Legal

Privacy Policy

This Privacy Policy explains how SitePoint Systems ApS ("Freyja", "we", "us") collects, uses, shares and protects personal data when you visit heyfreyja.com, use the Freyja chat agent embedded on a customer's website, or use our configuration console at app.heyfreyja.com.

1. Who we are

Freyja is operated by SitePoint Systems ApS, CVR no. 39299739, Rådhusstræde 15, 1466 Copenhagen K, Denmark. We are the data controller for this website and for the Freyja product offering. For chat conversations that take place inside a customer's deployment, our customer (the website operator who embeds Freyja) is typically the controller and we act as a processor on their behalf. A data processing agreement is available on request.

Contact: privacy@heyfreyja.com

2. Data we collect

  • Conversation data — messages exchanged with a Freyja agent and its replies on any connected channel (website widget, email, WhatsApp, Messenger, Instagram, Telegram, LINE, Slack or Missive), including any information you choose to provide (such as name or email) and attachments.
  • Context metadata — page URL, referrer, an anonymous visitor identifier, locale, device/browser information and timestamps.
  • Account data (console users) — name, email, organisation and authentication details. Passwords are stored only as salted hashes.
  • Billing data — subscription state and invoices via Stripe; we never see or store full card numbers. For AppSumo lifetime purchases we receive and store the license key — AppSumo does not send us your email.
  • Knowledge content — documents and website content our customers add to their knowledge bases so the agent can answer from them.
  • Technical logs — IP address and request logs used for security, debugging and abuse prevention.

3. How we use data

  • To operate the chat agent: understand your message, generate a relevant reply, and maintain conversation context.
  • To route conversations to a human agent when needed and deliver their replies back to you.
  • To improve answer quality and our knowledge base (for example, summarising closed conversations into help articles).
  • To provide, secure and support the configuration console.
  • To comply with legal obligations.

Where the GDPR applies, we rely on: performance of a contract (providing the service you request), legitimate interests (securing and improving the service), consent (where required, e.g. optional communications), and legal obligation.

5. AI processing

Replies are generated using large language models accessed through OpenRouter and the underlying model providers. Conversation content is sent to these providers solely to generate a response. Finding relevant answers in your knowledge base, and relevant products if you've connected a product feed, works the same way but through an embeddings provider — by default also OpenRouter, or a directly configured OpenAI key if a workspace sets one up — and includes the text of recent visitor messages used to build the search. If voice is enabled on a workspace, spoken audio and AI reply text are additionally sent to our speech providers (Deepgram, ElevenLabs and/or Smallest AI) to convert speech to text and text to speech; this processing does not go through OpenRouter. We do not sell your data, and we do not use your conversations to train third-party foundation models beyond what is necessary to produce a reply — today this is enforced through our contracts with these providers rather than a technical no-training flag set on every individual request.

6. Service providers & sub-processors

We share data only with providers that help us run the service:

  • OpenRouter and the model providers it routes to — generating AI replies, classifying conversations (including intent), and powering the AI copilot.
  • OpenRouter or OpenAI (embeddings) — semantic search over your knowledge base and, if configured, your product feed. Includes the text of recent visitor messages used to find matches.
  • Deepgram, ElevenLabs and Smallest AI — only for workspaces with voice enabled, to convert visitor speech to text and AI replies to speech.
  • Missive (optional) and Slack (optional) — only when a workspace configures one of these for human hand-off.
  • Telegram, Meta (Messenger, Instagram and WhatsApp) and LINE — only for workspaces that connect these channels, to send and receive messages.
  • Sinch Mailgun — receiving forwarded mail for the email channel; plus our SMTP provider for outbound replies and system notifications.
  • AppSumo — license validation for lifetime-deal purchases.
  • Amazon S3 or Cloudflare R2 (optional) — storing images and files shared in conversations.
  • Push notification services (Firebase, Mozilla, Apple) — encrypted alerts to agents' phones, containing a short excerpt of the message and the visitor's name or email if known.
  • Stripe — billing, using the workspace owner's name, email and payment details.
  • MCP servers you configure — if you connect your own systems via MCP, the AI sends them arguments derived from the conversation (for example an order reference) to look up information or take actions.
  • Sentry (optional) — error tracking, if enabled.

Our configuration console loads fonts from Google Fonts and connector logos from Clearbit; these see the console user's IP address and browser type only, never conversation data.

Conversation and knowledge data is stored and searched on our own self-hosted infrastructure (including Redis and Elasticsearch), hosted with Hetzner in the EU under our control — not as a third-party sub-processor. Encrypted backups are likewise stored with Hetzner in the EU.

Each third-party sub-processor above is bound by appropriate data protection terms.

7. Data retention

Live conversation state is short-lived (typically expiring within 24 hours). Transcripts and knowledge content are retained for as long as needed to provide the service or as instructed by the relevant controller, then deleted or anonymised. Console account data is retained for the life of the account. Encrypted backups are kept on a rolling retention schedule and age out automatically. When you ask us to delete data, we remove it from live systems without undue delay and normally within 30 days; backup copies expire with the backup rotation.

8. Cookies & local storage

The chat widget uses minimal local storage (for example, an anonymous visitor identifier and session continuity). The marketing website uses only strictly necessary storage. We do not use third-party advertising trackers.

9. International transfers

Our primary hosting and backups are within the EU/EEA. Some providers (such as OpenRouter, Stripe and Sentry) may process data in the United States or elsewhere; where this happens we rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

10. Your rights

Subject to applicable law, you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. To exercise these rights, contact privacy@heyfreyja.com. For chat data held on behalf of a website operator, please contact that operator; we will assist them as their processor. You may also lodge a complaint with your supervisory authority (in Denmark, the Datatilsynet).

11. Security

We use industry-standard measures including encryption in transit, access controls and tenant isolation. No method of transmission or storage is completely secure, but we work to protect your data and to notify of incidents where required.

12. Children

The service is not directed to children under 16, and we do not knowingly collect their data.

13. Changes

We may update this policy from time to time. Material changes will be posted here with a new "last updated" date.

14. Contact

SitePoint Systems ApS · CVR 39299739 · Rådhusstræde 15, 1466 Copenhagen K, Denmark · privacy@heyfreyja.com