Privacy Policy
This Privacy Policy explains how Bampot LLC (“Bampot”, “we”, “us” or “our”) collects, uses, shares and protects personal data in connection with the Bampot platform (the “Service”), and the rights available to individuals under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018. It should be read together with our Terms of Service.
This Policy addresses UK and US data protection law. Bampot does not offer the Service to, and does not monitor the behaviour of, individuals located in the European Economic Area or Switzerland, and accordingly does not maintain a representative in, or otherwise seek to comply with the General Data Protection Regulation as it applies in, the EU/EEA or Switzerland.
1. Who We Are
- Bampot LLC is a single-member limited liability company organised under the laws of the State of Connecticut, USA (registered agent address: 2389 Main St, Ste 100, Glastonbury, CT 06033, USA; correspondence address: 12 Reimer Rd, Westport, CT 06880, USA).
- Bampot LLC is the sole controller of the personal data described in this Policy.
- Bampot LLC is registered with the UK Information Commissioner’s Office (“ICO”) under registration reference ZC170816.
2. Our UK Representative
- In accordance with Article 27 of the UK GDPR, we have appointed Data Protection Representative (UK) Limited (trading as DataRep) as our UK representative. You may contact DataRep on matters relating to UK data protection law in addition to, or instead of, contacting us directly, using the details below:
- Email: datarequest@datarep.com (please use the subject line “Bampot LLC”)
- Online: datarep.com/data-request
- Post: DataRep, 107–111 Fleet Street, London EC4A 2AB, United Kingdom
- We do not have, and are not required to have, a representative in the EU/EEA or Switzerland, for the reason given above.
3. Scope of This Policy
- This Policy applies to personal data we process about: individuals who hold or use a Bampot Account on behalf of a business customer; visitors to our website; and individuals who contact our support team.
- Brief content. Our Terms of Service prohibit Customer from submitting personal data into a Brief or otherwise into the Service (see clause 5.2 of the Terms of Service). This Policy therefore does not address Brief content or Outputs as a source of personal data; if a Customer submits personal data into a Brief in breach of the Terms of Service, that submission, and Customer’s responsibility for it, is governed by the Terms of Service rather than by this Policy.
4. Personal Data We Collect and Why
- The table below summarises the personal data we collect and the purpose for which we use it.
| Personal data | Purpose | Notes |
|---|---|---|
| Account: name, email address, hashed password | To create and authenticate your Account | — |
| Usage events and metrics | To operate, secure and improve the Service | Product analytics |
| Payment and transaction metadata | Billing | Card data is handled directly by Creem as merchant of record; Bampot does not store it |
| Support communications | To respond to your queries | Sent to support@bampot.ai |
| Web analytics | To understand site usage | Cookieless; no personal identifiers are collected (see clause 10) |
- Lawful bases. We process Account, payment and support data because it is necessary to perform our contract with Customer (Article 6(1)(b) UK GDPR) or to take steps requested before entering into that contract. We process usage events and web analytics on the basis of our legitimate interests in operating, securing and improving the Service (Article 6(1)(f) UK GDPR), balanced against your interests and rights. Where we are required to retain data to comply with a legal obligation (for example, tax or accounting records), we rely on Article 6(1)(c) UK GDPR.
5. How We Use AI to Provide the Service
- We use third-party AI providers as sub-processors to generate the text and imagery returned by the Service in response to a Brief, as listed in clause 6 below.
- We do not train our own models on customer data. We do not use Account data, Brief content, or Outputs to train any AI model that Bampot itself develops or owns.
- Text generation. For text generation, we use paid-tier API and Vertex agreements with Anthropic, OpenAI and Google Vertex AI, under which those providers commit not to use the content we submit to train their models. Each provider retains submitted content only briefly and solely for abuse-monitoring purposes (approximately 7 days for Anthropic, 30 days for OpenAI and 24 hours for Google), and we use only the paid or Vertex tiers of these services, never any free tier.
- Image generation. We have not obtained, and do not make, any commitment that the image-generation services we use process data on a zero-data-retention basis, or that they do not use content submitted to them to train their own models. Those providers act as our sub-processors and are bound by their own terms and data processing agreements with us; if a no-training or data-retention commitment is important to you, you should review the relevant provider’s own published terms, which we have not independently verified for this purpose and do not warrant.
- We do not use any of the personal data described in this Policy to make decisions about an individual that produce legal effects or other similarly significant effects, and the Service does not carry out automated decision-making of that kind.
6. Who We Share Your Data With
- We share personal data with the service providers below, each acting as our sub-processor or, in the case of Creem, as an independent controller for the payment transaction it processes as merchant of record.
| Provider | Role | Location |
|---|---|---|
| Anthropic (Claude) | Text generation | USA |
| OpenAI (GPT, GPT Image) | Text generation and product-impression image generation | USA |
| Google (Vertex AI / Gemini, Imagen) | Text generation and mood-visual image generation | USA |
| Supabase | Database, authentication and storage | USA (us-east-1) |
| Vercel | Application hosting | USA |
| Resend | Transactional email | USA |
| Creem | Payments (merchant of record) | EU (Estonia) |
| Fathom Analytics | Cookieless web analytics | Canada |
- We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.
- We may also disclose personal data where required by law, to enforce our Terms of Service, or to protect the rights, property or safety of Bampot, our customers, or others.
7. International Data Transfers
- The Service is hosted in the United States (including our database, which is hosted by Supabase in the us-east-1 region). This means that personal data of individuals in the United Kingdom is transferred to, and processed in, the United States.
- Transfer mechanism. For our US-based sub-processors (Anthropic, OpenAI, Google Vertex AI, Supabase, Vercel and Resend), we rely primarily on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, as the basis for the transfer. Each of our three AI sub-processors’ data processing agreements also supports certification under the UK Extension to the EU–US Data Privacy Framework, which we treat as a secondary basis given ongoing legal challenges to that framework’s reauthorisation. Creem (established in Estonia) and Fathom Analytics (established in Canada) are not based in the United States; transfers to them are instead covered by the UK’s adequacy regulations, which recognise the European Economic Area, and Canada (in respect of organisations subject to Canadian federal private-sector data protection law), as providing an adequate level of protection, rather than by the mechanisms described above. Each of these mechanisms is designed to ensure that personal data transferred from the UK continues to benefit from a standard of protection that is essentially equivalent to that provided under UK data protection law. You can request further information about the safeguards that apply to a specific transfer by contacting us using the details in clause 15.
8. Additional Information for United States Residents
This section provides additional disclosures for individuals resident in the United States and supplements the information above. Depending on your state of residence, you may have specific rights under applicable US state privacy laws (for example, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and comparable laws in states including Connecticut, Virginia, Colorado and others).
Categories of personal information. We collect the categories of personal information described in the table above, which correspond to the following statutory categories: identifiers (such as name and email address); commercial information (such as transaction and billing metadata); internet or other electronic network activity (such as usage events and metrics); and customer records (such as account credentials). We collect this information from you directly and through your use of the Service, and use it for the business purposes described in this Policy. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
No sale or sharing. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising (including targeted advertising), as those terms are defined under applicable US state privacy laws. We have not done so in the preceding 12 months.
Your US state privacy rights. Subject to applicable law and verification of your request, you may have the right to: confirm whether we process your personal information and access it; request correction of inaccurate personal information; request deletion of your personal information; obtain a portable copy of your personal information; opt out of any sale or sharing of personal information or targeted advertising (none of which we conduct); and not receive discriminatory treatment for exercising your rights.
How to exercise your rights. You, or an authorized agent acting on your behalf, may submit a request by contacting us at support@bampot.ai. We will verify your request using the information associated with your account before responding. Where your state law provides a right to appeal a declined request, you may appeal by replying to our response or contacting us at the same address.
California “Shine the Light. ” California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
9. Retention
- We retain personal data for the duration of Customer’s contract with us, plus a further 30 days following termination to allow Customer to export its data, after which we delete it, save where we are required or permitted to retain it for longer to comply with a legal obligation, resolve a dispute, or enforce our agreements.
10. Cookies and Analytics
- Cookieless analytics. Our website uses Fathom Analytics, a web analytics tool that is designed not to set cookies and not to collect any personal identifiers. Because no cookies are set and no personal data is collected through web analytics, a cookie-consent banner is not required for this purpose and we do not operate one.
- We do not use third-party advertising cookies or tracking pixels on our website.
11. Your Rights
- Subject to applicable exceptions, you have the right to:
- be informed about how your personal data is used (as set out in this Policy);
- request access to the personal data we hold about you;
- request that we correct inaccurate or incomplete personal data;
- request that we delete your personal data;
- request that we restrict the processing of your personal data;
- receive a copy of personal data you have provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller (data portability); and
- object to our processing of your personal data where we rely on legitimate interests as the lawful basis.
- To exercise any of these rights, contact us at support@bampot.ai, or contact our UK representative, DataRep, using the details in clause 2. You also have the right to lodge a complaint with the ICO at [ico.org.uk](https://ico.org.uk) or by calling 0303 123 1113, although we would welcome the opportunity to address your concern directly first.
12. Security
- We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction, including access controls, encryption in transit, and the use of reputable infrastructure providers listed in clause 6. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children
- The Service is a business tool intended for use by business customers and their authorised personnel. It is not directed at, and we do not knowingly collect personal data from, children.
14. Changes to This Policy
- We may update this Policy from time to time to reflect changes to the Service or to applicable law. We will post the updated Policy on our website with a revised “Last updated” date, and where a change is material we will provide reasonable notice (such as by email or in-product notice).
15. How to Contact Us
- Bampot LLC: support@bampot.ai; 12 Reimer Rd, Westport, CT 06880, USA
- UK Representative (DataRep): datarequest@datarep.com (subject line “Bampot LLC”); datarep.com/data-request; 107–111 Fleet Street, London EC4A 2AB
- ICO (UK supervisory authority): [ico.org.uk](https://ico.org.uk); 0303 123 1113
