This notice explains which personal data OpenBridge processes, why, and which rights you have under the General Data Protection Regulation (GDPR). It describes the service as it is built today and must be completed and reviewed before launch.
1. Controller
[Company legal name, address, contact email]. Data protection officer, if appointed: [name and contact, or a statement that none is required].
2. Data we process
- Account data: email address, a salted password hash, sign-in sessions, the version and time of the Terms and Privacy Notice you accepted.
- Conversation data: the prompts you write, the replies you receive, the model used and timestamps.
- Usage records: for each request, the provider and model, token counts, an estimated cost, status, latency and a request ID. We do not log your prompt text in these records.
- Billing data: Stripe customer and subscription IDs, plan, payment status and billing period. Card details are handled by Stripe and never reach our servers.
- Technical data: IP address and browser data in server logs for security and abuse prevention.
3. Purposes and legal bases
- Providing the service and your account: Art. 6 (1) (b) GDPR (contract).
- Billing and tax records: Art. 6 (1) (b) and (c) GDPR.
- Security, abuse and cost protection, quota enforcement: Art. 6 (1) (f) GDPR (legitimate interest in a secure and sustainable service).
OpenBridge does not use your conversations to train AI models and does not sell personal data.
4. AI providers that receive your prompts
When you send a message, your prompt and the conversation context are transmitted only to the provider of the model you selected, through its official API:
- OpenAI (OpenAI): [legal entity, country, data processing agreement status, transfer mechanism, provider retention period]
- Anthropic (Claude): [legal entity, country, data processing agreement status, transfer mechanism, provider retention period]
- Google (Gemini): [legal entity, country, data processing agreement status, transfer mechanism, provider retention period]
- Mistral AI (Mistral): [legal entity, country, data processing agreement status, transfer mechanism, provider retention period]
- Octodus (Octo): [legal entity, country, data processing agreement status, transfer mechanism, provider retention period]
Some providers are located outside the EU or EEA. Transfers rely on [EU-US Data Privacy Framework certification or Standard Contractual Clauses, per provider].
5. Other processors
- Hosting and database: [hosting provider, data centre location]
- Payments: Stripe Payments Europe, Ltd. [confirm entity and agreement]
- Email delivery for verification and password reset: [email provider, if used]
6. Retention
Conversations are deleted automatically after 30 days (a setting the operator controls), or earlier when you delete them or your account. [confirm the final retention period]. Usage and billing records are kept as long as required for billing and statutory retention duties ([e.g. up to 10 years for accounting records under German law]).
7. Cookies
We use one strictly necessary session cookie to keep you signed in and protect forms. There is no advertising or analytics tracking. See Cookie settings.
8. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection (Art. 15 to 21 GDPR), and the right to withdraw consent at any time. To delete your account and data, use the deletion request. You may lodge a complaint with a supervisory authority, for example [competent German state data protection authority].