Legal
Privacy Policy
Last updated on September 6, 2026
About Patricia
Patricia is a digital service operated and managed by BETTERGROUP HOLDING INC (“Patricia”). For the purposes of this Policy, references to “Patricia” shall pertain to the digital service provided by BETTERGROUP HOLDING INC. All matters related to Patricia, including this Privacy Policy, are governed by the laws of the United States and the State of Delaware.
Patricia is an AI teammate for marketing agencies. She works inside your team's Slack workspace, takes on briefs, and produces marketing deliverables such as copy, images, and video. This Policy explains what personal data we process to provide that service and how we protect it.
Controller and Representatives
Data Controller: BETTERGROUP HOLDING INC (“Patricia”)
Contact for privacy matters: privacy@patricia.app
Registered office: 1111B S Governors Ave, STE 37790, Dover, Delaware 19904, United States
EU Representative (GDPR Article 27)
Name: Ria Pardeep
Email: ria@workstreet.com
Acts as our representative in the EU for GDPR-related inquiries from individuals and supervisory authorities.
UK Representative (UK GDPR Article 27)
Name: Daniel June
Email: daniel@workstreet.com
Acts as our representative in the UK for UK GDPR-related inquiries from individuals and the ICO.
For fastest handling of data subject requests, contact privacy@patricia.app; you may also contact the applicable representative above for EU or UK matters.
1. Scope and Definitions
Scope. This Personal Data Protection Policy (the “Policy”) describes Patricia's internal rules for personal data processing and protection. The Policy applies to Patricia, including Patricia employees and contractors (“we”, “us”, “our”, “Patricia”). The management of each entity is ultimately responsible for the implementation of this policy, as well as to ensure, at entity level, there are adequate and effective procedures in place for its implementation and ongoing compliance.
Privacy Manager. The Privacy Manager is an employee of Patricia responsible for personal data protection compliance within Patricia (the “Privacy Manager”). The Privacy Manager is in charge of performing the obligations imposed by this Policy and supervising other employees regarding their adherence to this Policy. The Privacy Manager must be involved in all projects at an early stage in order to take personal data protection aspects into account.
Definitions
- Competent Supervisory Authority means a public authority that is responsible for regulating and supervising personal data protection with regards to activities of Patricia.
- Data Breach means a breach of the security and/or confidentiality leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise processed.
- Data Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
- Data Processor means a natural or legal person, public authority, agency or other body which processes the Personal Data on behalf of the data controller.
- Data Protection Laws mean any laws and legal rules on personal data use and protection applicable to the activities of Patricia, including the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018.
- Data Subject Request (DSR) means any request from the Data Subject and concerning their personal data and/or data subject rights.
- Data Subject means a natural person, whose Personal Data we process. Data Subjects include but are not limited to users, website visitors, employees, contractors, and partners of Patricia.
- Personal Data means any information relating to an identified or identifiable Data Subject; a Data Subject can be identified by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or the combination of factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that Data Subject.
- Processing means any operation or set of operations which is performed by Patricia on Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Standard Contractual Clauses means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Decision (EU) 2021/914, together with the UK Addendum issued by the Information Commissioner and the Swiss adaptation, as applicable. This definition previously named Decision 2010/87/EU, which the 2021 decision repealed; the DPA has always cited the current one, and the two now agree.
- Third Party means a natural or legal person, who accesses the Personal Data for further processing and is not an employee, member or corporate affiliate of Patricia.
- User means a Data Subject who uses our services provided on Patricia's website or through connected workspaces such as Slack.
2. Data Processing Principles
2.1 Patricia's processing activities must be in line with the principles specified in this Section. The Privacy Manager must make sure that Patricia's compliance documentation, as well as data processing activities, are compliant with the data protection principles.
2.2 We must process the Personal Data in accordance with the following principles:
- Lawfulness, fairness and transparency. We shall always have a legal ground for the processing, collect the amount of data adequate to the purpose and legal grounds, and we make sure the Data Subjects are aware of the processing.
- Purpose limitation. Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- Data minimization. Adequate, relevant and limited to what is necessary for the purposes for which they are processed.
- Accuracy. Accurate and, where necessary, kept up to date. Data Subjects can ask us for a correction of the Personal Data.
- Storage period limitation. Kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the Personal Data are processed.
- Confidentiality, integrity, and availability. Processed in a manner that ensures appropriate security of the Personal Data, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.
2.3 Accountability
We shall be able to demonstrate our compliance with Data Protection Laws (accountability principle). In particular, we must ensure and document all relevant procedures, efforts, internal and external consultations on personal data protection including:
- The fact of appointing a person responsible for Patricia's data protection compliance;
- Where necessary, a record of a Data Processing Impact Assessment;
- Developed and implemented notices, policies, and procedures;
- The fact of staff training on compliance with Data Protection Laws;
- Assessment, implementation, and testing of organizational and technical data protection measures.
The Privacy Manager must maintain Patricia's Records of processing activities, prepared in accordance with Art. 30 of the GDPR.
3. Access to Personal Data. Legal Grounds and Purposes
3.1 Legal Grounds
Each processing activity must have one of the lawful grounds specified in this Section to process the Personal Data. If we do not have any of the described, we cannot collect or further process the Personal Data.
- Performance of the contract. Where Patricia has a contract with the Data Subject, e.g. the website's Terms of Use or the employment contract, and the contract requires the provision of personal data from the Data Subject.
- Consent. To process the personal data based on the consent, we must obtain the consent before the Processing and keep the evidence of the consent. The consent must be freely given, in the form of an active indication, with clearly articulated purposes.
- Legitimate interests. We have the right to use personal data in our ‘legitimate interests’. The interests can include the purposes that are justified by the nature of our business activities, such as the marketing analysis of personal data.
- Legal Compliance and Public Interest. We might be requested by the laws of the European Union or laws of an EU Member State to process Personal Data of our Users.
3.2 Access to Personal Data
Employees must have access to the personal data on a “need-to-know basis”. The data can be accessed only if it is strictly necessary to perform one of the activities specified in the Records of processing activities.
All employees accessing personal data shall keep strict confidentiality regarding the data they access. When an employee detects or believes there is suspicious activity, a data breach, or non-compliance, the employee must report such activity to the Privacy Manager.
4. Third Parties and Connected Services
Before sharing personal data with any person outside of Patricia, the Privacy Manager must ensure that this Third Party has an adequate data protection level and provides sufficient data protection guarantees in accordance with Data Protection Laws.
Patricia operates inside workspaces and platforms you connect, such as Slack and the marketing and social platforms your agency uses. When you connect such a service, we process the data from that service only to the extent necessary to perform the tasks you ask Patricia to do, and your use of that service remains governed by its own terms and privacy policy. We use vetted infrastructure and AI model providers as Data Processors to deliver the service; these providers are bound by data processing agreements and do not use your data to train their models for other customers. Each one is named, with what it does and where it runs, on our subprocessors page.
Google user data
This section applies when you connect a Google service to Patricia. It describes how Patricia accesses, uses, stores, and shares data received from Google APIs, and it applies in addition to the rest of this policy. It is separate from the Google advertising tags on our public website, which are described below and never see the contents of your workspace.
What we access. Patricia reaches your Google data only after you complete Google's own consent screen, and only within the scopes shown to you on it. Depending on what you choose to connect, that can include Gmail messages and drafts, Google Chat spaces and messages, Google Contacts, Google Forms and their responses, Google Workspace directory and audit information, and Google Ads accounts and reporting. You decide which services to connect, and Patricia works without any of them.
How we use it. Patricia acts on explicit requests from a member of your workspace. When someone asks a question or requests a task in Slack or Microsoft Teams, Patricia makes the specific Google API calls needed to answer or complete it, then returns the result in that conversation. We do not crawl your Google account in the background beyond what a requested task needs, and we do not use Google user data to build profiles, to target advertising, or to enrich any other dataset.
How we store it. Google user data is held inside your tenant, encrypted in transit and at rest, and is never visible to another customer. OAuth tokens are stored encrypted and are never exposed to end users. Retention follows section 8 of this policy.
How we share it. We do not sell Google user data, and we do not transfer it to anyone other than the subprocessors named on our subprocessors page, who act on our instructions under a data processing agreement. No Google user data is used to train, retrain, or fine-tune any AI model, ours or a provider's. That is a contractual commitment with our AI providers, not only a statement of policy.
Human access. Nobody at Patricia reads your Google user data, except where you have given specific consent, where it is necessary for security purposes such as investigating abuse, where we are required to by law, or where the data has been aggregated and de-identified so that it no longer identifies you or your workspace.
Withdrawing access. You can disconnect a Google service from Patricia at any time, or revoke Patricia's access directly from the permissions page of your Google Account. Disconnecting revokes our tokens and removes the data stored for that connection.
Limited Use. Patricia's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Our own website analytics
Separately from the providers above, our public website at www.patricia.app uses PostHog for product analytics and session replay, Google tags and Meta for advertising measurement, Dub for referral attribution, and Cal.com for demo bookings. These see visitors to our website, not the content of your workspace, and we are the controller for them rather than your processor. We also keep a small record in your browser: the campaign, referrer, or ad click that brought you, so that a demo booking can be matched back to it, and a random browser id that our site writes on every visit in the format Meta reads, whether or not an ad brought you. That record stays in your browser until you clear the site data, and you can ask us to delete what we hold about your visit by writing to privacy@patricia.app. The Patricia dashboard carries none of them: no advertising or marketing tracker runs there. It does send crash and error reports to Grafana Cloud so we can find and fix faults, which covers the error, the page it happened on, and a session identifier. Grafana Cloud is a subprocessor rather than a website analytics provider, so it is listed on the subprocessors page with the rest. It is the only one of those providers that stores data in the European Union rather than the United States.
When you fill in a form on our website
Our public website has forms: the waitlist, a webinar registration, an application for an offline workshop day, and a demo booking. What you type there is used to run the thing you asked for and to follow up about it. We are the controller for it, and it is separate from anything Patricia processes inside your workspace.
Depending on the form, that is your name and work email, your company website, how many people are in your team, which messaging tool your team runs on, which session or city you chose, the price you were shown, what you told us you want taken on, where on the page you signed up, and the campaign or referrer that brought you.
Those answers go to four places, and to nowhere else:
- Resend sends your confirmation and holds you as a contact with the answers above, so that what we send you is about the thing you actually signed up for. Applying for a workshop does not put you on our newsletter.
- Attio is our CRM. It holds you, your company, and the row for your registration or application, which is what we work from when we get back to you.
- Slack receives an internal alert in a private channel so someone picks it up the same day. It carries the same answers and goes nowhere outside our team.
- Meta is told that a signup happened, so an ad we paid for can be credited with it. That report carries your email address and your name, each hashed with SHA-256 and never sent in the clear, and, for a workshop application, the price you were shown. When your own browser sends it, the Meta advertising identifiers your browser carries, your IP address, your browser user agent, and the address of the page you were on go with it; a booking confirmed by Cal.com on its own server carries none of those four. For every form except the waitlist it is the same conversion the tag in your browser reports, sent once rather than twice. The waitlist reports only from our server.
Resend, Attio and Slack are in the United States. Meta receives its report at its own global API endpoint and keeps it in Meta's own regions, which we are confirming and will name on the subprocessors page. We keep what you sent for as long as we are still talking to you about it, and you can ask us to delete it at any time by writing to privacy@patricia.app. Ask and we remove you from Resend, Attio and Slack, and we ask Meta to delete the report it holds about you.
When you create a workspace or install Patricia
We are adding a second source of these conversion reports, from inside the product, for the same reason: so the advertising we pay for can be credited with a signup it produced. One trigger is a Patricia workspace being created, whichever way it was created, which includes signing in through Google or Microsoft and creating a workspace from the dashboard. The others are a first install of Slack and a first install of Microsoft Teams, which are two triggers for a workspace that installs both.
This has not started. We will publish the date it starts on our subprocessors page at least 14 days before it does.
It will carry less than the website report. It will carry the workspace id twice: hashed with SHA-256 as the identifier Meta matches on, and in the clear inside the key that stops a retried report being counted twice. It will carry the email address of the person who created the workspace or completed the install, hashed and never sent in the clear, and the name of what happened, which is a workspace being created or an install of Slack or Microsoft Teams. If the visit that led to the signup came from a Meta ad, the id of that ad click will travel with it. Nothing else will: no IP address, no browser user agent, no page address, and no content from your workspace. Some signup paths give us no email address at all, and those will report without one. Our servers will send it, and nothing will run in your browser to do it.
This is our own advertising measurement, so we are the controller for it rather than your processor, and we rely on our legitimate interest in measuring what our advertising produces. You can object to it, or ask us to delete what we hold and to ask Meta to delete its copy, by writing to privacy@patricia.app. Meta is named on our subprocessors page, in a section of its own, because it is not a subprocessor.
An employee can share personal data with third parties only if and to the extent that was directly prescribed by the manager and specified in the Records of processing activities.
If we are required to delete, change, or stop the processing of the Personal Data, we must ensure that the Third Parties, with whom we shared the Personal Data, will fulfill these obligations accordingly.
5. International Transfers
If we have employees, contractors, corporate affiliates, or Data Processors outside of the EEA, and we transfer Personal Data to them for processing, the Privacy Manager must make sure Patricia takes all necessary and appropriate safeguards in accordance with Data Protection Laws.
As a part of the information obligations, Patricia must inform the Data Subjects that their Personal Data is being transferred to other countries, as well as provide them with the information about the safeguards used for the transfer.
UK transfers. For transfers from the United Kingdom, we rely on approved UK transfer tools such as the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA), as appropriate.
6. Rights of Data Subjects
6.1 Our Responsibilities
The Privacy Manager is ultimately responsible for handling all DSRs received by Patricia. All DSRs from Users must be addressed at and answered from: privacy@patricia.app.
The responsible employee must answer the DSR within one (1) month from receiving the request. If complying with the DSR takes more than one month, the Data Subject must be informed about the prolongation for up to two (2) additional months.
6.2 The right to be informed
Patricia must notify each Data Subject about the collection and further processing of the Personal Data. The information includes: the name and contact details of Patricia; purposes and lawful basis for data collection; categories of Personal Data collected; recipients; retention periods; and information about data subject rights.
6.3 The right to access the information
A Data Subject has the right to:
- Learn if we process the Data Subject's Personal Data;
- Obtain disclosure regarding aspects of the processing, including purposes, categories, recipients, retention periods, and rights;
- Obtain a copy of the Personal Data undergoing processing upon request.
6.4 The right to rectification
If we reveal that the Personal Data is inaccurate or the Data Subject requests us to do so, we must ensure that we correct all mistakes and update the relevant information.
6.5 The right to restrict processing
This right applies when the Data Subject contests the accuracy of the Personal Data, believes that we process the Personal Data unlawfully, or objects against the processing.
6.6 The right to withdraw consent
For the activities that require consent, the Data Subject can revoke their consent at any time. The withdrawal of consent does not affect the lawfulness of the processing done before the withdrawal.
6.7 The right to object against processing
If we process the information in our legitimate interests, e.g., for direct marketing emails or for our marketing research purposes, the Data Subject can object against the processing.
6.8 Right to erasure / to be forgotten
The Data Subjects have the right to request us to erase their Personal Data if:
- Personal Data is no longer necessary for the purposes of collection;
- The Data Subject revokes consent or objects to the processing and there is no other legal ground;
- We process the Personal Data unlawfully or its erasure is required by applicable legislation.
6.9 Data portability
Data Subjects can ask us to transfer all the Personal Data and/or its part in a machine-readable format to a third party. This right applies when personal data was collected for the purpose of provision of our services or based on consent.
How to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority:
- EU: Your local Data Protection Authority.
- UK: The Information Commissioner's Office (ICO).
Automated Decision-Making and Profiling
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects within the meaning of GDPR/UK GDPR. Patricia uses machine learning to understand your requests and to generate marketing content such as copy, images, and video, but these processes do not determine rights or obligations about you.
Children's Privacy
Our Service is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@patricia.app so we can take appropriate action.
7. New Data Processing Activities
7.1 Notification to Privacy Manager
Before introducing any new activity that involves the processing of personal data, an employee responsible for its implementation must inform the Privacy Manager.
7.2 Data Processing Impact Assessment
To make sure that our current or prospective processing activities do not violate the Data Subjects' rights, Patricia must, where required by Data Protection Laws, conduct the Data Processing Impact Assessment (DPIA). A DPIA is required when:
- The processing involves the use of new technologies that creates certain legal, economic or similar effects to the Data Subject;
- We systematically assess and evaluate personal aspects of Data Subjects based on automated profiling;
- We process on a large scale sensitive data;
- We collect or process Personal Data from publicly accessible areas or public sources on a large scale;
- The Supervisory Authority requires conducting a DPIA for a certain type of activity.
8. Data Retention
8.1 General Rule
The Privacy Manager must make sure that Patricia clearly defined the data storage periods and/or criteria for determining the storage periods for each processing activity. After the storage period ends, the personal data must be removed or destroyed completely, including from back-up copies and other media.
8.2 Specific Retention Periods for User Data
You choose the window. Your workspace picks how long Patricia keeps the data she cleans up automatically. The control is in the dashboard under Settings, then Data & Privacy, and it offers three windows: 90 days, 1 year, or unlimited, which means nothing ages out on its own. New workspaces start on 1 year. A scheduled maintenance job deletes what has passed the window you chose. We do not promise a fixed interval between its runs, and if it is not running, anything past your window is deleted on request instead. Ask us at privacy@patricia.app and our team does it.
The list below says which categories that control governs today and which it does not. Where nothing deletes a category on a timer, we say so, rather than name a period no automatic process enforces.
- Cached workspace conversations and quality records. The workspace conversation history Patricia caches from Slack to do her work, and the records she keeps of her own reply quality, are deleted automatically on the window you choose. Quality records are capped at 1 year even on the unlimited setting.
- Briefs, files, and generated deliverables. Messages you direct to Patricia, briefs, brand assets, client materials, and the work she produces for you are kept for as long as your account is open, so you can pull up past work. Nothing deletes them on a timer today. Ask us and we delete them, by hand, at any time.
- Workspace memory and brand profiles. Patricia builds a working memory of your agency, its brands, and its preferences so she can deliver consistent work. This memory is kept for as long as your account remains active, is encrypted at rest, and is never shared across accounts.
- Customer account data. Email addresses, account information, billing records, and metadata are kept while your account is open. When you close the account, or ask us to delete, we delete or return the data within 30 days, the same window our DPA commits to, keeping only what the law requires us to keep, such as records we need for tax and accounting. Our team carries this out on request. There is no self-service button for it yet.
- Advertising conversion reports. The reports described in section 4 that we send to Meta. Nothing deletes them on a timer, and how long Meta keeps one is Meta's retention rather than ours. Ask us and we ask Meta to delete the reports it holds about you.
- Data location. Primary customer data storage is in the United States (US East, Virginia region) using secure data centers. AI processing also occurs in US data centers, with all data encrypted in transit and at rest. Transfers from the EU, UK, and Switzerland are safeguarded by the Standard Contractual Clauses in our DPA.
8.3 Exemptions
Business needs. Data retention periods can be prolonged, but no longer than 60 days, in the case that the data deletion will interrupt or harm our ongoing business. The Privacy Manager must approve any unforeseen prolongation. This internal rule does not extend the deletion commitments in section 8.2 or in the DPA, which are commitments we make to you.
Anonymization. If we anonymize the Personal Data, the restrictions and requirements of Data Protection Laws no longer apply to the anonymized data. To consider the data anonymous, it must be impossible to reidentify the Data Subject from the data set.
9. Data Breach
Patricia must report to the competent Supervisory Authority about any data breach that poses a risk to Data Subjects within 72 hours after becoming aware of such a breach. Where possible, Patricia must also notify the affected Data Subjects without undue delay.
The Privacy Manager must maintain a record of all data breaches, including facts, effects, and remedial actions taken.
10. Changes to This Policy
Patricia reserves the right to make changes to this Policy at any time by notifying its Users on this page. We strongly recommend checking this page often, referring to the date of the last modification listed at the top. If a User objects to any of the changes to the Policy, the User must cease using Patricia and can request that we remove the Personal Data.
If you have any questions about this Privacy Policy or our data practices, please contact us at privacy@patricia.app.