22 Privacy Policy
Last updated: 30 September 2026.
This policy explains how 22 ("22nd Floor", "we", "us") handles personal information. 22 is an AI "CEO and team" for business owners: an AI chief executive called Atlas and a team of AI agents that read the business's connected tools, draft work, and act only within the owner's approvals.
22 is operated by DSBC Group, LLC, a Delaware limited liability company. The service runs at 22floor.com and 22-app.pages.dev.
Contact: privacy@22floor.com (privacy and data requests) or support@22floor.com (everything else).
1. Who this policy covers
- Owners and their staff ("users"). People who sign up for 22 and use it for their business.
- People whose data flows through 22 ("end customers"). The customers, followers and contacts of a business that uses 22. For example, a person who emails the business, opens a support ticket, orders from its store or comments on its Facebook Page.
- Visitors to our public demo at /demo.
This policy does not cover the business's own privacy practices. Each business that uses 22 has its own privacy policy for its own customers.
2. Our role: controller or processor
Privacy laws give different duties to the party that decides why data is used (the controller; in Israeli law the "database owner/controller") and the party that handles data on its behalf (the processor; in Israeli law the "holder"; in California law the "service provider").
| Data | Our role |
|---|---|
| Your 22 account (name, email, password, sign-in records), billing, support mail you send us, demo visitors, our own security logs | Controller. This policy applies directly. |
| Everything a business puts into 22 or connects to it: its company memory, documents, conversations, mail, tickets, orders, ads, social comments, and the personal data of its end customers | Processor / holder / service provider. We act only on the business's instructions under our Data Processing Agreement. The business is the controller. |
If you are an end customer of a business that uses 22, please contact that business first. It decides what happens to your data. If you contact us, we will pass your request to the business and help it respond.
3. What we collect
3.1 From users (we are controller)
- Account: name, email address, password (stored only as a salted hash; we can't read it), the invite code used, the name you want Atlas to call you.
- Sign-in and security records: session records (we store only a hash of the session token), failed sign-in counts and the IP address they came from (used to stop password guessing), password-reset requests.
- Usage counts: how many chats, voice minutes and other actions an account used each day, so we can apply fair-use limits and control cost. Kept 8 days.
- Support: what you write to support@22floor.com.
- Billing: payments are processed by Stripe. We receive your billing name, email, plan, payment status and the last four digits of your card; we never see or store full card numbers.
3.2 From the business, as processor
What 22 holds depends on what the owner sets up and connects:
- Company setup: business name, website, the answers given in onboarding, the company design (departments, agents, their jobs), the charter and Company rules.
- Company memory: facts, rules, preferences and insights that Atlas and the agents learn from conversations, meetings, decisions, mail, tickets and ads, and that the owner approves, edits or removes.
- Knowledge: documents the owner uploads (we keep the text, not the file) and answers learned from closed support tickets. Personal details (names, emails, phone numbers, order and tracking numbers, addresses, personal links) are removed from ticket text before the AI reads it for learning.
- Conversations: chats with Atlas and the agents. Today chat threads are kept in the owner's browser; each message is sent through our server to the AI to be answered. Meeting minutes and decisions are saved with the company on our server. In progress: saving chats on our server too, with a retention setting that defaults to 12 months.
- Connected tools: when the owner connects a tool, 22 reads (and, only where the owner approves, writes) data in that tool. Today this includes:
- Email (Gmail, Outlook): messages, threads, senders, and replies the owner approves or switches to automatic.
- Help desks (Zoho Desk, Zendesk): tickets, customer names and emails, agent names, replies.
- Store (Shopify): orders, customers (name, email, city, country, order history), products, discounts, sales totals.
- Ads (Meta Ads, Google Ads): campaigns, spend, results. Meta Ads access is read only. Any change in another ad account needs the owner's Approve.
- Social (Facebook Pages, Instagram): posts, comments, commenter names, replies.
- Accounting and payments (QuickBooks, Xero, Stripe) where connected: profit and loss lines and payment totals.
- Amazon (Selling Partner API and Amazon Ads): being added. See section 12.
- Other apps the owner connects through Composio.
- P&L inputs: product costs, tax rates and other figures the owner enters.
- Voice: when the owner talks to Atlas, the audio is sent to our speech provider (OpenAI) to turn it into text, and Atlas's replies are turned into speech (OpenAI or ElevenLabs). 22 does not store the recordings.
- Ad images (feature switched off today): if the Creative feature is on, the briefs and generated images are kept 60 days, and saved favorites until the owner deletes them.
We do not ask for, and ask owners not to put into 22: government ID numbers, full payment card or bank account numbers, passwords, or health records. In progress: a sensitive-data guard that masks card, bank and ID numbers, passwords and keys before anything is stored.
3.3 From demo visitors (we are controller)
First name and website address (we read the public pages of that website), and, if you fill in the "Set it up" form, your name, email, company, website and note. What you ask the demo, by voice or text, is sent to our AI providers to answer; we keep only counts of questions, not the questions. We keep the IP address of each demo session and lead to stop abuse (daily limits).
3.4 Cookies and similar technology
- One essential cookie (
k22s) keeps you signed in. It is HttpOnly and Secure. - Browser storage (localStorage) keeps your settings and working copy of your company on your device.
- Google Fonts: our pages load fonts from Google, so Google receives your IP address and browser details when a page loads.
- We do not use advertising or analytics cookies or trackers. If that changes we will update this policy and ask for consent where the law requires it.
4. Why we use it (and our legal bases)
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Create and run your account, sign you in, provide the service | Contract (Art. 6(1)(b)) |
| Keep the service secure, stop abuse, apply usage limits, keep logs | Legitimate interests (Art. 6(1)(f)): protecting the service and its users |
| Process a business's data on its instructions | The business's own legal basis. We act as processor. |
| Answer support and privacy requests | Contract, or legal obligation (Art. 6(1)(c)) |
| Run the demo for a visitor | Legitimate interests (Art. 6(1)(f)): showing prospects what 22 does, at their request |
| Follow up with a demo visitor who asked us to | Consent (Art. 6(1)(a)) |
| Keep records the law requires; defend legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, you can ask us for the balancing test we did.
Do you have to give us your data? No law requires you to. An email address and password are needed to create an account (a contract requirement); without them we cannot give you 22. Everything else, including connecting tools, is your choice; features that need it will not work without it.
Where the data comes from: from you, from the tools you connect, and, for the demo, from the public pages of the website you give us.
We do not sell personal information, "share" it for cross-context behavioral advertising, or use it for advertising.
5. How the AI uses data
- Atlas and the agents are powered by Anthropic's Claude models. Some voice features and backup answers use OpenAI. Spoken replies may use ElevenLabs.
- For each request, 22 sends the AI only what that job needs: the question, the relevant rules and memory, and what the tool returned.
- Our AI providers do not train their models on the data we send them. Anthropic's and OpenAI's business terms exclude training on API data, and we don't opt in. ElevenLabs trains on data by default below its Enterprise plan; we switch its "Improve the models for everyone" setting off for 22's account. [Confirm before publishing: the ElevenLabs setting is off.]
- How long they keep it. Anthropic deletes API inputs and outputs within 30 days by default (longer, up to 2 years, only for content flagged under its Usage Policy). OpenAI may keep API data up to 30 days for abuse monitoring. See subprocessors.
- 22 does not train any AI model on your data. Your company memory is used only for your company. It is never shared with other businesses.
- Human approval. Agents act only within the approvals the owner sets. Spending money, sending email, posting publicly, creating discounts and changing connected apps need the owner's approval, unless the owner has deliberately switched a specific task to automatic (for example, automatic email replies, or social replies after a training period and an unlock step). Meta Ads access is read only.
- Automated decisions. 22 does not make decisions about individuals that have legal or similarly significant effects on them (such as credit, hiring or housing). Automatic replies to messages are drafted by AI for the business and the business is responsible for them.
- AI can be wrong. Owners should check important outputs.
6. Who we share data with
- Our subprocessors, only to run 22: Cloudflare (hosting and database), Anthropic (AI), OpenAI (voice and backup AI), ElevenLabs (voice), Composio (connections to other apps), Zoho (our support mailbox), and, if enabled, Resend (email). The current list, with what each touches and where, is at subprocessors. Each is bound by a data processing agreement.
- The apps you connect. When an agent acts in a connected app (for example sends an approved reply), the data goes to that app under the owner's own account with it.
- The law. When a valid legal order requires it. We will tell the business first unless the law forbids it.
- A buyer of our business, if 22 is sold or merged, under the same protections. We will tell you first.
We never sell data to data brokers, and we never share one business's data with another business.
7. Where data is stored and international transfers
DSBC Group, LLC is a US company, operated from Israel. 22 runs on Cloudflare's global network. Our database is hosted by Cloudflare in its Eastern Europe location (not locked to the EU by contract). Our AI and voice providers process data mainly in the United States.
When personal data from the EU, EEA, UK or Switzerland is transferred to a country without an adequacy decision, we use the EU Standard Contractual Clauses (Commission Decision 2021/914), the UK International Data Transfer Addendum, and the Swiss amendments, with each provider, or the provider's certification under the EU-US Data Privacy Framework where it has one. DSBC Group, LLC itself is not certified under the Data Privacy Framework; for customer data it signs the SCCs through our Data Processing Agreement. You can ask privacy@22floor.com for a copy of these safeguards. Israel has an EU adequacy decision. Transfers out of Israel follow the Israeli Transfer of Data to Databases Abroad Regulations, 2001.
8. How long we keep data
| Data | How long |
|---|---|
| Account | Until you delete it. Deletion is immediate. |
| Company data (setup, memory, knowledge, rules, drafts, logs of automatic replies) | Until the owner deletes it or the company. Deletion is immediate. |
| Conversations on our server (in progress) | The owner's retention setting; default 12 months. |
| Connection keys and tokens | Until the owner disconnects the app or deletes the company. |
| Short-term copies of connected-tool data (caches) | Minutes to 24 hours. |
| Usage counts | 8 days. |
| Sessions | 30 days, extended while you use 22. |
| Password-reset links | 30 minutes. |
| Security and admin logs | 24 months, then deleted (automatic deletion in progress). |
| Demo sessions | 30 days, deleted automatically. |
| Demo leads | 24 months after our last contact, or sooner if you ask (automatic deletion in progress). |
| Database restore points (Cloudflare Time Travel) | Up to 30 days, then gone. Deleted data leaves these points on the same schedule. |
9. Your rights
You can ask us to:
- access the personal data we hold about you and get a copy;
- correct it;
- delete it;
- export it in a common machine-readable format (in-app export in progress; until then we do it on request);
- object to or restrict our use of it;
- withdraw consent where we relied on it.
Owners can delete a company or their whole account themselves in Settings > Privacy and data. The company's data is removed from our live database at once, including the connections held at Composio. Usage counts expire within 8 days, the admin log keeps its record of admin actions, and database restore points expire within 30 days.
How to ask: email privacy@22floor.com. We will verify your identity and answer within 30 days (sooner where a law sets a shorter time). If your data is in a business's account, we will send the request to that business and help it answer.
Extra rights by place:
- EU, EEA and UK: you can complain to your local data protection authority.
- Israel: you have the rights in the Privacy Protection Law, 1981 (as amended by Amendment 13), including the right to review your data and ask to correct or delete it. This policy is also our notice under section 11 of that law: it says why we collect data, who receives it, and whether you must give it (section 4). You can complain to the Privacy Protection Authority.
- California and other US states with privacy laws: you have the right to know, delete, correct, and opt out of sale or sharing (we don't sell or share), and to limit use of sensitive personal information (we use it only to provide the service). We will not treat you differently for using your rights. You can use an authorized agent.
California notice at collection. In the last 12 months, for our own users and demo visitors, we collected:
| Category (CCPA) | Examples | Why | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email, IP address | Account, security, demo follow-up | Cloudflare (hosting), Zoho (support mail) |
| Commercial information | Plan and billing (once plans exist) | Billing | Payment processor (not chosen yet) |
| Internet activity | Sign-in records, usage counts | Security, fair-use limits | Cloudflare |
| Audio | Voice sent to be transcribed (not stored by 22) | Voice features | OpenAI |
| Professional information | Business name, role, website | Providing 22 | Cloudflare, AI providers |
| Sensitive personal information | Email and password (account log-in) | Sign-in only | Cloudflare |
Retention for each category is in section 8. We do not sell or share any of it. Data inside a customer's account is handled for that customer as its service provider (section 2).
10. Security
We protect data with: encryption in transit (HTTPS) everywhere; encryption at rest in our database; connection keys sealed with AES-GCM before storage; passwords stored as salted PBKDF2 hashes; per-company access checks on every request; limits on sign-in attempts; an owner-only admin panel that logs every change; and human approval for risky actions. Some protections are still being built: two-step sign-in, a per-company activity log, per-company encryption keys, a sensitive-data guard, stronger security headers and a public Security page. Our security procedure marks what is in place and what is in progress.
No system is perfectly secure. If a breach affects your data, we will tell you and, where required, the authorities, as the law requires.
11. Children
22 is a tool for businesses. You must be 18 or older to create an account. We do not knowingly collect personal information directly from children. A business may process information about children through 22 (for example, a support ticket from a parent); that business is responsible for it as controller, and we process it only on its instructions.
12. Data from Google, Meta, Shopify and Amazon
- Google: 22's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features the owner sees and uses; we do not use it for ads, sell it, or use it to train AI models; people at 22 read it only with the owner's permission, for security, or when the law requires.
- Meta (Facebook, Instagram): we use Meta platform data only to provide 22's features to the business that connected it, and never sell or license it. When the business disconnects, our access stops at once. Stored copies (cached posts and comments, drafted replies) are deleted when the business deletes its company or asks us to. In progress: deleting them automatically on disconnect. To ask for deletion, email privacy@22floor.com.
- Shopify: we ask the owner to grant only the store data 22's features need, use it only for that store's owner, and delete the store's keys at once when the store is disconnected. Drafts that quoted an order stay until the owner deletes them or the company.
- Amazon (when the connection launches): we will use Amazon data only for the seller who connected it, follow Amazon's Data Protection Policy and Acceptable Use Policy, encrypt it, and delete buyer personal information within 30 days after order delivery unless the law requires longer.
13. Changes
We will post changes here and change the date at the top. For material changes we will email account holders at least 30 days before they take effect, unless the law requires a faster change.
14. Contact
DSBC Group, LLC (operator of 22), a Delaware limited liability company, 1111b South Governors Avenue, STE 34401, Dover, DE 19904, USA privacy@22floor.com · support@22floor.com Privacy contact: Tal Sagie. We have not appointed a Data Protection Officer; neither Israeli law nor the GDPR requires one for 22 today.
Sources
- Israel Privacy Protection Law, 5741-1981, Amendment 13 (in force 14 Aug 2025): IAPP, Pearl Cohen; PPA DPO guidance: Arnon, Tadmor-Levy; DPO and notice duties: Baker McKenzie
- Privacy Protection (Data Security) Regulations, 5777-2017: English text
- EU GDPR (Regulation 2016/679): EUR-Lex; Standard Contractual Clauses (Decision 2021/914): EUR-Lex; UK Addendum: ICO; EU-US Data Privacy Framework
- California CCPA/CPRA: statute (eff. 1 Jan 2026), CPPA regulations
- Google API Services User Data Policy; Meta Platform Terms; Shopify API License and Terms, Shopify protected customer data; Amazon SP-API Data Protection Policy, Acceptable Use Policy; Amazon Ads API License Agreement
- GDPR Art. 13 (information to give): EUR-Lex; CCPA notice at collection: 11 CCR § 7012
- ElevenLabs data use: help center
- Anthropic retention: Privacy Center; OpenAI: Enterprise privacy; Cloudflare D1: data security, Time Travel