Legal

Compliance

How Buddy approaches privacy, security, and regulatory compliance across the regions we serve.

Effective June 12, 2026Plaxonic IT Services12 Sections

01Our Commitment

Plaxonic IT Services ("we", "us", "our") is committed to protecting the privacy and security of everyone who uses Buddy. This page summarizes the standards and practices we follow. It is provided for transparency and does not constitute legal advice or a warranty.

02GDPR (EU & UK)

For users in the European Economic Area and the United Kingdom, we process personal data in accordance with the GDPR and UK GDPR. This includes:

  • Processing on a lawful basis and only for stated purposes.
  • Honoring data subject rights of access, correction, deletion, portability, and objection.
  • Offering a Data Processing Addendum (DPA) with Standard Contractual Clauses for cross-border transfers.
  • Applying data minimization — we send only the minimum data required to AI providers.

03CCPA / CPRA (California)

For California residents, we support the rights granted under the CCPA and CPRA, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of sale. We do not sell personal information.

04Data Security

  • Encryption: All data is transmitted over encrypted connections (HTTPS/TLS).
  • Access Control: Role-based access and secure authentication (JWT) restrict data to authorized users.
  • Least Privilege: Internal access is limited to personnel who need it to operate the Service.
  • Monitoring: We log and monitor access to detect and respond to unusual activity.

05Infrastructure & Hosting

Buddy runs on reputable cloud infrastructure providers that maintain industry-recognized security certifications for their data centers, including physical security, redundancy, and network protection.

06Payment Security

Payments are processed by Stripe, a PCI DSS Level 1 certified provider. We do not store full payment card numbers on our servers; card data is handled directly by Stripe.

07Responsible AI & Data Use

When you use Buddy's AI features, we send only the minimum data necessary to generate content to trusted AI providers. We do not sell your content or brand data, and we apply safeguards to keep customer data separated and secure.

08Vendor & Sub-processor Management

We assess the security and privacy practices of the vendors and sub-processors that support the Service, and require data protection commitments consistent with our own. A current list of sub-processors is maintained in our DPA.

09Data Subject Rights

Regardless of location, you can contact us to access, correct, export, or delete your personal data, or to withdraw consent. We respond to verified requests within the timeframes required by applicable law.

10Incident Response

We maintain procedures to detect, investigate, and respond to security incidents. In the event of a personal data breach, we notify affected customers and regulators as required by applicable law and without undue delay.

11Reporting a Concern

If you believe you have found a security vulnerability or have a compliance concern, please contact us promptly so we can investigate. We appreciate responsible disclosure and will work with you in good faith.

12Contact

For compliance, security, or privacy inquiries, contact Plaxonic IT Services at support@superbuddy.io.

Still have questions?

Reach the Plaxonic team directly at support@superbuddy.io.

← Back to homeBuddy is a product of Plaxonic IT Services © 2026. All rights reserved.