Freakout AIFreakout AI

Compliance & GDPR

The frameworks Freakout's enterprise controls are built around, and how to exercise your data protection rights.

Framework alignment#

Freakout's enterprise security program is designed around the control requirements of:

  • ISO 27001 — logging and monitoring, access control, incident response, and evidence collection.
  • SOC 2 — logical access controls, system operations monitoring, change tracking, and confidentiality of restricted data.
  • GDPR — data minimization, defined retention, EU data residency, and data subject rights handling.

These are control frameworks, not a public certification claim. Freakout is not currently SOC 2 or ISO 27001 certified. The stack is prepared for a formal audit, and audit scope, auditor, and timeline are covered in the enterprise security review.

Data Processing Addendum#

A standard Data Processing Addendum (DPA) is available for enterprise contracting. It covers controller/processor roles, subprocessors, retention and deletion commitments, incident notification, transfer mechanisms, and security measures. See Data Processing Addendum.

The DPA flow:

  1. Commercial contact confirms the enterprise scope and contracting entity.
  2. Freakout provides the current DPA package and subprocessor list.
  3. Both teams review data residency, transfer mechanisms, support, retention, and deletion terms.
  4. Signed DPA and contract terms become the source of truth for legal commitments.

Breach notification#

Enterprise breach-notification timing is set in the DPA. Freakout's standard enterprise commitment is notification without undue delay and no later than 72 hours after confirmation of a notifiable incident affecting customer data. Incident evidence is preserved in the audit trail described in Audit Trail & Monitoring.

How we minimize personal data#

  • Audit and operational logs reference user IDs, not names or emails; IP addresses are stored only as one-way hashes.
  • Request bodies, uploaded content, secrets, and payment data are never written to logs.
  • Enterprise storefronts suppress third-party marketing and analytics scripts, so your visitors' data is not shared with advertising vendors through Freakout.
  • Enterprise data is hosted in the European Union (AWS Frankfurt).

AI feature processing#

AI provider calls are feature-triggered:

  • 3D asset generation. When an authenticated editor starts image-to-3D, text-to-3D, remesh, rigging, texture, or image generation, Freakout sends the selected product images, reference images, prompts, generation settings, and provider task identifiers needed for that generation to Meshy.
  • Room assistant. If the AI shopping assistant is enabled for a room, visitor messages and the room context needed to answer the request are sent to the configured AI provider. If no room-specific provider key is configured, Freakout's default OpenAI integration is used.
  • Voice and realtime sessions. When voice or realtime assistant features are used, the text, instructions, or live session input needed for the response is sent to OpenAI.
  • Camera interactions. Camera-driven hand, pose, and avatar interactions run in the visitor's browser. Camera frames are not sent to AI subprocessors for those interactions.
  • Disabled features. If an AI feature is not enabled or a generation is not started, Freakout does not send that feature's product images, prompts, voice input, or visitor messages to an AI provider.
  • Provider terms. AI provider training, retention, and deletion terms are confirmed during enterprise review before a provider is enabled for the customer.

Your data subject rights#

Under GDPR, you and your users can request:

  • Access / export — a copy of the personal data we hold.
  • Rectification — correction of inaccurate personal data.
  • Erasure — deletion of personal data, subject to the security-log exception below.
  • Restriction and objection — limits on how personal data is processed.

To make a request, email privacy@freakout.ai from the address associated with the account, or include information that lets us verify the requester's identity. We respond within the timelines required by GDPR (one month, extendable in complex cases). Every export, deletion, and consent-related request is recorded in the audit trail as evidence of handling.

Security-log exception to erasure#

Erasure requests do not remove entries from security audit logs before their fixed 365-day retention expires. These records are retained under legal obligation and legitimate interest for security incident investigation, and are minimized as described above (IDs and hashes, never content).

Subprocessors#

Freakout uses a small set of service providers to operate the platform. Provider locations and transfer mechanisms are reviewed during DPA onboarding.

ProviderPurposeData involved
Amazon Web ServicesHosting, storage, and content delivery (EU, Frankfurt)All platform data
StripePayment processingBilling details (card data is held by Stripe, never by Freakout)
MailjetTransactional emailEmail address, message content
Meshy3D, texture, and image generationProduct images, reference images, prompts, generation settings, and generated asset outputs submitted through generation features
OpenAIDefault assistant responses, speech, realtime sessions, embeddings, and room-generation workflowsVisitor messages, voice or realtime session input, prompts, room context, and generated responses submitted through enabled AI features
Google GeminiCustomer-configured room assistant providerVisitor messages, prompts, room context, and generated responses when a Gemini provider key is configured for the room
Anthropic ClaudeCustomer-configured room assistant providerVisitor messages, prompts, room context, and generated responses when a Claude provider key is configured for the room
ShopifyCommerce integrationCatalog and order data — only if you connect a Shopify store; enterprise iframe embeds can run without Shopify

We update this list when providers change. The signed DPA and current subprocessor list are the source of truth for provider locations, transfer mechanisms, notice periods, and AI provider training or retention terms.

Reporting a security issue#

If you believe you have found a security vulnerability or need to report a suspected incident, contact security@freakout.ai with details. Please do not publicly disclose an issue before we have had a chance to investigate.