This notice explains how Feret collects, uses and protects personal data when you use the Feret service. It is written for tenant users and invited pilot contacts.
Feret ("we", "us", "our") is the controller of the personal data described in this notice. Feret is designed and developed in Switzerland.
Feret is based in Switzerland and is currently available to a limited group of invited pilot tenants in the EU and UK. Before Feret becomes publicly available, we will appoint a representative in the EU (Art. 27 GDPR) and in the UK (UK GDPR) where required, and will name them in this notice.
During the pilot, you can reach us directly at hello@feret.ai on any matter a representative would otherwise handle, including any request to exercise your rights under section 8.
We process personal data for the following purposes only, each on the stated lawful basis:
| Purpose | Personal data | Lawful basis (Art. 6) |
|---|---|---|
| Account and authentication | Email, name, job function, role | Contract - Art. 6(1)(b) |
| AI companion (chat + layered memory) | Chat content, rolling summary, extracted facts | Contract - Art. 6(1)(b) |
| Document extraction | Uploaded supplier documents (may incidentally contain third-party personal data) | Contract - Art. 6(1)(b) |
| Security (tenant isolation, rate limiting, audit logging, breach detection) | IP / email / user / tenant identifiers, audit log entries | Legitimate interest - Art. 6(1)(f) |
| Invite management (Beta allowlist) | Email, invited-by email, notes | Contract / legitimate interest - Art. 6(1)(b)/(f) |
| Product improvement (experience feedback) | User ID, free text, mood, context | Legitimate interest - Art. 6(1)(f) |
We do not process personal data for any purpose beyond these six without updating this notice first.
Where we rely on legitimate interests (security, audit logging, invite management, product-improvement feedback), we have assessed that our interest in operating a secure, reliable, improving service is not overridden by your rights and interests, because the processing is limited to what is necessary for that purpose, tenant-scoped, and does not involve profiling that produces legal or similarly significant effects on you.
We share personal data only with the service providers who help us run Feret. These are the categories of recipient that receive personal data today:
| Category of recipient | Data received | Region |
|---|---|---|
| AI processing providers (AI companion chat and document extraction) | Chat transcripts, brief text, extracted facts, raw uploaded documents and extraction output | Processed outside the EEA, including the United States (see section 6) |
| Cloud hosting and database infrastructure | All tenant-scoped data; request data in transit | EU-hosted, with some control-plane operations outside the EEA |
| Transactional email provider | Recipient email address, magic-link URL | EU (Ireland) |
| Team communications tool (feedback notifications) | Feedback you submit - reason tags, free text and, for flagged responses, the flagged chat excerpt - plus your email address | Processed outside the EEA, including the United States (see section 6) |
A current list of the specific providers within each category is available to our tenant customers in our Data Processing Agreement, and to any user on request at hello@feret.ai.
We do not sell your personal data to third parties.
Some of the providers above - in particular our AI processing providers, our team communications tool (which receives feedback notifications) and parts of our cloud hosting - process personal data outside the EEA, including in the United States. Where that happens, we rely on the EU-US Data Privacy Framework (DPF), with Standard Contractual Clauses (SCCs) as a fallback safeguard under Art. 46 GDPR, because the DPF's predecessor frameworks were both struck down by the CJEU and the current DPF adequacy decision is under appeal.
Our AI providers do not use the data we send them to train their models, and retain it only for a limited period for security and abuse-monitoring purposes before deleting it. We are evaluating a zero-retention arrangement that would remove even that limited window. Our database and transactional email providers are hosted within the EEA and involve no third-country transfer. We do not knowingly process any special category data (Art. 9) through these transfers.
| Data category | Retention |
|---|---|
| Account / auth (email, name, role) | Contract duration + 12 months |
| Chat threads / memory | Contract duration; deletable on request; purged on account closure |
| Uploaded documents | Contract duration (durable store pending; today, our document-extraction provider auto-expires uploads after roughly 48 hours) |
| Magic-link tokens | Expire on use, or after 15 minutes |
| Sessions | Not stored - session tokens are not persisted (we use stateless JWT sessions) |
| Audit log | 24 months |
| Experience feedback | Contract duration + 12 months |
| Security / rate-limit logs | 90 days |
Full detail lives in our internal retention schedule, reviewed annually or on material change.
Your formulations, supplier specifications, costings and R&D history are among your most valuable commercial assets. Protecting them is built into the platform, not just promised in policy.
For any security or data-protection questions, you can reach us at hello@feret.ai.
Subject to the conditions in each article, you have the right to:
To exercise any of these rights, contact us at hello@feret.ai. We will respond within one month, extendable by two further months for complex requests.
We use AI to analyse the data you provide, for example to extract structured information from uploaded documents and to power the AI companion's chat responses. This has no legal or similarly significant effect on you: it assists your work inside Feret and does not make decisions about you as a person, such as decisions about eligibility, pricing, or access to the service.
If you believe we have not handled your personal data properly, you can contact us first at hello@feret.ai, or lodge a complaint directly with your supervisory authority:
Feret uses only essential cookies needed to keep you signed in and to operate the service. We do not use cookies for advertising or cross-site tracking.