This Privacy Notice explains how 800 ("we", "us") processes personal data when you visit eight-hundred.app, use app.eight-hundred.app, create an account, or run a build. It is written for customers and visitors. It is not legal advice.
Privacy at a glance
- 800 is established in the Netherlands (Plesostraat 245, 1043 BV Amsterdam; KvK 80076629).
- You control Customer Content (uploaded documents, extracted text, and generated project outputs). We process it to provide the service.
- Customer Content is stored in the European Union (Ireland).
- When you run a build, extracted text needed for that run is sent to Fireworks AI for transient inference. Fireworks is established in the United States; prompts and generations are not retained by default under Fireworks' zero data retention policy for this path.
- We do not use Customer Content to train shared or public models.
- Delete projects in the product, or email legal@eight-hundred.app for account deletion and privacy requests.
Who we are
- Controller: 800
- Registered address: Plesostraat 245, 1043 BV Amsterdam, the Netherlands
- Chamber of Commerce (KvK): 80076629
- Privacy and DPO contact: legal@eight-hundred.app
A data protection officer is appointed. Contact the DPO at the address above.
Controller and processor roles
800 as controller. We determine the purposes and means of processing for Account Data, billing records, service security, abuse prevention, transactional service messages, and our own product analytics.
800 as processor.When we process personal data contained in Customer Content on a business customer's instructions, the customer is normally the controller and 800 acts as its processor under our Data Processing Addendum (DPA), available on request. This Privacy Notice does not replace the processor contract required by GDPR Article 28.
Your responsibilities. If Customer Content mentions employees, customers, suppliers, or other people, you are responsible for having a lawful basis and providing any notices those people need. Only upload material you are allowed to share with a processor and its subprocessors.
Providers listed on Security & subprocessors act as subprocessors where they process personal data for these purposes.
Definitions
- Account Data: information used to create and administer an account (for example company email, display name, password hash, session identifiers).
- Customer Content: uploaded process documents, extracted text, project metadata, and generated outputs (overviews, tasks, agent briefs, and related exports).
Processing activities
Where 800 is processor for Customer Content, the customer's instructions and DPA govern the purpose.
| Activity | Data (summary) | Role | Legal basis (when we are controller) | Retention |
|---|---|---|---|---|
| Website and product use | Technical logs; product analytics events (PostHog EU Cloud) | Controller | Legitimate interests (secure delivery, understand product usage); consent where required for non-essential analytics | Security logs: 90 days |
| Account registration | Company email, name if provided, password hash | Controller | Performance of our contract with the business customer; legitimate interests in securing accounts for authorised users | While the account is active; deleted or anonymised within 30 days of a confirmed deletion request |
| Email / password authentication | Email, password hash, verification codes (hashed), session cookie | Controller | Contract; legitimate interests (account security) | Verification codes: 10 minutes. Sessions: up to 30 days or until sign-out |
| Google sign-in | Email and profile claims needed for the session | Controller | Contract; legitimate interests (account security) | As for account and session data |
| Uploaded documents and runs | Customer Content; may include third-party personal data. Extracted text sent to Fireworks for the run | Processor (typical B2B) | Customer's basis under the DPA | While the project and account remain. Projects deleted in the product are removed from active systems; backups cleared within 90 days. Account deletion: within 30 days of confirmation |
| Credits and billing | Credit balance; payment confirmation metadata from Stripe | Controller | Contract; legal obligation (accounting and tax) | Account active for balances. Invoices and statutory accounting records: generally 7 years |
| Transactional email | Email address; verification or reset codes | Controller | Contract; legitimate interests (secure access) | Codes: 10 minutes |
| Support | Email content you send us | Controller | Legitimate interests; contract | 24 months after the thread closes |
| Security and abuse prevention | IP, user agent, request metadata, security events | Controller | Legitimate interests (security, abuse prevention, reliability) | 90 days |
Legitimate interests we pursue include securing the service, preventing abuse, keeping accounts available, and understanding product usage so we can improve 800. You may object where applicable.
Account Data is required to use the product. Without it we cannot create a session or run builds. We do not send marketing emails; only transactional messages such as verification and password-reset codes.
AI processing of Customer Content
An open-weight model does not itself have a meaningful legal location. What matters is who receives the prompts, where inference runs, what is retained, and who can access the data.
When you run a build, we send only the extracted text and instructions needed for that run to Fireworks AI(Fireworks.ai, Inc.), our AI inference subprocessor. Inference uses Fireworks' Chat Completions API with a Kimi-family open-weight model running on Fireworks infrastructure. We do not use Fireworks' Responses API for this product path.
Customer Content is stored in the European Union (Ireland). For each run, extracted text is processed by Fireworks for transient AI inference. Fireworks is established in the United States and may process that request outside the EEA. Under Fireworks' published zero data retention policy for open-model inference, prompts and generations exist in volatile memory for the request and are not logged to persistent storage by default; Fireworks may retain limited service metadata such as token counts. Fireworks states that it does not use prompts or API inputs to train or improve its models without explicit opt-in. See Fireworks data handling and trust.fireworks.ai.
Where personal data is transferred outside the EEA, we rely on our DPA with customers, contractual transfer safeguards with Fireworks (such as standard contractual clauses), and supplementary security measures. Further information is available on request at legal@eight-hundred.app.
We do not use Customer Content to train shared or public models. See also Security & subprocessors.
Who we share with
We use service providers to operate 800. They receive only what they need for their role. The current list is on Security & subprocessors. We do not sell personal data.
We may disclose information if required by law, to protect rights and safety, or in connection with a corporate transaction, taking steps that are reasonable under the circumstances.
Cookies and similar technology
- Session cookie: required to keep you signed in (Auth.js). Strictly necessary for the product.
- Optional analytics: on marketing pages we ask before enabling usage analytics (EU-hosted). Necessary cookies are always on. You can choose Accept all cookies, Reject all, or open Cookie settings to turn analytics on or off. Your choice is stored in the browser (localStorage). In the product app, analytics may run to understand how 800 is used. Signed-in users are identified by an internal account ID; we may set email domain as a person property, not the full email address. Event properties are limited so document text, prompts, and model output are not sent.
You can limit cookies in your browser. Blocking the session cookie will prevent sign-in. Clearing site data resets your analytics choice on marketing pages.
Retention
| Category | Period |
|---|---|
| Verification and reset codes | 10 minutes |
| Sessions | Up to 30 days, or until you sign out |
| Active projects and Customer Content | While the account and project remain |
| Deleted projects | Removed from active systems when you delete; backups cleared within 90 days |
| Account deletion | Deleted or anonymised from active systems within 30 days of a confirmed request |
| Security and application logs | 90 days |
| Support communications | 24 months after the thread closes |
| Export after account closure | Request within 30 days of termination |
| Invoices and statutory accounting | Generally 7 years under Dutch rules |
Your rights
Depending on applicable law (including the GDPR), you may have rights to access, rectify, erase, or port personal data; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. We take reasonable steps to verify requests before acting.
For Customer Content where we act as processor, we assist the customer controller under the DPA. Individuals mentioned only in Customer Content should usually contact the customer organisation first.
You may lodge a complaint with the Autoriteit Persoonsgegevens or with another competent supervisory authority where you live or work.
Contact: legal@eight-hundred.app.
International transfers
Customer Content is stored in the EU (Ireland). Some providers process or may access data outside the EEA, in particular Fireworks AI for inference, and providers such as Google, Stripe, and Resend for authentication, payments, and email. Where required, we use appropriate safeguards such as standard contractual clauses. Details are available on request.
Automated decision-making
800 generates AI-assisted overviews and agent briefs for you to review. We do not use automated decision-making that produces legal or similarly significant effects about individuals without human involvement in the sense of GDPR Article 22. Review outputs before relying on them.
Children
800 is a business product. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
Changes to this notice
We may update this notice when our processing activities, providers, or legal obligations change. We will publish the revised notice and update the date above. Where a change materially affects your rights or requires consent, we will provide an additional notice or request consent as required.