FreyaSign in
For procurement & security teams

Trust & Security

Freya is built for enterprise pilots. This page describes where your data lives, who else processes it, how long we keep it, and the rights you and your users have.

Data residency

All customer data — accounts, session transcripts, AI feedback, audio metadata — is stored in the European Union. Our database is hosted in Frankfurt and compute runs on EU edge locations. AI inference is routed to EU endpoints where the provider supports them.

Encryption & access control

  • TLS 1.2+ in transit, AES-256 at rest.
  • Row-level security enforced in the database — users see only their own data.
  • Secrets stored in encrypted vault; least-privilege access for staff.
  • Password breach detection via Have I Been Pwned on every signup and password change.
  • SAML 2.0 single sign-on available for enterprise customers.

Retention

  • Session transcripts, feedback content, and AI call logs are deleted after 365 days.
  • Aggregate progression (NELO rating, achievements, daily challenge runs) is preserved.
  • Account profile and entitlements are retained until the user requests deletion.
  • Deleted accounts are purged from authentication after a 30-day grace period.

Your rights (GDPR)

Every Freya user has self-serve access to:

  • Export — download a JSON archive of your data once per 24 hours.
  • Delete — request account deletion; 30-day cancel window before permanent purge.
  • Rectify — edit profile fields directly in /profile.

Available at /settings/account once signed in. Controller-level requests: privacy@negotia.app.

Data Processing Agreement

Enterprise customers accept our DPA click-through in /settings/dpa. The current version is bundled with the in-app sign flow. For redlines or counter-signed copies email dpa@negotia.app.

Sub-processors

We use the following sub-processors to operate Freya. Material changes are notified to customers at least 30 days in advance.

VendorPurposeRegionDPA
Supabase (database, auth, storage)Primary data store, authentication, file storageEU (Frankfurt)View
CloudflareEdge compute & CDNEU edgeView
Lovable AI GatewayModel routing for AI feedbackEU-routedView
OpenAI (Whisper)Speech-to-text transcriptionEU/US (no training on data)View
AI voicesText-to-speech voices (Trial/Pro)EU/USView
Lovable EmailTransactional email deliveryEUView
SentryError tracking (planned)EU (Frankfurt)View
PostHogProduct analytics (planned)EU (Frankfurt)View

Incident response

We notify affected customers within 72 hours of confirming a personal-data breach, with the information required by Article 33 GDPR.

Questions a security review didn't answer? Email security@negotia.app.