team members.
- Third-party service providers under strict contractual obligations (e.g., Azure, Google Cloud Platform, Stripe).
- Regulatory authorities or legal bodies as required by law.
We may also share all or part of Your Personal Data with Our providers. Before engaging with any provider, we conduct audits to assess their privacy and security standards .
Our main providers are:
- Azure
- Purpose: Cloud Infrastructure
- Data location: France
- Google Cloud Platform
- Purpose: Cloud Infrastructure
- Data location: Ireland
- Google Cloud Platform
- Purpose: Cloud Infrastructure for the US version of Our APIs
- Data location: United States
- Sendgrid
- Purpose: Mailing
- Data location: United States
- Stripe
- Purpose: Payment management
- Data location: United States
7. Do We Transfer Your Personal Data Outside the EU?
Subgen AI prioritizes providers within the EU but ensures compliance with GDPR standards when engaging non-EU providers. Safeguards, such as the European Commission’s Standard Contractual Clauses, are implemented for international transfers.
8. Your Rights
You have the right to:
- Access, rectify, delete, or restrict the processing of Your Personal Data.
- Object to processing or withdraw consent at any time.
- Data portability and complaint filing with data protection authorities.
9. Changes to This Privacy Policy
This Privacy Policy may evolve to reflect changes in our Services or regulations. Please review it regularly.
For questions, contact us at [email protected].