Last updated: 5 June 2026
HARRIS ("we", "our", "us") is operated by Horizon Frame Limited, a company registered in England and Wales. This privacy policy explains how we collect, use, and protect your data when you use our AI marketing platform.
When you use HARRIS, we may collect:
When you connect your Meta account, we access:
We only access data you explicitly authorise via the OAuth consent screen. We do not sell, share, or use your Meta data for any purpose other than providing our services to you.
Under GDPR Article 6, we process your data on the following legal bases:
HARRIS runs an automated retention cleanup once a day (08:00 UTC). The schedule below is the source of truth: every row corresponds to a step the cleanup job actually performs (function runDataRetentionCleanup in src/routes/compliance.ts), alongside the user-controlled deletions described in sections 7 and 8.
This list is reconciled with the cleanup job line-for-line so policy and code cannot drift. If the cleanup job changes, the policy must change in the same commit, and vice versa — a unit test asserts both sides agree.
Under GDPR and UK data protection law, you have the right to:
GET /api/user/data-exportPOST /api/user/delete-accountPOST /api/user/restrict-processingPOST /api/user/object; our DPO will respond within 30 daysWe will respond to all data subject requests within 30 days as required by GDPR.
You can request deletion of your data at any time:
POST /api/user/delete-accountAlways engaged — required for the platform to function:
Optional — only engaged when you explicitly connect them per website:
gmail.modify plus non-sensitive gmail.labels; we do not request the broader https://mail.google.com/ scope), Search Console (read), Google Ads (campaign reads; writes pending basic-access upgrade), YouTube (channel read-only)Each optional integration is per-website and revocable at any time via Settings > Connections. Disconnecting deletes the stored credentials and (where supported) revokes the underlying token with the provider. Inbound webhook subscriptions you registered with the provider are deregistered at the same time.
A maintained, machine-generated register of the sub-processors we engage in production — with processing locations and DPA references — is published at /sub-processors. Customers are notified at least 30 days before a material change to the always-engaged set takes effect, in line with the commitment described on that page.
We do not sell your data to any third party. AI providers process data under their API terms, which prohibit using API inputs for model training.
HARRIS is an AI agent platform: every conversation, scheduled report, and delegated task is processed through third-party LLMs (primarily Anthropic Claude, with OpenAI used for image generation and specialised tasks). Before transmission, we strip personally identifiable information (PII) including email addresses, phone numbers, and postal codes from prompts. AI-generated marketing content always requires your review and approval before it is published or sent on your behalf; campaigns are created in a paused state by default.
Tool calls the AI makes on your behalf (e.g. "post to Facebook", "merge this PR", "send this email") are gated by a tier system: low-risk read tools run silently; write/external tools require interactive confirmation or a pre-authorised scheduled task. Every AI call is recorded against your website with model, token count, and USD cost.
Your data may be transferred to and processed in countries outside the United Kingdom and the EEA, including the United States — where Cloudflare, Anthropic, OpenAI, Perplexity, and Ideogram operate — and the other jurisdictions listed for each sub-processor in section 9. For transfers from the EEA we rely on the European Commission's Standard Contractual Clauses (2021 modules, in the controller-to-processor configuration appropriate to each engagement). For transfers from the United Kingdom we additionally rely on the UK International Data Transfer Addendum (UK IDTA) or the equivalent UK Addendum to the EU SCCs issued by the Information Commissioner's Office. These instruments are incorporated into our data processing agreements with each sub-processor and are reviewed when a sub-processor is added or its terms change.
We use two strictly necessary cookies to maintain your session:
auth_token — short-lived access token (2 hours), HttpOnly, Secure, SameSite=Strictrefresh_token — refresh token (30 days), HttpOnly, Secure, SameSite=Strict, scoped to /api/authWe do not use tracking cookies, advertising cookies, or third-party analytics. No cookie consent banner is required as these are strictly necessary for authentication. For a full breakdown — including the informational dismissal cookie set when you close the on-page notice — see our Cookie Policy.
In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours where required under GDPR Article 33. If the breach poses a high risk to your rights and freedoms, we will notify affected individuals directly.
When you connect a Google account, HARRIS accesses Google user data only to provide the features you explicitly enable. The Gmail integration uses the restricted gmail.modify scope together with the non-sensitive gmail.labels scope so an operations agent can read, organise, label, compose, and send email on your behalf during inbox triage; the Search Console, Google Ads, and YouTube integrations are read-only and inform marketing and SEO decisions.
HARRIS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
You can revoke HARRIS's access to your Google account at any time via myaccount.google.com/permissions or by disconnecting Google in Settings > Connections, which deletes the stored credentials.
HARRIS is a business-to-business platform intended for use by adults responsible for operating a business or website. The service is not directed at children under the age of 16, and we do not knowingly collect, store, or process personal data of children under 16. If you become aware that a child has provided us with personal data — for example through an account opened without the parent or guardian's knowledge, or through data inadvertently routed to us via a connected platform — please contact dpo@harrishq.ai. On verification we will delete the data without undue delay and will not retain copies, subject only to the minimum retention needed to demonstrate the deletion itself in line with section 6.
HARRIS does not currently send marketing or newsletter email. All email we send today is transactional — password resets, security alerts, billing receipts, and operational notifications about your account or connected platforms — and is sent only as needed to provide the service you signed up for.
If we introduce marketing or newsletter email in the future, the following terms will apply, and we have already built our systems to honour them:
List-Unsubscribe and List-Unsubscribe-Post headers (RFC 2369 / RFC 8058) so your mail client can unsubscribe you without you having to open the message — the same mechanism Gmail and Outlook expose as a banner unsubscribe button.The legal bases above are GDPR Article 7 (consent — freely given, specific, informed, unambiguous, withdrawable) and Privacy and Electronic Communications Regulations (PECR) regulation 22.
For any privacy-related questions or data subject requests:
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).