Legal

Privacy Policy

Last updated: 16 August 2026

1. Introduction

At Ragtime ("we", "our", or "us") we are committed to protecting your privacy and the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our conversational AI services (together, the "Services").

Ragtime AI is a trade name of De Cloe Advies BV, a private limited company incorporated in the Netherlands and based in Utrecht. As an EU-based provider serving customers globally, we recognise the importance of data protection and handle personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Dutch law. For personal data our customers process through the Services on behalf of their own users, we act as a processor, as further described in our Data Processing Addendum.

2. Information we collect

2.1 Information you provide to us

When you use the Services or interact with our website, you may provide personal information such as your name, email address, and company — for example, when you request a demo, create an account, or contact support. If you create an account, we store your account information, including credentials, which are held securely. We also retain records of correspondence and any feedback you provide.

2.2 Conversation data

When you interact with a Ragtime assistant, we process the content exchanged during the conversation. Where this occurs as part of a customer's deployment, we process that content as a processor on the customer's behalf and in accordance with their instructions. We do not use conversation content to train our AI models except on the documented instruction of the relevant customer.

2.3 Information we collect automatically

When you visit our website, we automatically collect log data such as your IP address, browser type, operating system, referring URLs, and actions taken, along with device information and general location (such as city or country) derived from your IP address. We use cookies and similar technologies to analyse usage, remember preferences, and provide a personalised experience.

3. How we use your information

We use the information we collect to provide, operate, and improve the Services; to create and manage accounts and process transactions; to communicate with you, including responding to enquiries and, with your consent, sending relevant updates; to analyse usage for analytics and reporting; and to detect, prevent, and address security issues, fraud, or other unlawful activity.

4. Legal basis for processing

Where the GDPR applies, we process personal data on one or more of the following bases: your consent; the performance of a contract with you; our legitimate interests in operating, securing, and improving the Services (balanced against your rights); and compliance with our legal obligations.

5. How we share your information

We do not sell your personal information. We may share it with service providers and business partners who perform services on our behalf — such as cloud hosting, AI infrastructure, payment processing, and analytics — under appropriate confidentiality and data-processing terms. Our current sub-processor register is available in the Data Processing Addendum. We may also disclose information where required by law or valid legal process, to protect our rights, prevent fraud, or protect the safety of our users or the public. If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, and we will notify you of any such change.

6. Your data protection rights

Depending on your location, you may have the right to access, rectify, or erase your personal information; to restrict or object to its processing; and to data portability. To exercise these rights, contact us using the details in the "Contact us" section below; we may need to verify your identity first. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.

7. Data retention

We apply the following default retention periods, subject to customer configuration, legal obligations, disputes, and security incidents:

  • Demo and contact enquiries: 24 months after the last contact.
  • Account data: for the account lifetime and as long as needed for support, security, or legal obligations.
  • Billing and financial records: for the legally required accounting and tax period.
  • Inactive conversations: 30 days by default, unless the customer configures another period.
  • Analytics events: 24 months.
  • Security and access logs: 12 months, or longer where needed to investigate an incident.
  • Consent records: for as long as needed to demonstrate the relevant consent and defend related claims.

8. Security

We implement a range of technical and organisational measures designed to protect personal information, including encryption of sensitive data, access controls, and regular security review. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. We encourage you to protect your account by choosing a strong, confidential password.

9. International data transfers

We may transfer and process your information in countries other than your own. Where we transfer personal data outside the European Economic Area to a country that does not benefit from an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with any supplementary measures required.

10. Children's privacy

Our Services are not intended for children under the age of 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will take steps to remove it.

11. Cookies

We use necessary local storage for theme and privacy-choice preferences. We load Google Analytics only after you expressly accept analytics in the privacy choices dialog. Analytics can be rejected or withdrawn at any time using the Privacy choices control displayed on the site. On withdrawal, we stop loading analytics and remove first-party Google Analytics cookies where technically possible. Google Analytics may process data outside the EEA under its applicable transfer safeguards. The analytics retention period is 24 months.

12. Changes to this Policy

We may update this Privacy Policy to reflect changes in our processing activities, legal requirements, or the Services. We will publish the updated version on this page and revise the "Last updated" date. Where a change materially affects how we process personal data or the rights of individuals, we will provide appropriate additional notice and, where required by law, obtain consent.

13. Contact us

For questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at support@ragtime-ai.com or, for legal matters, legal@ragtime-ai.com.

De Cloe Advies BV has not appointed a Data Protection Officer. Privacy requests and questions may be sent to legal@ragtime-ai.com.

Let's talk

Request a demo

Tell us a little about your context. We'll show you a working assistant grounded in your own content.