MotherX is built on business data, so privacy is not an afterthought. This policy explains what we collect, why, how long we keep it, and what rights you have under the GDPR.
MotherX is a Norwegian AI company that develops search, chat and GPT solutions trained on a business's own data. MotherX is the data controller for the personal data we process about visitors to this website, about people who contact us, and about users of our customer accounts.
For data that a customer uploads into the MotherX platform, the roles are reversed: the customer is the data controller and MotherX is the data processor. See section 4.
The website is a static site with no analytics, advertising or tracking scripts. Our web server writes ordinary access logs containing IP address, time, requested page, referrer and browser user agent. These logs are used for operations and security only.
If you email or call us, or fill in a form, we process the contact details and the content you send us — typically name, email address, phone number, company and what your enquiry is about.
We do not collect special categories of personal data (health, political opinions, biometrics and similar) about visitors or account users, and we ask you not to send such data to our support channels.
We only process personal data where we have a legal basis under Article 6 of the GDPR:
| Purpose | Legal basis |
|---|---|
| Delivering and operating the service, user administration and support | Performance of a contract, Art. 6(1)(b) |
| Answering enquiries from potential customers | Legitimate interest, Art. 6(1)(f) |
| Security, error correction, abuse prevention and server logs | Legitimate interest, Art. 6(1)(f) |
| Improving the product based on aggregated usage data | Legitimate interest, Art. 6(1)(f) |
| Accounting and invoicing | Legal obligation, Art. 6(1)(c) |
| Marketing emails to people who have signed up | Consent, Art. 6(1)(a) — withdrawable at any time |
We do not use personal data for automated decisions with legal effect, and we do not profile visitors for advertising.
MotherX is trained on the sources a customer connects — documents, web pages, product data, support articles and similar. If those sources contain personal data, the customer is the data controller and MotherX acts as a data processor on the customer's instructions.
Do you want a copy of our data processing agreement? Write to support@motherx.ai.
We never sell personal data. We share it only with suppliers who process data on our behalf, under a data processing agreement, and only to the extent needed to deliver the service:
| Category | Purpose | Location |
|---|---|---|
| Hosting and cloud infrastructure | Operating servers, databases and search indexes | EU/EEA |
| AI and language model providers | Generating answers and embeddings | EU/EEA or third country under safeguards |
| Payment and invoicing | Subscriptions, top-ups and accounting | EU/EEA |
| Email and support tools | Customer dialogue and case handling | EU/EEA |
An up-to-date list of named sub-processors is available on request from support@motherx.ai. Customers are notified before a new sub-processor is put into use.
Beyond this, we disclose personal data only where we are legally obliged to do so, or where it is necessary to establish, exercise or defend a legal claim.
Data is stored in the EU/EEA as our default. Where a supplier processes data outside the EEA, the transfer takes place under a valid transfer mechanism — an adequacy decision from the European Commission, or the EU Standard Contractual Clauses combined with supplementary technical and organisational measures.
We use technical and organisational measures appropriate to the risk, including:
If a personal data breach occurs that is likely to result in a risk to individuals, we notify the Norwegian Data Protection Authority within 72 hours, and affected customers without undue delay.
Under the GDPR you have the right to:
Write to support@motherx.ai to use a right. We reply within 30 days. If your request concerns data inside a customer's MotherX account, we forward it to that customer, who is the data controller.
If you believe we process your personal data unlawfully, we would like to hear from you first so we can put it right. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet), datatilsynet.no.
We update this policy when the service, our suppliers or the rules change. The current version is always published on this page with the date of the last update. Significant changes are communicated to customers by email.
Questions about privacy, a data processing agreement, or a request to exercise your rights:
See also our terms and conditions.