Privacy Policy — F-AI Contract Template Finder
This Privacy Policy explains how Junegust Products Ltd (trading as February AI) (“we”, “us”, “our”) processes information in connection with the F-AI Contract Template Finder plugin (the “Plugin”). It is designed to meet transparency requirements under the UK GDPR, the EU GDPR, and the California Consumer Privacy Act as amended by the CPRA (the “CCPA/CPRA”).
In this Policy, “personal data” has the meaning given in the UK GDPR and the EU GDPR. In the California section, we use “personal information” as defined under the CCPA/CPRA. Where both regimes apply, those terms are used in a corresponding sense.
1. Who we are
The data controller for the processing described in this Policy is:
Junegust Products Ltd (trading as February AI)
124 City Road
London
United Kingdom
EC1V 2NX
You can contact our Data Protection Officer at:
- Email: [email protected]
- Post: Junegust Products Ltd, 124 City Road, London, United Kingdom, EC1V 2NX
2. Scope of this Policy
This Policy applies only to the F-AI Contract Template Finder Plugin.
It does not apply to our website, applications, or other products, which are covered by separate privacy notices. Those notices are not incorporated into this Policy.
This Policy also does not describe how OpenAI processes data when you use ChatGPT. That processing is governed by OpenAI’s own privacy policy, which you agree to before using the Plugin. We do not control OpenAI’s storage or privacy practices.
3. How the Plugin works
When you use the Plugin:
- You enter search parameters in the Plugin’s form interface, which is provided by our MCP server.
- Those parameters are sent to our Plugin backend through ChatGPT.
- We process the parameters to generate instructions that enable ChatGPT to find publicly available links to legal document templates (such as contracts, agreements, policies, and letters).
- The Plugin returns links to template sources together with suitability notes and an indication of what could not be verified.
The Plugin does not download templates, copy their full text into our systems as a product function, or provide legal advice. Output is informational only.
4. Information we process
The Plugin is not designed for you to submit personal information such as your name, email address, account credentials in the Plugin's form. We do not require such information to provide the service.
We do, however, process the following categories of information, some of which may constitute personal data (or personal information) under applicable law:
| Category | Description |
|---|---|
| Search parameters | Required fields: document type and jurisdiction (selected from a list or entered as free text). Optional fields may include price model, licence or permitted use, file format, registration requirement, claimed lawyer review, source freshness year, minimum number of links, free-text additional requirements, and other fields. Search parameters are not intended to include identifying personal information, but may incidentally contain personal data if you choose to type it into free text fields. |
| Internet protocol (IP) address | Collected in connection with requests to our infrastructure. |
| Server and access logs | Technical request metadata such as timestamp, IP address, endpoint, and HTTP status code (and similar operational fields). |
| Security-related data | Flags or records associating an IP address with suspected abuse, where our criteria are met (see Retention). |
| Security technology data | Data processed by captcha, web application firewall (WAF), content delivery, hosting, and similar security or delivery mechanisms as needed to deliver and protect the Plugin. |
What we do not use in connection with the Plugin. We do not use analytics products, advertising or marketing pixels, profiling tools to process Plugin data.
Is providing information mandatory?
- Required search fields (document type and jurisdiction) are necessary to perform the service you request. If you do not provide them, we cannot run the search task.
- Optional search fields are voluntary. You may leave them blank.
- IP addresses and log data are collected automatically as part of using the service infrastructure.
5. Purposes and lawful bases (UK and EU GDPR)
We process personal data only where we have a lawful basis under the UK GDPR and, where applicable, the EU GDPR. We do not rely on consent for the core processing described below.
| Purpose | Data involved | Lawful basis |
|---|---|---|
| Provide the Plugin service (process the search task and return the instructions / results workflow) | Search parameters | Article 6(1)(b) — necessary to take steps at your request and to perform the service you ask us to provide |
| Security, abuse prevention, rate limiting, captcha, and investigating suspected attacks | IP address, security-related data, related log fields | Article 6(1)(f) — legitimate interests |
| Operate and maintain the service (access logs; hosting, content delivery, WAF, DDoS protection) | Server and access logs; infrastructure-related processing | Article 6(1)(f) — legitimate interests |
| Comply with binding legal obligations | Relevant subset of data, only when required | Article 6(1)(c) — legal obligation, only when applicable |
Legitimate interests
Our legitimate interests are ensuring the security, integrity, and availability of the Plugin; preventing fraud and abuse (including distributed denial-of-service (DDoS) attacks and exploit attempts); and maintaining the technical logs needed to operate the service reliably.
We balance these interests against your rights and freedoms. Security and logging processing is limited in scope and retention. We do not use form content for advertising or profiling. You may object to processing based on legitimate interests as described in the rights section below.
6. How long we keep information
We apply the following retention periods:
- Search parameters are processed in memory only for the duration of your user task and are then automatically deleted. They are not written to long-term application storage as a product design.
- Server access logs (all requests) are retained for 30 days, then deleted or anonymised.
- Flagged security IP addresses and related security records may be retained for up to 12 months or only while the threat remains relevant, whichever is shorter. We may associate an IP address with suspected abuse where we see indicators such as repeated abuse, DDoS patterns, or exploit attempts.
- We may delete or anonymise information sooner if the purpose has been achieved. We review retention periodically in line with the storage limitation principle.
7. Who we share information with
We use hosting and security providers, including providers of content delivery, web application firewall, DDoS protection, and third-party captcha and security services, to operate and protect the Plugin.
These providers may process IP addresses, request metadata, search-parameter traffic as it passes through our infrastructure, and related security data to help us deliver and protect the Plugin. We engage them as processors under the UK/EU GDPR and as service providers under the CCPA/CPRA, to process information for our specified business purposes under arrangements that limit their use of the data.
We do not sell personal data or personal information, and we do not share personal information for cross-context behavioural advertising.
We may also disclose information where required to comply with applicable law, legal process, or binding requests from public authorities, or to establish, exercise, or defend legal claims.
8. International transfers
Your data may be transferred, processed, and stored outside of the United Kingdom.
9. Cookies and similar technologies
Our hosting and security providers may use cookies or similar technologies that are strictly necessary to protect the Plugin (for example, security checks, captcha-related protections, and abuse prevention).
We do not use analytics, advertising, marketing, or profiling cookies or similar technologies in connection with the Plugin.
Because the technologies we use in connection with the Plugin are limited to what is necessary for security and service protection, we do not present a consent banner for core Plugin use on that basis. This Policy is our unified notice for these technologies; there is no separate cookie policy for the Plugin.
10. Your rights (United Kingdom and European Economic Area)
If the UK GDPR or the EU GDPR applies to our processing of your personal data, you have the following rights, subject to the conditions and exceptions in those laws:
- Access — to obtain confirmation of whether we process your personal data and, where we do, access to that data and related information.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to request deletion of personal data in certain circumstances. In practice, search parameters may already have been deleted after your task ends. We may retain security-related data where an exemption applies (for example, where processing remains necessary for legitamate interests or for ongoing security).
- Restriction — to request that we restrict processing in certain circumstances.
- Portability — to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where applicable. This right is mainly relevant to search parameters you provided, to the extent we still hold them.
- Objection — to object to processing based on legitimate interests, including processing of IP addresses, security-related data, and logs for security and service operation. If you object, we will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.
How to exercise your rights and raise privacy concerns
Please contact our Data Protection Officer at [email protected], or write to us at the postal address in Section 1.
We encourage you to contact us first about any privacy concern or complaint so that we can review and address it. We will handle privacy complaints through our Data Protection Officer.
We will respond to rights requests in accordance with applicable law. You will not ordinarily have to pay a fee. We may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive, as permitted by law. We may need to verify your identity before fulfilling a request.
11. Additional information for California residents
This section applies to residents of California and supplements the rest of this Policy. Under the CCPA/CPRA, “personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
Categories of personal information we collect
Consistent with Section 4, we may collect:
| CCPA/CPRA category (illustrative) | Examples in our data map | Sources |
|---|---|---|
| Identifiers | IP address | Automatically from use of the Plugin; service providers supporting hosting and security |
| Internet or other electronic network activity information | Server and access logs; security events; security technology data | Automatically from use of the Plugin; our hosting and security providers |
| Information you submit in the form | Search parameters, to the extent they constitute personal information | Directly from you via the Plugin form |
We do not collect personal information through the Plugin for analytics, advertising, or profiling purposes.
Business purposes for which we use personal information
- Providing the Plugin service
- Helping to ensure security and integrity
- Debugging to identify and repair errors
- Short-term, transient operational use
- Undertaking activities to verify or maintain the quality or safety of the service
We do not use Plugin personal information for cross-context behavioural advertising.
Sale and sharing
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
Our hosting and security providers (including captcha providers) are service providers that process personal information only for our business purposes under contract.
Because we do not sell or share personal information as described above, we do not offer a “Do Not Sell or Share My Personal Information” link for the Plugin.
Sensitive personal information
We do not use or disclose sensitive personal information collected through the Plugin to infer characteristics about you, or for purposes that would require a right to limit the use of sensitive personal information under this product model.
Retention
We retain personal information as described in Section 6 (search parameters: in memory for the task only, then deleted; access logs: 30 days; flagged security records: up to 12 months or while the threat remains relevant, whichever is shorter).
Your California rights
Subject to verification and applicable exceptions, California residents have the right to:
- Know and access the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom we disclose personal information
- Delete personal information we have collected from you
- Correct inaccurate personal information
- Opt out of sale or sharing of personal information — not applicable to the Plugin because we do not sell personal information and do not share it for cross-context behavioural advertising
- Non-discrimination for exercising your CCPA/CPRA rights
How to submit a California request
Email our Data Protection Officer at [email protected], or write to Junegust Products Ltd, 124 City Road, London, United Kingdom, EC1V 2NX. Please state that you are making a California privacy rights request and describe the request clearly.
We will take reasonable steps to verify your identity before fulfilling a request. You may use an authorised agent to make a request on your behalf; we may require proof of authorisation and may still need to verify your identity directly, as permitted by law.
12. Security
We implement appropriate technical and organisational measures to protect personal data and personal information, taking into account the nature of ephemeral form processing, limited security logging, and the risks involved.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will post the updated Policy with a new effective date. Where appropriate for material changes, we may provide additional notice via the Plugin listing or other reasonable means.
The updated Policy applies to processing that occurs after its effective date.