Privacy Policy
Last updated: 10 September 2026
Negoso helps creators, models, photographers and other talent handle and price the brand enquiries they receive. To do that we read messages you choose to connect, draft replies on your behalf, and keep track of the bookings that follow. This policy explains what personal data we collect, why, who we share it with, and the rights you have. We are based in the UK and follow the UK GDPR and the Data Protection Act 2018.
1. Who we are
The data controller is Negoso Ltd (company number 17224710). We are registered with the Information Commissioner's Office under number ZC214018. You can reach us about anything in this policy at hello@negoso.ai.
2. Who this policy covers
- Talent — people who create a Negoso account (creators, models, photographers, influencers and similar).
- Agencies — agency staff who use Negoso to manage talent they represent.
- Brands and other senders — people who email or message talent whose inbox is connected to Negoso, or who use a talent’s public enquiry form. You do not need a Negoso account for us to process some of your data; see section 6.
- Website visitors — anyone browsing negoso.ai.
3. What we collect from talent and agencies
Account and profile
Name, email address, password (held by our authentication provider, never visible to us), profile type, pronouns, profile photo, tagline, location and home postcode (used for travel pricing), portfolio images and links, showreel and comp card, and your onboarding answers.
Rate card and working preferences
Your day rates, floor and ideal rates, add-on and usage rates, cancellation terms, availability and weekly capacity, minimum notice, negotiation style, and whether replies are sent automatically or held for your approval. This is the data the pricing engine uses to draft quotes.
Optional demographic and physical details
Models and some other profile types can add date of birth, gender, self-declared ethnicity and fit measurements so that brands searching for specific casting requirements can find them. These fields are optional. Ethnicity is special category data under UK GDPR, so we only process it with your explicit consent, which you give by filling the field in and can withdraw at any time by clearing it.
Business and payment details
VAT number, invoicing address, and the bank name, sort code and account number you want printed on invoices we generate for you. If payments through Negoso are switched on for your account, Stripe holds your payout details and identity checks; we store only a reference to your Stripe account.
Connected channels
When you connect an inbox or calendar we store the access and refresh tokens needed to keep it connected, the account address or handle, and sync state. What we read from each channel is set out in section 5.
Enquiries, negotiations and bookings
For each enquiry we keep the message content and sender details, the parsed brief (dates, location, deliverables, usage, budget), every draft and reply, the negotiation history, calendar entries, contracts, usage licences, invoices, and any expenses and receipts you upload.
Device and technical data
IP address, browser and device type, and timestamps in our server logs. If you use the Negoso mobile app and turn on notifications, a push notification token for your device.
Your agreements and permissions
When you accept these terms — at signup, or again when we change them — we record which version you accepted, the date and time, and the IP address and browser you accepted from. We do the same when you turn an optional permission on or off. We keep that record so that we can show what you agreed to and when, which UK GDPR requires of us. You can see your own record at any time on the Your data page in your dashboard.
4. Cookies
We use only strictly necessary cookies: a session cookie that keeps you signed in, and short-lived cookies that protect the “Connect” flows for Gmail, Outlook, Instagram and Google Calendar against forgery. We do not currently use analytics, advertising or tracking cookies, so there is no cookie banner. If that changes we will update this policy and ask for consent first.
5. Connected inboxes, messaging and calendars
You choose which channels to connect, and you can disconnect any of them yourself at any time from Channel Settings in your dashboard (Google Calendar from the Calendar page). Disconnecting stops us reading that channel and deletes the stored access and refresh tokens from our database immediately; where the provider allows it we also revoke the token and cancel our notification subscription on their side. You can additionally revoke Negoso’s access from your Google, Microsoft or Meta account security settings, which has the same effect. Messages already stored remain in your account until you delete them or close your account.
Gmail
We request read-only access to your mailbox and permission to send email as you. Each new message is stored with its sender, subject, body and thread reference, then checked by our AI parser. Messages it identifies as booking enquiries are handled by Negoso; anything else is marked as dismissed and is never replied to. Dismissed messages stay in your Messages view for 30 days so that a misclassified enquiry can be recovered, then are deleted automatically unless you have converted them into an enquiry. We never read your drafts, contacts, or other Google data.
Negoso’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we only use Gmail data to provide the enquiry handling features you see in the app, we do not use it for advertising, we do not sell it, and humans at Negoso do not read it except with your permission, for security purposes, to comply with the law, or when it has been aggregated and anonymised.
Outlook and Microsoft 365
We request permission to read your mail, send mail as you, read your basic profile, and keep the connection alive when you are not signed in. We use these in exactly the same way as Gmail above.
Instagram and Facebook Messenger
We read direct messages sent to your connected professional account to identify booking enquiries and reply to them. We store message metadata and the content of enquiries. We do not access your followers, posts, stories, comments or insights. Our use of Meta data follows Meta’s Platform Terms.
Forwarding address
Every account has a personal forwarding address ending in @in.negoso.com. Anything you forward there is received by our inbound email provider and handled like any other enquiry.
Calendars
Google Calendar is read-only: we look at busy times so the pricing engine can check whether you are free on the dates a brand asks for. We store event times and busy/free status, not event contents. Apple and other calendars are connected via a subscription (ICS) link you paste in, which we fetch on a daily schedule.
6. Brands and other people who contact talent
If you email, message or submit an enquiry form to someone who uses Negoso, we will process your name, email address or handle, and the content of your message so that the talent can respond. Our lawful basis is our legitimate interest, and the talent’s, in handling their business correspondence. Your data is visible only to the talent you contacted (and their agency, if they have one). We never use it for marketing. If you want to know what we hold about you or want it deleted, email hello@negoso.ai.
7. How we use your data and why we are allowed to
| What we do | Lawful basis |
|---|---|
| Create and run your account, parse enquiries, draft and send replies, manage bookings, contracts and invoices | Performance of our contract with you |
| Send service emails and push notifications (new enquiry, draft waiting for approval, booking reminders, invoice due) | Performance of our contract with you |
| Publish your public profile and enquiry form, if you turn them on | Performance of our contract with you |
| Process optional ethnicity information for casting searches | Your explicit consent |
| Keep the service secure, prevent abuse, and debug problems | Legitimate interests |
| Improve the pricing engine and reply quality using aggregated, de-identified outcomes | Legitimate interests |
| Keep invoices and contract records | Legal obligation (UK tax and company law) |
| Respond to your questions and rights requests | Legal obligation and legitimate interests |
We do not sell personal data and we do not use it for third-party advertising.
8. How we use AI
Negoso uses large language models to read enquiries and write replies. When an enquiry arrives we send the message content, the sender details, and the relevant parts of your rate card and preferences to our AI provider, currently OpenAI, through its business API. OpenAI does not use data sent through the API to train its models and retains it only briefly for abuse monitoring.
The prices in a draft come from your own rate card and the rules you set, not from the model. The model writes the words. You decide whether replies go out automatically or are held for your approval, and you can change that at any time in Settings. No decision that has a legal or similarly significant effect on you is made solely by automated means.
9. Who we share data with
We use a small number of service providers who process data on our instructions under written contracts:
| Provider | What they do for us | Where |
|---|---|---|
| Vercel | Hosts the website and application | US / global edge |
| Supabase | Database, authentication and file storage | EU |
| OpenAI | AI parsing and drafting (section 8) | US |
| Resend | Sends service emails from Negoso to you | US |
| Postmark | Receives email sent to your forwarding address | US |
| Gmail, Google Calendar and address autocomplete | US / global | |
| Microsoft | Outlook and Microsoft 365 mail | US / global |
| Meta | Instagram and Messenger | US / global |
| Dropbox Sign | Electronic signing of contracts | US |
| Stripe | Payments and payouts, only if payments are enabled for you | US / global |
| Expo | Delivers mobile push notifications | US |
We also share data in these situations:
- With brands — the replies, quotes, contracts and invoices we send on your behalf naturally contain your name, rates and business details.
- With your agency — if you accept an agency’s invitation, its staff can see your profile, enquiries and negotiations for the division they manage.
- Public profile — if you publish your profile page, the details you mark as public are visible to anyone with the link and may be indexed by search engines. Brands and casting tools can also search published profiles by the filters you have chosen to show.
- Legal — if the law requires it, or to protect the rights and safety of Negoso, our users or others.
- Business transfer — if Negoso is sold or merged, your data would pass to the new owner under this policy.
10. International transfers
Several of the providers above are in the United States. Where data leaves the UK we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
11. How long we keep data
| Data | Retention |
|---|---|
| Account, profile, rate card, enquiries, negotiations, calendar | While your account is open, then deleted 30 days after closure |
| Channel tokens | Deleted immediately when you disconnect the channel or close your account |
| Messages the parser dismissed as not enquiries | Deleted automatically 30 days after we receive them, unless you convert one into an enquiry in the meantime; deleted sooner if you close your account |
| Contracts, invoices and payment records | 6 years after the end of the tax year they relate to, as UK law requires |
| Server logs and error records | 30 days |
| Record of the terms and permissions you agreed to | While your account is open, then kept as a dated record of what was agreed, with the IP address and browser removed |
| Database backups | Rolling 30 days, after which deleted data is gone from backups too |
12. Security
All traffic is encrypted in transit and data is encrypted at rest. Channel tokens are stored server-side only and never sent to your browser. Inbound webhooks from Google, Microsoft, Meta and Postmark are signature-verified and rejected otherwise. Access to production systems is limited to the people who need it. No system is perfectly secure, so if we ever discover a breach that puts you at risk we will tell you and the ICO without undue delay.
13. Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong (most profile data you can edit yourself in Settings);
- delete your data, or close your account;
- restrict or object to particular processing;
- give you your data in a portable format;
- withdraw consent where we rely on it, such as for ethnicity information.
Three of those you can do yourself, straight away, from the Your data page in your dashboard: download a copy of everything we hold, turn optional permissions on or off, and close your account. Closing disconnects every channel immediately; the rest of your data is deleted 30 days later, and you can undo it during those 30 days. Contracts, usage licences, invoices and payment records are kept for six years as the table above explains, because UK law requires it of us and of you.
For anything else, email hello@negoso.ai and we will respond within one month. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, though we would appreciate the chance to sort things out first.
14. Age
Negoso accounts are for people aged 18 or over. If you are under 18, an agency or parent must hold the account on your behalf. If we learn we have collected data from someone under 18 without that arrangement in place we will delete it.
15. Changes to this policy
We will update this page when our practices change and update the date at the top. For significant changes we will email you or show a notice in the app before they take effect.
16. Contact
Questions, requests or concerns: hello@negoso.ai.