Legal
Compliance
How Buddy approaches privacy, security, and regulatory compliance across the regions we serve.
01Our Commitment
Plaxonic IT Services ("we", "us", "our") is committed to protecting the privacy and security of everyone who uses Buddy. This page summarizes the standards and practices we follow. It is provided for transparency and does not constitute legal advice or a warranty.
02GDPR (EU & UK)
For users in the European Economic Area and the United Kingdom, we process personal data in accordance with the GDPR and UK GDPR. This includes:
- Processing on a lawful basis and only for stated purposes.
- Honoring data subject rights of access, correction, deletion, portability, and objection.
- Offering a Data Processing Addendum (DPA) with Standard Contractual Clauses for cross-border transfers.
- Applying data minimization — we send only the minimum data required to AI providers.
03CCPA / CPRA (California)
For California residents, we support the rights granted under the CCPA and CPRA, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of sale. We do not sell personal information.
04Data Security
- Encryption: All data is transmitted over encrypted connections (HTTPS/TLS).
- Access Control: Role-based access and secure authentication (JWT) restrict data to authorized users.
- Least Privilege: Internal access is limited to personnel who need it to operate the Service.
- Monitoring: We log and monitor access to detect and respond to unusual activity.
05Infrastructure & Hosting
Buddy runs on reputable cloud infrastructure providers that maintain industry-recognized security certifications for their data centers, including physical security, redundancy, and network protection.
06Payment Security
Payments are processed by Stripe, a PCI DSS Level 1 certified provider. We do not store full payment card numbers on our servers; card data is handled directly by Stripe.
07Responsible AI & Data Use
When you use Buddy's AI features, we send only the minimum data necessary to generate content to trusted AI providers. We do not sell your content or brand data, and we apply safeguards to keep customer data separated and secure.
08Vendor & Sub-processor Management
We assess the security and privacy practices of the vendors and sub-processors that support the Service, and require data protection commitments consistent with our own. A current list of sub-processors is maintained in our DPA.
09Data Subject Rights
Regardless of location, you can contact us to access, correct, export, or delete your personal data, or to withdraw consent. We respond to verified requests within the timeframes required by applicable law.
10Incident Response
We maintain procedures to detect, investigate, and respond to security incidents. In the event of a personal data breach, we notify affected customers and regulators as required by applicable law and without undue delay.
11Reporting a Concern
If you believe you have found a security vulnerability or have a compliance concern, please contact us promptly so we can investigate. We appreciate responsible disclosure and will work with you in good faith.
12Contact
For compliance, security, or privacy inquiries, contact Plaxonic IT Services at support@superbuddy.io.
Still have questions?
Reach the Plaxonic team directly at support@superbuddy.io.