Privacy Policy
Last updated: 2026-08-03
1. Who we are
SupportAI is a customer support automation service. Throughout this policy, “SupportAI,” “we,” “us,” and “our” refer to the operator of the SupportAI website and platform.
SupportAI acts as the data controller for personal data collected through our public website, marketing interactions, account registration, and the billing relationship with customers.
For support tickets, chat transcripts, end-customer identifiers, and other business data submitted by our customers into the SupportAI platform, SupportAI acts as a data processor (or service provider) on behalf of that customer. In those cases, the customer is the controller and determines the purposes and means of processing. Our role is explained in more detail in Section 5.
We have not designated a Data Protection Officer unless required to do so by applicable law. For privacy-related inquiries, you may contact us using the methods described in Section 14.
2. Scope
This Privacy Policy applies to personal data we process in connection with:
- Website visitors and prospects individuals who browse ai4support.app, request a demo, submit a contact form, or otherwise interact with our marketing and sales materials.
- Customer account holders and users , individuals who create an account, log into the SupportAI platform, manage settings, or are added as team members by an account administrator.
- Support ticket and helpdesk data , personal data contained in support tickets, chat conversations, and associated metadata that our customers process through the SupportAI platform. This includes data pulled from integrated third-party systems such as helpdesks (Zendesk, Gorgias, Intercom, Freshdesk), ecommerce platforms (Shopify, WooCommerce), and knowledge bases.
- Integration and connected-platform data , personal data that flows into SupportAI through APIs and integrations configured by the customer.
This policy does not cover how our business customers handle personal data within their own organisations. Customers are responsible for their own privacy notices and lawful bases when they upload or connect data to the SupportAI platform.
3. Categories of personal data collected
We collect and process the following categories of personal data, depending on how you interact with us:
Contact and identity data
- •Name
- •Work email address
- •Company or organisation name
- •Job title or role
- •Phone number (if submitted via a form or call)
Account data
- •Login credentials (hashed passwords)
- •User role and permissions within a workspace
- •Workspace and account metadata (account name, team size, configuration settings)
Billing and transaction data
- •Billing contact name and email
- •Billing address, where provided
- •Invoice records and payment status
- •Payment provider transaction references (we do not store full payment card details)
Usage and technical data
- •IP address
- •Browser type and version
- •Device type and operating system
- •Timestamped log files
- •Feature interaction data and in-product diagnostics
- •Referring URL and pages visited on our website
Customer content
- •Support ticket text and metadata submitted by customers
- •Chat transcripts
- •File attachments included in tickets
- •Order references and support request identifiers
- •Internal notes added by customer users
- •AI-generated draft replies and automation outputs generated by the platform
Integration data
- •Personal data pulled from connected helpdesks, ecommerce systems, CRMs, or knowledge bases as configured by the customer
- •API access tokens and connection metadata (stored encrypted)
Communications data
- •Emails and messages sent to our support, sales, or privacy teams
- •Demo request and contact form submissions
- •Survey and feedback responses
Cookie and analytics data
- •Data collected via cookies and similar technologies on our website, where you have provided consent or where essential for the functioning of the site
- •Aggregated analytics about website usage
4. Purposes and legal bases
Under the GDPR, we must have a lawful basis for each purpose of processing. The table below sets out our processing purposes and the corresponding legal bases we rely on.
| Purpose | Lawful basis | Notes |
|---|---|---|
| Operating and securing our website | Legitimate interests | Ensuring website availability, security, and functionality |
| Responding to inquiries and demo requests | Legitimate interests / pre-contractual steps | Responding to your request; taking steps before entering a contract |
| Creating and managing customer accounts | Performance of a contract | Necessary to provide your account and access to the platform |
| Providing the SupportAI platform and integrations | Performance of a contract | Core service delivery, including AI features and connected integrations |
| Authenticating users and securing accounts | Performance of a contract / legitimate interests | Protecting accounts from unauthorised access |
| Generating AI-assisted draft replies and automation outputs | Performance of a contract | Core feature of the platform; processing based on customer configuration and instructions |
| Monitoring performance, debugging, and preventing abuse or fraud | Legitimate interests | Maintaining platform stability, reliability, and preventing misuse |
| Billing and invoicing, where applicable | Performance of a contract / legal obligation | Processing payments and maintaining records as required by tax law |
| Sending service-related notices | Performance of a contract / legitimate interests | Account updates, maintenance notifications, security alerts |
| Product analytics and improvement | Legitimate interests / consent | Understanding feature usage to improve the product; consent for non-essential analytics where required |
| Marketing communications (where consent is required) | Consent | We send marketing emails only where you have opted in or where we have an existing customer relationship within legal limits |
| Complying with legal obligations | Legal obligation | Responding to lawful requests, regulatory requirements, and tax/accounting duties |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You can object to processing based on legitimate interests; see Section 9.
5. Controller vs processor roles
Because SupportAI processes data in different contexts, it is important to distinguish between our role as a controller and our role as a processor.
SupportAI as data controller
We act as the controller when we determine the purposes and means of processing personal data for:
- •Website visits and analytics
- •Marketing and sales interactions
- •Account registration and management
- •Billing and contract management
- •Product analytics and service improvement
SupportAI as data processor
We act as a processor when our business customers use the SupportAI platform to process support tickets, end-customer data, and connected platform data. In this context:
- •The customer is the controller and determines what data is uploaded and how it is used
- •We process that data according to the customer’s instructions, our Data Processing Agreement (where applicable), and the platform configuration
- •Customers are responsible for ensuring they have a lawful basis to upload and use personal data in the platform
7. International data transfers
Our primary hosting infrastructure is located in the European Economic Area (EEA). Where possible, we process and store personal data within the EEA.
Where personal data is transferred outside the EEA, the United Kingdom, or Switzerland, we aim to use appropriate safeguards as required by applicable data protection law. These safeguards may include contractual protections (such as the European Commission’s Standard Contractual Clauses), the UK International Data Transfer Agreement or Addendum, or transfers to jurisdictions recognised as providing an adequate level of protection.
You may request more information about the safeguards that apply to your data by contacting us through the methods described in Section 14.
8. Data retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. The table below summarises our retention approach.
| Data category | Retention approach |
|---|---|
| Website inquiry and demo request data | Retained only as long as necessary to respond and follow up on your inquiry, and for a limited period afterward for reference and service improvement. |
| Account and profile data | Retained for the duration of the customer relationship and for a limited period after account closure to handle any residual matters, unless earlier deletion is requested. |
| Billing and transaction records | Retained for the period required by applicable tax, accounting, and commercial law. |
| Support communications | Retained for the duration of the customer relationship and for a reasonable period afterward to resolve follow-up queries and maintain service continuity. |
| Customer workspace data (tickets, drafts, AI outputs) | Retained for as long as the customer account is active, or as otherwise agreed in the customer contract and Data Processing Agreement. Customers may delete data earlier through their account settings. |
| Logs and security data | Retained for a limited and proportionate period as necessary for security monitoring, troubleshooting, and service integrity. |
| Backups | Retained on a rolling schedule for disaster recovery purposes. Backup data is periodically overwritten and is not retained indefinitely. |
| Marketing consent records | Retained for as long as consent remains valid and for a reasonable period after withdrawal to demonstrate compliance. |
9. Your data subject rights
Under the GDPR and applicable data protection laws, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you and information about how it is processed.
- Right to rectification: You can ask us to correct inaccurate or incomplete personal data.
- Right to erasure: You can request deletion of your personal data where there is no compelling reason for us to continue processing it (the "right to be forgotten").
- Right to restriction: You can ask us to restrict processing of your personal data in certain circumstances, for example while we verify a correction request.
- Right to data portability: You can request a copy of your personal data in a structured, commonly used, and machine-readable format, and have it transmitted to another controller where technically feasible.
- Right to object: You can object to processing based on legitimate interests, including profiling. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint: You have the right to lodge a complaint with the data protection supervisory authority in your place of residence, place of work, or where you believe an infringement may have occurred.
We aim to respond to valid requests within one month, subject to lawful extensions and identity verification. Where we act as a processor on behalf of a business customer, we will direct your request to that customer, who is responsible for handling it.
To exercise any of these rights, contact us through the methods described in Section 14.
10. Automated decision-making and AI
The SupportAI platform uses artificial intelligence and machine learning to:
- classify and route incoming support tickets;
- generate suggested draft replies for customer review;
- autonomously resolve certain low-risk, high-confidence support requests based on customer-configured rules and confidence thresholds;
- summarise ticket history and extract relevant information from connected data sources.
Whether an AI-generated reply is sent automatically or held for human review depends on the customer’s platform configuration, including confidence thresholds, escalation rules, and approval workflows. Customers remain in control of these settings.
Important: Unless a customer specifically configures the platform to do so and such configuration is lawful under applicable regulations, SupportAI does not intend to make solely automated decisions that produce legal effects or similarly significant effects concerning individuals on its own behalf. The platform is designed to support human decision-making, not replace it.
Business customers are responsible for reviewing and configuring automated workflows in line with applicable law, including any obligations under Article 22 GDPR concerning automated individual decision-making.
11. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include:
- encryption of data in transit (TLS) and at rest;
- role-based access controls and least-privilege principles;
- logging and monitoring of system access and activity;
- logical isolation of customer workspaces and tenant data;
- vendor security assessments for key service providers; and
- regular review of security practices and incident response procedures.
While we strive to protect personal data, no method of transmission or electronic storage is completely secure. We cannot guarantee absolute security.
12. Children
SupportAI is a business-to-business service intended for use by professionals and organisations. It is not directed to individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or product functionality. When we make material changes, we will:
- post the updated policy on this page with a new “Last updated” date;
- notify account holders by email or through an in-product notice where the changes are significant; and
- where required by law, obtain your consent to the updated terms.
We encourage you to review this policy periodically. Continued use of the website or platform after changes are posted constitutes acceptance of the updated policy to the extent permitted by law.
14. Contact
For questions, requests, or complaints about this Privacy Policy or our data practices, you may contact us through:
Website: ai4support.app/contact
Email: support@ai4support.app
Please mark correspondence “Attention: Privacy Team” where appropriate.
You also have the right to lodge a complaint with the data protection supervisory authority in your place of residence, place of work, or where you believe an infringement may have occurred.