1. What this policy is for
This policy explains what we do with personal data when you visit open-climate.ai, ask us for access, or use the Service with an account. It is written for the people whose data it is: visitors, prospects, and the individuals who use the Service on behalf of a customer.
It does not cover the content our customers send us for processing. When a customer uploads a procurement file or sends us activity lines, we act on that customer's instructions, not our own, and the Data Processing Agreement governs it. Article 4 below explains where the line falls.
2. Who is responsible
2.1 The controller is Songbird AI BV, Rue Emile Wittmann 50, 1030 Schaerbeek, Belgium, enterprise and VAT number BE 1033.450.866. open-climate.ai is its trading name.
2.2 For anything in this policy, write to hello@open-climate.ai.
2.3 We have not appointed a Data Protection Officer. Our core activity is not the large scale monitoring of individuals, nor the large scale processing of special categories of data, so Article 37 GDPR does not require one. If that changes, we will appoint one and say so here.
3. What we collect, why, and on what basis
3.1 When you visit the site
Our servers log the request: IP address, the page or endpoint, the time, the user agent, and the response. We need these to serve the page, to keep the Service up, and to detect abuse, which is our legitimate interest under Article 6(1)(f) GDPR. Logs are kept for 12 months.
If you agree to analytics, we also collect usage data as described in article 6. The basis for that is your consent, Article 6(1)(a) GDPR, and you can withdraw it at any time.
3.2 When you ask us for access
The request form collects your name, your work email, your company, your role, optionally the tool you use today, your message, and optionally a file you attach so we can show you what the Service does with it. We use it to answer you, to evaluate the fit, and to keep in touch about the product. The basis is our legitimate interest in responding to a business enquiry and in business to business marketing, Article 6(1)(f) GDPR, and taking steps at your request before entering a contract, Article 6(1)(b) GDPR.
The form also carries a hidden field that only automated submitters fill in. If it is filled in we discard the submission. That is spam protection, not profiling.
We keep prospect records for 24 months after our last meaningful contact, and delete them after that unless you have become a customer. You can ask us to stop contacting you at any time, and we will act on it without asking for a reason.
3.3 When you use the Service with an account
We process your identity (email address, display name, and either a password that we store only as a hash or, where you sign in through your own identity provider, the identifier that provider gives us), the API keys and MCP connections issued to you, and a record of what your account did: which jobs ran, when, from which address, and with which result. We need this to give you the Service and to bill for it, Article 6(1)(b) GDPR, to keep it secure and to investigate misuse, Article 6(1)(f) GDPR, and to meet our accounting obligations, Article 6(1)(c) GDPR.
Account and access records are kept for as long as the account is open, and for 12 months after it closes. Accounting records are kept for 7 years, as Belgian law requires.
3.4 When something breaks
The Service reports errors and performance traces to our monitoring tool so we can fix them. It is configured not to attach personal data to those reports. A stack trace can still incidentally contain an identifier, so we treat the monitoring data as personal data and apply the same rules to it. The basis is our legitimate interest in a Service that works, Article 6(1)(f) GDPR. Retention is 90 days.
3.5 When you write to us
Email you send us, and our replies, are kept for 24 months so we have a record of what was agreed and what was asked. The basis is our legitimate interest in managing the relationship, Article 6(1)(f) GDPR. Our email runs on Google Workspace, listed in article 5.
3.6 When we contact you first
We also approach people we think the Service is useful to. If we contact you without your having contacted us first, this section is the notice Article 14 GDPR requires, and you are reading it at or before our first message.
Where it comes from. Professional profiles you have made public, your employer's website, public company registers, and, if we have met, what you told us.
What we hold. Your name, job title, employer, the public address of your profile, the location it states, your work email and phone number when you have made them available to us, our notes on the conversation, and the messages exchanged between us.
Why, and on what basis. To assess whether your organisation has a use for the Service and to contact you about it in your professional capacity. The basis is our legitimate interest in business to business marketing, Article 6(1)(f) GDPR. We have weighed that against your interests: the data is professional rather than private, it concerns you in your working role and not your private life, we do not build a profile or score you, we do not take any decision about you by automated means, and one word from you ends it.
How long. 24 months from our last meaningful contact, and immediately if you ask us to stop.
What you can do. Object at any time under Article 21 GDPR, by replying to any message or writing to hello@open-climate.ai. We will stop and delete the record without asking you for a reason. Article 9 sets out your other rights.
4. Customer content is different
When a customer uses the Service to map their own data, the files and lines they send us may contain personal data: a supplier's contact name, an employee named on a travel line, an approver in a procurement system. We process that content only to run the Service, only on the customer's instructions, and we do not decide what happens to it. In GDPR terms the customer is the controller and we are the processor.
Two consequences follow. If you are an individual whose data appears in a customer's file and you want it accessed, corrected or deleted, ask that customer, and we will help them answer you. And the rules that govern that content, including our commitments on model training, on where it is processed and on how long it is kept, are in the Data Processing Agreement and in articles 7.3 to 7.6 of the Terms of Service, not in this policy.
5. Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers, and they process data only on our instructions.
| Provider | What it does | Where the data sits |
|---|---|---|
| OVHcloud | Hosting, database, object storage, backups | France |
| Sentry (EU region) | Error and performance monitoring | Germany |
| Mailgun EU | Transactional and support email | European Union |
| Google Ireland (Workspace) | Our own email and documents | European Union, with transfers to the United States |
| Odoo SA | Customer relationship management: prospect and customer records | European Union |
| Notion Labs | Prospect and contact records, and our internal working notes | United States |
Neither of the two customer relationship tools ever receives customer content. The files and lines a customer uploads to the Service stay on the infrastructure in the first row of the table; article 4 and the Data Processing Agreement govern them, and no business tool listed here has access to them. What those two rows hold is contact and prospect records: names, job titles, employers, work email addresses and phone numbers, and our own notes on the conversation.
Our authentication runs on software we host ourselves, on the infrastructure above, so signing in does not hand your credentials to a third party. So does our site analytics: the usage data in article 6.2 goes to our own servers on the infrastructure above and to no analytics company, so there is no row for it in this table.
The model provider that powers the Service processes customer content, not the data in this policy. It is listed in Annex III of the Data Processing Agreement, and it processes in the European Union.
We also disclose personal data where the law requires it, and to our professional advisers under a duty of confidentiality. If we are ever part of a merger or a sale of the business, data moves with it, and we will tell you before that happens.
6. Cookies and analytics
6.1 Strictly necessary cookies. Signing in sets a session cookie, forms carry a token that prevents cross-site request forgery, and long running requests carry a cookie that keeps you on the same server for the life of the connection. These are needed for the Service to work, we do not ask consent for them, and Article 129 of the Belgian Act of 13 June 2005 does not require it.
6.2 Analytics. We count visits and see which pages are read with our own software, on our own servers. There is no third-party analytics product, no advertising network and no tag manager: the page sends an event to our API, and it stays in our database on the infrastructure in article 5.
Recognising the same browser across visits is the part that is not strictly
necessary, so it is the part we ask about. Until you answer the banner, and if
you decline it, your visit is counted without any identifier and nothing
persistent is stored for it. If you accept, we store a random identifier that
says nothing about you: a __Secure-ocai_aid cookie our server sets, and a copy
of the same value in your browser's local storage in case the cookie is cleared.
It is a number, it is not linked to your name unless you later give us one by
signing in or writing to us, and we use it only to tell a returning visit from a
new one.
We remember your answer in a first-party cookie called ocai_consent for
thirteen months. That cookie needs no consent of its own, because remembering
that you declined is what honouring it means. You can change your mind at any
time through the cookie settings on our privacy page, which brings the banner
back.
6.3 We do not build profiles of individuals. We do not currently use advertising cookies. If we start, they will sit behind the same consent gate as article 6.2, we will list them here before we set them, and declining costs you nothing.
7. Where your data is
The Service itself runs entirely in the European Union. Our servers, our database, our object storage, our backups, our monitoring and the model processing behind the Service are in EU data centres, and our staff access them from within the EU or the EEA.
Site analytics is part of that: it runs on our own servers, so nothing about your visit leaves the European Union for it.
Two of the business tools in article 5 are the exception: our email and documents on Google Workspace, and the contact records and working notes on Notion. Neither holds customer content. Those transfers rely on the EU to US Data Privacy Framework where the recipient is certified under it, together with the European Commission's standard contractual clauses.
Where we ever need to transfer personal data outside the EEA for another reason, we will do it under an adequacy decision or under the European Commission's standard contractual clauses, and we will assess whether the law of the destination country actually lets those safeguards work before we rely on them.
8. How we protect it
Traffic is encrypted in transit with TLS. Data at rest, including backups, is encrypted. Access is role based and granted on need, credentials and secrets are held encrypted, file downloads are re-checked against an access token on every request rather than exposed as public links, and we keep an access log we can reconstruct an incident from. Annex II of the Data Processing Agreement sets out the measures in more detail.
No system is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will tell the Belgian Data Protection Authority within 72 hours and tell you without undue delay.
9. Your rights
Under the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict what we do with it, or hand it to another provider in a portable format. Where we rely on legitimate interest, you can object, and we will stop unless we have compelling grounds that override your interests. Where we rely on consent, you can withdraw it at any time, which does not affect what we did lawfully before.
Write to hello@open-climate.ai. We answer within one month, and we will tell you if we need longer because a request is complex. We do not charge for this, and we do not make you justify a request to stop marketing.
If you think we have got it wrong, you can complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, www.dataprotectionauthority.be, or to the authority where you live or work.
10. Automated decisions
We do not take decisions about individuals by automated means, and we do not profile people. The Service classifies and matches business activity data, not people. Article 22 GDPR does not apply to what we do.
11. Children
The Service is for organisations, not individuals acting privately, and it is not directed at children. We do not knowingly collect their data.
12. Changes
We may update this policy. If a change matters to you, we will say so by email or on the site before it takes effect, and the version and date at the top will change. We keep previous versions and will send you any of them on request to hello@open-climate.ai.
13. Language
This policy is drafted in English. Where we publish a translation of it, or of the privacy notice on our site, and the versions differ, the English version prevails.
14. Contact
Songbird AI BV Rue Emile Wittmann 50, 1030 Schaerbeek, Belgium Enterprise and VAT number BE 1033.450.866 Privacy, and everything else: hello@open-climate.ai