Who is responsible?
Rosa ONE is operated by Rosa Group Ltd, company number 09766720, registered in England and Wales. Our registered office is 120a Church Road, Benfleet, Essex, SS7 4EP, United Kingdom. Use our private contact form.
Rosa Group is the controller of information used for its own accounts, subscriptions, enquiries and service security. When a business uses Rosa ONE for its customers and staff, that business normally determines the purposes of those records and Rosa ONE processes them on its behalf. Its own privacy notice also applies. Please contact that business first about your appointment, payment or staff record; we can help direct a request.
What information do we use?
Account and business details: names, email addresses, business contact and address details, language, country, staff roles, verified command-phone numbers and sign-in records.
Workspace records: information entered or imported by a business, including customer contact details, appointments, services, payment history, stock, expenses and staff-related costs. Record changes can include the person responsible, the time and whether the action came from the dashboard or WhatsApp.
Messages and connections: WhatsApp account and phone identifiers, message content, relevant contact information, delivery events, approved templates, authorisation credentials and assistant conversations. We also process support requests and feature suggestions.
Billing and technical information: subscription references and status, transaction information, browser and network information, and security or diagnostic events. Payment-card details entered in Stripe's payment interface are handled by Stripe; Rosa ONE does not store full card numbers.
Information comes from you, authorised colleagues, businesses that hold your records, and the connected providers needed for a feature. Providing sign-in and essential account details is necessary to use the account; optional information can be left out. Please include only information needed for the business task.
Why do we use it?
We use information to sign you in, provide your workspace, carry out authorised instructions, organise appointments and business records, deliver requested communications, manage subscriptions and help with support.
For our own account administration, we rely on performing our contract with the account holder. Where the user is acting for a business, and for support, fraud prevention, access controls and service reliability, we rely on our legitimate interests in providing and protecting the service. Financial recordkeeping can also be necessary to comply with legal obligations. Where optional communications require consent, that consent can be withdrawn.
A subscribing business is responsible for its own lawful basis and the permissions needed to use its customer and employee records, including promotional messages. Connecting WhatsApp or reading this notice does not give blanket consent to marketing.
We do not sell personal information or use workspace customer lists for advertising. We do not use the assistant to decide eligibility for employment, credit, insurance or similar significant matters. It helps carry out business tasks under the user's permissions; users should check important results.
How does WhatsApp work?
Staff can link a phone to send commands to the Rosa ONE assistant. We use proof of phone ownership and current workspace permissions to decide which business and actions that person can access.
A business can separately connect its customer-facing WhatsApp number. Messages, replies and delivery information received through that connection are processed for that business. Automated reminders and other enabled messages use the connected business account.
Meta receives and processes information needed to provide WhatsApp. Sharing chat history during a supported connection is subject to the choices shown in Meta's setup. Connecting an account does not mean every historic phone conversation is automatically imported. Removing an integration stops the connection; it does not automatically erase business records, recipient copies or information held independently by Meta.
What does the AI assistant see?
When you use Rosa, your request, relevant conversation context and results from permitted business tools are sent to Anthropic's Claude API to prepare an answer or carry out your instruction. For example, checking tomorrow's diary may involve appointment and customer details. The same applies whether you ask through the dashboard or WhatsApp.
Access checks apply to the assistant's tools as well as the dashboard. A separate API key does not remove the AI provider's processing. Please avoid including passwords, access keys, or unrelated sensitive information in a message. AI outputs can be mistaken, so review details before relying on them.
Who helps us deliver Rosa ONE?
The providers below process information relevant to their role. The linked notices explain their processing. Depending on the service and purpose, a provider may act on our instructions or have responsibilities of its own.
Authorised Rosa Group personnel may access information for support, maintenance, security and administration. Your colleagues' access depends on their workspace role. Information may also be disclosed where required by law or necessary to establish or defend legal rights.
Where is information processed?
The main Rosa ONE application and databases are currently hosted with Hetzner in Finland, in the European Union. Rosa Group is established in the United Kingdom. Our providers and authorised support operations may process information in the UK, EU, United States and other countries described in their notices. We do not promise that all processing stays in your country.
International-transfer protection depends on the countries, provider and applicable law. For UK/EU data, the relevant provider processing terms include contractual protections such as standard contractual clauses and the UK addendum where applicable, or a recognised adequacy arrangement. Anthropic, Resend and Cloudflare publish these terms. Brazilian transfers require a mechanism recognised under the LGPD; European clauses alone should not be taken as ANPD approval.
You can contact us for details of the safeguards applicable to your information and to request a copy. Provider terms: Anthropic, Resend and Cloudflare.
How long do we keep it?
We assess retention by the purpose of the record rather than apply one deletion period to every type of information. Workspace records remain available while needed for the business's use of the service, its instructions and applicable recordkeeping obligations. An expired trial or cancelled subscription does not itself erase the workspace; account closure and deletion can be requested separately.
For support and enquiry records, we consider whether the request is still open, whether follow-up is needed and whether a dispute requires the history. For security and activity records, we consider incident investigation, abuse prevention and accountability. Subscription and financial records may need to be retained for applicable accounting, tax or legal obligations. Information that is no longer needed is deleted or anonymised through our retention and request-handling process.
Backups are kept for recovery. A deletion request includes review of backup copies; deletion from active systems may not immediately remove an older protected backup. Where a backup is retained, its use is restricted to recovery and required legal purposes, and completed deletions must be reapplied before restored data is used. We will explain any retention exception relevant to your request.
How do we protect it?
We use HTTPS, account access controls, workspace permissions, separate operational databases and application environments, encrypted credentials, and protected backups. Workspaces share hosting infrastructure; authorised platform administrators retain technical access needed to operate the service. No online service can guarantee absolute security.
Your choices and rights
Depending on the law that applies, you can request confirmation of processing, access, correction, deletion, restriction or a portable copy of your information. Where processing relies on consent, you can withdraw it without changing the lawfulness of earlier processing. You may also ask about the organisations with which information is shared.
You can object to processing based on legitimate interests and to direct marketing. Contact us to make a request or explain your concern. We may need proportionate information to verify your identity or authority. We will respond within the applicable legal timeframe and explain any lawful exception or extension.
Use our private contact form, or follow our data-deletion instructions. You can also raise a concern with the UK Information Commissioner's Office, Brazil's ANPD, or the regulator responsible for your location. Where US state privacy rights apply, you may exercise them without unlawful discrimination and ask us to review a refused request.
Changes and getting in touch
We update this notice when the service or its processing changes and show the revision date here. Material changes will be brought to affected users' attention where required. If something is unclear, please use our contact form—we will help you understand how it applies to your information.
We are here to help.
Tell us what you need through our private form. You do not need to sign in.
Open contact form →