Legal

Privacy policy.

How Rosy AI, MB collects, processes and protects your personal data. Written in plain language, structured for GDPR compliance.

01

Who we are.

This privacy policy applies to the Confee website (confee.io) and the Confee wearable product, both operated by Rosy AI, MB ("Rosy AI", "we", "us"), a private company registered in the Republic of Lithuania with its registered office in Vilnius.

For the purposes of the EU General Data Protection Regulation (GDPR), Rosy AI, MB acts as the data controller for personal data processed via our website, marketing channels and the Confee product. The supervisory authority for our processing is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija).

02

What we collect.

Waitlist & contact data: when you submit your email through our waitlist, investor contact, or product contact forms, we collect your email address and any optional information you provide. We use this data to respond to you and to update you on the product launch.

Conversation data (Confee product): when you actively start a session with the Confee pendant, the device captures audio in real time and streams it via Bluetooth Low Energy to your paired companion app. Audio is processed into structured fields (e.g. name, company, budget, pain points). Raw audio is held in a local rolling buffer and is not retained by default; the structured fields are stored locally first and synced to your CRM via your configured webhook.

Device telemetry: anonymous diagnostic information about firmware version, battery state and connectivity quality may be collected to operate and improve the device.

Website analytics: privacy-respecting, cookie-light analytics for aggregate visitor counts. We do not use tracking pixels, advertising cookies or fingerprinting.

03

Legal basis for processing.

Performance of contract (Art. 6(1)(b) GDPR): when we process data to deliver the product or services you have asked for.

Legitimate interest (Art. 6(1)(f) GDPR): for diagnostic telemetry, fraud prevention, and basic website analytics, balanced against your privacy.

Consent (Art. 6(1)(a) GDPR): for waitlist email communications and any optional features you toggle on. You can withdraw consent at any time.

04

How conversations are handled.

Confee is designed to be transparent. The pendant features a visible LED trust light that illuminates while recording is active, making it immediately clear to anyone in the conversation that capture is in progress. The companion app provides an in-app consent flow so the other party can be presented with a clear notice and confirm before recording begins.

Audio is processed inside a 30-second rolling buffer. By default it is not retained beyond extraction. Structured lead data is encrypted at rest on your phone and in transit, and only ever leaves your phone via the destination webhook you configure (Salesforce, HubSpot, Pipedrive, Attio, Make.com, Zapier or any custom endpoint).

05

Your rights under GDPR.

You have the right to: access the personal data we hold about you; rectify inaccurate data; have your data erased; restrict or object to processing; receive your data in a portable format; and lodge a complaint with the State Data Protection Inspectorate of Lithuania.

To exercise any of these rights, email privacy@rosyai.lt. We will respond within 30 days.

06

International transfers.

Data is hosted in the European Union by default. Where any third-party processor is located outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the transfer mechanism.

07

Retention.

Waitlist email addresses are retained until you unsubscribe or for 24 months of inactivity, whichever is sooner. Operational records (e.g. invoices, contracts) are retained for the period required by Lithuanian commercial and tax law.

08

Sub-processors.

We use a small number of carefully chosen sub-processors to run our infrastructure (transactional email, hosting, AI inference for transcription and extraction). We will publish the current list on request and notify waitlist members of any material changes before they take effect.

09

Children.

Our services are not directed at children under 16 and we do not knowingly collect their personal data. If you believe a minor has submitted data to us, please contact privacy@rosyai.lt and we will delete it.

10

Changes to this policy.

We may update this policy from time to time. The "last updated" date below will reflect any change. For material changes affecting how we handle your data, we will notify you by email where we have a contact for you.

11

Contact.

For any privacy-related question, contact us at privacy@rosyai.lt.

Rosy AI, MB · Vilnius, Lithuania.