Privacy Policy

Your data matters. This policy explains what we collect, why we collect it, how we use it, and the rights you have under UK and EU data protection law.

Effective 26 September 2026

1. About this Privacy Policy

PostAgency.ai ("PostAgency", "we", "us", "our") is committed to protecting your personal data and respecting your privacy. This policy sets out how we collect, use, share, store, and protect personal data when you visit postagency.ai, submit a brief, use the free roast, subscribe to a paid plan, or otherwise interact with our services.

This policy applies to prospects, customers, website visitors, and anyone who contacts us. It should be read alongside our Terms of Service and Cookie Policy.

We act as the data controller for the personal data we collect through our own marketing site and customer onboarding. Where we process personal data on behalf of a client (for example, strategy reports we generate about their business), we act as a data processor and are governed by a separate Data Processing Agreement.

2. Who we are and how to contact us

postagency.ai is operated by Paul Fawcett EI (entreprise individuelle), trading as PostAgency, registered in France (SIREN 921 491 908, VAT FR83921491908), Doussard, 74210, France. You can contact us by email at privacy@postagency.ai for anything related to this policy or your personal data.

If you are based in the United Kingdom or European Economic Area (EEA), you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL) in France. If you are elsewhere in the EEA, you may also contact the supervisory authority in your country of residence.

3. What personal data we collect

We only collect personal data that is necessary to provide our service. The data we collect falls into the following categories.

Identity and contact data: your name, email address, company name, job title, and business phone number when you submit a brief, create an account, or contact us.

Brief and account data: the website URL you submit, the sector you operate in, your stated goals, the content of any brief you submit, usage of your customer dashboard, and records of emails we have sent you.

Payment data: we do not store full payment card details. When you pay, you provide your card information directly to Stripe, our payment processor. We receive a token, the last four digits of your card, the card brand, the billing country, and the amount charged.

Technical data: IP address, approximate geographic location (derived from IP address at the country and region level), browser type and version, time zone, device type, operating system, and pages visited. This data is used for geo-localisation, fraud prevention, and analytics.

Communications data: the content of emails, support messages, or other correspondence you send us, and our responses.

We do not knowingly collect special category personal data (such as health, political opinions, religious beliefs, or biometric data) through our services.

4. How we use your personal data

We use your personal data only for the purposes set out below.

To provide our service: creating your account, generating the free roast report, producing strategy briefs, running the onboarding pipeline, issuing receipts and invoices, and delivering the work you have paid for.

To communicate with you: sending transactional emails (such as roast links, account verification, receipts, and service updates) and responding to your enquiries.

To send marketing communications: only where you have explicitly opted in, or where we have a legitimate interest to contact existing customers about similar services and you have not opted out.

To improve our service: aggregated and anonymised analytics on how visitors use our website and which features of our service perform well.

To prevent fraud and abuse: rate-limiting the free roast, detecting payment fraud, and enforcing our Terms of Service.

To comply with legal obligations: keeping accounting records, responding to lawful requests from authorities, and enforcing our rights.

5. Legal basis for processing

Under the UK GDPR and the EU GDPR, we must have a lawful basis for every use of your personal data. The bases we rely on are:

Contract (Article 6(1)(b)): processing is necessary to provide the service you have signed up for, including generating your roast, producing your brief, running your subscription, and delivering strategy reports.

Legitimate interests (Article 6(1)(f)): keeping our service secure, preventing fraud and abuse, improving our product, and contacting existing customers about similar services. When we rely on legitimate interests we balance them against your rights and freedoms, and you can object at any time.

Consent (Article 6(1)(a)): where you have opted in, for example to receive marketing emails or to accept non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of processing carried out beforehand.

Legal obligation (Article 6(1)(c)): keeping records required by tax, accounting, and consumer protection law.

Where we process special category data (we do not do so in the ordinary course of business), we will only do so on a lawful Article 9 basis, which will usually be your explicit consent.

6. Who we share your data with

We do not sell your personal data. We share it only with the service providers we need to run PostAgency, and only to the extent necessary.

Supabase (database, authentication and storage): hosted in the European Union (Ireland region). Stores your account, brief, roast results, site content and generated reports.

Stripe (payments): processes all card payments and subscription billing. Stripe is certified to PCI DSS Level 1 and is the controller of your full card data.

Resend (transactional email): sends account verification, roast links, receipts and service notifications on our behalf.

Vercel (hosting): hosts the postagency.ai website, the API and client sites. Processes IP addresses and request metadata.

Anthropic (AI processing): we use Anthropic's Claude models to generate roast summaries, briefs, site copy, strategy content and the dashboard assistant's replies. See section 7.

Gamma, fal.ai and Recraft (AI image generation): generate images, logos and graphics for your site. They receive the text of the image request, which can include your business name and a description of your business, and the image references we send.

GitHub (code hosting): stores the code of the sites we build, including your site's content where it is part of the code.

Analytics providers: privacy-friendly website analytics used to understand aggregate traffic patterns. No personal profiles are built.

Professional advisors, auditors and authorities: lawyers, accountants and regulators where required by law or to defend our rights.

Each provider processes personal data under data processing terms intended to meet Article 28 of the EU GDPR and the UK GDPR. Where a provider transfers data outside the European Economic Area, the transfer relies on the European Commission's standard contractual clauses or an adequacy decision.

7. Artificial intelligence and automated processing

PostAgency uses Anthropic's Claude large language models to produce parts of our service, including the free roast, the brief synthesis, and our strategy content. This is the honest, up-front position you are entitled to.

The text of your website URL, your brief answers, and public information about your business (pulled from your live site) is sent to Anthropic's API for processing. Anthropic's commercial terms for the API state that customer inputs and outputs are not used to train general models.

Paid deliverables are reviewed by a person at PostAgency before we first deliver them. Changes you ask the dashboard assistant for are applied only after you approve them. We do not delegate legally significant decisions to AI: subscriptions, refunds and service outcomes are controlled by a person at PostAgency.

You have the right to request that a human reviews any AI-assisted output that you disagree with, and you can object to any purely automated processing at any time.

8. International transfers

Some of our processors (notably Anthropic, Stripe, and Resend) are based in the United States. When your personal data is transferred outside the United Kingdom or the European Economic Area, we rely on one of the following safeguards:

The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, for transfers out of the United Kingdom.

The EU Standard Contractual Clauses (2021 version) for transfers out of the EEA.

The EU-US Data Privacy Framework (DPF), where a processor is self-certified under it.

You can request a copy of the specific transfer mechanism that applies to your data by writing to privacy@postagency.ai.

9. How long we keep your data

We keep personal data only for as long as we need it for the purpose for which it was collected, plus the time required by law.

Free roast results: stored for 48 hours from generation. After that the temporary link expires and the underlying data is anonymised or deleted.

Brief submissions and prospect records: retained for 12 months from your last interaction. After that we anonymise the record for analytics continuity and delete the personal data.

Paying customer records: retained for the duration of your subscription and for 7 years after termination, to meet UK accounting and tax retention requirements.

Email logs and support correspondence: retained for 24 months.

Marketing consents and preferences: retained for as long as you remain subscribed, plus 2 years thereafter to demonstrate prior consent.

You may request earlier deletion at any time (see section 11), subject to any legal retention obligations we are required to observe.

10. Cookies and similar technologies

We use a small number of cookies and similar technologies to run the site. They are described in full in our Cookie Policy.

Strictly necessary cookies: required for the site to function, including session cookies and the locale cookie (pa_locale) used to remember your language preference. These do not require consent.

Analytics cookies: used to measure aggregate traffic. These are only set after you give consent through our cookie banner.

We do not use advertising cookies, third-party tracking pixels, or cross-site profiling technologies.

You can change or withdraw your cookie choices at any time through the link in our website footer.

11. Your rights

Under the UK GDPR and the EU GDPR you have the following rights. Most of them can be exercised free of charge.

Right of access: obtain a copy of the personal data we hold about you.

Right to rectification: have inaccurate data corrected or incomplete data completed.

Right to erasure (the right to be forgotten): ask us to delete your data where one of the grounds in Article 17 applies.

Right to restriction of processing: ask us to pause processing while a concern is resolved.

Right to data portability: receive the personal data you have provided to us in a structured, commonly used, machine-readable format, or have it sent directly to another controller where technically feasible.

Right to object: object to processing based on legitimate interests or to processing for direct marketing.

Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.

Rights in relation to automated decision-making: not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not make such decisions, but you can always ask for human review of AI-assisted output).

Right to lodge a complaint: contact the ICO in the United Kingdom or your local EEA supervisory authority.

12. How to exercise your rights

To exercise any of your rights, email privacy@postagency.ai from the address associated with your account. We may ask for additional information to verify your identity.

We will respond within one calendar month. If your request is especially complex or you have made multiple requests, we may extend that period by a further two months and will tell you why.

There is no fee unless your request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse the request, as permitted by law.

13. How we protect your data

We take security seriously. The measures we operate include encryption in transit (HTTPS with TLS 1.2 or better), encryption at rest for databases and backups, strict access controls and least-privilege permissions for our team, Supabase Row Level Security on every data table, isolated data per tenant, audit logging of administrative actions, secret scanning in our code, and regular dependency audits.

Despite these measures, no internet transmission or storage system is completely secure. We cannot guarantee absolute security, but we commit to handling any incident transparently.

14. Data breach notification

If a personal data breach occurs and is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, as required by UK GDPR.

If the breach is likely to result in a high risk to you personally, we will also contact you directly, without undue delay, with a description of the breach, its likely consequences, the measures we have taken, and steps you can take to protect yourself.

15. Children's privacy

Our services are directed at businesses and professionals. They are not intended for children under the age of 16. We do not knowingly collect personal data from children.

If you believe a child has provided us with personal data, please contact privacy@postagency.ai and we will delete it.

16. Automated decision-making and profiling

We do not make decisions that produce legal or similarly significant effects based solely on automated processing. AI is used as an assistant inside our pipeline, but a human at PostAgency always reviews the output before it is delivered.

If you have concerns about any AI-assisted output you have received, you can request a human review at any time by writing to hello@postagency.ai.

17. Marketing communications

We only send marketing emails where you have asked us to, or where you are an existing customer and we have a legitimate interest to tell you about similar services. You can unsubscribe at any time using the link at the foot of every marketing email, or by writing to privacy@postagency.ai.

Transactional emails (verification, receipts, service status) are not marketing and will continue for as long as your account is active, because they are necessary to perform our contract with you.

18. Changes to this Privacy Policy

We may update this policy from time to time to reflect changes in the law, our services, or our practices. When we do, we will update the effective date at the top of the page and, for material changes, notify registered users by email at least 30 days before the change takes effect.

We keep previous versions on file and will provide them on request.

19. Complaints and supervisory authorities

If you believe we have not handled your personal data properly, please raise it with us first by writing to privacy@postagency.ai. We take complaints seriously and will work to resolve them quickly.

You also have the right to contact a supervisory authority. In the United Kingdom, that is the Information Commissioner's Office (ICO) at ico.org.uk. In the European Economic Area, you can contact the supervisory authority in the country where you live or work, or where you believe the breach took place.

20. Contact us

Questions, requests, or complaints about this policy should be sent to privacy@postagency.ai.

General enquiries: hello@postagency.ai.

Support: support@postagency.ai.

Back to all policies