Trust & Security
Freya is built for enterprise pilots. This page describes where your data lives, who else processes it, how long we keep it, and the rights you and your users have.
Data residency
All customer data — accounts, session transcripts, AI feedback, audio metadata — is stored in the European Union. Our database is hosted in Frankfurt and compute runs on EU edge locations. AI inference is routed to EU endpoints where the provider supports them.
Encryption & access control
- TLS 1.2+ in transit, AES-256 at rest.
- Row-level security enforced in the database — users see only their own data.
- Secrets stored in encrypted vault; least-privilege access for staff.
- Password breach detection via Have I Been Pwned on every signup and password change.
- SAML 2.0 single sign-on available for enterprise customers.
Retention
- Session transcripts, feedback content, and AI call logs are deleted after 365 days.
- Aggregate progression (NELO rating, achievements, daily challenge runs) is preserved.
- Account profile and entitlements are retained until the user requests deletion.
- Deleted accounts are purged from authentication after a 30-day grace period.
Your rights (GDPR)
Every Freya user has self-serve access to:
- Export — download a JSON archive of your data once per 24 hours.
- Delete — request account deletion; 30-day cancel window before permanent purge.
- Rectify — edit profile fields directly in
/profile.
Available at /settings/account once signed in. Controller-level requests: privacy@negotia.app.
Data Processing Agreement
Enterprise customers accept our DPA click-through in /settings/dpa. The current version is bundled with the in-app sign flow. For redlines or counter-signed copies email dpa@negotia.app.
Sub-processors
We use the following sub-processors to operate Freya. Material changes are notified to customers at least 30 days in advance.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Supabase (database, auth, storage) | Primary data store, authentication, file storage | EU (Frankfurt) | View |
| Cloudflare | Edge compute & CDN | EU edge | View |
| Lovable AI Gateway | Model routing for AI feedback | EU-routed | View |
| OpenAI (Whisper) | Speech-to-text transcription | EU/US (no training on data) | View |
| AI voices | Text-to-speech voices (Trial/Pro) | EU/US | View |
| Lovable Email | Transactional email delivery | EU | View |
| Sentry | Error tracking (planned) | EU (Frankfurt) | View |
| PostHog | Product analytics (planned) | EU (Frankfurt) | View |
Incident response
We notify affected customers within 72 hours of confirming a personal-data breach, with the information required by Article 33 GDPR.