Privacy Policy
What personal data BroomAI collects, why, on what lawful basis, who we share it with, how long we keep it, your rights, and how to exercise them. For the full technical data-flow specification, see our Data Handling reference and our Data Processing Agreement.
1. Who we are and our role
1.1 BroomAI Ltd ("BroomAI", "we", "us", "our") (company number: [to be inserted upon incorporation]), a company registered in England and Wales, operates the BroomAI AI workforce platform for e-commerce sellers.
1.2 BroomAI acts as: (a) Data Controller — for your account information, billing metadata, usage records, platform audit logs, and Terms acceptance records; and (b) Data Processor — for the store data, customer data, and email data you connect to the Platform, processed on your instructions as the data controller.
1.3 As a store owner using BroomAI, you are the data controller for your customers' personal data. You are responsible for your own privacy notices, lawful bases, and data subject rights obligations with respect to your customers.
1.4 Privacy contact: contact@broom-ai.com | Legal/ICO notices: legal@broom-ai.com
2. Data we collect, why, and our lawful basis
2.1 The table below sets out each category of personal data we process as data controller, the purpose, and the lawful basis under UK GDPR Article 6.
| Data category | Examples | Purpose | Lawful basis (UK GDPR Art.6) |
|---|---|---|---|
| Account Identity | Email (from Google Sign-In), name | Authenticate your account; bind you to your Store; provide access | Art.6(1)(b) — contract performance |
| Connected Store Data (Shopify) | Orders, products, inventory, fulfilment, customer names/emails/addresses associated with orders | Operate AI Agents (Ava, Jim, Sarah, Maya, Kai); execute approved actions; propose → approve → execute model | Art.6(1)(b) — contract (processed on your instruction as data controller) |
| Email Data (Gmail) | Inbound support emails; approved outbound replies (Sarah); supplier drafts (Maya) | Enable Sarah to triage customer support; enable Maya to draft supplier communications | Art.6(1)(b) — contract (opt-in integration) |
| Web Analytics (GA4) | Read-only sessions, traffic sources, conversion metrics from the GA4 property you connect | Power Kai's analytics insights (opt-in; analytics.readonly, read-only) | Art.6(1)(b) — contract (opt-in integration) |
| Messaging Identifiers | Telegram chat ID; owner ↔ agent messages | Provide owner messaging channel for approvals and agent interactions | Art.6(1)(b) — contract (opt-in) |
| Billing Metadata | Stripe customer reference, token balance, transaction reference | Process fees; financial records | Art.6(1)(b) — contract; Art.6(1)(c) — legal obligation (financial records) |
| Platform Audit Logs | Every agent action proposed; every approval/rejection; inputs and outputs | Accountability, security, dispute resolution, fraud prevention | Art.6(1)(f) — legitimate interests (see §2.2) |
| Terms Acceptance Records | Acceptance timestamp, version, IP metadata | Record acceptance of Terms; legal compliance | Art.6(1)(c) — legal obligation; Art.6(1)(f) — legitimate interests (legal protection) |
| Technical/Usage Data | Session logs, API logs, error logs | Security, debugging, abuse prevention, service improvement | Art.6(1)(f) — legitimate interests (anonymised/aggregated for improvement) |
2.2 Legitimate Interests Assessment (LIA). Where we rely on Art.6(1)(f) (legitimate interests), we have conducted and documented a Legitimate Interests Assessment for each such processing activity. Those LIAs record BroomAI's assessment that our interests — platform security, accountability, fraud prevention, and service improvement — are not overridden by your interests or fundamental rights, given: (a) you are a business customer operating in a commercial context; (b) the processing is limited to what is necessary; and (c) appropriate safeguards are in place. A copy of each LIA is maintained on file and is available to the UK Information Commissioner's Office (ICO) on request. You have the right to object to legitimate-interests processing — see §9.
2.3 We do not process special categories of personal data (Art.9 UK GDPR — health, biometric, racial or ethnic origin, etc.) through the Platform. Do not submit such data through the Platform without prior written agreement with BroomAI.
2.4 We do not sell personal data.
2.5 Data Protection Impact Assessment (DPIA). BroomAI has considered its obligations under Article 35 of the UK GDPR and conducted an internal DPIA covering the AI Agent processing of Shopify store data and Gmail data, the use of automated processing within the propose → approve → execute model (which requires human approval for all material store changes and outbound customer communications), and the use of large language models (Anthropic's Claude API) as new technology — including hallucination risk, data minimisation for API calls, and the fact that Anthropic's API terms prohibit training on submitted data. The DPIA is a living document, maintained on file, available to the ICO on request, and reviewed when BroomAI introduces materially new processing activities, new AI models, or new integrations.
3. How we use your data
3.1 Account data is used to create and manage your account, authenticate you, and communicate with you about the Platform.
3.2 Store and email data is used exclusively to operate the AI Agents you have hired, execute your approved actions, and provide the AI workforce service. This data is not used for any purpose unrelated to your use of the Platform.
3.3 Audit logs are maintained to provide an auditable record of all agent activity.
3.4 Billing data is used to process payments and maintain legally required financial records.
3.5 Anonymised and aggregated data (which cannot identify you or your customers) may be used to improve the Platform, benchmark performance, and develop new features.
4. AI processing of your data
4.1 BroomAI uses Anthropic's Claude models to power the AI Agents. Relevant context is sent to Anthropic's API over TLS for each task. Only data necessary for the specific task is sent.
4.2 Anthropic processes submitted data under API terms that prohibit using submitted data to train Anthropic's models.
4.3 Before any observability trace is sent to our monitoring provider (Braintrust), a redaction layer removes personal data. Emails, phone numbers, names, and addresses are replaced with salted hashes. Raw customer PII is never sent to the observability layer.
4.4 Deterministic code, not the AI model, handles the highest-risk decisions: inventory arithmetic, identity verification, and critical-action escalation. The model generates prose within those guardrails.
5. Google API Limited Use affirmation
5.1 BroomAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5.2 Data obtained from Google APIs (including Gmail and Google Analytics): (a) is used only to provide and improve the user-facing features the store owner has explicitly enabled; (b) is not transferred or sold to third parties for advertising, market research, or any unrelated purpose; (c) is not used to train, fine-tune, or develop generalised AI or machine learning models — email content is sent to Anthropic's API solely to generate the specific reply or decision for that message, under terms that prohibit training on submitted data; (d) is not read by humans, except (i) with explicit consent, (ii) where necessary for security or legal compliance, or (iii) where aggregated and anonymised; and (e) is not used for advertising purposes.
6. Sub-processors and data sharing
6.1 We share personal data only with the service providers necessary to operate the Platform, each bound by a data processing agreement. We do not share data for advertising or marketing purposes.
| Sub-processor | Location | What we share | Purpose |
|---|---|---|---|
| Anthropic (Claude API) | USA | Message/email content and order facts needed for the task | AI Agent reasoning and response. Not used for model training. |
| Railway (Hosting) | EU / US | All application data (encrypted at rest) | Application hosting, PostgreSQL, Redis queues |
| Google (Gmail, OAuth, Pub/Sub, Analytics) | USA | Per granted OAuth scopes; Google Limited Use policy applies | Email integration (Sarah/Maya), GA4 analytics (Kai), owner authentication |
| Shopify | Canada / USA | Per granted OAuth scopes | Store data source and write target for Jim, Maya, Sarah, Kai |
| Stripe | USA | Payment details (on Stripe-hosted Checkout only) | Payment processing. We never receive or store card numbers. |
| Braintrust (Observability) | USA | Redacted traces only — PII removed before export | AI call observability and debugging. Can be disabled. |
| Telegram | UAE | Owner ↔ agent messages (if connected) | Owner messaging channel for approvals |
7. International transfers of personal data
7.1 Some sub-processors are located outside the United Kingdom. Personal data may be transferred to the USA and other countries.
7.2 Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place: (a) UK adequacy regulations under Section 17A of the Data Protection Act 2018; (b) UK International Data Transfer Agreements (UK IDTAs) or UK Addendums to EU Standard Contractual Clauses (SCCs); or (c) Standard Contractual Clauses to the extent recognised under UK law.
7.3 Specific mechanisms: Anthropic (USA) — UK IDTA/SCCs; Stripe (USA) — UK IDTA/SCCs; Google (USA) — UK adequacy/SCCs; Railway (EU/US) — SCCs; Telegram (UAE) — SCCs. You may request information about specific transfer mechanisms at legal@broom-ai.com.
8. Data retention
8.1 We retain personal data only as long as necessary for the purpose collected or as required by Applicable Law:
| Data category | Standard retention period | Basis |
|---|---|---|
| Account identity (name, email) | Duration of account + 30 days after closure | Contract; administrative necessity |
| Connected store data (Shopify) | While integration active; auto-deleted on receipt of Shopify shop/redact webhook (~48 hours after uninstall) | Contract; Shopify mandatory compliance |
| Customer PII in support tickets | While Gmail integration active and ticket live; deleted on inbox disconnection or account deletion | Contract; customers/redact webhook |
| Email content (Gmail) | While Gmail integration connected; deleted on disconnection or account deletion | Contract |
| Billing and financial records | 7 years from transaction date | Legal obligation (UK financial/tax law) |
| Platform audit logs | 12 months from recorded action | Legitimate interests (accountability, security, disputes) |
| Terms acceptance records | Duration of account + minimum 6 years | Legal obligation; legitimate interests |
| Technical/session logs | 90 days (automated deletion) | Legitimate interests (security, debugging) |
8.2 On Shopify uninstall, BroomAI honours the shop/redact webhook automatically within ~48 hours.
8.3 On Gmail disconnection, BroomAI immediately revokes the token with Google and clears stored encrypted credentials.
8.4 Account deletion requests are processed within 30 days, subject to legally required retention.
9. Your rights under UK GDPR
9.1 You have the following rights under UK GDPR, subject to applicable exemptions: (a) Right of Access (Art.15); (b) Right to Rectification (Art.16); (c) Right to Erasure (Art.17), subject to legal retention obligations; (d) Right to Restriction (Art.18); (e) Right to Data Portability (Art.20); (f) Right to Object (Art.21) to processing based on legitimate interests — we will stop unless we can demonstrate compelling legitimate grounds or the processing is for legal claims; and (g) Rights re Automated Decision-Making (Art.22).
9.2 To exercise any right, email contact@broom-ai.com. We respond within one month (extendable by two months for complex requests with notice). Identity verification may be required.
9.3 Right to Lodge a Complaint with the ICO. If you consider our processing infringes UK data protection law, you may complain to the UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk | 0303 123 1113 | casework@ico.org.uk. We encourage you to contact us first at contact@broom-ai.com so we can address your concern directly.
10. Your rights under CCPA (California residents)
10.1 California residents have the following additional rights under the CCPA/CPRA: (a) Right to Know; (b) Right to Delete, subject to certain exceptions; (c) Right to Correct; (d) Right to Opt Out of Sale or Sharing — we do not sell or share personal information for cross-context behavioural advertising; (e) Right to Limit Use of Sensitive Personal Information — we do not use sensitive personal information beyond Platform provision; and (f) Right to Non-Discrimination.
10.2 To exercise CCPA rights, email contact@broom-ai.com with "CCPA Request" in the subject line. We respond within 45 days (extendable by 45 days with notice).
11. Automated decision-making and profiling
11.1 All material store changes and outbound customer communications require your explicit approval before execution (propose → approve → execute). BroomAI does not make decisions about you with legal or similarly significant effects on a solely automated basis.
11.2 Where AI Agents interact with your customers, you as data controller are responsible for ensuring compliance with Article 22 of the UK GDPR, including providing appropriate notices and safeguards.
11.3 Deterministic code, not the AI model, handles high-risk decisions such as identity verification and critical-action escalation.
12. Cookies
12.1 This section reflects a cookie audit of broom-ai.com conducted on [audit date to be confirmed] and will be updated following any changes to cookies or tracking on the Platform. If you identify any discrepancy, please notify us at contact@broom-ai.com.
12.2 Based on that audit, we use only technically necessary cookies for authentication (session management) and security (CSRF protection nonces). We do not use advertising, tracking, analytics, or preference cookies. If this changes, we will update this section and, where PECR requires it, obtain your consent before setting any non-essential cookies.
12.3 Technically necessary cookies cannot be disabled without preventing login to the Platform. By using the Platform, you consent to our use of technically necessary cookies.
12.4 We use a short-lived session state nonce (server-side, 10-minute TTL) for OAuth CSRF protection. This is verified and deleted on callback and is not retained.
13. Children's data
13.1 The Platform is not directed at individuals under 16. We do not knowingly collect personal data from children under 16.
13.2 If you become aware we have collected data from a child under 16 without parental consent, contact contact@broom-ai.com immediately.
14. Security
14.1 We implement commercially reasonable technical and organisational measures including: AES-256-GCM encryption of OAuth tokens at rest; TLS encryption in transit; HMAC-SHA256 webhook verification; short-lived JWT-based API authentication; PII redaction before observability traces; and audit logging of all agent actions and approvals.
14.2 No security system is completely secure. We do not guarantee immunity from unauthorised access, disclosure, or data loss.
14.3 You are responsible for maintaining security of your own systems and connected accounts.
15. Changes to this policy
15.1 We may update this Privacy Policy at any time. For material changes, we will update the "Last Updated" date and notify you by email or in-Platform notification. We may require renewed in-app acceptance for material changes.
15.2 Continued use after an updated Policy takes effect constitutes acceptance.
16. Contact us
© 2026 BroomAI Ltd. All rights reserved. | broom-ai.com | legal@broom-ai.com | Privacy Policy v2.0 — UK GDPR Art.13 compliant.