Skip to content
Legalrouteur.aiLast updated 22 June 2026

Privacy policy.

How Oliver Tappin Ltd, trading as routeur.ai, collects, uses and protects personal data across the website, enquiries, billing and the gateway service.

What we hold, why, and for how long
01

Who we are

routeur.ai is a trading name of Oliver Tappin Ltd. For the purposes of this privacy policy, Oliver Tappin Ltd is the data controller for personal data collected through the routeur.ai website, commercial enquiries, billing, and account administration.

Our named Data Protection Officer (DPO) is Oliver Tappin. Privacy enquiries can be sent to legal@routeur.ai.

02

What this policy covers

This policy explains how we collect, use, store, and disclose personal data when you visit the routeur.ai website, request early access, create an account, buy a subscription, or contact us.

When routeur.ai processes prompts or responses on behalf of a customer, we generally act as a processor to that customer under our Data Processing Agreement. The customer remains responsible for deciding what personal data they send through the service and for providing any notices required to their end users.

03

Data we collect

  • Contact data: name, work email address, company, and anything you include in forms or emails to us.
  • Account and billing data: organisation name, account owner details, subscription status, invoices, and payment metadata from our payment processor.
  • Service administration data: API key labels, audit logs, security events, provider configuration metadata, and operational traces.
  • Website data: standard server logs such as IP address, user agent, and request path needed to run and secure the site.
  • Customer content: prompts, messages, and responses sent through the gateway when customers enable those features or choose payload retention.
04

How we use personal data

  • to provide, secure, and operate the routeur.ai service;
  • to respond to demos, early-access applications, support tickets, and legal requests;
  • to bill customers, prevent fraud, and maintain accounting records;
  • to monitor reliability, detect abuse, and investigate incidents;
  • to comply with legal obligations and enforce our terms.
05

Lawful bases

We rely on one or more of the following lawful bases under UK GDPR and EU GDPR, depending on the context: contract performance, legitimate interests, legal obligation, and consent where you voluntarily submit contact details for early access or other marketing-adjacent contact, or where you accept non-essential cookies.

06

Processors and recipients

We use a limited number of processors to run the service, including infrastructure providers, transactional email providers, payment processors, and upstream LLM providers selected by our customers.

Examples include Google Cloud Platform for hosting and storage, payment processors for subscription billing, and upstream model providers such as OpenAI, Google, Anthropic, or DeepSeek when customers configure them. A current list of sub-processors is set out in our Data Processing Agreement.

07

International transfers

Customer data may be sent to upstream LLM providers in regions chosen by the customer or required by the selected provider. Customers are responsible for selecting providers appropriate to their compliance obligations.

Where we transfer personal data outside the UK or EEA, we use appropriate safeguards such as contractual commitments, adequacy decisions, or the processor's published transfer mechanisms where available.

08

Retention

We keep personal data only for as long as needed to provide the service, satisfy legal or accounting obligations, resolve disputes, and maintain security records. Our typical retention periods are set out below; where data sits in more than one category, the longest applicable period applies.

Data categoryRetention period
Contact & enquiry dataUntil you opt out
Account dataWhile your account is active; deleted within 30 days of account closure
Billing & invoicing records6 years, to meet accounting and tax obligations
Audit logs & security events7 days (Starter), 90 days (Pro), configurable (Enterprise)
Encrypted backups7 days (configurable on Enterprise)
Website / server logs30 days
Platform-level system logs (Google Cloud)400 days
Support tickets & correspondence24 months
Customer content (only if payload retention is enabled)7 days (Starter), 90 days (Pro), configurable (Enterprise)

Customers control whether payload retention is enabled for gateway traces. If payload retention is disabled, we still retain minimal operational metadata needed for security, billing, and abuse detection.

09

Cookies and analytics

Essential cookies needed to serve and secure the site are always active. Beyond those, the routeur.ai website uses a small number of third-party analytics tools to understand how the site is used so we can improve it:

  • Google Analytics (via Google Tag Manager) — aggregate, measurement-level traffic and usage analytics.
  • Microsoft Clarity — anonymised interaction analytics, such as heatmaps and session replay, to see where the site can be clearer.

These are non-essential cookies and are loaded only after you accept them through our cookie banner. You can decline, or withdraw consent at any time, and they will not be loaded. We do not use advertising pixels, and we do not sell your data to advertisers.

10

Automated decision-making

routeur.ai routes each request to a model using automated rules and scoring. This selects a provider and model for a request; it does not make decisions that produce legal or similarly significant effects on individual data subjects, and we do not carry out profiling of website visitors or end users.

Any automated decision-making you build on top of the responses the service returns is your responsibility as controller, including providing any notices or safeguards required under Data Protection Law.

11

Security

We use technical and organisational measures designed to protect personal data, including encryption in transit, encrypted secret storage, access controls, audit logging, and least-privilege access practices. See the security page for operational detail.

12

Your rights

Depending on your location, you may have rights to access, correct, erase, restrict, object to, or port your personal data, and to withdraw consent. Where we act only as a processor for customer-submitted content, we may direct you to the relevant customer as controller.

You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ICO) at ico.org.uk; in the EU it is the supervisory authority in your country of residence.

13

Contact

For privacy requests or DPO enquiries, contact legal@routeur.ai. routeur.ai is operated by Oliver Tappin Ltd, and Oliver Tappin is the named DPO for privacy matters.