Privacy Policy
Last updated: September 9, 2026
This Privacy Policy explains how PRAgency and the wider suite handle your information, and the rights you have over it. Bracketed items are placeholders to be completed before go-live.
1. Scope
This Privacy Policy explains how [Operator Legal Entity, Inc.] (“we,” “us,” or “the Operator”) collects, uses, shares, and protects personal information across the suite — PodOps and PRAgency, including PRAgency — its websites, and related services (the “Service”). It applies to visitors of our marketing sites and to account holders and their invited members.
2. Roles: controller and processor
For our own marketing sites and account administration, we act as the data controller. For the content and personal data you and your team put into the Service to run your operation — for example guest records in PodOps or talent and contact data in PRAgency — we generally act as a data processor on your behalf, and you are the controller.
Where we act as processor, our Data Processing Addendum (DPA) governs that processing and lists our subprocessors.
3. Information we collect
- Account & profile data — name, email, organization/workspace name, role, and settings you provide.
- Content you create — podcasts, episodes, guest records, talent profiles, pitches, documents, and other data you put into PRAgency.
- Usage & device data — log data, IP address, browser/device information, and interactions, used to operate and secure the Service.
- Cookies & similar technologies — see the Cookies section below.
- Communications — messages you send us (for example, support requests).
- Billing data (future) — when paid plans launch, payment details will be collected and processed by our payment processor, not stored by us directly. Self-serve billing is not enabled today.
4. How we use information
We use personal information to:
- provide, maintain, secure, and improve the Service;
- authenticate you and administer your account and workspace;
- power features you request, including AI-assisted drafting;
- communicate with you about your account, support, and changes;
- detect, prevent, and address fraud, abuse, and security issues;
- comply with legal obligations.
We do not sell your personal information, and we do not use the content in your workspace to train third-party AI models except as needed to provide the feature you invoked.
5. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the bases of: performance of a contract (providing the Service), our legitimate interests (securing and improving the Service), consent (where required, e.g. certain cookies or marketing), and compliance with legal obligations.
7. International transfers
Personal data may be processed in countries other than your own. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum. [Confirm hosting regions and transfer mechanism with counsel.]
8. Data retention
We retain personal data for as long as your account is active or as needed to provide the Service, then delete or anonymize it within a reasonable period unless a longer period is required by law (for example, tax or accounting records) or to resolve disputes and enforce agreements. Backups are purged on a rolling schedule. [Confirm concrete retention windows before go-live.]
10. Your privacy rights (GDPR / CCPA/CPRA)
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access & portability — obtain a copy of your data in a portable format (see Export your data below).
- Rectification — correct inaccurate or incomplete data.
- Erasure / deletion — request deletion of your data (see Delete your data below).
- Restriction & objection — restrict or object to certain processing, including profiling.
- Withdraw consent — where processing is based on consent, at any time.
- Opt out of “sale” / “sharing” — we do not sell or share personal information as those terms are defined under the CCPA/CPRA; there is nothing to opt out of, but you may still exercise your other rights.
- Non-discrimination — we will not discriminate against you for exercising your rights.
We respond to verifiable requests within the timeframes required by applicable law (generally 30 days under the GDPR and 45 days under the CCPA/CPRA, extendable where permitted). You also have the right to lodge a complaint with your data protection authority. If your data lives in a workspace controlled by an organization (your employer or agency), we may direct your request to that controller.
11. Export your data
You can obtain a copy of the personal data and content associated with your account:
- In the app — sign in and go to Workspace settings → Privacy & data → Export data. Your export is prepared and made available for download (structured formats such as JSON/CSV). [Wire this to the app's export endpoint before go-live.]
- By request — if you cannot access the app, submit a request via our contact page or email [privacy@your-domain.com], and we will provide your data after verifying your identity.
12. Delete your data
You can request deletion of your personal data and content:
- In the app — sign in and go to Workspace settings → Privacy & data → Delete account to delete your account and associated content. [Wire this to the app's deletion flow before go-live.]
- By request — submit a deletion request via our contact page or email [privacy@your-domain.com].
After we verify your request, we delete or anonymize your personal data, except where we must retain certain records to comply with law or resolve disputes. Residual copies are removed from backups on our rolling purge schedule. If you are a member of an organization's workspace, deletion may be handled by that organization as the controller.
13. Security
We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated, and the “Last updated” date above reflects the current version.
16. Contact
Questions about this policy or to exercise your rights? Reach out through our contact page or email [privacy@your-domain.com]. If we have appointed a Data Protection Officer or EU/UK representative, their details will be listed here.