Manessa AI Privacy Policy
Last updated: June 17, 2026
1. Introduction
Manessa AI is committed to protecting your privacy and handling your data with transparency and care. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our AI-powered conversational companion application.
1.1. Data Controller
The data controller responsible for your personal information is Michal Waszczuk, operating as Manessa AI. Our contact details are:
Michal Waszczuk Manessa AI
Skrytka Pocztowa 800, Wrocław 68
Wrocław, Dolnośląskie 50-950
Poland
Email: support@manessaai.com
2. Information We Collect
2.1 Information You Provide
- Name (stored on our servers for account management)
- Email address (stored on our servers for authentication)
- Personal information you choose to share with our AI companions in conversation (stored locally on your device as conversation history and not on our servers)
- Voice data (for speech-to-text functionality, processed in real time; we do not store voice content on our servers, although providers may retain limited operational logs or metadata)
- Any custom information provided for AI personalization through your profile (stored locally on your device only, never on our servers)
- Companion memory — a snapshot of what your companion has learned about you over time — is by default stored locally on your device. If you opt in to Private Memory Sync as described in Section 4.7, this snapshot is end-to-end encrypted on your device and uploaded to our servers in encrypted form we cannot read.
Relevant providers for user-submitted data may include Supabase, Google's Gemini Developer API and/or Google Cloud Vertex AI, Nebius AI Studio, Deepgram, AssemblyAI, Inworld AI, Stripe, Daily.co, and Modal Labs, depending on the feature used.
2.2 Automatically Collected Information
- IP address
- Browser type and version
- Operating system
- Date and time of access
- Pages visited
- Device information
Relevant providers for automatically collected technical or operational data may include Vercel, Supabase, Sentry, Upstash, Daily.co, Modal Labs, Stripe, and, where needed to provide a feature, our AI and voice providers.
2.3 Conversation Data
Raw conversation history (the messages you exchange with your AI companions) is stored locally in your browser. We do not collect or store conversation content on our servers. Inputs are processed by our AI providers in real time to generate responses. If you opt in to Private Memory Sync (Section 4.7), only an end-to-end encrypted snapshot of your companion's memory — not your raw conversation history — is stored on our servers.
2.4 AI Personalization Information
Any information you provide through your profile to personalize your AI companions (such as your interests, preferences, background, or other details you want the AI to remember) is stored exclusively on your device in your browser's local storage. This information is not stored on our servers and is not included in Private Memory Sync. It may be transmitted transiently through our servers during active conversations and is then forwarded to AI providers to enable personalized responses. We configure or contractually require our providers not to use this data for model training. Separately, your companion may build up its own memory about you over time (for example, things it noted from your conversations) — this companion memory is stored locally by default and is the data that may be synced if you opt in to Private Memory Sync (Section 4.7). For provider-specific retention exceptions, including Google-specific abuse monitoring and Google Search grounding, see Section 6.1.
2.5 Data Sources
- OAuth providers (e.g., Google) for your email and basic profile during authentication.
- Stripe for subscription and payment status updates via secure webhooks.
- Google Play Billing (for app users who subscribe through the Google Play Store) for purchase verification and subscription status updates, via the Google Play Developer API and secure server notifications.
2.6 Whether You Need to Provide Data
- Account creation: email is required to register and authenticate.
- Payments: billing details are required for premium subscriptions.
- Voice features: microphone access is optional but required to use voice functionality; you can revoke permission at any time in your device/browser settings.
3. How We Use Your Information
We use your personal information to:
- Provide, operate, and maintain our Services.
- Process your transactions and manage your subscription.
- Authenticate your account and enable voice interactions.
- Communicate with you, including responding to your inquiries and providing customer support.
- Send you technical notices, updates, and security alerts.
- Ensure the security of our Services and prevent fraud.
4. Data Storage and Security
4.1 Server-Side Storage
- User profile data (name and email address) is securely stored and managed by Supabase.
- AI personalization information you enter in your profile is not stored on our servers — it remains exclusively on your device.
- If you opt in to Private Memory Sync (Section 4.7), an end-to-end encrypted snapshot of your companion's memory is stored on our servers; we cannot read or decrypt the snapshot.
- We do not store conversation histories or conversation content on our servers. We do keep limited account-linked operational analytics and usage records as described in Section 16, but these do not include conversation content.
4.2 Local Storage
- Conversation data is stored locally in your browser.
- AI personalization information you enter in your profile (details about yourself that you want AI companions to remember) is stored locally in your browser's local storage and never leaves your device except transiently during active conversations to generate responses.
- Companion memory (the snapshot of what your companion has learned about you over time) is stored locally by default. If you opt in to Private Memory Sync (Section 4.7), it is encrypted on your device and uploaded in encrypted form we cannot read.
- User preferences and settings are handled locally on your device.
4.3 Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption of data in transit and at rest
- Regular security audits and updates
- Strict access controls for any server-side data
- Use of reputable, security-compliant service providers
4.4 Data Control
- You have full control over your locally stored data. You can clear your browser data at any time to remove conversation histories and local settings.
- For server-side profile data, you can request modification or deletion through your account settings or by contacting us.
4.5 Server-Side Caching and Operational Data
To ensure our service is fast, reliable, and secure, we use temporary server-side caching for performance optimization, rate limiting, and payment processing reliability. This operational data is stored for short periods and does not include your conversation content.
4.6 Retention Periods
- Profile and authentication data: retained while your account is active and deleted upon account deletion.
- Billing/subscription records: retained as required by law (e.g., up to 10 years for tax/accounting).
- Operational cache data: up to 24 hours (automatic expiry).
- Usage/quota account state (for enforcing limits): retained while needed for the current service period and deleted upon account deletion.
- Operational cost analytics: may be retained after account deletion only after direct account identifiers are removed, so we can understand provider and infrastructure costs without identifying you.
- Failed payment event records: deleted after reprocessing or within 30 days, whichever comes first.
- Immediate-performance consent records: retained for the applicable limitation period for consumer claims and chargebacks (e.g., up to 6 years), then deleted.
- Consent audit records: pseudonymous identifiers for sensitive-data consents and payment references retained for up to 6 years solely for legal compliance and defense of claims; direct account links are removed on account deletion.
- Private Memory Sync encrypted snapshot: retained while sync is enabled on your account; deleted when you turn off sync, delete the synced memory in-app, or delete your account.
4.7 Private Memory Sync (Optional)
Private Memory Sync is an opt-in feature that lets your companion's memory follow you across your devices while keeping it private from us.
- What is synced: only your companion's memory (a snapshot of what your companion has learned about you). Raw conversation history is never synced.
- End-to-end encryption: the snapshot is encrypted on your device using a Memory Password that only you know. We never receive the password and cannot decrypt the snapshot. We store only the encrypted snapshot and the technical information needed to let you decrypt it on your other devices.
- Where it is stored: the encrypted snapshot is stored in our Supabase database and is only accessible to your account.
- Legal basis: Consent (Art. 6(1)(a) GDPR). You enable Memory Sync explicitly in the app and can disable it at any time.
- Retention: the encrypted snapshot is retained while Memory Sync is enabled. It is deleted when you turn sync off, use the in-app "delete synced memory" action, or delete your account.
- No recovery: because we never see your Memory Password, we cannot recover or reset it. If you lose it, the only path forward is to create a new Memory Password and upload a fresh snapshot from a device that still has the local memory.
5. Legal Bases for Processing (EEA/UK Users)
We process your personal data on the following legal bases:
- Contractual Necessity (Art. 6(1)(b) GDPR): We process your account and payment information to fulfill our service contract with you.
- Consent (Art. 6(1)(a) GDPR): We rely on your explicit consent to access your device's microphone for voice interactions. You can revoke this consent at any time through your browser or device settings.
- Special-Category Data (Art. 9(2)(a) GDPR): We rely on your explicit consent before using sensitive personal data (e.g., health, religious beliefs, political opinions, sexual orientation, racial/ethnic origin) to generate responses. We may automatically detect potentially sensitive content in order to block processing or request consent first. You can withdraw this consent at any time.
- Legitimate Interests (Art. 6(1)(f) GDPR): We process device and usage data for security monitoring, fraud prevention, and service optimization, provided our interests do not override your fundamental rights.
6. Third-Party Services and Data Processing
We use the following third-party services:
- Vercel for hosting and analytics
- Supabase, Inc. for user authentication and database management
- AI providers for processing user inputs and generating responses:
- Google Gemini Developer API
- Google Cloud Vertex AI
- Nebius AI Studio
- Deepgram, Inc. and AssemblyAI, Inc. for speech-to-text functionality
- Inworld AI (Theai, Inc.) for text-to-speech functionality
- Stripe, Inc. for payment processing (web purchases)
- Google LLC (Google Play Billing) for in-app purchase processing and subscription management when you subscribe through the Google Play Store
- Mailjet for transactional email delivery
- Zoho for email hosting and customer support communications
- Upstash, Inc. for serverless Redis and API rate limiting
- Sentry (Functional Software, Inc.) for error tracking and performance monitoring
- Daily.co for real-time voice connectivity
- Modal Labs for hosting our voice processing infrastructure
These services receive only the data necessary to perform their specific functions. Depending on the feature used, this may include your email address, the content of an email or support message, and related delivery or communication metadata. We do not share your personal information with these services beyond what is required for their operation.
Processing by these providers is governed by data processing agreements or equivalent contractual terms. Where required for international transfers, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), and for some providers additional lawful transfer mechanisms, such as the EU-U.S. Data Privacy Framework, may also apply.
6.1 AI Processing
When you interact with our AI companions, your text inputs are sent to our AI providers for processing. We use Google's Gemini Developer API and/or Google Cloud Vertex AI, as well as Nebius AI Studio, for LLM processing, and we configure or contractually require these providers not to use your data for model training. For the Gemini Developer API, Google documents abuse-monitoring logging and states that prompts, context, and generated output may be retained for up to 55 days. For Google Cloud Vertex AI, Google documents abuse-monitoring prompt logging for some Google Cloud accounts. If Grounding with Google Search is used through Vertex AI, Google states that prompts, contextual information, and generated output may be retained for up to 30 days for grounding-related debugging and testing.
6.2 Voice Data Processing
For voice interactions:
- Speech-to-Text (Deepgram / AssemblyAI): Your voice data is streamed to Deepgram, Inc. or AssemblyAI, Inc. for real-time transcription. We configure or contractually require both providers not to use submitted data for model training. Deepgram is configured with model-improvement opt-out, and Deepgram states that data from opted-out requests is retained only for the time necessary to process the request. Deepgram may still retain operational request, usage, and billing logs or metadata. For AssemblyAI, we have opted out of model training on our account. AssemblyAI may still retain operational metadata such as request, usage, and billing logs even where audio or transcript retention is minimized.
- Text-to-Speech: Text from AI responses is sent to Inworld AI for voice synthesis. No end-user identifiers are included in TTS requests; only the response text and audio configuration are transmitted.
- Inworld AI (Theai, Inc., USA): Text from AI responses is processed for voice synthesis with zero data retention enabled. All text and generated audio are immediately discarded after processing - nothing is persistently stored. Inworld AI does not use your data for model training. International transfers are protected by SCCs as described in Section 11.
6.3 Voice Connectivity and Hosting
For voice sessions, we use Daily.co to provide the real-time audio connection and Modal Labs to run our voice infrastructure. These providers play different roles in the live voice flow.
- Daily.co: Daily carries the live audio connection and processes the call media and session/connection metadata needed to keep the voice session working, such as IP address, device/network details, and connection events. We do not enable call recording in our current setup, and we do not use Daily as a long-term store for conversation content.
- Modal Labs: Modal-hosted workers process the information needed to establish and operate the live session and to pass necessary inputs to our AI and voice providers.
- Conversation context on Modal: To provide a coherent live conversation, the Modal-hosted worker may also process recent conversation context, memory snippets, selected bot/language/settings, limited identifiers needed to authenticate the session, and user-provided personalization or profile/context fields that we send at session start. This processing is limited to providing the voice session and related AI responses.
- Retention: Connection and infrastructure data is kept only as long as needed for service operation, security, troubleshooting, and cost control.
6.4 European Data Processing
Where supported and practical for the relevant service, we prefer EEA processing; otherwise transfers rely on the safeguards described in Section 11:
For Google-based AI processing, the location and transfer posture depend on the service path used. Where requests use Google Cloud Vertex AI, processing occurs in the locations supported by the selected model and endpoint. Where requests use the Gemini Developer API, processing occurs under Google's service infrastructure for that API. Where processing occurs outside the EEA, transfers rely on the safeguards described in Section 11.
- Speech-to-text: where supported and practical, we choose EEA or EU processing options. Processing location may still vary by provider, endpoint, language support, and service configuration. For both providers, operational logs or metadata may still be retained.
- Text-to-speech: Inworld AI (Theai, Inc., USA); international transfers are protected by SCCs as described in Section 11.
- For Nebius and other relevant providers, we select EU regions where available; if processing occurs outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
6.5 Rate Limiting (Upstash)
We use Upstash Redis and its rate limiting service to prevent abuse and ensure service stability.
- Data processed: a pseudonymous identifier (your user ID) and ephemeral counters; for non-user cron endpoints we may use the request IP as an identifier.
- Legal basis: Legitimate interests (Art. 6(1)(f)) in securing and operating the service.
- Retention: keys expire automatically after the configured rate window (typically 60 seconds or less).
- Transfers: EU regions are used where available; otherwise transfers rely on SCCs.
6.6 Subprocessor Changes
The provider list in this section is a general description of the third-party services we use. Where a provider offers its own subprocessor list or notice mechanism, that provider's materials govern those subprocessor updates. If a change meaningfully affects how we process your personal data, we will provide additional notice where required by law.
7. Payment Processing
The payment processor depends on how you access our Services. Web purchases are processed by Stripe, Inc. In-app purchases and subscriptions made through the Google Play Store are processed by Google Play Billing (Google LLC). In both cases, your payment card details are collected and processed by the payment provider, not by us — we do not store your full credit card details on our servers.
7.1 Information Collected by Stripe
When you make a payment, Stripe may collect the following information:
- Name
- Email address
- Billing address
- Payment card information
- Transaction amount
- Date of transaction
7.2 How Stripe Uses Your Information
Stripe uses the information collected to:
- Process payments
- Prevent, detect, and investigate fraud or other prohibited activities
- Comply with legal obligations
7.3 Our Billing Data Processing
To manage your subscription and billing, we also collect and process:
- Stripe customer ID (to link your account with Stripe)
- Subscription status and billing cycle information
- Payment failure tracking for grace period management
- Usage data linked to billing cycles for premium features
This data is used solely for subscription management, billing operations, and ensuring proper access to premium features.
7.4 Stripe's Data Practices
Stripe adheres to the Payment Card Industry Data Security Standards (PCI-DSS). For more information on Stripe's privacy practices, please refer to Stripe's Privacy Policy.
7.5 Webhook Reliability and Dead Letter Queue
To ensure reliable billing, failed Stripe webhook payloads may be stored temporarily in a secure dead letter queue for reprocessing. These records contain Stripe event metadata and are deleted after successful processing or within 30 days, whichever comes first.
7.6 Google Play Billing (App Users)
If you subscribe through the Google Play Store, your payment is processed by Google Play Billing. Google collects and processes your payment information (such as your payment method, billing details, and transaction data) under Google's own privacy policy; we do not receive or store your payment card details.
To verify your purchase and manage your subscription and entitlement, we collect and store the following on our servers:
- Google Play purchase token and any linked purchase token (to verify the purchase and identify the subscription)
- Product ID and package name
- Subscription status, billing period start/end, billing cycle anchor, acknowledgement state, and renewal/cancellation state
- Subscription lifecycle events received from Google via real-time developer notifications (e.g., renewals, cancellations, expirations, revocations, and refunds/voided purchases)
- A copy of the raw subscription data and notification payloads returned by Google's billing systems, which we retain for verification, troubleshooting, and audit purposes
We use this data solely to verify your purchase, grant and manage access to premium features, and keep your subscription status accurate. Verification is performed by calling the Google Play Developer API using a server-side service account, and renewals, cancellations, and refunds are received through Google's real-time developer notifications (delivered via an authenticated Google Pub/Sub push). This data is processed by Supabase (our database) as described in Section 4, and we do not store your payment card details. Google's processing of your payment information is governed by the Google Privacy Policy.
Managing and canceling: You can manage or cancel your subscription at any time through your Google Play account settings. When you delete your account, we also attempt to cancel auto-renewal of an active Google Play subscription on your behalf; because this is not guaranteed, you should confirm cancellation in your Google Play account settings to ensure you are not charged again.
Retention on account deletion: When you delete your account, the Google Play subscription and notification records we hold for you are deleted from our systems. Google, as the seller of in-app purchases, retains its own transaction records under its policies.
8. Cookies and Local Storage
We use only essential cookies necessary for core functionality and Supabase authentication. No advertising or tracking cookies are used.
- Supabase auth cookies (e.g., sb-*-auth-token): maintain your session and refresh tokens; access tokens are short-lived and refresh tokens persist longer to keep you signed in. These are required for login and security.
- NEXT_LOCALE: stores your language preference (e.g., 'en' or 'pl') to display the interface in your chosen language. This cookie expires after 1 year and is essential for providing the service in your preferred language.
Your browser's local storage is used for your conversation data, AI personalization information, companion memory, and preferences on your device. By default, this data leaves your device only during active conversations, when it is sent to AI providers to generate personalized responses. If you opt in to Private Memory Sync (Section 4.7), an end-to-end encrypted snapshot of your companion's memory — not your conversation history or your profile personalization information — is also uploaded to our servers; we cannot read or decrypt it.
9. Your Rights and Choices
Under GDPR and other applicable data protection laws, you have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Erase your personal data
- Restrict processing of your personal data
- Data portability
- Object to processing of your personal data
- Withdraw consent at any time
Where processing is based on our legitimate interests, you have the right to object to such processing at any time on grounds relating to your particular situation.
You can exercise some of these rights directly through your account profile page, including updating profile details, managing certain consents, and deleting your account. For other requests, email us at support@manessaai.com. We may need to verify your identity before fulfilling a request.
We aim to respond within one month of receiving your request. If your request is complex or numerous, we may extend this period by up to two additional months, and we will inform you of any extension.
For data portability, we provide server-side personal data that we control (e.g., account/profile and subscription metadata) in a commonly used, machine-readable format (e.g., JSON). Conversation data, AI personalization information, and companion memory are by default stored locally on your device; you control, export, or delete them via your browser/device data tools. If you have enabled Private Memory Sync (Section 4.7), the encrypted companion-memory snapshot we store on your behalf can be exported in encrypted form on request, but we cannot decrypt it for you.
Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
10. Data Retention
We retain your personal data only for as long as necessary to provide you with our services and as described in this Privacy Policy. We will retain and use your data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
11. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that are different from the laws of your country. When we transfer your data outside the European Economic Area (EEA), we do so in compliance with GDPR. We rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) where applicable and, for Google Cloud, Google's published alternative transfer solution commitments, including Google LLC's certification to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework where applicable. We have entered into or accepted Data Processing Agreements or equivalent data-processing terms with our processors where offered.
12. Age Restriction
Our service is intended for use only by individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you are under 18, please do not use our service or provide any personal information to us. If we become aware that we have collected personal information from a person under 18, we will take steps to delete that information as soon as possible.
13. Special Categories of Data
We do not seek to collect special category data (e.g., health, political opinions, religious beliefs, sexual orientation, racial/ethnic origin). Please avoid sharing such information. If you do, we may automatically detect that the content is potentially sensitive in order to block processing or request your consent before generating a response. If you consent, the content may be transmitted transiently to Google's Gemini Developer API and/or Google Cloud Vertex AI or to Nebius AI Studio for LLM processing, to Deepgram or AssemblyAI for speech-to-text, and to Inworld AI for text-to-speech. We configure or contractually require these providers not to use your data for model training. For the Gemini Developer API, Google documents abuse-monitoring logging and states that prompts, context, and generated output may be retained for up to 55 days. For Google Cloud Vertex AI, Google documents abuse-monitoring prompt logging for some Google Cloud accounts. If Grounding with Google Search is used through Vertex AI, Google states that prompts, contextual information, and generated output may be retained for up to 30 days. Deepgram is configured with model-improvement opt-out, and Deepgram states data from opted-out requests is retained only for the time necessary to process the request, although operational request and usage metadata may still be retained. For AssemblyAI, we have opted out of model training, but operational metadata may still be retained even where audio or transcript retention is minimized. Inworld AI is configured with zero data retention. We do not store this content on our servers. We may retain a pseudonymous consent identifier for audit purposes as described in Section 14; this does not contain conversation content or allow us to identify you after account deletion.
14. Sensitive Information Processing Consent
We may automatically detect messages that could include sensitive categories (e.g., health, religion, politics, sexual orientation, racial/ethnic origin) in order to block processing or request your explicit consent. If you do not consent, the request is blocked and the content is not sent onward to AI providers to generate a response.
If you do consent:
- Your message is used to generate a response.
- Conversation content is not stored on our servers.
- Third-party processing: Your message may be temporarily processed by Google's Gemini Developer API and/or Google Cloud Vertex AI or by Nebius AI Studio for LLM responses, by Deepgram or AssemblyAI for speech-to-text where voice is used, and by Inworld AI for voice synthesis. We configure or contractually require these providers not to use your data for model training. For the Gemini Developer API, Google documents abuse-monitoring logging and states that prompts, context, and generated output may be retained for up to 55 days. For Google Cloud Vertex AI, Google documents abuse-monitoring prompt logging for some Google Cloud accounts. If Grounding with Google Search is used through Vertex AI, Google states that prompts, contextual information, and generated output may be retained for up to 30 days. Deepgram is configured with model-improvement opt-out, and Deepgram states data from opted-out requests is retained only for the time necessary to process the request, although operational request and usage metadata may still be retained. Inworld AI operates with zero data retention.
- For speech-to-text, we use Deepgram with model-improvement opt-out and we have opted out of model training with AssemblyAI. Operational logs or metadata may still be retained by those providers.
- You can withdraw consent at any time in your profile settings.
For audit purposes, we store a pseudonymous consent identifier (HMAC of your normalized email) that cannot identify you after account deletion; retention is up to 6 years.
15. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you. Automated quota checks may restrict usage when limits are reached.
16. Analytics and Logging
We use Vercel Analytics and Speed Insights to understand general product usage. These tools are cookie-less and are not used to store your conversation content.
We also keep limited account-linked service analytics, such as which AI service was used, token counts, speech length, session length, connection timing, and estimated cost. We use this information only for running the service, preventing abuse, understanding costs, and managing billing. It does not include the content of your conversations. After account deletion, retained cost and operational analytics are unlinked from your account.
- Legal basis: Legitimate interests (Art. 6(1)(f)) to operate and secure the service.
- Retention: Short-lived operational events may be cached for up to 24 hours. Usage and service records are kept only as long as needed for billing, cost control, security, and account deletion handling.
We also use Sentry for error tracking and performance monitoring. Error reports may include a pseudonymous user ID and technical context, but not conversation content.
17. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide a more prominent notice or email notification.
18. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
support@manessaai.com
19. Data Protection Authority
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes on the GDPR or other applicable data protection laws.
For users in Poland, the competent supervisory authority is:
Urzad Ochrony Danych Osobowych (UODO)
ul. Stanislawa Moniuszki 1A, 00-014 Warszawa, Poland
Website: https://uodo.gov.pl
20. Personal Data Breaches
We maintain processes to detect, investigate, and remediate personal data breaches. Where required by law, we will notify the competent supervisory authority within 72 hours of becoming aware of a breach, and will notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms.