Legal

Privacy Policy

What we collect, how we process it, where it lives, and the rights you have under GDPR. Written in plain English. For technical context, also read the security page.

Effective date: 18 May 2026 · Controller for site visitors: ElennAI ApS, VAT: DK46697146 (Denmark) · Data requests: support@elenn.ai

Plain English, not a law firm

Elennai is operated by ElennAI ApS, VAT: DK46697146, a Danish company. This Privacy Policy is written in good faith to reflect how the service actually handles personal data. For GDPR requests (access, correction, deletion, portability) or anything else privacy-related, write to support@elenn.ai.

1. Our role under GDPR

Your data, our responsibility.

When you sign up and pay us, we decide what we collect about you (name, email, billing details) and why - to run your account and bill you. That makes us the data controller for our own customer relationship.

When you upload documents to train your bot or your end users chat with it, that data belongs to you. We process it on your instructions - you're the controller, we're the processor. Pro and Scale customers get a Data Processing Agreement (DPA) on request.

2. What we collect

Three buckets: account info, uploaded content, operational logs.

Account information: your name, email, a securely hashed password, workspace name, billing address, VAT number, and Stripe customer ID. We need this to log you in, send service emails, and charge your card.

Uploaded content and chat data: documents you upload (indexed so the bot can find relevant answers), the prompts and personas you configure, conversation transcripts between your customers and your bot, and the sources behind each answer. This is yours; we just process it on your behalf.

Operational logs: timestamps, IP addresses, user agents, plan and usage counters, audit-log entries (logins, plan changes, document uploads), and error reports. We use these to keep the service running, prevent abuse, and meet our security obligations.

3. How we process it

From upload to answer.

When you upload a document, it's stored in Europe and then indexed so your bot can find the right passage for any question. Every search is filtered to your account only - your data never mixes with other customers'.

When a customer chats with your bot, we search your content using both semantic and keyword matching, build a prompt with the most relevant passages, and stream an answer from Google Cloud (Vertex AI) in europe-west4 (Eemshaven, NL). Conversations are saved so you can read them back in your dashboard. We keep them until you delete them or close the account - there is no automatic expiry - and the account owner can delete a single conversation, or delete in bulk by chatbot, channel, date range or rating, at any time. Every deletion is written to the audit log.

We never train models on your content, and we run no AI training pipeline of our own. What Google Cloud may do with what we send it is governed by its terms for this service; we will publish the applicable clause on the sub-processor page rather than paraphrase it here.

4. Sub-processors

The companies that help us deliver the service.

Railway runs the Node backend and the Postgres database in europe-west4 (Eemshaven, NL). Cloudflare R2 (EU jurisdiction, migrating to Railway object storage) holds uploaded documents with server-side encryption. Stripe (billing) handles payment methods and subscription state; we never see raw card numbers. Google Cloud generates the answers and prepares your content so the agent can find the right passage, on its Vertex AI service in europe-west4 (Eemshaven, NL). Google's data processing terms apply; the contracting entity is stated on Google's own published terms rather than guessed at here. Application errors are captured by our own first-party error tracker, self-hosted on Railway (EU) and PII-redacted at ingest - there is no third-party error sub-processor.

The current sub-processor list is published above and on the sub-processors page, and updated when it changes. Material additions are announced at least 30 days in advance to account owners; you can object before the new processor goes live. Our first-party product analytics is self-hosted on the EU infrastructure already listed here, so it is not a separate sub-processor; the cookies it sets are listed in § 7.

5. Where your data lives

EU data residency, and the honest limits of it.

The application backend and database run on Railway in the EU. Uploaded documents live in S3-compatible object storage under EU jurisdiction (Cloudflare R2), asserted by a boot-time check before we serve traffic. Backups stay in the same region with a 7-day point-in-time recovery window. The model that writes the answers runs in the same region: we call Google Cloud's europe-west4 (Eemshaven, NL) service rather than whichever of its data centres has capacity, so the request is served inside the EU rather than merely contracted to be. Preparing your content so it can be searched moved to that same region on 4 September 2026. One thing we will not overstate: material prepared before that date was handled by a Google service outside the EU region. It has always been stored in the EU, it is still correct, and we did not redo it, because redoing it would have produced the same result. The sub-processor list states where each thing runs.

Two of the companies doing this work, Google and Stripe, belong to groups headquartered in the United States, and a company in such a group can in principle be ordered by a US authority to produce data it holds anywhere in the world. No contract removes that, ours included, so we say it here rather than let you find it out elsewhere. The sub-processor list linked above sets out what we do to keep the exposure small. Scale customers can negotiate a self-hosted or dedicated deployment, which is outside the standard hosted setup.

6. Retention

How long we keep things.

Account records (email, billing) are kept while your account is active and for a reasonable period afterwards to meet our accounting and tax obligations under EU/Danish law (typically up to 5 years for billing records). Audit-log entries are retained for 365 days. Operational logs (request traces, error logs) are retained for up to 30 days unless a security investigation extends that window. Product-analytics events (opt-in only - see § 7) keep their raw row for 14 days; the identifier-free aggregates derived from them are kept for 13 months. The per-browser record described in § 7 - a one-way identifier, first and last seen, visit and conversation counts, country and any derived organisation - is kept for 13 months after that browser was last seen, and the daily per-workspace totals computed from it, which carry no identifier at all, for the same 13 months.

Customer content (documents, embeddings, chat history) is kept for as long as your account is open. We do not expire it on a timer, and there is no retention period to configure - instead you delete what you want gone, when you want it gone, from the dashboard. When you ask us to delete the account, we hold the content for 90 days so you can change your mind and export what you need; after that we strip it from production systems and it ages out of encrypted backups on the standard cycle. You can request earlier deletion at any time via support@elenn.ai - see § 8.

Anti-abuse domain log. To stop the same operator from cycling multiple Free-tier accounts by churning and re-signing-up, we keep a small permanent record of every domain that has been added to a chatbot's embed allowlist and every signup email's domain. The record contains the domain itself, its registrable root (e.g. customer.com), and a one-way SHA-256 hash of the signup email - no clear-text email address, no name. On account deletion, the row stays so the abuse check still fires, but the link back to the deleted user (user_id, account_id, email hash) is wiped within the same transaction. This processing is justified under GDPR Art. 6(1)(f) as a legitimate interest in preventing fraud against our paid plans.

7. Cookies and similar tech

A session cookie, plus opt-in first-party analytics. No third-party trackers.

We use a single first-party authentication cookie/local-storage token so you stay logged in. That is strictly necessary and always on.

On our own domains (elenn.ai, app.elenn.ai, admin.elenn.ai, status.elenn.ai) we run first-party product analytics that lives entirely on our EU infrastructure. It is off by default and only starts after you opt in via the "Analytics" category in the cookie banner. When enabled, the page posts page views, clicks and scroll depth to our own /api/events address on the same domain. It sets no cookie and writes nothing to your browser's storage, so nothing is added to the cookie policy table. On the server each event is stored with your IP address, a coarse location derived from it (city and network), and your browser user-agent for 14 days; after that only identifier-free aggregates remain, kept for 13 months. We attach no account identity to these events. Lawful basis: your consent (GDPR Art. 6(1)(a)).

We sometimes test two wordings of a page against each other on this website. When you have allowed analytics cookies, we set a first-party cookie called el_ab that holds a random identifier and lasts 90 days. Its only job is to keep you on the same version of the page from one visit to the next, and to let us see which version led to a sign-up. It carries no name, no email and nothing you typed, it is never sent to anyone else, and if you have not allowed analytics cookies it is never set at all - you simply see the page as it ships. Lawful basis: your consent (GDPR Art. 6(1)(a)).

We do not load Google Analytics, Meta Pixel, or any other third-party or cross-site tracker on the customer-facing surfaces. Application error reports are handled by our own first-party error tracker (self-hosted on Railway in the EU, PII-redacted at ingest) under our legitimate interest in keeping the service reliable - no third party receives them.

The chat widget you embed on your own website is separate: its analytics are off by default and only run when you, the operator, switch them on per bot. In that case you are the controller and decide how consent is collected from your visitors. It is also handled differently on our side: for widget traffic we store only a salted hash of the visitor's IP address and a country-level location, never the raw IP, unless you as the operator explicitly turn raw capture on. See the widget documentation for the available modes and for the browser-storage keys the widget uses.

Recognising a returning browser. Separately from the behavioural analytics above, and whether or not they are switched on, we derive a one-way identifier for each browser that uses an operator's chat, so the operator can tell a returning visitor from a new one. It is computed on our servers from the random session identifier the widget already stores on the operator's own site, mixed with a secret we hold and the operator's workspace id: it adds nothing to the visitor's browser, it cannot be read by any page script, and because the workspace id is part of it, the same browser visiting two different Elennai customers produces two unrelated identifiers. Following a person between our customers' sites is not something we are able to do. It resets when the visitor clears the site's data.

Country and organisation. From the visitor's IP address we also derive a country and, where the address belongs to an organisation's own network, that organisation's name. The lookup is made on the network range (a /24 or /48 block), never on the individual address, against an offline database and the public registry that publishes which organisation a range is registered to. It names a network, not a person and not an employer: for a visitor on a home connection, a mobile network or a cloud provider there is no organisation to find, and we record none rather than guess. No new third party is involved. Operators who would rather we did not derive the organisation can switch it off for their workspace; the country is derived either way. Lawful basis: our and the operator's legitimate interest in understanding who the service is used by and in protecting it from abuse (GDPR Art. 6(1)(f)).

The record this produces - the one-way browser identifier, when it was first and last seen, how many visits and conversations it accounts for, the country and any organisation - is kept for 13 months after the browser was last seen, and is then deleted.

8. Your GDPR rights

Access, rectification, deletion, portability - and how to use them.

If you're an EU/EEA/UK resident, you have the right to access the personal data we hold about you, ask us to correct anything that's wrong, ask us to delete it, restrict or object to certain processing, withdraw consent where consent was the legal basis, and receive your data in a portable format. You also have the right to lodge a complaint with your national data protection authority - for Denmark that's Datatilsynet.

To exercise any of these rights, email support@elenn.ai from the address on your account (or your end-user contact email if you're chatting with one of our customers' bots - we'll route the request to the right controller). We respond within 30 days and don't charge a fee unless the request is excessive or repetitive, as permitted by GDPR.

9. How we keep it safe

Encryption, isolation, and a public security page.

Passwords and integration credentials are encrypted at rest with industry-standard methods. All traffic is HTTPS-only in production. Every database query is filtered by account, so your data never appears in someone else's results. Incoming webhooks are cryptographically verified before we touch the database.

For more, see the security page - it covers data residency, encryption, RAG-specific protections, and incident response in detail. If you discover a security issue, write to support@elenn.ai. We'll acknowledge within 24 hours.

10. Children

Not intended for under-16s.

The Elennai platform is a B2B SaaS product not directed at children under 16, and we don't knowingly collect personal data from children. If you're a customer deploying a bot that may interact with under-16s, you are the controller for that processing and must obtain parental consent where required by your local law. If you believe we've inadvertently collected data from a child, write to support@elenn.ai and we'll delete it.

11. Changes to this policy

We announce material changes.

We may update this Privacy Policy to reflect new sub-processors, new features, or legal changes. Material changes are emailed to the account owner at least 30 days before they take effect and summarised at the top of this policy. Continued use of the service after the effective date constitutes acceptance. The latest version is always at this URL.

12. Contact

How to reach us.

All privacy, security and general questions: support@elenn.ai. Operated by ElennAI ApS, VAT: DK46697146 (Denmark). For postal correspondence, write to that mailbox and we'll respond with the registered address. If we are required by law to designate a Data Protection Officer or an Article 27 representative, their details will appear here.

Want a signed DPA before you upload anything?

Pro and Scale customers can request a Data Processing Agreement at any time. Write to support@elenn.ai and we'll send our standard DPA the same day.