Privacy Policy for CostCare AI
Legal entity: CostCare AI Limited • Address: 2301, 23/F BAYFIELD BLDG 99
HENNESSY RD WAN CHAI
HONG KONG
Contact: support@costcare.ai • Privacy: privacy@costcare.ai
This Privacy Policy explains how CostCare AI Limited (“CostCare”, “we”, “us”) collects, uses, shares, and protects information when you use CostCare AI (the “Service”).
This Service is designed for business users. If you are an end-customer contacting one of our business customers, your messages/calls are handled by that customer and processed by us on their behalf.
This Policy applies to information processed through:
Depending on the data, we act as:
We can provide a Data Processing Addendum (“DPA”) on request (and we publish a template at /dpa).
To keep integrations working, we store access tokens/credentials (e.g., Meta/WhatsApp/Instagram). We store tokens in our database today and plan to migrate to a dedicated secrets manager (e.g., Vault). Tokens are restricted and protected with access controls.
We use information to:
The Service uses AI to generate suggested or automated responses. AI outputs may be inaccurate or incomplete and should be reviewed when appropriate. Customers control configuration and are responsible for how the Service is used with their end-customers.
Training: We do not train our proprietary models on Customer Content unless a customer explicitly opts in (e.g., a separate agreement or setting).
When GDPR applies, we rely on the following legal bases (as Controller):
For Customer Content (Processor), the customer determines the legal basis and provides instructions.
We share data only as needed to provide the Service:
We may update subprocessors over time. We will maintain an up-to-date list upon request via privacy@costcare.ai.
We currently host primary infrastructure in the European Union (Frankfurt, Germany). Our team and subprocessors may access or process data from other countries (including Ukraine). Where required, we use appropriate safeguards for international transfers (such as standard contractual clauses or equivalent mechanisms).
We use reasonable technical and organizational measures designed to protect data, including encryption in transit (TLS), access controls, and logging. No system is 100% secure; customers are responsible for maintaining the confidentiality of their credentials and enabling security features available in the Service.
We use essential cookies required to operate the Service (e.g., authentication). We do not currently use advertising cookies. If we add product analytics or session replay tools (for example, Hotjar), we will update this Policy and, where required, request consent.
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object or restrict certain processing. To exercise rights related to account data, contact privacy@costcare.ai.
For rights related to Customer Content (end-customer messages/calls), please contact the business you interacted with (our customer). We will assist our customer as required under the DPA.
The Service is not intended for children under 16 and should not be used to knowingly collect data from children.
We may update this Policy from time to time. We will post the updated version on this page and revise the “Last updated” date.
Privacy questions: privacy@costcare.ai • Support: support@costcare.ai