Privacy Policy

Last updated: 10 September 2026

Negoso helps creators, models, photographers and other talent handle and price the brand enquiries they receive. To do that we read messages you choose to connect, draft replies on your behalf, and keep track of the bookings that follow. This policy explains what personal data we collect, why, who we share it with, and the rights you have. We are based in the UK and follow the UK GDPR and the Data Protection Act 2018.

1. Who we are

The data controller is Negoso Ltd (company number 17224710). We are registered with the Information Commissioner's Office under number ZC214018. You can reach us about anything in this policy at hello@negoso.ai.

2. Who this policy covers

3. What we collect from talent and agencies

Account and profile

Name, email address, password (held by our authentication provider, never visible to us), profile type, pronouns, profile photo, tagline, location and home postcode (used for travel pricing), portfolio images and links, showreel and comp card, and your onboarding answers.

Rate card and working preferences

Your day rates, floor and ideal rates, add-on and usage rates, cancellation terms, availability and weekly capacity, minimum notice, negotiation style, and whether replies are sent automatically or held for your approval. This is the data the pricing engine uses to draft quotes.

Optional demographic and physical details

Models and some other profile types can add date of birth, gender, self-declared ethnicity and fit measurements so that brands searching for specific casting requirements can find them. These fields are optional. Ethnicity is special category data under UK GDPR, so we only process it with your explicit consent, which you give by filling the field in and can withdraw at any time by clearing it.

Business and payment details

VAT number, invoicing address, and the bank name, sort code and account number you want printed on invoices we generate for you. If payments through Negoso are switched on for your account, Stripe holds your payout details and identity checks; we store only a reference to your Stripe account.

Connected channels

When you connect an inbox or calendar we store the access and refresh tokens needed to keep it connected, the account address or handle, and sync state. What we read from each channel is set out in section 5.

Enquiries, negotiations and bookings

For each enquiry we keep the message content and sender details, the parsed brief (dates, location, deliverables, usage, budget), every draft and reply, the negotiation history, calendar entries, contracts, usage licences, invoices, and any expenses and receipts you upload.

Device and technical data

IP address, browser and device type, and timestamps in our server logs. If you use the Negoso mobile app and turn on notifications, a push notification token for your device.

Your agreements and permissions

When you accept these terms — at signup, or again when we change them — we record which version you accepted, the date and time, and the IP address and browser you accepted from. We do the same when you turn an optional permission on or off. We keep that record so that we can show what you agreed to and when, which UK GDPR requires of us. You can see your own record at any time on the Your data page in your dashboard.

4. Cookies

We use only strictly necessary cookies: a session cookie that keeps you signed in, and short-lived cookies that protect the “Connect” flows for Gmail, Outlook, Instagram and Google Calendar against forgery. We do not currently use analytics, advertising or tracking cookies, so there is no cookie banner. If that changes we will update this policy and ask for consent first.

5. Connected inboxes, messaging and calendars

You choose which channels to connect, and you can disconnect any of them yourself at any time from Channel Settings in your dashboard (Google Calendar from the Calendar page). Disconnecting stops us reading that channel and deletes the stored access and refresh tokens from our database immediately; where the provider allows it we also revoke the token and cancel our notification subscription on their side. You can additionally revoke Negoso’s access from your Google, Microsoft or Meta account security settings, which has the same effect. Messages already stored remain in your account until you delete them or close your account.

Gmail

We request read-only access to your mailbox and permission to send email as you. Each new message is stored with its sender, subject, body and thread reference, then checked by our AI parser. Messages it identifies as booking enquiries are handled by Negoso; anything else is marked as dismissed and is never replied to. Dismissed messages stay in your Messages view for 30 days so that a misclassified enquiry can be recovered, then are deleted automatically unless you have converted them into an enquiry. We never read your drafts, contacts, or other Google data.

Negoso’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we only use Gmail data to provide the enquiry handling features you see in the app, we do not use it for advertising, we do not sell it, and humans at Negoso do not read it except with your permission, for security purposes, to comply with the law, or when it has been aggregated and anonymised.

Outlook and Microsoft 365

We request permission to read your mail, send mail as you, read your basic profile, and keep the connection alive when you are not signed in. We use these in exactly the same way as Gmail above.

Instagram and Facebook Messenger

We read direct messages sent to your connected professional account to identify booking enquiries and reply to them. We store message metadata and the content of enquiries. We do not access your followers, posts, stories, comments or insights. Our use of Meta data follows Meta’s Platform Terms.

Forwarding address

Every account has a personal forwarding address ending in @in.negoso.com. Anything you forward there is received by our inbound email provider and handled like any other enquiry.

Calendars

Google Calendar is read-only: we look at busy times so the pricing engine can check whether you are free on the dates a brand asks for. We store event times and busy/free status, not event contents. Apple and other calendars are connected via a subscription (ICS) link you paste in, which we fetch on a daily schedule.

6. Brands and other people who contact talent

If you email, message or submit an enquiry form to someone who uses Negoso, we will process your name, email address or handle, and the content of your message so that the talent can respond. Our lawful basis is our legitimate interest, and the talent’s, in handling their business correspondence. Your data is visible only to the talent you contacted (and their agency, if they have one). We never use it for marketing. If you want to know what we hold about you or want it deleted, email hello@negoso.ai.

7. How we use your data and why we are allowed to

What we doLawful basis
Create and run your account, parse enquiries, draft and send replies, manage bookings, contracts and invoicesPerformance of our contract with you
Send service emails and push notifications (new enquiry, draft waiting for approval, booking reminders, invoice due)Performance of our contract with you
Publish your public profile and enquiry form, if you turn them onPerformance of our contract with you
Process optional ethnicity information for casting searchesYour explicit consent
Keep the service secure, prevent abuse, and debug problemsLegitimate interests
Improve the pricing engine and reply quality using aggregated, de-identified outcomesLegitimate interests
Keep invoices and contract recordsLegal obligation (UK tax and company law)
Respond to your questions and rights requestsLegal obligation and legitimate interests

We do not sell personal data and we do not use it for third-party advertising.

8. How we use AI

Negoso uses large language models to read enquiries and write replies. When an enquiry arrives we send the message content, the sender details, and the relevant parts of your rate card and preferences to our AI provider, currently OpenAI, through its business API. OpenAI does not use data sent through the API to train its models and retains it only briefly for abuse monitoring.

The prices in a draft come from your own rate card and the rules you set, not from the model. The model writes the words. You decide whether replies go out automatically or are held for your approval, and you can change that at any time in Settings. No decision that has a legal or similarly significant effect on you is made solely by automated means.

9. Who we share data with

We use a small number of service providers who process data on our instructions under written contracts:

ProviderWhat they do for usWhere
VercelHosts the website and applicationUS / global edge
SupabaseDatabase, authentication and file storageEU
OpenAIAI parsing and drafting (section 8)US
ResendSends service emails from Negoso to youUS
PostmarkReceives email sent to your forwarding addressUS
GoogleGmail, Google Calendar and address autocompleteUS / global
MicrosoftOutlook and Microsoft 365 mailUS / global
MetaInstagram and MessengerUS / global
Dropbox SignElectronic signing of contractsUS
StripePayments and payouts, only if payments are enabled for youUS / global
ExpoDelivers mobile push notificationsUS

We also share data in these situations:

10. International transfers

Several of the providers above are in the United States. Where data leaves the UK we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

11. How long we keep data

DataRetention
Account, profile, rate card, enquiries, negotiations, calendarWhile your account is open, then deleted 30 days after closure
Channel tokensDeleted immediately when you disconnect the channel or close your account
Messages the parser dismissed as not enquiriesDeleted automatically 30 days after we receive them, unless you convert one into an enquiry in the meantime; deleted sooner if you close your account
Contracts, invoices and payment records6 years after the end of the tax year they relate to, as UK law requires
Server logs and error records30 days
Record of the terms and permissions you agreed toWhile your account is open, then kept as a dated record of what was agreed, with the IP address and browser removed
Database backupsRolling 30 days, after which deleted data is gone from backups too

12. Security

All traffic is encrypted in transit and data is encrypted at rest. Channel tokens are stored server-side only and never sent to your browser. Inbound webhooks from Google, Microsoft, Meta and Postmark are signature-verified and rejected otherwise. Access to production systems is limited to the people who need it. No system is perfectly secure, so if we ever discover a breach that puts you at risk we will tell you and the ICO without undue delay.

13. Your rights

Under UK GDPR you can ask us to:

Three of those you can do yourself, straight away, from the Your data page in your dashboard: download a copy of everything we hold, turn optional permissions on or off, and close your account. Closing disconnects every channel immediately; the rest of your data is deleted 30 days later, and you can undo it during those 30 days. Contracts, usage licences, invoices and payment records are kept for six years as the table above explains, because UK law requires it of us and of you.

For anything else, email hello@negoso.ai and we will respond within one month. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, though we would appreciate the chance to sort things out first.

14. Age

Negoso accounts are for people aged 18 or over. If you are under 18, an agency or parent must hold the account on your behalf. If we learn we have collected data from someone under 18 without that arrangement in place we will delete it.

15. Changes to this policy

We will update this page when our practices change and update the date at the top. For significant changes we will email you or show a notice in the app before they take effect.

16. Contact

Questions, requests or concerns: hello@negoso.ai.