Last updated: March 2026
The Only Suite (“we”, “us”, or “our”) is committed to protecting your personal information and the personal information of your customers that is processed through our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service. Please read this policy carefully. If you do not agree with its terms, please discontinue use of the Service.
We collect information in the following ways:
We use collected information to:
To protect all projects on our platform from abuse, fraud, and harmful content, we operate a cross-project reputation network. Customer identifiers (email addresses and IP addresses) are hashed using SHA-256 before being contributed to this network — we never share raw personal data across projects. Reputation signals (spam, fraud, abuse history) are shared in anonymised, aggregated form only. This processing is conducted under GDPR Legitimate Interest grounds (Article 6(1)(f)) to protect our network and its users. You may opt out of contributing signals to the network by contacting us, though this may limit certain moderation capabilities.
We do not sell your personal data. We may share information with:
We retain account data for the duration of your subscription and for up to 90 days after account closure to allow for recovery. Customer support ticket content and AI-generated summaries are retained indefinitely to power permanent customer memory features; you may request deletion of specific records. Anonymised network reputation signals are retained indefinitely as they contain no personal data. Server logs are retained for 30 days.
Depending on your jurisdiction, you may have rights including: access to your personal data, rectification of inaccurate data, erasure (“right to be forgotten”), restriction of processing, data portability, and objection to processing based on legitimate interest. To exercise any of these rights, contact us at privacy@theonlysuite.com. We will respond within 30 days. Where we act as a data processor on behalf of your customers, requests should be directed through you as the data controller.
We implement industry-standard technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, API key encryption using Fernet symmetric encryption, network segmentation, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but will notify you of any confirmed breach affecting your data within 72 hours of discovery, as required by GDPR.