Privacy policy

This notice explains how Feret collects, uses and protects personal data when you use the Feret service. It is written for tenant users and invited pilot contacts.

1. Who we are

Feret ("we", "us", "our") is the controller of the personal data described in this notice. Feret is designed and developed in Switzerland.

  • Privacy contact: hello@feret.ai

2. Representatives

Feret is based in Switzerland and is currently available to a limited group of invited pilot tenants in the EU and UK. Before Feret becomes publicly available, we will appoint a representative in the EU (Art. 27 GDPR) and in the UK (UK GDPR) where required, and will name them in this notice.

During the pilot, you can reach us directly at hello@feret.ai on any matter a representative would otherwise handle, including any request to exercise your rights under section 8.

3. What we process, and why

We process personal data for the following purposes only, each on the stated lawful basis:

PurposePersonal dataLawful basis (Art. 6)
Account and authenticationEmail, name, job function, roleContract - Art. 6(1)(b)
AI companion (chat + layered memory)Chat content, rolling summary, extracted factsContract - Art. 6(1)(b)
Document extractionUploaded supplier documents (may incidentally contain third-party personal data)Contract - Art. 6(1)(b)
Security (tenant isolation, rate limiting, audit logging, breach detection)IP / email / user / tenant identifiers, audit log entriesLegitimate interest - Art. 6(1)(f)
Invite management (Beta allowlist)Email, invited-by email, notesContract / legitimate interest - Art. 6(1)(b)/(f)
Product improvement (experience feedback)User ID, free text, mood, contextLegitimate interest - Art. 6(1)(f)

We do not process personal data for any purpose beyond these six without updating this notice first.

4. Our legitimate interests

Where we rely on legitimate interests (security, audit logging, invite management, product-improvement feedback), we have assessed that our interest in operating a secure, reliable, improving service is not overridden by your rights and interests, because the processing is limited to what is necessary for that purpose, tenant-scoped, and does not involve profiling that produces legal or similarly significant effects on you.

5. Who we share data with

We share personal data only with the service providers who help us run Feret. These are the categories of recipient that receive personal data today:

Category of recipientData receivedRegion
AI processing providers (AI companion chat and document extraction)Chat transcripts, brief text, extracted facts, raw uploaded documents and extraction outputProcessed outside the EEA, including the United States (see section 6)
Cloud hosting and database infrastructureAll tenant-scoped data; request data in transitEU-hosted, with some control-plane operations outside the EEA
Transactional email providerRecipient email address, magic-link URLEU (Ireland)
Team communications tool (feedback notifications)Feedback you submit - reason tags, free text and, for flagged responses, the flagged chat excerpt - plus your email addressProcessed outside the EEA, including the United States (see section 6)

A current list of the specific providers within each category is available to our tenant customers in our Data Processing Agreement, and to any user on request at hello@feret.ai.

We do not sell your personal data to third parties.

6. International transfers

Some of the providers above - in particular our AI processing providers, our team communications tool (which receives feedback notifications) and parts of our cloud hosting - process personal data outside the EEA, including in the United States. Where that happens, we rely on the EU-US Data Privacy Framework (DPF), with Standard Contractual Clauses (SCCs) as a fallback safeguard under Art. 46 GDPR, because the DPF's predecessor frameworks were both struck down by the CJEU and the current DPF adequacy decision is under appeal.

Our AI providers do not use the data we send them to train their models, and retain it only for a limited period for security and abuse-monitoring purposes before deleting it. We are evaluating a zero-retention arrangement that would remove even that limited window. Our database and transactional email providers are hosted within the EEA and involve no third-country transfer. We do not knowingly process any special category data (Art. 9) through these transfers.

7. How long we keep data

Data categoryRetention
Account / auth (email, name, role)Contract duration + 12 months
Chat threads / memoryContract duration; deletable on request; purged on account closure
Uploaded documentsContract duration (durable store pending; today, our document-extraction provider auto-expires uploads after roughly 48 hours)
Magic-link tokensExpire on use, or after 15 minutes
SessionsNot stored - session tokens are not persisted (we use stateless JWT sessions)
Audit log24 months
Experience feedbackContract duration + 12 months
Security / rate-limit logs90 days

Full detail lives in our internal retention schedule, reviewed annually or on material change.

8. How we protect your data

Your formulations, supplier specifications, costings and R&D history are among your most valuable commercial assets. Protecting them is built into the platform, not just promised in policy.

  • Per-tenant isolation. Every record - documents, formulations, projects, chat history - is bound to your own workspace and is invisible to any other customer. This is enforced automatically in the software: every database query is filtered by your workspace identity by default, a build-time rule blocks any code that would bypass it, and the isolation is covered by an automated test suite. Per-user data such as chat carries an additional user-level filter.
  • Encryption and access control. Data is encrypted in transit (TLS) and at rest. Sign-in uses passwordless magic links; magic-link tokens are stored only as one-way hashes, and sessions are stateless and not persisted. Application secrets are held in managed environment configuration, never in the codebase.
  • Governed, certified sub-processors. We use a small, deliberately-chosen set of infrastructure providers, each under a Data Processing Agreement (Art. 28) with dated copies on file. Our core infrastructure providers hold SOC 2 and ISO 27001 certifications.
  • Privacy-lean monitoring. We use an EU-hosted (Frankfurt) error-tracking and usage-analytics service to detect failures and understand which features are used. Events carry pseudonymous account identifiers only - error reports and usage events are scrubbed of message content, document content and contact details before they are stored, and we use no advertising cookies or cross-site tracking.
  • EU-first data residency. Your core data - database, documents, email - is hosted within the EU/EEA (Frankfurt and Ireland). The limited processing that occurs outside the EEA is covered by the safeguards in section 6.
  • Not used to train AI. As set out in section 6, our AI providers are engaged on commercial tiers that contractually prohibit using your prompts, documents or outputs to train their models.

For any security or data-protection questions, you can reach us at hello@feret.ai.

9. Your rights

Subject to the conditions in each article, you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Rectification of inaccurate or incomplete data (Art. 16)
  • Erasure of your data in certain circumstances (Art. 17)
  • Restriction of our processing in certain circumstances (Art. 18)
  • Data portability for data you provided under contract (Art. 20)
  • Object to processing based on our legitimate interests (Art. 21)
  • Withdraw consent at any time, without affecting processing carried out before withdrawal (Art. 7(3))

To exercise any of these rights, contact us at hello@feret.ai. We will respond within one month, extendable by two further months for complex requests.

10. Automated processing

We use AI to analyse the data you provide, for example to extract structured information from uploaded documents and to power the AI companion's chat responses. This has no legal or similarly significant effect on you: it assists your work inside Feret and does not make decisions about you as a person, such as decisions about eligibility, pricing, or access to the service.

11. Complaints

If you believe we have not handled your personal data properly, you can contact us first at hello@feret.ai, or lodge a complaint directly with your supervisory authority:

  • In Switzerland: the FDPIC (Federal Data Protection and Information Commissioner)
  • In the EU: your local data protection authority
  • In the UK: the ICO (Information Commissioner's Office) - ico.org.uk

12. Cookies

Feret uses only essential cookies needed to keep you signed in and to operate the service. We do not use cookies for advertising or cross-site tracking.