Privacy Policy
1. Introduction
Welcome to February AI. Junegust Products Ltd., a company registered in England and Wales with a registered office at 124 City Road, London, United Kingdom, EC1V 2NX ("we", "us", or "our"), operates the self-help AI contract drafting tool, February AI (the "Service").
This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the website or use the Service, and our practices for collecting, using, maintaining, protecting, and disclosing that information.
2. Definitions
For the purposes of this Privacy Policy, the following terms bear the stated meanings:
- Service: The self-help AI contract drafting tool, February AI, operated by Junegust Products Ltd.
- User Content: The documents, plan drafts, and AI chat inputs where you strictly prohibit the insertion of PII.
- PII/Personal Data: Personally Identifiable Information or Personal Data relating to an identified or identifiable natural person as defined under the UK GDPR.
- Cookie Banner: is a user interface component on the getfebruary.ai website that informs users about the use of cookies and allows them to accept, reject, or manage their preferences for optional cookies that are not strictly necessary for the operation of the Service.
3. Information Collection and Categorization
To align with our Terms of Service (specifically the strict prohibition of Personal Data in our core AI workflows), we categorically separate the data required to administer your account and understand our business from the content you process using our Service.
3.1 Account & Billing Data
We intentionally and necessarily collect the following administrative data to operationalize the Service, maintain your account, and fulfill our financial and legal obligations:
- Identity & Contact Information: First name, last name, and email address (including information automatically populated via our authenticated in-app support and feedback widgets). If using Google SSO, we may additionally receive your basic profile information, including your avatar.
- Financial & Transactional Information: Billing address, business name and tax identification numbers (if applicable for your organization), applied promotional or discount codes, specific organizational details required for tax and contracting records, and limited payment method fingerprints (we DO NOT process or store raw, full primary account numbers/credit card numbers ourselves; these are handled securely by our designated third-party payment processor).
- Technical Administrative Data: Account creation and login IP addresses, referring pages, essential cookies, and analytical or marketing attribution cookies. Analytical or marketing attribution cookies are strictly subject to your explicit opt-in consent via the Cookie Banner).
3.2 Business Profiling Data
As our Service is strictly intended for business, commercial, and professional use, we may collect or infer context regarding your professional profile based on the interactions and initial conversations you have with us or the Service. This "Business Profiling Data" comprises:
- Job title or professional role.
- Organizational type or industry segment.
- Approximate organizational size.
3.3 Actionable Logging
For the purposes of maintaining the operational security of our systems and preventing abusive exploitation, we maintain technical logs consisting of:
- IP addresses.
- Device identifiers (e.g., browser type and version, operating system, screen size).
- Language preferences.
- Platform analytics.
- Data collected by our security mitigation partners, such as Cloudflare or CAPTCHA providers, to thwart malicious traffic and automated attacks.
4. Absolute PII Interdiction in User Content
As explicitly mandated in Section 3.3 of our Terms of Service, you are fundamentally and strictly prohibited from inserting, embedding, typing, or uploading any Personally Identifiable Information (PII) or Personal Data—whether belonging to you or any third party—into the core Service workflows, specifically defining User Content as outlined in Section 2.
This absolute restriction applies across our entire interface:
- Into AI conversational inputs or prompt boxes.
- Into text directly authored or pasted within our document editors.
- Within any external files or documents uploaded to our AI engine.
4.1 Automated Technical Safeguard Disclaimer
We deploy automated scrubbing and anonymization pipelines as a mandatory technical safeguard to comprehensively sanitize input streams prior to any AI model training or processing. However, you expressly acknowledge that the presence of this technical safeguard does not excuse, waive, or mitigate your fundamental obligation to exclude all Personal Data from your User Content. You bear absolute responsibility for ensuring no unauthorized PII enters the Service workflow.
5. Lawful Basis and Use of Data
We process the distinct data categories identified in Section 3 under the following bases:
- Contractual Necessity (Performance of a Contract): We process Identity & Contact Information and Financial & Transactional Information primarily because it is necessary to deliver the Service, manage your subscription, accurately apply promotional codes or discounts to your order, process related payments, and send transactional communications.
- Legal Obligation: We are required to process and retain certain Financial & Transactional Information, including first and last name, billing addresses, business name, organizational tax identifiers, and records of applied promotional codes, to guarantee absolute compliance with UK tax requirements (e.g., HMRC standards) and applicable statutory financial reporting (such as the Companies Act 2006).
- Legitimate Interest: We rely on our legitimate business interests to process data for the following indispensable purposes:
- Security and Fraud Prevention: Utilizing Actionable Logging and security partner network data (e.g., Cloudflare) to prevent account hijacking, combat fraudulent subscriptions, and neutralize cyber threats.
- Marketing Attribution and Analytics: Analyzing Business Profiling Data and the usage of promotional codes to refine our platform features, evaluate marketing attribution effectiveness, and measure the return on investment of campaigns. Note: Data collected via analytical or attribution cookies is strictly subject to your prior opt-in consent via the Cookie Banner.
- Support and Feedback: Using Identity & Contact Information automatically transmitted when a user submits a message through our authenticated user interface (UI) widgets, together with any PII/Personal Data that the user includes in the message, to provide technical support, process user feedback, and efficiently manage customer inquiries.
- Support: Using Identity & Contact Information, together with any PII/Personal Data included in messages submitted by users via email, to provide technical support, process user feedback, and efficiently manage customer inquiries.
- Legal Defense and Rights Enforcement: Retaining necessary account details to enforce our Terms of Service (such as excluding suspended users) or to resolutely defend against imminent legal declarations or disputes.
6. Retention Policies
We retain your personal data strictly for as long as reasonably necessary to fulfill the purposes for which it was collected, and in robust alignment with English law and UK statutory requirements.
- Tax and Accounting Records: Account & Billing Data integral to financial records is retained for a standard period of six (6) years from the date of the transaction to comply unconditionally with His Majesty's Revenue and Customs (HMRC) legal requirements. This period may be extended if we are legally compelled by an active investigation or statutory audit.
- Fraud Prevention and Legal Defense (Long-stop Retention): To ensure comprehensive mitigation against latent contractual disputes and to cover the statutory periods outlined in the Limitation Act 1980, certain essential administrative records may be retained for up to ten (10) years post-account closure. This incorporates the standard 6-year limitation period with an appropriate buffer to account for delayed discovery of fraud or legal action.
- Abusive User Suppression: In scenarios where a user's account is fundamentally terminated for cause (e.g., committing fraud, or violating the Terms of Service), we will retain their basic identifiers (such as email address or distinct device IDs) indefinitely or for the maximum period permissible under applicable law, strictly to enforce perpetual platform exclusion and prevent subsequent fraudulent registrations.
- Actionable Logging: Technical logs, including IP addresses and device identifiers collected for operational security and incident analysis, are retained for up to one (1) year.
- Marketing & Business Profiling: Data utilized for marketing attribution and ROI analytics is retained for a standard period of three (3) years. However, data connected to financial relationships or revenue-sharing models that necessitate proof for tax authorities (e.g., HMRC) will be retained for up to six (6) years in alignment with our tax and accounting retention policy.
- Support & Feedback: Communications and data processed for technical support and feedback are securely retained for the active lifespan of your account plus one (1) year following account closure to address trailing inquiries. Should a support interaction escalate into a legal dispute or formal complaint, the relevant records will be reclassified under our "Fraud Prevention and Legal Defense" retention policy (retained for up to 10 years).
7. International Data Transfers
Your data may be transferred, processed, and stored outside of the United Kingdom.
8. Data Subject Rights & Erasure Mechanics
Under the UK GDPR, you possess absolute and qualified rights regarding your personal data:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request the correction of inaccurate or incomplete personal data.
- Right to Object & Restrict Processing: You may object to our processing of your personal data (particularly when based on legitimate interests) or request that we restrict its processing under specific conditions.
- Right to Data Portability: You may request that we transfer your structured data directly to you or another organization.
- Right to Erasure ("Right to be Forgotten"): You may request the deletion of your personal data, subject to the conditions and exceptions detailed below.
To exercise any of these rights, please communicate your formal request to our Data Protection Officer electronically at [email protected].
8.1 Erasure Request Execution (Active Systems)
Upon verification of a valid erasure request, we will initiate the comprehensive deletion of your personal data from all active, live production databases within twenty (20) days.
8.2 Backup Expiration (The 30-Day Window)
To ensure robust disaster recovery, our live production systems generate comprehensive encrypted backups on rolling schedules. Your data is not immediately zeroed from these inaccessible offline backups the moment active deletion concludes. Instead, the backups expire naturally. The duration of active deletion combined with our backup rotation confirms that total technical disappearance definitively completes within the overarching thirty (30) day statutory response window.
8.3 Restoration Re-erasure Rule
In an extreme disaster recovery scenario necessitating the catastrophic restoration of a system backup to the live environment, we mandate the programmatic reapplication of all historical erasure logs. This guarantees previously deleted accounts are immediately re-deleted, strictly avoiding accidental resurrection.
8.4 Erasure Exceptions
Please be explicitly clear: the right to erasure is deeply constrained and not absolute. Data legally retained for active anti-fraud suppression, pending legal disputes, or mandatory UK tax compliance architectures cannot and will not be erased prematurely.
9. Security and AI Risk
We deploy commercially reasonable technical and organizational efforts—including relying on industry-standard partner frameworks (e.g., Cloudflare/CAPTCHA)—to secure your data against unauthorized access, destruction, and alteration.
However, recognizing the inherent complexities of cutting-edge technology, we fundamentally disclaim absolute guarantees. We cannot assure impenetrability against advanced, highly conceptual artificial intelligence-enabled cyberattacks and novel exploitation matrices.
Furthermore, you are formally reminded that while we deploy scrubbing technologies on uploaded materials, the very act of uploading documents via the Service carries an inherent architectural risk. The absolute security of documents containing impermissibly uploaded Personal Data cannot be guaranteed, and you execute such uploads directly at your own hazard, therefor we prohibited it under our Terms of Service (specifically the strict prohibition of Personal Data in our core AI workflows).
10. Changes to this Privacy Policy
We reserve the right to substantively update or amend this Privacy Policy at our unilateral discretion. We will communicate material alterations by publishing the freshly updated document natively on our platform. All revisions achieve immediate active effect upon posting. Your persistent utilization of the Service precisely constitutes your explicit and informed acceptance of any and all modifications.
You can also read our Disclaimer and Terms of Service.