Legal

PRIVACY POLICY

Last updated: 23 June 2026 ยท Effective date: 23 June 2026

1. WHO WE ARE

Ragedom AI ("the Service") is operated by OSQOM GROUP, a group of companies including Softomatics (development) and The Design Agency (design). For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws, the data controller is OSQOM GROUP.

Contact:
Email: privacy@ragedom.ai
Data Protection Officer: dpo@ragedom.ai

2. DATA WE COLLECT

We collect the following categories of personal data:

  • Account data: name, work email address, company name, role.
  • Session data: conversation transcripts generated during AI roleplay sessions, session duration, message counts, and performance analytics.
  • Usage data: pages visited, features used, browser type, IP address, operating system, referring URLs.
  • Communication data: emails or messages you send us via the contact/demo form.
  • Payment data: handled exclusively by our payment processor (Stripe). We do not store card numbers.

3. LEGAL BASIS FOR PROCESSING (GDPR)

We process your personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b)): to provide the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): to improve the Service, prevent fraud, and ensure security.
  • Consent (Art. 6(1)(a)): for marketing communications and non-essential cookies. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): where required by applicable law.

4. HOW WE USE YOUR DATA

  • To create and manage your account.
  • To deliver AI conversation sessions and generate performance analytics.
  • To respond to demo requests and support inquiries.
  • To send transactional emails (password resets, invoices).
  • To send marketing updates, only where you have consented.
  • To detect and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations.

5. DATA RETENTION

We retain your personal data for as long as your account is active or as needed to provide the Service. Session transcripts and analytics are retained for a maximum of 24 months from creation, after which they are automatically deleted. You may request earlier deletion at any time (see Section 8).

6. DATA SHARING & THIRD PARTIES

We do not sell your personal data. We may share data with:

  • Infrastructure providers (hosting, cloud storage) โ€” under GDPR-compliant data processing agreements.
  • AI model providers โ€” conversation content is processed by AI APIs solely to generate responses; it is not used to train third-party models without your consent.
  • Payment processors (Stripe) โ€” for billing purposes only.
  • Analytics providers โ€” anonymised or pseudonymised data only.
  • Legal authorities โ€” when required by law or court order.

7. INTERNATIONAL TRANSFERS

Our primary infrastructure is located within the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.

8. YOUR RIGHTS UNDER GDPR

You have the following rights regarding your personal data:

  • Right of access โ€” obtain a copy of the data we hold about you.
  • Right to rectification โ€” correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") โ€” request deletion of your data.
  • Right to restriction โ€” limit how we process your data.
  • Right to data portability โ€” receive your data in a structured, machine-readable format.
  • Right to object โ€” object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent โ€” at any time, without affecting lawfulness of prior processing.

To exercise any of these rights, contact us at dpo@ragedom.ai. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (in Greece: Hellenic Data Protection Authority โ€” dpa.gr).

9. SECURITY

We implement appropriate technical and organisational measures to protect your personal data, including TLS encryption in transit, encryption at rest, access controls, and regular security reviews. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within the timeframes required by GDPR.

10. COOKIES

We use cookies and similar tracking technologies. For full details, please see our Cookie Policy.

11. CHILDREN'S PRIVACY

The Service is intended for professional use by individuals aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at privacy@ragedom.ai and we will delete it promptly.

12. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or in-app notification at least 14 days before changes take effect. Continued use of the Service after that date constitutes acceptance of the updated policy.

13. CONTACT US

For any privacy-related questions or requests:
dpo@ragedom.ai
OSQOM GROUP ยท Ragedom AI