Legal

Privacy Policy

This Privacy Policy explains how PrimeRise AI handles personal data across Instagram, WhatsApp, and web-based AI assistants.

Effective and last updated: 31 July 2026

1. Who we are

PrimeRise AI is operated by Prime Rise IT Company, a sole proprietorship registered in Denmark.

Company
Prime Rise IT Company
CVR number
46 12 68 31
Address
Helgolandsgade 15, 1. th, 9000 Aalborg, Denmark

2. Scope and our data protection roles

This Policy applies when you:

  • visit the PrimeRise AI website or use its web chat;
  • communicate with an AI assistant through Instagram Direct or WhatsApp;
  • use a PrimeRise AI assistant embedded on a business customer’s website; or
  • contact us, request a demonstration, or use a PrimeRise AI business account.

When PrimeRise determines why and how data is used, including data from our own website, demonstrations, direct enquiries, and business administration, Prime Rise IT Company acts as the data controller.

When a business customer uses PrimeRise AI to respond to its own customers, that business normally acts as the data controller and Prime Rise IT Company acts as its data processor. In that situation, we process personal data only on the business customer’s documented instructions. The business customer’s own privacy notice also applies and should explain its purposes and legal basis.

3. Personal data we process

Depending on the channel and how you use the Service, we may process:

  • Identity and channel data: name, display name, Instagram or WhatsApp identifier, username, profile information made available by the channel, phone number for WhatsApp, and conversation or thread identifiers.
  • Communications: messages, questions, replies, timestamps, and attachments or media when the selected channel makes them available to the assistant.
  • AI interaction data: generated replies, relevant knowledge-base excerpts, conversation context, and feedback about a response.
  • Website and technical data: IP address, browser and device information, request timestamps, pages or endpoints used, response status, security events, and diagnostic logs.
  • Business customer data: contact details, company details, account information, support correspondence, service configuration, and billing or contract records where applicable.
  • Information you choose to provide: any other personal data included in your message or uploaded by an authorised business customer to its knowledge base.

Some assistants, such as assistants configured for healthcare businesses, may receive special-category data such as health information. The relevant business customer must establish an appropriate legal basis and conditions for this processing. We process such data only on documented instructions and only where the assistant has been configured for that purpose. Please avoid sharing sensitive information unless it is necessary for your request.

4. Where the data comes from

We receive personal data:

  • directly from you when you send a message or contact us;
  • from the business whose assistant you are using, when it has lawfully provided configuration or customer information;
  • from Meta platforms, including Instagram and WhatsApp, when they deliver messages and related identifiers through their APIs; and
  • automatically from browsers, servers, and security systems when you use the Service.

5. Purposes and legal bases

PurposeLegal basis when Prime Rise IT Company is controller
Deliver the Service, process messages, generate replies, provide support, and take steps requested before a contractPerformance of a contract or steps before entering a contract (GDPR Article 6(1)(b))
Protect the Service, prevent abuse, troubleshoot errors, and maintain reliabilityOur legitimate interests in operating a secure and reliable service (GDPR Article 6(1)(f))
Maintain business, tax, accounting, and compliance recordsCompliance with legal obligations (GDPR Article 6(1)(c))
Send optional marketing communications or use non-essential tracking technologiesConsent where required (GDPR Article 6(1)(a)); consent may be withdrawn at any time

When we act as a processor, the business customer determines the relevant legal basis and we process the data under its instructions and our data processing agreement. We do not sell personal data.

6. How AI assistants process messages

The Service sends the text of your message, relevant conversation context, and selected business knowledge to an AI model so that it can generate a response. Automated retrieval may select relevant information from the business customer’s knowledge base before the response is generated.

Core AI inference is currently performed on infrastructure controlled by Prime Rise IT Company using locally hosted models. Message content is not used to train general-purpose AI models. If a business customer later enables a separate third-party AI integration, that integration and any related recipients must be disclosed before it is used for personal data.

AI-generated answers may be incomplete or incorrect. They should not replace professional medical, legal, financial, or other qualified advice.

7. Sharing and recipients

We may disclose personal data only as necessary to:

  • the business customer whose assistant you contacted and its authorised staff;
  • Meta and its relevant companies when Instagram or WhatsApp is used as the communication channel;
  • hosting, website, network, security, database, and technical service providers acting under appropriate contractual terms, including Vercel for public website hosting and Tailscale for secure private networking where those services are used;
  • professional advisers, authorities, courts, or law-enforcement bodies where disclosure is required by law or necessary to establish, exercise, or defend legal claims; and
  • a successor in connection with a business transfer, subject to applicable data protection requirements.

We do not sell or rent conversation data to advertisers.

8. International data transfers

Our core systems are operated in or from Denmark. Some channel and infrastructure providers, including Meta and Vercel, may process data outside Denmark or the European Economic Area. Where required, international transfers are protected through an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate supplementary safeguards where necessary.

9. How long we keep data

Unless a shorter period is agreed with a business customer:

  • Messages and user identifiers: no longer than 12 months after the last message in the conversation.
  • Technical and security logs: no longer than 30 days, unless a specific security incident requires limited longer retention.
  • Backups: deleted data may remain in protected backups for no longer than 30 days after deletion from active systems and is not restored except for disaster recovery.
  • Business and legal records: kept for the period required by applicable Danish accounting, tax, and other legal obligations, or as necessary for legal claims.

Data will be deleted earlier following a verified request where no law or overriding legal reason requires us or the relevant business customer to retain it.

10. Security

We use technical and organisational measures designed to protect personal data, including encrypted connections, access controls, restricted administrative access, system monitoring, backups, and separation of service components. No online service can guarantee absolute security, but we review and improve these measures as the Service develops.

11. Your data protection rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • receive information about and access your personal data;
  • correct inaccurate or incomplete personal data;
  • request erasure of personal data;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive portable data where the right applies;
  • withdraw consent at any time, without affecting earlier processing;
  • lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or another competent supervisory authority.

You can contact Datatilsynet through its official website at datatilsynet.dk. We normally respond to a valid rights request within one month. We may request information necessary to verify your identity and protect other users’ data.

If you used an assistant operated for another business, contacting that business directly may be the fastest route because it is normally the data controller. You may also contact us, and we will help the business respond where required.

12. How to request data deletion

To request deletion of data processed through Instagram, WhatsApp, a web assistant, or the PrimeRise AI website, email dmytrokondaurov@gmail.com with the subject Data deletion request.

Please include:

  • the channel used: Instagram, WhatsApp, or web chat;
  • the Instagram username, WhatsApp phone number, or other identifier needed to locate the conversation;
  • the name of the business or assistant you contacted; and
  • the approximate date of the conversation.

Do not send passwords or unnecessary sensitive information. We may ask you to verify control of the relevant account or identifier. After verification, we will delete the relevant data from active PrimeRise systems earlier than the normal retention period unless applicable law requires retention. Residual backup copies will be removed within a maximum of 30 days. We will confirm the outcome or explain any lawful limitation within the time required by data protection law.

Deletion from PrimeRise systems does not automatically delete data independently retained by Instagram, WhatsApp, Meta, or the business customer. You may need to use their own privacy or deletion tools as well.

13. Automated decision-making

PrimeRise AI generates conversational responses and may route or classify requests. It is not intended to make decisions based solely on automated processing that produce legal or similarly significant effects about individuals. Business customers must add appropriate human review before using assistant output for consequential decisions.

14. Children

The PrimeRise AI business service is not directed to children. A business customer that provides services to children is responsible for establishing an appropriate legal basis, providing required notices, and obtaining parental authorisation where applicable.

15. Third-party channels and websites

Instagram, WhatsApp, Meta, and business-customer websites process data under their own terms and privacy notices. We do not control their independent processing. The public PrimeRise AI website may use strictly necessary storage or cookies for security and session functionality. We will not use non-essential analytics or advertising cookies without providing any notice and consent mechanism required by law.

16. Changes to this Policy

We may update this Policy when the Service, legal requirements, or our processing practices change. The current version will remain available at this URL and the date at the top will be updated. Material changes will be communicated through an appropriate channel where required.

17. Contact

For privacy questions, rights requests, or deletion requests, contact:

Prime Rise IT CompanyCVR: 46 12 68 31Helgolandsgade 15, 1. th9000 Aalborg, Denmarkdmytrokondaurov@gmail.com