Privacy policy
This policy explains how HonchoSuite collects, uses, protects, and shares personal data. We operate under two regimes: the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Where they differ, we apply the stronger protection.
Who we are and how to reach us
HonchoSuite is the data controller for the personal data described here. For any privacy question, request, or grievance, contact our privacy team at privacy@honchosuite.com. A named grievance officer handles escalations (see “Your rights”).
Data we collect, why, and our lawful basis
We collect only what each feature needs. The lawful basis is shown for each purpose.
- Account, authentication, and billing — your name, email, and subscription details, to create and run your account. Basis: performance of a contract (and consent where required).
- Brief generation — your Intelligence Profile (company, sector, role, tracked competitors, regulatory jurisdictions, strategic priorities) used to produce your Daily Brief. Basis: contract / consent.
- Personalization from implicit signals — how you engage with briefs and content, used to tune relevance. Basis: legitimate interest, with an opt-out (consent where required).
- Email open pixel — measures whether brief emails are opened. Off until you consent; basis: consent.
- Marketing and lifecycle emails — onboarding and product updates. Basis: separate, specific consent you can withdraw at any time.
- Transactional emails — receipts, security and service notices. Basis: contract.
- Referral cookie — attributes a sign-up to a referrer. Basis: consent.
- Product and site analytics — aggregate usage to improve the product and this website. Basis: consent for non-essential analytics.
- Voice learning from your edits — comparing your edits to AI drafts to match your writing voice. Basis: contract / consent.
How AI processing works
Your content is processed through third-party AI models (currently Anthropic and OpenAI) configured under no-training and zero-data-retention terms. No user data is used to train HonchoSuite's own models, and no user data is sold to third parties.
How we protect your data
Data is encrypted at rest (AES-256) and in transit (TLS 1.3). LinkedIn OAuth tokens are encrypted at the application layer before storage. Access is limited to what is necessary to operate the service.
LinkedIn data handling
Where you connect LinkedIn, we handle LinkedIn-sourced data under strict commitments:
- LinkedIn-sourced data is deleted when you disconnect LinkedIn or revoke access.
- Stored LinkedIn data is kept fresh, not stale.
- LinkedIn data is never resold, never shared, and never commingled with non-LinkedIn data.
- Source attribution is preserved.
Subprocessors
We use a small set of vendors to operate the service. Each is bound by a data processing agreement, and our AI and search vendors are configured for no-training / zero-retention. See the full list on our subprocessors page. We give 30 days' advance notice of any new subprocessor or material change.
International transfers
EU personal data transferred outside the EEA is protected by Standard Contractual Clauses (SCCs). Under the DPDP Act, cross-border transfer is permitted except to countries the government restricts; our current vendor jurisdictions (US and EU) are not restricted.
Data minimization to vendors
External search queries sent to vendors are deduplicated, pseudonymous, and carry no user identifier. This is enforced at the query-builder layer, so vendors cannot tie a query back to you.
How long we keep data
- Account and profile — life of the account, plus a 30-day grace period after deletion.
- Engagement signals — a rolling 24 months, then anonymized.
- Consent records and audit log — 7 years (pseudonymized after account deletion), to evidence lawful processing.
- Server logs — 90 days.
- Backups — 30-day rolling; deletions are re-applied if a backup is restored.
- Billing records — held by the payment provider as required by tax law.
Your rights
Under both regimes you can exercise the following rights:
- Access and portability — a self-serve export of your data in JSON.
- Rectification — edit your details in settings.
- Erasure — self-serve deletion, followed by a 7-day grace period, then hard deletion.
- Restriction and objection — per-purpose consent toggles.
- Grievance redressal — contact our named grievance officer at privacy@honchosuite.com. We acknowledge within 72 hours and aim to resolve within 15 days. You may escalate to the Data Protection Board of India.
- Nomination — under DPDP §14, you may nominate someone to exercise your rights in the event of death or incapacity.
Managing your consent
Consent is granular and itemized: you choose per purpose. Withdrawing consent is as easy as giving it — a single toggle, applied immediately. We show a cookie banner before setting any non-essential cookie, and the email open pixel stays off until you opt in.
If there is a data breach
Under the GDPR, we notify the relevant authority within 72 hours where required. Under the DPDP Act, we notify the Data Protection Board and every affected Data Principal, with no materiality threshold.
Age
HonchoSuite is intended for users aged 18 and over. It is not directed at minors.
Changes to this policy
We may update this policy; we will revise the “Last updated” date and notice version above and, for material changes, give notice through the service.