▲22  22nd Floor

22 Privacy Policy

Last updated: 30 September 2026.

This policy explains how 22 ("22nd Floor", "we", "us") handles personal information. 22 is an AI "CEO and team" for business owners: an AI chief executive called Atlas and a team of AI agents that read the business's connected tools, draft work, and act only within the owner's approvals.

22 is operated by DSBC Group, LLC, a Delaware limited liability company. The service runs at 22floor.com and 22-app.pages.dev.

Contact: privacy@22floor.com (privacy and data requests) or support@22floor.com (everything else).


1. Who this policy covers

This policy does not cover the business's own privacy practices. Each business that uses 22 has its own privacy policy for its own customers.

2. Our role: controller or processor

Privacy laws give different duties to the party that decides why data is used (the controller; in Israeli law the "database owner/controller") and the party that handles data on its behalf (the processor; in Israeli law the "holder"; in California law the "service provider").

Data Our role
Your 22 account (name, email, password, sign-in records), billing, support mail you send us, demo visitors, our own security logs Controller. This policy applies directly.
Everything a business puts into 22 or connects to it: its company memory, documents, conversations, mail, tickets, orders, ads, social comments, and the personal data of its end customers Processor / holder / service provider. We act only on the business's instructions under our Data Processing Agreement. The business is the controller.

If you are an end customer of a business that uses 22, please contact that business first. It decides what happens to your data. If you contact us, we will pass your request to the business and help it respond.

3. What we collect

3.1 From users (we are controller)

3.2 From the business, as processor

What 22 holds depends on what the owner sets up and connects:

We do not ask for, and ask owners not to put into 22: government ID numbers, full payment card or bank account numbers, passwords, or health records. In progress: a sensitive-data guard that masks card, bank and ID numbers, passwords and keys before anything is stored.

3.3 From demo visitors (we are controller)

First name and website address (we read the public pages of that website), and, if you fill in the "Set it up" form, your name, email, company, website and note. What you ask the demo, by voice or text, is sent to our AI providers to answer; we keep only counts of questions, not the questions. We keep the IP address of each demo session and lead to stop abuse (daily limits).

3.4 Cookies and similar technology

4. Why we use it (and our legal bases)

Purpose Legal basis (GDPR / UK GDPR)
Create and run your account, sign you in, provide the service Contract (Art. 6(1)(b))
Keep the service secure, stop abuse, apply usage limits, keep logs Legitimate interests (Art. 6(1)(f)): protecting the service and its users
Process a business's data on its instructions The business's own legal basis. We act as processor.
Answer support and privacy requests Contract, or legal obligation (Art. 6(1)(c))
Run the demo for a visitor Legitimate interests (Art. 6(1)(f)): showing prospects what 22 does, at their request
Follow up with a demo visitor who asked us to Consent (Art. 6(1)(a))
Keep records the law requires; defend legal claims Legal obligation; legitimate interests

Where we rely on legitimate interests, you can ask us for the balancing test we did.

Do you have to give us your data? No law requires you to. An email address and password are needed to create an account (a contract requirement); without them we cannot give you 22. Everything else, including connecting tools, is your choice; features that need it will not work without it.

Where the data comes from: from you, from the tools you connect, and, for the demo, from the public pages of the website you give us.

We do not sell personal information, "share" it for cross-context behavioral advertising, or use it for advertising.

5. How the AI uses data

6. Who we share data with

We never sell data to data brokers, and we never share one business's data with another business.

7. Where data is stored and international transfers

DSBC Group, LLC is a US company, operated from Israel. 22 runs on Cloudflare's global network. Our database is hosted by Cloudflare in its Eastern Europe location (not locked to the EU by contract). Our AI and voice providers process data mainly in the United States.

When personal data from the EU, EEA, UK or Switzerland is transferred to a country without an adequacy decision, we use the EU Standard Contractual Clauses (Commission Decision 2021/914), the UK International Data Transfer Addendum, and the Swiss amendments, with each provider, or the provider's certification under the EU-US Data Privacy Framework where it has one. DSBC Group, LLC itself is not certified under the Data Privacy Framework; for customer data it signs the SCCs through our Data Processing Agreement. You can ask privacy@22floor.com for a copy of these safeguards. Israel has an EU adequacy decision. Transfers out of Israel follow the Israeli Transfer of Data to Databases Abroad Regulations, 2001.

8. How long we keep data

Data How long
Account Until you delete it. Deletion is immediate.
Company data (setup, memory, knowledge, rules, drafts, logs of automatic replies) Until the owner deletes it or the company. Deletion is immediate.
Conversations on our server (in progress) The owner's retention setting; default 12 months.
Connection keys and tokens Until the owner disconnects the app or deletes the company.
Short-term copies of connected-tool data (caches) Minutes to 24 hours.
Usage counts 8 days.
Sessions 30 days, extended while you use 22.
Password-reset links 30 minutes.
Security and admin logs 24 months, then deleted (automatic deletion in progress).
Demo sessions 30 days, deleted automatically.
Demo leads 24 months after our last contact, or sooner if you ask (automatic deletion in progress).
Database restore points (Cloudflare Time Travel) Up to 30 days, then gone. Deleted data leaves these points on the same schedule.

9. Your rights

You can ask us to:

Owners can delete a company or their whole account themselves in Settings > Privacy and data. The company's data is removed from our live database at once, including the connections held at Composio. Usage counts expire within 8 days, the admin log keeps its record of admin actions, and database restore points expire within 30 days.

How to ask: email privacy@22floor.com. We will verify your identity and answer within 30 days (sooner where a law sets a shorter time). If your data is in a business's account, we will send the request to that business and help it answer.

Extra rights by place:

California notice at collection. In the last 12 months, for our own users and demo visitors, we collected:

Category (CCPA) Examples Why Disclosed to
Identifiers Name, email, IP address Account, security, demo follow-up Cloudflare (hosting), Zoho (support mail)
Commercial information Plan and billing (once plans exist) Billing Payment processor (not chosen yet)
Internet activity Sign-in records, usage counts Security, fair-use limits Cloudflare
Audio Voice sent to be transcribed (not stored by 22) Voice features OpenAI
Professional information Business name, role, website Providing 22 Cloudflare, AI providers
Sensitive personal information Email and password (account log-in) Sign-in only Cloudflare

Retention for each category is in section 8. We do not sell or share any of it. Data inside a customer's account is handled for that customer as its service provider (section 2).

10. Security

We protect data with: encryption in transit (HTTPS) everywhere; encryption at rest in our database; connection keys sealed with AES-GCM before storage; passwords stored as salted PBKDF2 hashes; per-company access checks on every request; limits on sign-in attempts; an owner-only admin panel that logs every change; and human approval for risky actions. Some protections are still being built: two-step sign-in, a per-company activity log, per-company encryption keys, a sensitive-data guard, stronger security headers and a public Security page. Our security procedure marks what is in place and what is in progress.

No system is perfectly secure. If a breach affects your data, we will tell you and, where required, the authorities, as the law requires.

11. Children

22 is a tool for businesses. You must be 18 or older to create an account. We do not knowingly collect personal information directly from children. A business may process information about children through 22 (for example, a support ticket from a parent); that business is responsible for it as controller, and we process it only on its instructions.

12. Data from Google, Meta, Shopify and Amazon

13. Changes

We will post changes here and change the date at the top. For material changes we will email account holders at least 30 days before they take effect, unless the law requires a faster change.

14. Contact

DSBC Group, LLC (operator of 22), a Delaware limited liability company, 1111b South Governors Avenue, STE 34401, Dover, DE 19904, USA privacy@22floor.com · support@22floor.com Privacy contact: Tal Sagie. We have not appointed a Data Protection Officer; neither Israeli law nor the GDPR requires one for 22 today.


Sources