1. Scope and Applicability
This Privacy Policy applies to all personal data processed by PropensityAI ("we," "us," or "our") through our Services, including our website, mobile app, and related services (collectively, the "Services"). This policy complies with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
2. Responsible Party
The party responsible for the collection, processing, and use of your personal data within the meaning of the Federal Data Protection Act is:
FetchCFD UG (haftungsbeschränkt), Managing Director, Dr.-Ing. Rao Muhammad Atif Masood, c/o Factory Works, Rheinsberger Str. 76/77 10115 Berlin, Germany
Email: contact@PropensityAI.com
3. Types of Data Collected
Identity Data: Name, username, date of birth (if applicable and only for paid customers).
Contact Data: Email address, phone number, postal address.
Technical Data: IP address, device information, browser type, cookies.
Usage Data: Pages visited, features used, session duration.
Payment Data: Credit card details, billing address (processed securely via third-party providers).
User-Generated Content: Inputs, queries, and outputs generated through our AI Services. We strongly advise against submitting sensitive personal information through the Standard AI Model. When you use our AI-powered features, your queries, uploaded files (PDFs, audio, video, images, text), and associated metadata may be temporarily processed to generate responses. Uploaded content is stored securely in Vercel storage and is not used for model training unless explicitly stated.
Sensitive Data: We do not intentionally process sensitive data unless explicitly provided by you with consent.
4. Legal Basis for Processing
Under GDPR, we process personal data only where lawful, including
Contractual Necessity: To fulfill agreements with you.
Consent: For marketing, cookies, or non-essential processing (withdrawable at any time).
Legitimate Interests: To improve our Services, prevent fraud, or ensure IT security.
Legal Obligations: To comply with German/EU laws.
5. How We Use Your Data
We use your data to
- Provide and personalize the Services.
- Process payments and fulfill orders.
- Communicate updates, security alerts, or marketing (with consent).
- Analyze usage trends and improve functionality.
- Comply with legal obligations (e.g., tax reporting).
- To operate AI-based features in compliance with the EU AI Act, including maintaining transparency, safety, and user control over AI-generated content.
6. Data Sharing and Transfers
Third-Party Processors: We ensure that all AI-related data processing by third-party providers (e.g., Google, Chaperone AI) complies with the EU AI Act and GDPR. Each provider is contractually required to implement risk management, transparency, and security measures consistent with the EU AI Act framework.
International Transfers: If data is transferred outside the EU/EEA, we ensure safeguards such as:
- Adequacy Decisions (e.g., EU-U.S. Data Privacy Framework).
- Standard Contractual Clauses (SCCs).
- Binding Corporate Rules (BCRs).
Legal Disclosures: We may disclose data to authorities if required by law.
AI Model Providers (Third-Party LLMs): To provide certain AI-powered features within our search engine and related services, we use external large language model (LLM) APIs operated by trusted third-party providers such as Chaperone AI (Chaperone AI API) and Google (Gemini API).
Purpose: These LLMs analyze or summarize search queries, generate natural-language results, and improve relevance of responses.
Data Shared: When you use AI-powered features, the text of your query (and minimal technical metadata such as device type or language setting) may be securely transmitted to the provider's servers for processing.
Data Handling: Providers process this data solely to generate the requested response and may retain it in accordance with their own privacy terms for model-safety and quality purposes.
International Transfers: Some providers process data in the United States. Transfers occur under the EU–U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs) approved by the European Commission.
User Guidance: Please avoid submitting personal, confidential, or sensitive information in AI-powered search queries.
Transparency: Outputs generated by these models are marked or indicated as "AI-generated" or "AI-assisted."
7. Data Retention
We retain personal data only as long as necessary
Account Data: Until account deletion (requestable at any time).
Transaction Data: 10 years (to comply with German tax laws).
Marketing Data: Until consent is withdrawn.
AI Model Training: For queries processed by our Reasoning AI Model: We do not retain or use your input data for AI model training purposes. For queries handled by the Standard AI Model: Aggregated data may be used for model improvement and training. By using the Standard AI Model, you acknowledge your input data may be stored and used for model training purposes. We strongly advise against submitting sensitive personal information through the Standard AI Model.
Google AI Tools: We utilize Google AI tools through the Gemini API to enhance user experience and provide advanced features. While these tools are designed to process data efficiently, please note:
- Data Processing: Inputs to Gemini-powered features may be collected by Google to improve its products and machine learning technologies, including conversation data and usage information.
- Anonymization: Google disconnects data from personal identifiers (e.g., Google Accounts) before review or training use.
- Retention: Data may be retained by Google for up to three years, independent of our storage practices.
- Recommendation: Avoid entering sensitive or confidential information in Gemini-powered features.
For full details, see Google's Gemini API Terms of Service.
8. Your Rights Under GDPR
You have the right to
- To request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you may request information about the purpose of processing, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, deletion, restriction of processing or objection, the existence of a right of appeal, the origin of your data, if these have not been collected by us, and the existence of automated decision-making including profiling and, if applicable, meaningful information on their details;
- in accordance with Art. 16 GDPR, to demand without delay the correction of incorrect or complete personal data stored by us;
- to request the deletion of your personal data stored with us in accordance with Art. 17 GDPR, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
- in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data if you dispute the accuracy of the data, if the processing is unlawful but you refuse to delete the data and if you no longer require the data for the purpose of asserting, exercising or defending legal claims, or if you have lodged an objection against the processing in accordance with Art. 21 GDPR.
- in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, current and machine-readable format or to request its transfer to another person responsible;
- in accordance with Art. 7(3) GDPR, to revoke your consent to us at any time. As a result, we are no longer allowed to continue processing data based on this consent in the future;
- and to complain to a supervisory authority pursuant to Art. 77 GDPR. As a rule, you can contact the supervisory authority at your usual place of residence or workplace or at our company headquarters.
9. Cookies and Tracking Technologies
We use cookies for
- Essential functionality (no consent required).
- Analytics and marketing (consent required).
Consent Management: Users consent via a GDPR-compliant banner, adjustable anytime through cookie settings.
10. Children's Privacy
Our Services are not directed at children under 16. If we become aware that a child under 16 has provided data without parental consent, we will delete it promptly.
11. Security Measures
We implement GDPR-compliant safeguards, including
- Encryption (SSL/TLS) for data transmission.
- Access controls and regular security audits.
12. Automated Decision-Making
Our AI-powered search features use automated processing, including large language models supplied by third-party providers, to generate outputs. These outputs are AI-generated and may contain inaccuracies. Our AI-powered features perform automated reasoning and text generation but do not engage in high-risk or legally binding automated decision-making. You have the right to:
- Request human intervention.
- Contest decisions.
- Express your viewpoint.
13. Updates to This Policy
We will notify users of material changes via email or in-app alerts. The latest version will always be available on our website.
14. AI Transparency and Compliance (EU AI Act)
In accordance with the EU Artificial Intelligence Act (AI Act), we ensure that all AI-powered features within our Services are deployed transparently and responsibly.
Transparency Notice
When interacting with AI-powered features, you are engaging with an automated system that uses large language models (LLMs) and retrieval-augmented generation (RAG) technology to generate responses. AI-generated outputs are clearly indicated as "AI-generated" or "AI-assisted."
Purpose and Function
The AI components of our Services are designed to retrieve, summarize, and generate information based on your input and publicly available sources. The AI does not make legally binding, employment-related, or health-related decisions.
Human Oversight
Our AI systems operate under human supervision. You may request human review or clarification of AI-generated outputs by contacting our support team at contact@propensityai.com.
Data Handling for AI Interactions
- Inputs provided to AI-powered features are processed to generate relevant responses.
- We do not use your personal data for autonomous decision-making or profiling with legal or significant effects.
- We maintain logs of AI activity (queries, timestamps, and technical metadata) for traceability and compliance purposes.
Risk and Safety Management
We perform internal risk assessments to ensure the robustness, security, and fairness of our AI systems and to minimize risks of bias, misinformation, or misuse.
Foundation and Third-Party Models
We integrate external AI models, including Google Gemini and Chaperone AI. These providers are responsible for compliance with AI Act obligations applicable to foundation model providers. We act as a "deployer" under Article 26 of the AI Act and comply with relevant deployer responsibilities, including transparency and user information duties.
Your Rights Regarding AI Decisions
- Request human intervention in any AI-assisted output.
- Obtain an explanation of the logic behind AI-generated content.
- Object to automated processing or request review of outputs.
Updates
This section will be updated to reflect evolving AI Act implementation and EU guidance.
Contact Us
For questions or to exercise your rights
Email: contact@PropensityAI.com
Address: FetchCFD UG (haftungsbeschränkt), c/o Factory Works, Rheinsberger Str. 76/77 10115 Berlin.