The frameworks Freakout's enterprise controls are built around, and how to exercise your data protection rights.
Freakout's enterprise security program is designed around the control requirements of:
These are control frameworks, not a public certification claim. Freakout is not currently SOC 2 or ISO 27001 certified. The stack is prepared for a formal audit, and audit scope, auditor, and timeline are covered in the enterprise security review.
A standard Data Processing Addendum (DPA) is available for enterprise contracting. It covers controller/processor roles, subprocessors, retention and deletion commitments, incident notification, transfer mechanisms, and security measures. See Data Processing Addendum.
The DPA flow:
Enterprise breach-notification timing is set in the DPA. Freakout's standard enterprise commitment is notification without undue delay and no later than 72 hours after confirmation of a notifiable incident affecting customer data. Incident evidence is preserved in the audit trail described in Audit Trail & Monitoring.
AI provider calls are feature-triggered:
Under GDPR, you and your users can request:
To make a request, email privacy@freakout.ai from the address associated with the account, or include information that lets us verify the requester's identity. We respond within the timelines required by GDPR (one month, extendable in complex cases). Every export, deletion, and consent-related request is recorded in the audit trail as evidence of handling.
Erasure requests do not remove entries from security audit logs before their fixed 365-day retention expires. These records are retained under legal obligation and legitimate interest for security incident investigation, and are minimized as described above (IDs and hashes, never content).
Freakout uses a small set of service providers to operate the platform. Provider locations and transfer mechanisms are reviewed during DPA onboarding.
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting, storage, and content delivery (EU, Frankfurt) | All platform data |
| Stripe | Payment processing | Billing details (card data is held by Stripe, never by Freakout) |
| Mailjet | Transactional email | Email address, message content |
| Meshy | 3D, texture, and image generation | Product images, reference images, prompts, generation settings, and generated asset outputs submitted through generation features |
| OpenAI | Default assistant responses, speech, realtime sessions, embeddings, and room-generation workflows | Visitor messages, voice or realtime session input, prompts, room context, and generated responses submitted through enabled AI features |
| Google Gemini | Customer-configured room assistant provider | Visitor messages, prompts, room context, and generated responses when a Gemini provider key is configured for the room |
| Anthropic Claude | Customer-configured room assistant provider | Visitor messages, prompts, room context, and generated responses when a Claude provider key is configured for the room |
| Shopify | Commerce integration | Catalog and order data — only if you connect a Shopify store; enterprise iframe embeds can run without Shopify |
We update this list when providers change. The signed DPA and current subprocessor list are the source of truth for provider locations, transfer mechanisms, notice periods, and AI provider training or retention terms.
If you believe you have found a security vulnerability or need to report a suspected incident, contact security@freakout.ai with details. Please do not publicly disclose an issue before we have had a chance to investigate.