Preparing your AI conversation experience...
Initializing AI models...
Last Updated: September 8, 2026
Welcome to DemAI ApS ("we", "us", "our"). We are committed to protecting the privacy and security of your personal data.
This Privacy Policy explains how we collect, use, share, and protect your personal information when you:
We process your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable Danish data protection laws.
The entity responsible for the processing of your personal data (the data controller) is:
DemAI ApS
CVR: 45511731
Marken 30, 4000 Roskilde, Denmark
Email:
We may collect and process the following types of personal data:
Such as your name and email address when you create an account on the Service, subscribe to our newsletter, or contact us.
Such as your Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Service or Website. This is often collected automatically via cookies and server logs.
Information about how you use the Service and Website, including pages viewed, time spent on pages, links clicked, and navigation paths.
Your preferences in receiving marketing from us (like our newsletter) and your communication preferences.
When you connect an AI assistant or use an API key, we process your account identifier, email address where required for authentication, hashed credential and connection metadata, OAuth client identifier, requested method and tool, quota usage, response status, duration, and non-free-text entity references such as a vote or procedure identifier. We do not store full API keys or refresh tokens in readable form.
We use different methods to collect data from and about you, including through:
You may give us your Identity and Contact Data by filling in forms on the Service or Website (e.g., account registration, newsletter sign-up, contact form) or by corresponding with us by email or otherwise.
As you interact with the Service or Website, we may automatically collect Technical Data and Usage Data. We collect this personal data by using server logs, cookies, and other similar technologies.
We may receive Technical Data from analytics providers such as Google Analytics.
We receive MCP requests from the assistant, connector or software you choose to connect. Enterprise customers may authenticate users through their own identity provider, which supplies the verified claims required to identify and authorise the user.
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
Where you have given us clear consent to process your personal data for a specific purpose (e.g., subscribing to our newsletter). You can withdraw your consent at any time.
Where processing is necessary to provide your account, subscription and requested Parl8 features, including MCP and API access.
Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. This includes operating and improving the Service, understanding user behaviour, securing the Service, enforcing fair-use limits, detecting abuse, and responding to your inquiries.
Where we need to comply with a legal or regulatory obligation.
We use the information we collect for various purposes, including:
If you choose to subscribe to our newsletter, we will collect your name (optional) and email address. We use this information solely to send you newsletters containing updates about DemAI ApS, our work in AI and democracy, articles, and related information.
The legal basis for processing this data is your explicit consent, given at the time of subscription.
You can unsubscribe from our newsletter at any time by clicking the "unsubscribe" link provided in every email we send or by contacting us directly at .
We use Brevo to manage our newsletter distribution. This provider acts as a data processor on our behalf and is obligated to protect your data.
We do not sell your personal data. We may share your personal data with trusted third parties only when necessary, such as:
Companies that provide services on our behalf, such as website hosting, data analysis (e.g., Google Analytics), email delivery services (for the newsletter), and IT support. These providers are contractually bound to protect your data and use it only for the purposes we specify.
If required by law, regulation, legal process, or governmental request.
In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.
We use service providers for hosting, databases, edge security, observability and AI processing. Some MCP search requests send the user's search text to OpenAI to create a numerical embedding used for retrieval. These providers process data under their contractual and legal obligations.
The MCP host you connect, such as Claude, ChatGPT, Copilot, Mistral, Cursor or another assistant, receives the tool inputs and outputs needed for your conversation. That provider controls its own chat history, model processing and retention under its privacy terms and may act as an independent data controller. Parl8 does not receive unrelated parts of your conversation with that provider.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
We have implemented appropriate technical and organizational security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed. Access to your personal data is limited to those employees, agents, contractors, and other third parties who have a business need to know.
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
We retain your contact information as long as you are subscribed. If you unsubscribe, we will delete your data promptly, subject to any backup retention cycles.
Typically retained for a period before being anonymized or deleted.
Retained as long as necessary to address your inquiry and for any legally required archival period.
Tool name, non-free-text entity references, status, duration, client and account identifiers used for security, quotas and reliability are retained for up to 13 months and then deleted. Free-text search queries are not stored in the MCP call-event table.
Anonymous widget render, error and click events that do not contain a Parl8 user identifier or query text are retained for up to 13 months and then deleted.
Connection and credential metadata is retained until it expires, you revoke or disconnect it, or your account is deleted, subject to limited records required for security or legal obligations. OAuth authorisation codes expire after 10 minutes and refresh tokens normally expire after 30 days.
Some of our third-party service providers may be based outside the European Economic Area (EEA). If we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used when transferring your personal data out of the EEA.
When you choose a third-party AI assistant, its processing may occur outside the EEA. Some search text may also be processed by OpenAI outside the EEA to create retrieval embeddings. Review the assistant provider's privacy terms before connecting it.
Under data protection law, you have rights including:
To exercise any of these rights, please contact us at .
You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet), the supervisory authority for data protection issues in Denmark (www.datatilsynet.dk).
You can revoke personal API keys, disconnect OAuth assistants and view your current MCP usage from Settings → Integrations. Deleting your account removes active keys and connections; limited security and call telemetry may remain for the stated retention period where necessary for our legitimate interests or legal obligations.
Parl8's MCP server lets you give a third-party assistant read-only access to Parl8's parliamentary research tools. The assistant cannot change your Parl8 account, billing, alerts or source data.
The assistant sends the tool name and arguments required for your request and receives the resulting cited text and structured parliamentary data. Search text may be processed transiently by Parl8 and OpenAI to retrieve relevant records.
We store connection metadata, quota counters and limited call telemetry for security, abuse prevention, reliability and product measurement. We deliberately exclude free-text search queries from MCP call telemetry. Anonymous MCP Apps events measure widget rendering and link use.
Your AI provider decides how it stores and uses your prompt, the returned Parl8 data and the rest of your conversation. Disconnecting the assistant in Parl8 prevents future access but does not delete information already retained by that provider; contact the provider for its controls.
Only approve assistants you recognise and trust. You can revoke API keys, disconnect OAuth clients and review usage in Settings → Integrations. Organisation usage may be counted in a shared subscription quota while each connection remains attributable for security.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
DemAI ApS
Marken 30, 4000 Roskilde, Denmark
Email: