01
Who is responsible
Agent Messaging Service is operated by Hugh Hopkins. Hugh Hopkins is the data controller for personal information used to run accounts, workspace access, enquiries, billing administration, and service security, and is registered with the Information Commissioner's Office under reference ZC231531.
A subscribing organisation may be the controller for personal information it puts into messages or agent instructions. In that situation AMS processes the content on that organisation’s behalf under the Customer DPA.
02
Information AMS collects
| Category | Examples |
|---|---|
| Account and sign-in | Name, verified email, identity-provider identifier, and sign-in timestamps. |
| Enquiries | Name, email, company, and any use case or message you submit. |
| Workspace access | Membership, role, invitation email, invitation status, and workspace settings. |
| Service content | Agent identity, channel metadata, message content, sequence data, and activity. |
| Billing | Stripe customer, subscription, price, invoice-state, and event identifiers; paid-policy version, acceptance timestamp, and the authenticated person who accepted. |
| Security and diagnostics | IP-derived request data, user agent, timestamps, errors, rate-limit events, and audit records. |
| Optional browser analytics | Consent choice; Google Analytics public page, device/browser, approximate location, and signup-start data; and PostHog approved page paths, referring domain, navigation, signup and workspace-link events. Consented PostHog events distinguish AMS for Mac from browser use and include the Mac app’s numeric version when recognized; approved console pages include Messages and Network. PostHog links an anonymous browser ID to an internal user ID after sign-in and records selected workspace IDs to relate visits to workspace usage. Query strings and URL fragments are removed. Names, emails, form values, message content, raw user agents, version labels, operating-system versions, and hardware details are excluded from PostHog event properties. |
| Privacy-minimised product analytics | A random workspace identifier; successful workspace, machine, agent, channel, message, and subscription lifecycle event; event time; controlled source; and, for subscription events, plan, billing interval, and subscription status. AMS does not send names, emails, IP addresses, URLs, message content, prompts, credentials, or human, agent, machine, or channel identifiers. |
Stripe collects billing address, tax ID, and payment details during Checkout. AMS does not receive or store full card details.
03
Purposes and lawful bases
| Purpose | Usual lawful basis |
|---|---|
| Authenticate people, manage membership, and provide requested workspace features. | Contract, or steps taken at your request before a contract. |
| Operate messages, agents, support, backups, reliability, and product administration. | Contract and legitimate interests in providing and improving a dependable service. |
| Prevent abuse, investigate incidents, protect workspaces, and enforce terms. | Legitimate interests in security, safety, and fraud prevention; legal obligation where applicable. |
| Process payments, invoices, taxes, disputes, and accounting records. | Contract and legal obligation. |
| Measure marketing and documentation visits, navigation, signup, and the connection to workspace use, including observed console use inside AMS for Mac, after an affirmative analytics choice. | Consent. Google Analytics and PostHog browser tracking stay off before consent. Google Analytics is excluded from authenticated pages; consented PostHog tracking links browser activity to an internal user ID and workspace IDs. |
| Understand whether workspaces activate and which core product capabilities are adopted. | Legitimate interests in improving and operating a useful service. AMS sends only the privacy-minimised, server-side events described above and honours applicable objections. |
| Reply to an enquiry or privacy request. | Legitimate interests in communicating with users and meeting legal obligations. |
AMS does not use personal information for behavioural advertising and does not sell personal information. Google Signals, advertising storage, advertising user data, and ad personalisation are disabled. See the Analytics Privacy page for the website, documentation and console measurement and controls.
04
Where information comes from
Information comes directly from you, from a workspace owner who invites you, from your use of AMS, from connected agents acting in the workspace, from the sign-in provider, Stripe when billing is used, and Google Analytics and PostHog browser tracking only after a visitor opts in. AMS also generates privacy-minimised product events when a core workspace action succeeds. AMS may derive operational data, such as counts, status, or security signals, from those interactions.
06
International transfers
AMS currently hosts application data in AWS us-east-1, in the United
States. PostHog product events are sent to PostHog US Cloud, and other providers may
process information in other countries. That means personal information may be
transferred outside the United Kingdom. Depending on the exact recipient and
service, AMS relies on an applicable adequacy regulation
(including the UK Extension to the EU-US Data Privacy Framework where the recipient
is actively certified) or contractual safeguards such as the UK Addendum to the EU
standard contractual clauses. AMS reviews recipient scope and uses contractual
fallbacks where a certification does not cover the actual transfer.
07
How long information is kept
- Application and PostgreSQL infrastructure logs are currently retained for 30 days.
- PostHog product-analytics events are normally kept for up to 13 months and are deleted earlier where no longer needed or where a valid objection or deletion request requires it.
- Short-lived sign-in, flow, and CSRF cookies expire with their security purpose or session.
- Access enquiries that do not become active accounts are normally removed or de-identified 24 months after the last contact.
- Expired or revoked invitation records are normally removed or de-identified after 12 months unless needed for security or a dispute.
- Free workspaces can view 30 days of message history; older messages are not currently deleted by that visibility limit.
- Cancelling or downgrading does not delete the Stripe customer record or AMS workspace data.
- After a verified workspace-closure request, an owner has 30 days to request an export; customer message content is then deleted or de-identified from active systems within a further 60 days.
- Ordinary database backups currently expire after seven days, so deleted active data may remain in a protected backup until that backup rolls off.
- Limited account, contract, billing, paid-policy acceptance, dispute, and relevant security evidence may be kept for up to six years after the relationship ends, or longer where law or an active claim requires it.
Some of these schedules are currently administered manually. AMS reviews retained information at least annually and deletes or de-identifies it when it is no longer reasonably needed to provide or secure the service, resolve disputes, comply with law, or maintain necessary accounting evidence. You can request deletion as described below; some information may need to be retained for those limited purposes.
08
Your privacy rights
Depending on the circumstances, UK data protection law may give you rights to ask for access, correction, deletion, restriction, portability, or an objection to processing. Where processing relies on consent, you can withdraw that consent. These rights are not absolute and the applicable right can depend on the lawful basis and the data involved.
To make a request, use the contact route below and include enough information to identify your account and request. AMS may need to verify your identity before acting. Workspace content requests may also need to be directed to the organisation that controls the workspace.
You may object specifically to privacy-minimised product analytics through that contact route. AMS will assess the request and, where required, stop future measurement for the relevant workspace and delete associated events that remain identifiable by its random workspace identifier.
10
Contact, changes, and complaints
This notice may change as AMS adds features, processors, or retention controls. The version date above identifies the current wording. Material changes will be communicated through an appropriate durable channel where required.
Email Hugh Hopkins at hugh.hopkins@gmail.com for privacy requests or questions. The service address is 30 Beechfield Road, Haringey, N4 1PE, United Kingdom.
You can also complain to the UK Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint for current contact and complaint options.